also @ TechSpot: Intel confirms a smartwatch is in the pipeline

Computer started crashing after clicking a link on the net

Discussion in 'Virus and Malware Removal' started by Pete26, Oct 19, 2012.

Post New Reply
  1. Pete26 Newcomer, in training Posts: 30

    aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
    Run date: 2012-10-20 22:38:16
    -----------------------------
    22:38:16.824 OS Version: Windows x64 6.1.7601 Service Pack 1
    22:38:16.824 Number of processors: 2 586 0xF06
    22:38:16.824 ComputerName: PRADEEPS-PC UserName: Pradeep
    22:38:18.040 Initialize success
    22:39:43.397 AVAST engine defs: 12102001
    22:39:54.239 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-2
    22:39:54.255 Disk 0 Vendor: WDC_WD25 10.0 Size: 238475MB BusType: 8
    22:39:54.255 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IAAStorageDevice-3
    22:39:54.255 Disk 1 Vendor: WDC_WD25 10.0 Size: 238475MB BusType: 8
    22:39:54.271 Disk 0 MBR read successfully
    22:39:54.286 Disk 0 MBR scan
    22:39:54.286 Disk 0 Windows 7 default MBR code
    22:39:54.286 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 231836 MB offset 63
    22:39:54.317 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 6636 MB offset 474801075
    22:39:54.380 Disk 0 scanning C:\Windows\system32\drivers
    22:40:09.279 Service scanning
    22:40:43.561 Modules scanning
    22:40:43.561 Disk 0 trace - called modules:
    22:40:43.577 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStorV.sys hal.dll
    22:40:43.577 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8003374120]
    22:40:43.592 3 CLASSPNP.SYS[fffff88001ab643f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-2[0xfffffa8002e4f050]
    22:40:46.119 AVAST engine scan C:\Windows
    22:40:48.818 AVAST engine scan C:\Windows\system32
    22:44:23.314 AVAST engine scan C:\Windows\system32\drivers
    22:44:44.639 AVAST engine scan C:\Users\Pradeep
    22:45:07.337 Disk 0 MBR has been saved successfully to "C:\Users\Pradeep\Desktop\MBR.dat"
    22:45:07.353 The log file has been saved successfully to "C:\Users\Pradeep\Desktop\aswMBR.txt"
  2. Broni Malware Annihilator Posts: 40,051   +187

    Good :)

    Please download ComboFix from Here, Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    • Never rename Combofix unless instructed.
    • Close any open browsers.
    • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    • Double click on combofix.exe & follow the prompts.

    • NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
    • When finished, it will produce a report for you.
    • Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG and CA Internet Security (Total Defense Internet Security) users: ComboFix will not run until AVG/CA Internet Security is uninstalled as a protective measure against the anti-virus. This is because AVG/CA Internet Security "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG/CA Internet Security cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG/CA Internet Security first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion", restart computer to fix the issue.
    **Note 4: Some infections may take some significant time to be cured. As long as your computer clock is running Combofix is still working. Be patient.


    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try the following...

    Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
    Do NOT run it yet.
    Download Rkill (courtesy of BleepingComputer.com) to your desktop.
    There are 2 different versions. If one of them won't run then download and try to run the other one.
    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    rKill.exe: http://www.bleepingcomputer.com/download/rkill/dl/10/
    iExplore.exe (renamed rKill.exe): http://www.bleepingcomputer.com/download/rkill/dl/11/

    Restart computer in safe mode

    • Double-click on the Rkill desktop icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.

    When the scan is done Notepad will open with rKill.txt log.
    NOTE. rKill.txt log will also be present on your desktop.

    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    IF you had to run rKill post BOTH logs, rKill.txt and Combofix.txt.
  3. Pete26 Newcomer, in training Posts: 30

    Ran the Combofix after installing it to the desktop of the infected machine. Combofix restarted the machine.
    But started facing another issue after the restart. I could not access " "C:\ComboFix.txt" for the log.
    Getting an error message "Illegal operation atttempted on a registry key that has been marked for deletion", when click on the windows explorer or IE.
    Attached below is the log that Combofix created and displayed in notepad before restarting the machine.

    ComboFix 12-10-21.02 - Pradeep 10/21/2012 11:13:17.1.2 - x64
    Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.2046.1196 [GMT -5:00]
    Running from: c:\users\Pradeep\Desktop\ComboFix.exe
    AV: Norton 360 *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
    FW: Norton 360 *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
    SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\users\Pradeep\videos\iLividSetupV1.exe
    c:\windows\SysWow64\Packet.dll
    c:\windows\SysWow64\pthreadVC.dll
    c:\windows\SysWow64\wpcap.dll
    D:\install.exe
    .
    Infected copy of c:\windows\system32\Services.exe was found and disinfected
    Restored copy from - c:\windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    -------\Legacy_NPF
    -------\Service_npf
    -------\Service_nvsvc
    .
    .
    ((((((((((((((((((((((((( Files Created from 2012-09-21 to 2012-10-21 )))))))))))))))))))))))))))))))
    .
    .
    2012-10-21 16:22 . 2012-10-21 16:22 -------- d-----w- c:\users\Default\AppData\Local\temp
    2012-10-20 22:58 . 2012-10-20 22:58 -------- d-----w- C:\TDSSKiller_Quarantine
    2012-10-20 04:34 . 2012-10-20 04:34 -------- d-----w- C:\FRST
    2012-10-20 02:35 . 2012-10-20 02:35 -------- d-----w- c:\programdata\NVIDIA
    2012-10-20 02:22 . 2012-10-20 02:22 -------- d-----w- c:\programdata\NVIDIA Corporation
    2012-10-20 02:21 . 2012-10-20 02:25 -------- d-----w- c:\program files\NVIDIA Corporation
    2012-10-19 02:47 . 2012-10-19 02:47 -------- d-----w- c:\users\Pradeep\AppData\Roaming\SUPERAntiSpyware.com
    2012-10-19 02:47 . 2012-10-19 02:47 -------- d-----w- c:\program files\SUPERAntiSpyware
    2012-10-19 02:47 . 2012-10-19 02:47 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
    2012-10-19 02:42 . 2012-10-19 02:42 -------- d-----w- c:\programdata\Kaspersky Lab
    2012-10-18 02:37 . 2012-10-18 02:37 -------- d-----w- c:\users\Pradeep\AppData\Roaming\Malwarebytes
    2012-10-18 02:36 . 2012-10-18 02:36 -------- d-----w- c:\programdata\Malwarebytes
    2012-10-18 02:36 . 2012-10-18 03:17 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
    2012-10-18 02:36 . 2012-09-30 00:54 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
    2012-10-17 23:14 . 2012-10-17 23:14 -------- d-----w- c:\users\Pradeep\AppData\Local\ElevatedDiagnostics
    2012-10-17 02:57 . 2012-10-17 03:14 -------- d-----w- c:\users\Pradeep\AppData\Local\NPE
    2012-10-11 03:05 . 2012-10-11 03:05 -------- d-sh--w- c:\windows\SysWow64\%APPDATA%
    2012-10-10 13:07 . 2012-08-24 18:05 220160 ----a-w- c:\windows\system32\wintrust.dll
    2012-10-10 13:07 . 2012-08-24 16:57 172544 ----a-w- c:\windows\SysWow64\wintrust.dll
    2012-10-10 13:07 . 2012-09-14 19:19 2048 ----a-w- c:\windows\system32\tzres.dll
    2012-10-10 13:07 . 2012-09-14 18:28 2048 ----a-w- c:\windows\SysWow64\tzres.dll
    2012-10-10 13:07 . 2012-08-11 00:56 715776 ----a-w- c:\windows\system32\kerberos.dll
    2012-10-10 13:07 . 2012-08-10 23:56 542208 ----a-w- c:\windows\SysWow64\kerberos.dll
    2012-10-10 13:07 . 2012-06-02 05:41 1464320 ----a-w- c:\windows\system32\crypt32.dll
    2012-10-10 13:07 . 2012-06-02 05:41 184320 ----a-w- c:\windows\system32\cryptsvc.dll
    2012-10-10 13:07 . 2012-06-02 05:41 140288 ----a-w- c:\windows\system32\cryptnet.dll
    2012-10-10 13:07 . 2012-06-02 04:36 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll
    2012-10-10 13:07 . 2012-06-02 04:36 1159680 ----a-w- c:\windows\SysWow64\crypt32.dll
    2012-10-10 13:07 . 2012-06-02 04:36 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
    2012-10-09 02:39 . 2012-10-09 02:39 -------- d-----w- c:\users\Pradeep\AppData\Local\CrashDumps
    2012-10-08 13:43 . 2012-10-09 01:06 -------- d-----w- C:\w
    2012-10-08 13:43 . 2012-10-08 13:43 -------- d-----w- C:\skins
    2012-10-08 13:43 . 2012-10-08 13:43 -------- d-----w- C:\Cache
    2012-10-07 01:01 . 2012-10-07 01:01 -------- d-----w- c:\users\Pradeep\AppData\Roaming\Media Player Classic
    2012-10-06 22:26 . 2012-10-07 01:47 -------- d-----w- c:\users\Pradeep\AppData\Roaming\IDM
    2012-10-06 22:26 . 2012-10-21 16:23 -------- d-----w- c:\users\Pradeep\AppData\Roaming\DMCache
    2012-10-06 22:26 . 2012-10-06 22:26 -------- d-----w- c:\program files (x86)\Internet Download Manager
    2012-10-06 21:26 . 2012-10-06 21:26 -------- d-----w- c:\users\Pradeep\AppData\Local\Ilivid Player
    2012-10-06 21:25 . 2012-10-20 04:14 -------- dc-h--w- c:\programdata\{B49A644A-1076-4A3D-B124-DAA7862F2318}
    2012-10-06 21:24 . 2012-10-06 21:24 -------- d-----w- c:\users\Pradeep\AppData\Local\PackageAware
    2012-10-03 03:14 . 2012-10-03 03:14 -------- d-----w- c:\windows\Sun
    2012-10-02 04:19 . 2012-10-02 04:20 -------- d-----w- c:\program files (x86)\Java
    2012-10-02 04:19 . 2012-10-02 04:19 -------- d-----w- c:\program files (x86)\Common Files\Java
    2012-10-02 03:12 . 2012-10-04 03:58 -------- d-----w- c:\program files (x86)\Yahoo SiteBuilder
    2012-10-02 00:11 . 2012-10-16 01:51 -------- d-----w- c:\windows\system32\drivers\N360x64\0604000.009
    2012-09-27 15:08 . 2012-09-27 18:07 160992 ----a-w- c:\windows\system32\drivers\idmwfp.sys
    2012-09-25 18:59 . 2012-08-21 21:01 245760 ----a-w- c:\windows\system32\OxpsConverter.exe
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2012-08-22 18:12 . 2012-09-12 12:02 1913200 ----a-w- c:\windows\system32\drivers\tcpip.sys
    2012-08-22 18:12 . 2012-09-12 12:02 950128 ----a-w- c:\windows\system32\drivers\ndis.sys
    2012-08-22 18:12 . 2012-09-12 12:02 376688 ----a-w- c:\windows\system32\drivers\netio.sys
    2012-08-22 18:12 . 2012-09-12 12:02 288624 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
    2012-08-20 17:38 . 2012-10-10 13:08 44032 ----a-w- c:\windows\apppatch\acwow64.dll
    2012-08-02 17:58 . 2012-09-12 12:02 574464 ----a-w- c:\windows\system32\d3d10level9.dll
    2012-08-02 16:57 . 2012-09-12 12:02 490496 ----a-w- c:\windows\SysWow64\d3d10level9.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll" [2012-06-11 1524056]
    .
    [HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
    [HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin.1]
    [HKEY_CLASSES_ROOT\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}]
    [HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin]
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2012-04-23 39408]
    "LightScribe Control Panel"="c:\program files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" [2011-06-20 2736128]
    "IDMan"="c:\program files (x86)\Internet Download Manager\IDMan.exe" [2012-09-27 3532224]
    "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-05-21 4786048]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "ISUSPM"="c:\programdata\FLEXnet\Connect\11\isuspm.exe" [2010-05-21 324976]
    "OmniPage Preload"="c:\program files (x86)\Nuance\OmniPage18\OmniPage.exe" [2011-05-10 1466144]
    "Nuance OmniPage 18-reminder"="c:\program files (x86)\Nuance\OmniPage18\Ereg\Ereg.exe" [2010-10-27 333088]
    "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-31 59280]
    "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
    "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
    "AdobeCS6ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-03-09 1073312]
    "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-06-08 421776]
    "SunJavaUpdateSched"="c:\program files (x86)\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableUIADesktopToggle"= 0 (0x0)
    "PromptOnSecureDesktop"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
    "LoadAppInit_DLLs"=0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
    "aux"=wdmaud.drv
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
    @=""
    .
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
    R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-23 116648]
    R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
    R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-23 116648]
    R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-21 20992]
    R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
    R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [2010-11-21 88960]
    R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2010-11-21 34816]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
    R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
    R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-21 117248]
    R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-02-15 52736]
    R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-04-24 1255736]
    S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2011-11-03 56208]
    S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360x64\0604000.009\SYMDS64.SYS [2012-03-29 451192]
    S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360x64\0604000.009\SYMEFA64.SYS [2012-05-22 1129120]
    S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\Definitions\BASHDefs\20120928.001\BHDrvx64.sys [2012-08-31 1385120]
    S1 ccSet_N360;Norton 360 Settings Manager;c:\windows\system32\drivers\N360x64\0604000.009\ccSetx64.sys [2012-06-07 167072]
    S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\Definitions\IPSDefs\20121019.001\IDSvia64.sys [2012-10-10 513184]
    S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
    S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
    S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360x64\0604000.009\Ironx64.SYS [2012-03-29 190072]
    S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\N360x64\0604000.009\SYMNETS.SYS [2012-03-29 405624]
    S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
    S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-08-11 140672]
    S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
    S2 IDMWFP;IDMWFP;c:\windows\system32\DRIVERS\idmwfp.sys [2012-09-27 160992]
    S2 N360;Norton 360;c:\program files (x86)\Norton 360\Engine\6.4.0.9\ccSvcHst.exe [2012-06-16 138272]
    S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-10-12 138912]
    S3 VST64_DPV;VST64_DPV;c:\windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
    S3 VST64HWBS2;VST64HWBS2;c:\windows\system32\DRIVERS\VSTBS26.SYS [2009-06-10 411136]
    .
    .
    --- Other Services/Drivers In Memory ---
    .
    *NewlyCreated* - WS2IFSL
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
    2011-06-20 20:05 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2012-10-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-23 00:33]
    .
    2012-10-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-23 00:33]
    .
    2012-10-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2262249602-3662098830-2808129073-1000Core.job
    - c:\users\Pradeep\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-24 00:33]
    .
    2012-10-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2262249602-3662098830-2808129073-1000UA.job
    - c:\users\Pradeep\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-24 00:33]
    .
    .
    --------- X64 Entries -----------
    .
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
    @="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
    [HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
    2012-02-08 00:49 23432 ----a-w- c:\program files (x86)\Internet Download Manager\IDMShellExt64.dll
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-04-04 446392]
    .
    ------- Supplementary Scan -------
    .
    uLocal Page = c:\windows\system32\blank.htm
    uStart Page = hxxp://www.yahoo.com/?fr=fp-tyc8
    mLocal Page = c:\windows\SysWOW64\blank.htm
    uInternet Settings,ProxyOverride = *.local
    IE: Download all links with IDM - c:\program files (x86)\Internet Download Manager\IEGetAll.htm
    IE: Download with IDM - c:\program files (x86)\Internet Download Manager\IEExt.htm
    IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
    TCP: DhcpNameServer = 208.67.222.222 208.67.220.220 208.67.220.222
    .
    - - - - ORPHANS REMOVED - - - -
    .
    Wow6432Node-HKCU-Run-OpAgent - OpAgent.exe
    Wow6432Node-HKCU-Run-AdobeBridge - (no file)
    SafeBoot-66171102.sys
    .
    .
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\services\N360]
    "ImagePath"="\"c:\program files (x86)\Norton 360\Engine\6.4.0.9\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files (x86)\Norton 360\Engine\6.4.0.9\diMaster.dll\" /prefetch:1"
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
    @Denied: (2) (LocalSystem)
    "{EF99BD32-C1FB-11D2-892F-0090271D4F88}"=hex:51,66,7a,6c,4c,1d,38,12,5c,be,8a,
    eb,c9,8f,bc,54,f6,39,43,d0,22,43,0b,9c
    "{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"=hex:51,66,7a,6c,4c,1d,38,12,8d,ec,f8,
    7b,2b,25,27,06,e7,c4,bc,f0,98,15,0d,de
    "{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=hex:51,66,7a,6c,4c,1d,38,12,df,c1,0b,
    27,57,07,ba,54,e4,0e,43,d0,22,fb,89,5b
    "{0055C089-8582-441B-A0BF-17B458C2A3A8}"=hex:51,66,7a,6c,4c,1d,38,12,e7,c3,46,
    04,b0,cb,75,01,df,a9,54,f4,5d,9c,e7,bc
    "{02478D38-C3F9-4EFB-9B51-7695ECA05670}"=hex:51,66,7a,6c,4c,1d,38,12,56,8e,54,
    06,cb,8d,95,0b,e4,47,35,d5,e9,fe,12,64
    "{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
    1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
    "{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}"=hex:51,66,7a,6c,4c,1d,38,12,60,d8,39,
    64,cd,04,79,07,f5,b7,d6,9a,c1,81,e0,1c
    "{6D53EC84-6AAE-4787-AEEE-F4628F01010C}"=hex:51,66,7a,6c,4c,1d,38,12,ea,ef,40,
    69,9c,24,e9,02,d1,f8,b7,22,8a,5f,45,18
    "{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,
    72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57
    "{AA58ED58-01DD-4D91-8333-CF10577473F7}"=hex:51,66,7a,6c,4c,1d,38,12,36,ee,4b,
    ae,ef,4f,ff,08,fc,25,8c,50,52,2a,37,e3
    "{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16,
    fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17
    "{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9,
    b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b
    .
    [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
    @Denied: (2) (LocalSystem)
    "Timestamp"=hex:a9,5b,fd,8e,5f,ac,cd,01
    .
    [HKEY_USERS\S-1-5-21-2262249602-3662098830-2808129073-1000_Classes\Wow6432Node\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
    @Denied: (Full) (Everyone)
    @Allowed: (Read) (RestrictedCode)
    "scansk"=hex(0):d4,c4,9a,40,2f,be,57,ac,2c,62,db,1b,d0,d5,68,6e,f8,a9,b1,30,7d,
    df,3a,74,41,88,2a,d0,1e,3e,df,ed,d4,0b,9f,f1,ce,df,b9,ce,00,00,00,00,00,00,\
    .
    [HKEY_USERS\S-1-5-21-2262249602-3662098830-2808129073-1000_Classes\Wow6432Node\CLSID\{c37861b1-326f-4c2b-90b9-dfc3b59b50e2}]
    @Denied: (Full) (Everyone)
    @Allowed: (Read) (RestrictedCode)
    "Model"=dword:00000126
    "Therad"=dword:00000010
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{1171A62F-05D2-11D1-83FC-00A0C9089C5A}]
    @Denied: (A 2) (Everyone)
    @="FlashProp Class"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{1171A62F-05D2-11D1-83FC-00A0C9089C5A}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlDbg9c.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Shockwave Flash Object"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\ZillaTube\\Flash10u.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    @="0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    @="ShockwaveFlash.ShockwaveFlash.10"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\ZillaTube\\Flash10u.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="ShockwaveFlash.ShockwaveFlash"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Macromedia Flash Factory Object"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\ZillaTube\\Flash10u.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    @="FlashFactory.FlashFactory.1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\ZillaTube\\Flash10u.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="FlashFactory.FlashFactory"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil9c.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\LocalServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil9c.exe"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
    c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
    .
    **************************************************************************
    .
    Completion time: 2012-10-21 11:33:23 - machine was rebooted
    ComboFix-quarantined-files.txt 2012-10-21 16:33
    .
    Pre-Run: 145,174,585,344 bytes free
    Post-Run: 145,035,476,992 bytes free
    .
    - - End Of File - - CBF6BB2D8AC33698E029A5D707B71224
  4. Broni Malware Annihilator Posts: 40,051   +187

    How about reading my instructions carefully?
  5. Broni Malware Annihilator Posts: 40,051   +187

    Combofix log looks good.

    Any current issues?

    ================================

    Download OTL to your Desktop.
    Alternate download: http://www.itxassociates.com/OT-Tools/OTL.exe

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Click the Scan All Users checkbox.
    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
  6. Pete26 Newcomer, in training Posts: 30

    Could see your intstructions more clearly after getting some sleep. The "Illegal operation atttempted on a registry key that has been marked for deletion", disappeared after machine was restarted. Could not feel any issues with the machine - no uninvited pop ups, blue screen or misdirected to wrong web pages from google results, which were experienec earlier.
    Attached below are the OTL logs:

    OTL logfile created on: 10/21/2012 6:35:32 PM - Run 1
    OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Pradeep\Desktop
    64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    2.00 Gb Total Physical Memory | 1.22 Gb Available Physical Memory | 61.03% Memory free
    4.00 Gb Paging File | 2.71 Gb Available in Paging File | 67.75% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 226.40 Gb Total Space | 135.14 Gb Free Space | 59.69% Space Free | Partition Type: NTFS
    Drive D: | 232.88 Gb Total Space | 209.72 Gb Free Space | 90.06% Space Free | Partition Type: NTFS
    Drive E: | 6.48 Gb Total Space | 0.87 Gb Free Space | 13.47% Space Free | Partition Type: NTFS

    Computer Name: PRADEEPS-PC | User Name: Pradeep | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2012/10/21 18:33:10 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Pradeep\Desktop\OTL.exe
    PRC - [2012/09/27 07:37:12 | 003,532,224 | ---- | M] (Tonec Inc.) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe
    PRC - [2012/07/27 15:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    PRC - [2012/06/15 21:24:19 | 000,138,272 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton 360\Engine\6.4.0.9\ccsvchst.exe
    PRC - [2011/05/10 10:48:58 | 001,466,144 | ---- | M] (Nuance Communications, Inc.) -- C:\Program Files (x86)\Nuance\OmniPage18\omnipage.exe
    PRC - [2010/05/25 07:28:58 | 000,263,600 | ---- | M] (Tonec Inc.) -- C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
    PRC - [2010/05/21 13:40:26 | 000,324,976 | ---- | M] (Flexera Software, Inc.) -- C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
    PRC - [2008/11/09 15:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
    PRC - [2008/06/10 04:27:04 | 000,144,784 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe


    ========== Modules (No Company Name) ==========

    MOD - [2012/02/20 21:29:04 | 000,087,912 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
    MOD - [2012/02/20 21:28:42 | 001,242,472 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
    MOD - [2011/06/17 11:46:04 | 008,626,176 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll
    MOD - [2011/06/17 11:46:02 | 002,408,448 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll
    MOD - [2011/06/17 11:46:02 | 000,212,992 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll


    ========== Services (SafeList) ==========

    SRV:64bit: - [2011/08/11 18:38:04 | 000,140,672 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCore64.exe -- (!SASCORE)
    SRV:64bit: - [2009/07/13 20:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
    SRV:64bit: - [2009/07/13 20:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
    SRV - [2012/07/27 15:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
    SRV - [2012/06/15 21:24:19 | 000,138,272 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Norton 360\Engine\6.4.0.9\ccSvcHst.exe -- (N360)
    SRV - [2012/04/22 18:58:20 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
    SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
    SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
    SRV - [2009/06/10 16:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
    SRV - [2008/11/09 15:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)


    ========== Driver Services (SafeList) ==========

    DRV:64bit: - [2012/09/27 13:07:26 | 000,160,992 | ---- | M] (Tonec Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\idmwfp.sys -- (IDMWFP)
    DRV:64bit: - [2012/07/05 21:17:58 | 000,037,536 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\0604000.009\srtspx64.sys -- (SRTSPX)
    DRV:64bit: - [2012/07/05 21:17:57 | 000,737,952 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\N360x64\0604000.009\srtsp64.sys -- (SRTSP)
    DRV:64bit: - [2012/06/30 12:55:53 | 000,175,736 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS -- (SymEvent)
    DRV:64bit: - [2012/06/06 23:43:38 | 000,167,072 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\0604000.009\ccsetx64.sys -- (ccSet_N360)
    DRV:64bit: - [2012/05/21 20:37:12 | 001,129,120 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\N360x64\0604000.009\symefa64.sys -- (SymEFA)
    DRV:64bit: - [2012/03/29 01:28:38 | 000,405,624 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\0604000.009\symnets.sys -- (SymNetS)
    DRV:64bit: - [2012/03/29 01:28:25 | 000,451,192 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\N360x64\0604000.009\symds64.sys -- (SymDS)
    DRV:64bit: - [2012/03/29 01:06:25 | 000,190,072 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\0604000.009\ironx64.sys -- (SymIRON)
    DRV:64bit: - [2012/03/01 01:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
    DRV:64bit: - [2012/02/15 11:01:50 | 000,052,736 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
    DRV:64bit: - [2011/11/03 03:01:00 | 000,056,208 | ---- | M] (Rovi Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
    DRV:64bit: - [2011/07/22 11:26:56 | 000,014,928 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV)
    DRV:64bit: - [2011/07/12 16:55:18 | 000,012,368 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL)
    DRV:64bit: - [2011/03/11 01:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
    DRV:64bit: - [2011/03/11 01:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
    DRV:64bit: - [2010/11/20 22:24:43 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
    DRV:64bit: - [2010/11/20 22:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
    DRV:64bit: - [2010/11/20 22:23:48 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tsusbhub.sys -- (tsusbhub)
    DRV:64bit: - [2010/11/20 22:23:48 | 000,088,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc)
    DRV:64bit: - [2010/11/20 22:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
    DRV:64bit: - [2010/11/20 22:23:48 | 000,034,816 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
    DRV:64bit: - [2010/11/20 22:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
    DRV:64bit: - [2010/11/20 22:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
    DRV:64bit: - [2009/10/09 02:41:02 | 001,394,176 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
    DRV:64bit: - [2009/07/13 20:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
    DRV:64bit: - [2009/07/13 20:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
    DRV:64bit: - [2009/07/13 20:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
    DRV:64bit: - [2009/06/10 16:01:11 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VSTDPV6.SYS -- (VST64_DPV)
    DRV:64bit: - [2009/06/10 16:01:11 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS -- (winachsf)
    DRV:64bit: - [2009/06/10 16:01:11 | 000,411,136 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VSTBS26.SYS -- (VST64HWBS2)
    DRV:64bit: - [2009/06/10 15:35:20 | 000,278,016 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\e1e6032e.sys -- (e1express)
    DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
    DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
    DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
    DRV:64bit: - [2009/06/10 15:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
    DRV:64bit: - [2009/05/18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
    DRV:64bit: - [2007/05/14 16:06:18 | 000,027,520 | ---- | M] (Research In Motion Limited) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RimUsb_AMD64.sys -- (RimUsb)
    DRV - [2012/10/20 21:06:14 | 002,084,000 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\Definitions\VirusDefs\20121020.007\ex64.sys -- (NAVEX15)
    DRV - [2012/10/20 21:06:14 | 000,126,112 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\Definitions\VirusDefs\20121020.007\eng64.sys -- (NAVENG)
    DRV - [2012/10/11 19:07:40 | 000,138,912 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
    DRV - [2012/10/10 15:32:50 | 000,513,184 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\Definitions\IPSDefs\20121019.001\IDSviA64.sys -- (IDSVia64)
    DRV - [2012/08/31 17:09:13 | 001,385,120 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\Definitions\BASHDefs\20120928.001\BHDrvx64.sys -- (BHDrvx64)
    DRV - [2012/08/08 23:55:15 | 000,484,512 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys -- (eeCtrl)
    DRV - [2009/07/13 20:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
    IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
    IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={sea...putEncoding}&oe={outputEncoding}&sourceid=ie7
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
    IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={sea...putEncoding}&oe={outputEncoding}&sourceid=ie7


    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


    IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-21-2262249602-3662098830-2808129073-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?fr=fp-tyc8
    IE - HKU\S-1-5-21-2262249602-3662098830-2808129073-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
    IE - HKU\S-1-5-21-2262249602-3662098830-2808129073-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 34 12 01 FA E1 20 CD 01 [binary data]
    IE - HKU\S-1-5-21-2262249602-3662098830-2808129073-1000\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
    IE - HKU\S-1-5-21-2262249602-3662098830-2808129073-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
    IE - HKU\S-1-5-21-2262249602-3662098830-2808129073-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
    IE - HKU\S-1-5-21-2262249602-3662098830-2808129073-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={sea...putEncoding}&sourceid=ie7&rlz=1I7GZAG_enUS480
    IE - HKU\S-1-5-21-2262249602-3662098830-2808129073-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKU\S-1-5-21-2262249602-3662098830-2808129073-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


    ========== FireFox ==========

    FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Pradeep\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Pradeep\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\IPSFFPlgn\ [2012/10/15 22:41:11 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\coFFPlgn\ [2012/10/21 18:27:41 | 000,000,000 | ---D | M]
    FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\mozilla_cc@internetdownloadmanager.com: C:\Users\Pradeep\AppData\Roaming\IDM\idmmzcc5 [2012/10/06 17:26:43 | 000,000,000 | ---D | M]

    [2012/04/23 21:18:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Pradeep\AppData\Roaming\Mozilla\Extensions
    [2012/04/23 21:18:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Pradeep\AppData\Roaming\Mozilla\Extensions\celtx@celtx.com

    ========== Chrome ==========

    CHR - homepage: http://www.yahoo.com/?fr=fp-tyc8
    CHR - default_search_provider: Google (Enabled)
    CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:eek:riginalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
    CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
    CHR - homepage: http://www.yahoo.com/?fr=fp-tyc8
    CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
    CHR - plugin: Native Client (Enabled) = C:\Users\Pradeep\AppData\Local\Google\Chrome\Application\22.0.1229.94\ppGoogleNaClPluginChrome.dll
    CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Pradeep\AppData\Local\Google\Chrome\Application\22.0.1229.94\pdf.dll
    CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Pradeep\AppData\Local\Google\Chrome\Application\22.0.1229.94\gcswf32.dll
    CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Pradeep\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
    CHR - plugin: Norton Confidential (Enabled) = C:\Users\Pradeep\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.5.3.7_0\npcoplgn.dll
    CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
    CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
    CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
    CHR - Extension: YouTube = C:\Users\Pradeep\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
    CHR - Extension: Google Search = C:\Users\Pradeep\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
    CHR - Extension: IDM Integration = C:\Users\Pradeep\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmolcgpienlcieaajfkkdamlngancncm\6.12.21_0\
    CHR - Extension: Norton Identity Protection = C:\Users\Pradeep\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.5.6.10_0\
    CHR - Extension: Gmail = C:\Users\Pradeep\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

    O1 HOSTS File: ([2012/10/21 11:26:22 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2:64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll (Internet Download Manager, Tonec Inc.)
    O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
    O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)
    O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
    O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\6.4.0.9\coieplg.dll (Symantec Corporation)
    O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\6.4.0.9\ips\ipsbho.dll (Symantec Corporation)
    O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
    O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
    O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\6.4.0.9\coieplg.dll (Symantec Corporation)
    O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
    O3:64bit: - HKU\S-1-5-21-2262249602-3662098830-2808129073-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
    O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
    O4 - HKLM..\Run: [AdobeCS6ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated)
    O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
    O4 - HKLM..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\isuspm.exe (Flexera Software, Inc.)
    O4 - HKLM..\Run: [Nuance OmniPage 18-reminder] C:\Program Files (x86)\Nuance\OmniPage18\Ereg\Ereg.exe (Nuance Communications, Inc.)
    O4 - HKLM..\Run: [OmniPage Preload] C:\Program Files (x86)\Nuance\OmniPage18\OmniPage.exe (Nuance Communications, Inc.)
    O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
    O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
    O4 - HKU\S-1-5-21-2262249602-3662098830-2808129073-1000..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.)
    O4 - HKU\S-1-5-21-2262249602-3662098830-2808129073-1000..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
    O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-2262249602-3662098830-2808129073-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-2262249602-3662098830-2808129073-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O8:64bit: - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
    O8:64bit: - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
    O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
    O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
    O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
    O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
    O13 - gopher Prefix: missing
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab (QuickTime Plugin Control)
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files (x86)\Yahoo!\Common\Yinsthelper.dll (Installation Support)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
    O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 208.67.222.222 208.67.220.220 208.67.220.222
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1DC2EB72-102F-41F8-97AC-4E26CAF3015A}: DhcpNameServer = 208.67.222.222 208.67.220.220 208.67.220.222
    O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
    O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
    O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
    O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
    O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
    O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2006/01/15 14:41:08 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35:64bit: - HKLM\..comfile [open] -- "%1" %*
    O35:64bit: - HKLM\..exefile [open] -- "%1" %*
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
    O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
    O37 - HKLM\...com [@ = ComFile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*
    O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
    O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
    O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

    ========== Files/Folders - Created Within 30 Days ==========

    [2012/10/21 18:33:26 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Pradeep\Desktop\OTL.exe
    [2012/10/21 11:33:25 | 000,000,000 | ---D | C] -- C:\Windows\temp
    [2012/10/21 11:26:29 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
    [2012/10/21 11:10:50 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
    [2012/10/21 11:10:50 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
    [2012/10/21 11:10:50 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
    [2012/10/21 11:08:15 | 000,000,000 | ---D | C] -- C:\Qoobox
    [2012/10/21 11:07:32 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
    [2012/10/21 11:00:24 | 004,986,495 | R--- | C] (Swearware) -- C:\Users\Pradeep\Desktop\ComboFix.exe
    [2012/10/20 22:37:43 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\Pradeep\Desktop\aswMBR.exe
    [2012/10/20 22:16:19 | 000,000,000 | ---D | C] -- C:\Users\Pradeep\Desktop\RK_Quarantine
    [2012/10/20 17:58:32 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
    [2012/10/19 23:34:30 | 000,000,000 | ---D | C] -- C:\FRST
    [2012/10/19 21:35:12 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
    [2012/10/19 21:22:27 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA Corporation
    [2012/10/19 21:21:06 | 000,000,000 | ---D | C] -- C:\Program Files\NVIDIA Corporation
    [2012/10/18 21:47:34 | 000,000,000 | ---D | C] -- C:\Users\Pradeep\AppData\Roaming\SUPERAntiSpyware.com
    [2012/10/18 21:47:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
    [2012/10/18 21:47:11 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
    [2012/10/18 21:47:11 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
    [2012/10/18 21:42:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
    [2012/10/17 21:37:03 | 000,000,000 | ---D | C] -- C:\Users\Pradeep\AppData\Roaming\Malwarebytes
    [2012/10/17 21:36:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
    [2012/10/17 21:36:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
    [2012/10/17 21:36:54 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
    [2012/10/17 21:36:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
    [2012/10/17 18:14:17 | 000,000,000 | ---D | C] -- C:\Users\Pradeep\AppData\Local\ElevatedDiagnostics
    [2012/10/16 21:57:18 | 000,000,000 | ---D | C] -- C:\Users\Pradeep\AppData\Local\NPE
    [2012/10/12 17:27:22 | 002,213,464 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Pradeep\Desktop\TDSSKiller.exe
    [2012/10/10 22:05:19 | 000,000,000 | -HSD | C] -- C:\Windows\SysWow64\%APPDATA%
    [2012/10/10 21:55:16 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
    [2012/10/08 21:39:28 | 000,000,000 | ---D | C] -- C:\Users\Pradeep\AppData\Local\CrashDumps
    [2012/10/08 08:43:33 | 000,000,000 | ---D | C] -- C:\w
    [2012/10/08 08:43:33 | 000,000,000 | ---D | C] -- C:\skins
    [2012/10/08 08:43:32 | 000,000,000 | ---D | C] -- C:\Cache
    [2012/10/06 20:01:59 | 000,000,000 | ---D | C] -- C:\Users\Pradeep\AppData\Roaming\Media Player Classic
    [2012/10/06 17:26:33 | 000,000,000 | ---D | C] -- C:\Users\Pradeep\AppData\Roaming\IDM
    [2012/10/06 17:26:32 | 000,000,000 | ---D | C] -- C:\Users\Pradeep\AppData\Roaming\DMCache
    [2012/10/06 17:26:24 | 000,000,000 | ---D | C] -- C:\Users\Pradeep\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
    [2012/10/06 17:26:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
    [2012/10/06 17:26:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Internet Download Manager
    [2012/10/06 16:26:25 | 000,000,000 | ---D | C] -- C:\Users\Pradeep\AppData\Local\Ilivid Player
    [2012/10/06 16:25:35 | 000,000,000 | -H-D | C] -- C:\ProgramData\{B49A644A-1076-4A3D-B124-DAA7862F2318}
    [2012/10/06 16:25:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iLivid
    [2012/10/06 16:24:41 | 000,000,000 | ---D | C] -- C:\Users\Pradeep\AppData\Local\PackageAware
    [2012/10/02 22:14:05 | 000,000,000 | ---D | C] -- C:\Windows\Sun
    [2012/10/01 23:19:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
    [2012/10/01 23:19:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
    [2012/10/01 22:12:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Yahoo SiteBuilder
    [2012/10/01 22:04:35 | 000,000,000 | ---D | C] -- C:\Users\Pradeep\Desktop\sites
    [2012/10/01 21:26:07 | 000,000,000 | ---D | C] -- C:\Users\Pradeep\Desktop\Website Thumbnails
    [2012/09/27 10:08:37 | 000,160,992 | ---- | C] (Tonec Inc.) -- C:\Windows\SysNative\drivers\idmwfp.sys

    ========== Files - Modified Within 30 Days ==========

    [2012/10/21 18:33:25 | 000,021,872 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    [2012/10/21 18:33:25 | 000,021,872 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    [2012/10/21 18:33:10 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Pradeep\Desktop\OTL.exe
    [2012/10/21 18:26:35 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2012/10/21 18:25:47 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2012/10/21 18:25:38 | 1609,396,224 | -HS- | M] () -- C:\hiberfil.sys
    [2012/10/21 18:23:37 | 000,000,864 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2262249602-3662098830-2808129073-1000Core.job
    [2012/10/21 18:23:34 | 000,000,916 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2262249602-3662098830-2808129073-1000UA.job
    [2012/10/21 18:23:34 | 000,000,900 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2012/10/21 11:26:22 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
    [2012/10/21 11:00:57 | 004,986,495 | R--- | M] (Swearware) -- C:\Users\Pradeep\Desktop\ComboFix.exe
    [2012/10/20 22:45:07 | 000,000,512 | ---- | M] () -- C:\Users\Pradeep\Desktop\MBR.dat
    [2012/10/20 22:37:35 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\Pradeep\Desktop\aswMBR.exe
    [2012/10/20 17:25:07 | 305,745,908 | ---- | M] () -- C:\Windows\MEMORY.DMP
    [2012/10/19 22:24:00 | 000,782,922 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
    [2012/10/19 22:24:00 | 000,663,010 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
    [2012/10/19 22:24:00 | 000,121,878 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
    [2012/10/19 21:20:51 | 001,442,105 | ---- | M] () -- C:\Windows\SysNative\drivers\N360x64\0604000.009\Cat.DB
    [2012/10/18 21:47:14 | 000,001,810 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
    [2012/10/17 22:17:41 | 000,001,115 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    [2012/10/15 20:49:29 | 000,010,074 | ---- | M] () -- C:\Windows\SysNative\drivers\N360x64\0604000.009\VT20121008.022
    [2012/10/12 17:27:22 | 002,213,464 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Pradeep\Desktop\TDSSKiller.exe
    [2012/10/11 10:50:26 | 000,002,504 | ---- | M] () -- C:\Users\Pradeep\Desktop\Google Chrome.lnk
    [2012/10/09 21:57:37 | 000,330,122 | ---- | M] () -- C:\Users\Pradeep\Desktop\Lab Requisition Form - Order 229.pdf
    [2012/10/08 08:43:34 | 000,000,370 | ---- | M] () -- C:\bmrc_1.gif
    [2012/10/08 08:43:34 | 000,000,367 | ---- | M] () -- C:\bmfav_1.gif
    [2012/10/08 08:43:34 | 000,000,355 | ---- | M] () -- C:\bmpref_1.gif
    [2012/10/08 08:43:34 | 000,000,235 | ---- | M] () -- C:\bmsearch_1.gif
    [2012/10/08 08:43:34 | 000,000,166 | ---- | M] () -- C:\bmfol_1_s0.gif
    [2012/10/06 16:25:33 | 000,000,957 | ---- | M] () -- C:\Users\Public\Desktop\iLivid Download Manager.lnk
    [2012/10/05 10:09:20 | 000,795,928 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
    [2012/10/03 21:47:51 | 000,005,297 | ---- | M] () -- C:\Users\Pradeep\Desktop\Art Beau.jpg
    [2012/10/03 14:21:45 | 000,000,380 | ---- | M] () -- C:\edu.bmp
    [2012/10/03 14:21:45 | 000,000,304 | ---- | M] () -- C:\dir.bmp
    [2012/10/03 14:21:45 | 000,000,284 | ---- | M] () -- C:\srch_map_1.gif
    [2012/10/03 14:21:45 | 000,000,279 | ---- | M] () -- C:\hj_1.gif
    [2012/10/03 14:21:45 | 000,000,277 | ---- | M] () -- C:\mov_1.gif
    [2012/10/03 14:21:45 | 000,000,274 | ---- | M] () -- C:\trav_1.gif
    [2012/10/03 14:21:45 | 000,000,273 | ---- | M] () -- C:\srch_stk_1.gif
    [2012/10/03 14:21:45 | 000,000,268 | ---- | M] () -- C:\ab_1.gif
    [2012/10/03 14:21:45 | 000,000,240 | ---- | M] () -- C:\srch_site_1.gif
    [2012/10/03 14:21:45 | 000,000,138 | ---- | M] () -- C:\flk2.gif
    [2012/10/03 14:21:45 | 000,000,121 | ---- | M] () -- C:\srch_nws_1.gif
    [2012/10/03 14:21:45 | 000,000,103 | ---- | M] () -- C:\del_1.gif
    [2012/10/03 14:21:44 | 000,000,265 | ---- | M] () -- C:\srch_ans_1.gif
    [2012/10/03 14:21:44 | 000,000,235 | ---- | M] () -- C:\srch_1.gif
    [2012/10/03 14:21:44 | 000,000,131 | ---- | M] () -- C:\srch_loc_1.gif
    [2012/10/03 14:21:44 | 000,000,123 | ---- | M] () -- C:\srch_sh_1.gif
    [2012/10/03 14:21:44 | 000,000,113 | ---- | M] () -- C:\srch_aud_1.gif
    [2012/10/03 14:21:44 | 000,000,112 | ---- | M] () -- C:\srch_vid_1.gif
    [2012/10/03 14:21:44 | 000,000,112 | ---- | M] () -- C:\srch_img_1.gif
    [2012/10/02 20:28:22 | 000,002,264 | ---- | M] () -- C:\Users\Public\Desktop\Norton 360.lnk
    [2012/10/01 23:21:26 | 000,002,008 | ---- | M] () -- C:\Users\Pradeep\Desktop\Yahoo! SiteBuilder.lnk
    [2012/09/30 16:24:20 | 000,423,531 | ---- | M] () -- C:\Users\Pradeep\Desktop\new%20notice%20board%202.png
    [2012/09/30 15:38:04 | 000,350,262 | ---- | M] () -- C:\Users\Pradeep\Desktop\noticeboard.png
    [2012/09/29 19:54:26 | 000,025,928 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
    [2012/09/27 13:07:26 | 000,160,992 | ---- | M] (Tonec Inc.) -- C:\Windows\SysNative\drivers\idmwfp.sys
    [2012/09/26 16:52:32 | 000,010,218 | ---- | M] () -- C:\Users\Pradeep\Desktop\imagesCA63ERNZ.jpg
    [2012/09/26 16:51:18 | 000,037,306 | ---- | M] () -- C:\Users\Pradeep\Desktop\dfsad.png
    [2012/09/26 16:50:04 | 000,031,044 | ---- | M] () -- C:\Users\Pradeep\Desktop\untitled.png
    [2012/09/26 05:52:07 | 000,000,172 | ---- | M] () -- C:\Windows\SysNative\drivers\N360x64\0604000.009\isolate.ini
    [2012/09/24 22:15:16 | 000,090,874 | ---- | M] () -- C:\Users\Pradeep\Desktop\iaza18999047392300_3.jpg
    [2012/09/24 22:13:31 | 000,065,058 | ---- | M] () -- C:\Users\Pradeep\Desktop\iaza18999047392300_2.jpg
    [2012/09/24 22:09:54 | 000,087,307 | ---- | M] () -- C:\Users\Pradeep\Desktop\iaza18999097403700.jpg

    ========== Files Created - No Company Name ==========

    [2012/10/21 11:10:50 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
    [2012/10/21 11:10:50 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
    [2012/10/21 11:10:50 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
    [2012/10/21 11:10:50 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
    [2012/10/21 11:10:50 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
    [2012/10/20 22:45:07 | 000,000,512 | ---- | C] () -- C:\Users\Pradeep\Desktop\MBR.dat
    [2012/10/18 21:47:14 | 000,001,810 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
    [2012/10/17 22:06:04 | 305,745,908 | ---- | C] () -- C:\Windows\MEMORY.DMP
    [2012/10/17 21:36:56 | 000,001,115 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    [2012/10/09 21:57:37 | 000,330,122 | ---- | C] () -- C:\Users\Pradeep\Desktop\Lab Requisition Form - Order 229.pdf
    [2012/10/08 08:43:34 | 000,000,370 | ---- | C] () -- C:\bmrc_1.gif
    [2012/10/08 08:43:34 | 000,000,367 | ---- | C] () -- C:\bmfav_1.gif
    [2012/10/08 08:43:34 | 000,000,355 | ---- | C] () -- C:\bmpref_1.gif
    [2012/10/08 08:43:34 | 000,000,235 | ---- | C] () -- C:\bmsearch_1.gif
    [2012/10/08 08:43:34 | 000,000,166 | ---- | C] () -- C:\bmfol_1_s0.gif
    [2012/10/06 16:25:33 | 000,000,957 | ---- | C] () -- C:\Users\Public\Desktop\iLivid Download Manager.lnk
    [2012/10/03 14:21:45 | 000,000,380 | ---- | C] () -- C:\edu.bmp
    [2012/10/03 14:21:45 | 000,000,304 | ---- | C] () -- C:\dir.bmp
    [2012/10/03 14:21:45 | 000,000,284 | ---- | C] () -- C:\srch_map_1.gif
    [2012/10/03 14:21:45 | 000,000,279 | ---- | C] () -- C:\hj_1.gif
    [2012/10/03 14:21:45 | 000,000,277 | ---- | C] () -- C:\mov_1.gif
    [2012/10/03 14:21:45 | 000,000,274 | ---- | C] () -- C:\trav_1.gif
    [2012/10/03 14:21:45 | 000,000,273 | ---- | C] () -- C:\srch_stk_1.gif
    [2012/10/03 14:21:45 | 000,000,268 | ---- | C] () -- C:\ab_1.gif
    [2012/10/03 14:21:45 | 000,000,240 | ---- | C] () -- C:\srch_site_1.gif
    [2012/10/03 14:21:45 | 000,000,138 | ---- | C] () -- C:\flk2.gif
    [2012/10/03 14:21:45 | 000,000,121 | ---- | C] () -- C:\srch_nws_1.gif
    [2012/10/03 14:21:45 | 000,000,103 | ---- | C] () -- C:\del_1.gif
    [2012/10/03 14:21:44 | 000,000,265 | ---- | C] () -- C:\srch_ans_1.gif
    [2012/10/03 14:21:44 | 000,000,235 | ---- | C] () -- C:\srch_1.gif
    [2012/10/03 14:21:44 | 000,000,131 | ---- | C] () -- C:\srch_loc_1.gif
    [2012/10/03 14:21:44 | 000,000,123 | ---- | C] () -- C:\srch_sh_1.gif
    [2012/10/03 14:21:44 | 000,000,113 | ---- | C] () -- C:\srch_aud_1.gif
    [2012/10/03 14:21:44 | 000,000,112 | ---- | C] () -- C:\srch_vid_1.gif
    [2012/10/03 14:21:44 | 000,000,112 | ---- | C] () -- C:\srch_img_1.gif
    [2012/10/01 23:21:26 | 000,002,008 | ---- | C] () -- C:\Users\Pradeep\Desktop\Yahoo! SiteBuilder.lnk
    [2012/09/29 12:44:31 | 000,005,297 | ---- | C] () -- C:\Users\Pradeep\Desktop\Art Beau.jpg
    [2012/09/29 12:23:39 | 000,350,262 | ---- | C] () -- C:\Users\Pradeep\Desktop\noticeboard.png
    [2012/09/29 12:15:23 | 000,423,531 | ---- | C] () -- C:\Users\Pradeep\Desktop\new%20notice%20board%202.png
    [2012/09/26 16:52:48 | 000,010,218 | ---- | C] () -- C:\Users\Pradeep\Desktop\imagesCA63ERNZ.jpg
    [2012/09/26 16:51:18 | 000,037,306 | ---- | C] () -- C:\Users\Pradeep\Desktop\dfsad.png
    [2012/09/24 22:15:15 | 000,090,874 | ---- | C] () -- C:\Users\Pradeep\Desktop\iaza18999047392300_3.jpg
    [2012/09/24 22:13:31 | 000,065,058 | ---- | C] () -- C:\Users\Pradeep\Desktop\iaza18999047392300_2.jpg
    [2012/09/24 22:10:03 | 000,087,307 | ---- | C] () -- C:\Users\Pradeep\Desktop\iaza18999097403700.jpg
    [2012/08/25 17:00:57 | 000,001,456 | ---- | C] () -- C:\Users\Pradeep\AppData\Local\Adobe Save for Web 13.0 Prefs
    [2012/06/23 11:46:54 | 000,007,630 | ---- | C] () -- C:\Users\Pradeep\AppData\Local\Resmon.ResmonCfg
    [2012/05/06 17:28:45 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
    [2012/05/06 17:18:52 | 000,165,376 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
    [2012/05/04 18:12:51 | 000,000,006 | -HS- | C] () -- C:\Users\Pradeep\AppData\Roaming\date
    [2012/05/04 18:12:40 | 000,000,002 | -HS- | C] () -- C:\Users\Pradeep\AppData\Roaming\evf9
    [2012/05/03 22:49:22 | 000,096,857 | ---- | C] () -- C:\Users\Pradeep\Panjabi - Selected.lsl
    [2012/04/25 18:37:38 | 000,000,403 | ---- | C] () -- C:\Windows\MAXLINK.INI
    [2012/04/25 18:31:01 | 000,795,928 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
    [2012/04/22 19:03:49 | 002,463,976 | ---- | C] () -- C:\Windows\SysWow64\NPSWF32.dll

    ========== ZeroAccess Check ==========

    [2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

    [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

    [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

    [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

    [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
    "" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 00:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Apartment

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
    "" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 23:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Apartment

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
    "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 20:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Free

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
    "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 22:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Free

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
    "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 20:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Both

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

    ========== LOP Check ==========

    [2012/07/30 20:24:04 | 000,000,000 | ---D | M] -- C:\Users\Pradeep\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
    [2012/10/21 11:23:23 | 000,000,000 | ---D | M] -- C:\Users\Pradeep\AppData\Roaming\DMCache
    [2012/04/23 21:51:18 | 000,000,000 | ---D | M] -- C:\Users\Pradeep\AppData\Roaming\EPSON
    [2012/04/23 21:18:43 | 000,000,000 | ---D | M] -- C:\Users\Pradeep\AppData\Roaming\Greyfirst
    [2012/10/06 20:47:14 | 000,000,000 | ---D | M] -- C:\Users\Pradeep\AppData\Roaming\IDM
    [2012/04/25 18:37:03 | 000,000,000 | ---D | M] -- C:\Users\Pradeep\AppData\Roaming\Nuance
    [2012/05/15 23:50:41 | 000,000,000 | ---D | M] -- C:\Users\Pradeep\AppData\Roaming\PACE Anti-Piracy
    [2012/05/15 23:48:46 | 000,000,000 | ---D | M] -- C:\Users\Pradeep\AppData\Roaming\PDAppFlex
    [2012/04/25 18:42:31 | 000,000,000 | ---D | M] -- C:\Users\Pradeep\AppData\Roaming\ScanSoft
    [2012/04/25 18:42:35 | 000,000,000 | ---D | M] -- C:\Users\Pradeep\AppData\Roaming\Zeon

    ========== Purity Check ==========



    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 218 bytes -> C:\ProgramData\TEMP:A303874F
    < End of report >
     
  7. Pete26 Newcomer, in training Posts: 30

    OTL Extras logfile created on: 10/21/2012 6:35:32 PM - Run 1
    OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Pradeep\Desktop
    64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    2.00 Gb Total Physical Memory | 1.22 Gb Available Physical Memory | 61.03% Memory free
    4.00 Gb Paging File | 2.71 Gb Available in Paging File | 67.75% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 226.40 Gb Total Space | 135.14 Gb Free Space | 59.69% Space Free | Partition Type: NTFS
    Drive D: | 232.88 Gb Total Space | 209.72 Gb Free Space | 90.06% Space Free | Partition Type: NTFS
    Drive E: | 6.48 Gb Total Space | 0.87 Gb Free Space | 13.47% Space Free | Partition Type: NTFS

    Computer Name: PRADEEPS-PC | User Name: Pradeep | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

    ========== Shell Spawning ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
    inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
    InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
    InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [Bridge] -- C:\Program Files (x86)\Adobe\Adobe Bridge CS6\Bridge.exe "%L" (Adobe Systems, Inc.)
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [Bridge] -- C:\Program Files (x86)\Adobe\Adobe Bridge CS6\Bridge.exe "%L" (Adobe Systems, Inc.)
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "cval" = 1
    "FirewallDisableNotify" = 0
    "AntiVirusDisableNotify" = 0
    "UpdatesDisableNotify" = 0

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
    "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
    "AntiVirusOverride" = 0
    "AntiSpywareOverride" = 0
    "FirewallOverride" = 0

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

    ========== System Restore Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
    "DisableSR" = 0

    ========== Firewall Settings ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


    ========== Vista Active Open Ports Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{0D3D17A6-8ECF-4556-9274-DC97A79BC51F}" = lport=138 | protocol=17 | dir=in | app=system |
    "{12FBE955-29ED-4D00-BE75-07D7F1932D62}" = rport=138 | protocol=17 | dir=out | app=system |
    "{2C24A448-34AA-465D-9806-AD97ECF5B1CF}" = rport=137 | protocol=17 | dir=out | app=system |
    "{2E544952-7A22-48BC-8B66-B2C93F749B36}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{403A7857-D465-46DC-BA93-11E1D44C8A6F}" = lport=2869 | protocol=6 | dir=in | app=system |
    "{4E289B97-682F-48D6-9348-026F81A85B3A}" = lport=137 | protocol=17 | dir=in | app=system |
    "{4F1C2493-5D31-41EA-BA78-15383E02BAA6}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{5595940B-E1DF-4E5D-84B0-DCCD529F4F1D}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
    "{6EC1F541-60EC-4ED7-9D84-0CA9C54F9480}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{A2EAD659-60FE-45F7-9B5C-0E445A04E821}" = rport=139 | protocol=6 | dir=out | app=system |
    "{AB4D8796-BBEA-4280-B930-D1A30C160A3D}" = lport=10243 | protocol=6 | dir=in | app=system |
    "{ABFDCD1D-93DF-4C91-9A9E-F980068D08D2}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{AEBFCD65-E861-4F90-B0B4-DC70C6B9C9FF}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{AF7AF116-EF34-4162-A8B1-F5F63FE07CD8}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
    "{B1669E38-447A-488F-B0C6-06B4CE295AE3}" = rport=445 | protocol=6 | dir=out | app=system |
    "{C0BBB2C5-A875-4CD4-A881-D7FB3ADEC35B}" = rport=10243 | protocol=6 | dir=out | app=system |
    "{C760D805-6348-4E44-9E99-F4BEEAEB84C7}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{D9455B04-A8AE-43C6-9803-BF163983046B}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{D9EA80CF-2A9A-447C-8B86-98841186C25F}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{DD31F8AF-D3AE-4FD8-875B-1A46D7DEE108}" = lport=445 | protocol=6 | dir=in | app=system |
    "{E548FC8C-4F4F-42B6-B832-C16CC3A0214F}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{F6F413A3-F98B-4B10-9D60-C59EC0A87743}" = lport=139 | protocol=6 | dir=in | app=system |
    "{FD1D3093-C0E0-4667-913D-80C69145D6CF}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |

    ========== Vista Active Application Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{004DCFBA-919E-4AC5-A36F-C69E37693216}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
    "{007C213B-6D2A-4832-924D-F6ECECA3EF20}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
    "{05634A16-13C0-4BA0-A877-D8D291A9FBFA}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
    "{066B4176-3A48-4D19-BDD6-E471D916E101}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{07D8FDC5-7A78-4EE5-86F4-06445562416E}" = protocol=6 | dir=in | app=c:\program files (x86)\nuance\omnipage18\omnipage18.exe |
    "{1208FECA-F673-4BC2-9DCF-7E8C17951B4D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
    "{1B586434-1310-48D3-8B61-75D0C78BCECB}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
    "{1DA8C4D2-F2EC-40EC-BE23-9C1CC9E23460}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
    "{35112494-2D0B-4718-A040-3ABEB5C24291}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{36ADD9E9-F441-4769-9484-15F18F806472}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{3915CA2D-B025-4752-B406-BACC7A072B7B}" = protocol=6 | dir=in | app=c:\program files (x86)\nuance\omnipage18\ereg\ereg.exe |
    "{3FA5D683-DB8B-47D2-A98D-3428D0317944}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
    "{4121C9AF-8168-48CC-89C2-6EFA782A69F2}" = protocol=6 | dir=in | app=c:\program files (x86)\nuance\omnipage18\ppmv.exe |
    "{47F77224-73E1-4F98-805A-F87ADC3A79CA}" = protocol=17 | dir=in | app=c:\program files (x86)\nuance\omnipage18\ppmv.exe |
    "{4A2774BF-BE67-4074-9412-578161B94CFD}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
    "{4E42DA90-2215-41C9-80A9-DC92B161165A}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
    "{5F082CB1-0E26-4919-8907-8D6BE26A42E0}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{9055D408-F370-4883-A7B6-5FCEBCD0A59F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{AC472913-B802-4A8F-9D27-05013DF3B7DF}" = protocol=6 | dir=out | app=system |
    "{C7E3B5AA-C552-48AE-AD00-2765CCFCCA95}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
    "{CABEE31C-509E-40CA-9796-CA3ED876A372}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{CFC2ACC1-7C16-4C2E-BBF8-EF7C1CE0A359}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{D201DF51-D7E6-4B13-80D2-52A9A2BA3D9F}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
    "{D97E1EBA-7D98-4D6C-B048-8935EF17D6CC}" = protocol=17 | dir=in | app=c:\program files (x86)\nuance\omnipage18\omnipage18.exe |
    "{DBE585A7-4714-4578-AE5C-76A26D45D11C}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
    "{E6C6EDF6-FDB1-457C-8372-2BE0C037144A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{EA03FCB6-7BB4-4202-86CD-D76B38EA08E7}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
    "{EA9B1388-E449-40BF-9DCF-E0585515B00A}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
    "{F1A8F321-5BBD-4A6D-BECA-69EDCF327590}" = protocol=17 | dir=in | app=c:\program files (x86)\nuance\omnipage18\ereg\ereg.exe |
    "{F1FD333E-0012-4CE6-B8BE-D0F8F16C7FEE}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
    "{FEB26B02-F3BA-493A-AFF0-677EB8806701}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |

    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
    "{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
    "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
    "{6A76BEAF-6D1F-4273-A79B-DA8410A2E56B}" = Apple Mobile Device Support
    "{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
    "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
    "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
    "{840A3BAA-4C68-4581-9C7A-6F8D6CF531B9}" = iTunes
    "{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
    "{A1F2C608-32D6-467D-B035-BBEF509042BA}_is1" = Free Opener
    "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
    "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
    "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
    "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
    "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
    "NVIDIA Display Control Panel" = NVIDIA Display Control Panel
    "NVIDIA Drivers" = NVIDIA Drivers

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{0046FA01-C5B9-4985-BACB-398DC480FC05}" = Adobe Photoshop CS3
    "{0224CACC-994D-45F8-B973-D65056EA9C2F}" = Adobe XMP DVA Panels CS3
    "{0327FA9D-975C-448C-A086-577D57BB25B8}" = Adobe Soundbooth CS3 Codecs
    "{045D4EDF-8DC1-43D7-BAFC-7AAEF99C7168}" = Adobe Creative Suite 6 Production Premium
    "{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
    "{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
    "{122ADF8C-DDA1-480C-9936-C88F2825B265}" = Apple Application Support
    "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
    "{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
    "{185F9795-9663-4F13-9EF9-307A282ADB5A}" = ph
    "{193EAFD0-1BAF-4FB4-B18F-79D5D6A4B285}" = Adobe After Effects CS3 Presets
    "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
    "{243DA072-8E39-424A-86A3-F63152021383}" = Adobe Glyphlet Creation Tool CS3
    "{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
    "{2A075BB4-E976-4278-BF3F-E5C6945D84C0}" = bl
    "{2EFFFC71-1E66-454E-A6E6-CEEC800B96D2}" = Adobe Flash Video Encoder
    "{2FA75B40-17C9-4D22-88CA-80A5D52FAB13}" = LightScribe System Software
    "{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
    "{40F2BCF4-4EED-4AD4-BFB6-A58946C561A1}" = Adobe Creative Suite 3 Production Premium
    "{485ACF57-F364-440A-8496-E1E81C8FA1AA}" = Adobe Premiere Pro CS3 Third Party Content
    "{4ECA4128-8B48-44A0-90E8-B93C6A69CE4B}" = LightScribe Template Designs - Music Pack 1
    "{50F102CA-4BE2-41A9-9810-5BB05EB91B9A}" = Adobe Premiere Pro CS3 Functional Content
    "{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
    "{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
    "{54B2EAD9-A110-43F7-B010-2859A1BD2AFE}" = Adobe Encore CS3
    "{58DCEEE5-532E-44F4-B1D7-A146EF9E9FDA}" = Adobe Premiere Pro CS3
    "{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
    "{6B52140A-F189-4945-BFFC-DB3F00B8C589}" = Adobe Flash CS3
    "{6B708481-748A-4EB4-97C1-CD386244FF77}" = Adobe MotionPicture Color Files
    "{6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD}" = AHV content for Acrobat and Flash
    "{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
    "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
    "{73E81E9B-7319-43AD-B7CC-1C61405E5089}" = Adobe After Effects CS3 Template Projects & Footage
    "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
    "{7ACFB90E-8FD0-4397-AD3A-5195412623A3}" = Adobe Help Viewer CS3
    "{7ECEF10B-F1C2-4FD5-861F-A3FCB4653304}" = Adobe After Effects CS3 Third Party Content
    "{83721450-E604-4C37-ABEB-CE7F18C587C8}" = LightScribe Template Labeler
    "{845A8DB9-8802-4FD3-9FE3-938A6C46A2EC}" = Adobe Video Profiles
    "{88D422DB-E9C7-4E16-9D80-2999F4FD6AD9}" = Adobe Flash Player 9 Plugin
    "{8D15E1B2-D2B7-4A17-B44B-D2DDE5981406}" = iLivid
    "{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
    "{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
    "{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
    "{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
    "{92A300C0-E97B-48CC-9702-AB1AAED167E1}" = Adobe Soundbooth CS3 Scores
    "{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
    "{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
    "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    "{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
    "{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
    "{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
    "{A4C7E916-23CD-40ED-B18C-6ADE7B0C74DA}" = Nuance OmniPage 18
    "{A6B23EFA-6590-482C-A11F-5ACE1B91F5B9}" = Adobe Soundbooth CS3
    "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
    "{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.4)
    "{AF37176A-78CA-545B-34EF-8B6A21514DD1}" = Adobe Help Manager
    "{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
    "{B8B7A4D8-80E1-4DAE-BD33-7FD535BA3931}" = Adobe Encore CS3 Codecs
    "{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
    "{BA67E3E1-25EE-4481-857D-D3CA99DA71C8}" = Adobe Setup
    "{BC4F8E84-5E29-49EC-B4E7-E6F9CB50986C}" = Adobe Flash Player 9 ActiveX
    "{BE5F3842-8309-4754-92D5-83E02E6077A3}" = Adobe Extension Manager CS3
    "{BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}" = PDF Settings CS6
    "{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
    "{C5BD220A-EFE8-48A5-B70E-9503D535FACE}" = Adobe WAS CS3
    "{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
    "{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
    "{D5A31AB1-345D-47C7-A87B-036A669F6DF1}" = Adobe XMP Panels CS3
    "{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
    "{DC017035-1939-425F-8F86-63B462C76C6A}" = PDF Settings
    "{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
    "{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
    "{EB0202F7-016A-410C-ADE4-40F848CCC661}" = Adobe After Effects CS3
    "{F08E8D2E-F132-4742-9C87-D5FF223A016A}" = Adobe Illustrator CS3
    "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
    "{F1D93F5B-881F-49E3-BA56-B4B8FA991059}" = Adobe Encore CS3 Library
    "{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
    "{FFB278E6-2945-4FF0-8F3F-268CDD09FCF6}" = Adobe OnLocation CS3
    "Adobe AIR" = Adobe AIR
    "Adobe_aefc483f26b23ab60cc5653016d5017" = Add or Remove Adobe Creative Suite 3 Production Premium
    "Celtx (2.9.7)" = Celtx (2.9.7)
    "chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Help Manager
    "EPSON Scanner" = EPSON Scan
    "iLivid" = iLivid
    "InstallShield_{FFB278E6-2945-4FF0-8F3F-268CDD09FCF6}" = Adobe OnLocation CS3
    "Internet Download Manager" = Internet Download Manager
    "IsoBuster_is1" = IsoBuster 3.0
    "KLiteCodecPack_is1" = K-Lite Codec Pack 7.0.0 (Standard)
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.1.1000
    "N360" = Norton 360
    "WinPcapInst" = WinPcap 4.1.2
    "Yahoo! Companion" = Yahoo! Toolbar
    "Yahoo! SiteBuilder" = Yahoo! SiteBuilder
    "Yahoo! Software Update" = Yahoo! Software Update
    "YInstHelper" = Yahoo! Install Manager
    "ZillaTube" = ZillaTube 5.2

    ========== HKEY_USERS Uninstall List ==========

    [HKEY_USERS\S-1-5-21-2262249602-3662098830-2808129073-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "Google Chrome" = Google Chrome

    ========== Last 20 Event Log Errors ==========

    [ Application Events ]
    Error - 10/21/2012 4:17:25 AM | Computer Name = Pradeeps-PC | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: m->NextScheduledSPRetry 12539017

    Error - 10/21/2012 4:17:41 AM | Computer Name = Pradeeps-PC | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: Continuously busy for more than a second

    Error - 10/21/2012 4:17:41 AM | Computer Name = Pradeeps-PC | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: m->NextScheduledEvent 12554711

    Error - 10/21/2012 4:17:41 AM | Computer Name = Pradeeps-PC | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: m->NextScheduledSPRetry 12554711

    Error - 10/21/2012 4:21:01 AM | Computer Name = Pradeeps-PC | Source = WinMgmt | ID = 10
    Description =

    Error - 10/21/2012 11:26:40 AM | Computer Name = Pradeeps-PC | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: Continuously busy for more than a second

    Error - 10/21/2012 11:59:11 AM | Computer Name = Pradeeps-PC | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: m->NextScheduledEvent 15819

    Error - 10/21/2012 11:59:11 AM | Computer Name = Pradeeps-PC | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: m->NextScheduledSPRetry 15819

    Error - 10/21/2012 12:27:03 PM | Computer Name = Pradeeps-PC | Source = WinMgmt | ID = 10
    Description =

    Error - 10/21/2012 7:27:18 PM | Computer Name = Pradeeps-PC | Source = WinMgmt | ID = 10
    Description =

    [ System Events ]
    Error - 10/21/2012 12:48:45 AM | Computer Name = Pradeeps-PC | Source = Microsoft-Windows-HAL | ID = 12
    Description = The platform firmware has corrupted memory across the previous system
    power transition. Please check for updated firmware for your system.

    Error - 10/21/2012 4:49:49 AM | Computer Name = Pradeeps-PC | Source = Microsoft-Windows-HAL | ID = 12
    Description = The platform firmware has corrupted memory across the previous system
    power transition. Please check for updated firmware for your system.

    Error - 10/21/2012 12:18:33 PM | Computer Name = Pradeeps-PC | Source = Service Control Manager | ID = 7030
    Description = The PEVSystemStart service is marked as an interactive service. However,
    the system is configured to not allow interactive services. This service may not
    function properly.

    Error - 10/21/2012 12:21:47 PM | Computer Name = Pradeeps-PC | Source = Application Popup | ID = 1060
    Description = \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility
    with this system. Please contact your software vendor for a compatible version
    of the driver.

    Error - 10/21/2012 12:22:43 PM | Computer Name = Pradeeps-PC | Source = Service Control Manager | ID = 7030
    Description = The PEVSystemStart service is marked as an interactive service. However,
    the system is configured to not allow interactive services. This service may not
    function properly.

    Error - 10/21/2012 12:23:00 PM | Computer Name = Pradeeps-PC | Source = Service Control Manager | ID = 7030
    Description = The PEVSystemStart service is marked as an interactive service. However,
    the system is configured to not allow interactive services. This service may not
    function properly.

    Error - 10/21/2012 1:21:12 PM | Computer Name = Pradeeps-PC | Source = Microsoft-Windows-HAL | ID = 12
    Description = The platform firmware has corrupted memory across the previous system
    power transition. Please check for updated firmware for your system.

    Error - 10/21/2012 4:09:41 PM | Computer Name = Pradeeps-PC | Source = bowser | ID = 8003
    Description =

    Error - 10/21/2012 4:33:38 PM | Computer Name = Pradeeps-PC | Source = bowser | ID = 8003
    Description =

    Error - 10/21/2012 7:26:58 PM | Computer Name = Pradeeps-PC | Source = bowser | ID = 8003
    Description =


    < End of report >
  8. Broni Malware Annihilator Posts: 40,051   +187

    Run OTL
    • Under the Custom Scans/Fixes box at the bottom, paste in the following

      Code:
      :OTL
      [2012/05/04 18:12:51 | 000,000,006 | -HS- | C] () -- C:\Users\Pradeep\AppData\Roaming\date
      [2012/05/04 18:12:40 | 000,000,002 | -HS- | C] () -- C:\Users\Pradeep\AppData\Roaming\evf9
      [2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
      
      [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
      
      [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
      
      [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
      
      [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
      
      [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
      "" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 00:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
      "ThreadingModel" = Apartment
      
      [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
      "" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 23:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
      "ThreadingModel" = Apartment
      
      [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
      "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 20:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
      "ThreadingModel" = Free
      
      [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
      "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 22:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
      "ThreadingModel" = Free
      
      [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
      "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 20:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
      "ThreadingModel" = Both
      
      [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
      @Alternate Data Stream - 218 bytes -> C:\ProgramData\TEMP:A303874F
      
      :Services
      
      :Reg
      
      :Files
      
      :Commands
      [purity]
      [emptytemp]
      [emptyjava]
      [emptyflash]
      [Reboot]
      
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.

    NOTE. If for any reason OTL stalls (most likely at "killing processes..." step) run the fix from safe mode.

    ==================================

    Last scans....

    1. Download Security Check from HERE, and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

      NOTE SecurityCheck may produce some false warning(s), so leave the results reading to me.

    2. Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
    • Make sure the following options are checked:
      • Internet Services
      • Windows Firewall
      • System Restore
      • Security Center
      • Windows Update
      • Windows Defender
    • Press "Scan".
    • It will create a log (FSS.txt) in the same directory the tool is run.
    • Please copy and paste the log to your reply.

    3. Please download AdwCleaner by Xplode onto your desktop.
    • Close all open programs and internet browsers.
    • Double click on adwcleaner.exe to run the tool.
    • Click on Delete.
    • Confirm each time with Ok.
    • Your computer will be rebooted automatically. A text file will open after the restart.
    • Please post the contents of that logfile with your next reply.
    • You can find the logfile at C:\AdwCleaner[S1].txt as well.

    Next...

    • Double click on adwcleaner.exe to run the tool.
    • Click on Uninstall.
    • Confirm with yes.

    4. Download Temp File Cleaner (TFC)
    Alternate download: http://www.itxassociates.com/OT-Tools/TFC.exe
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.

    5. Please run a free online scan with the ESET Online Scanner

    • Disable your antivirus program
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • Accept any security warnings from your browser.
    • Check Scan archives
    • Click Start
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, click on List of found threats
    • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • NOTE. If Eset won't find any threats, it won't produce any log.
  9. Pete26 Newcomer, in training Posts: 30

    OTL Fix Log attached below. Rest will post tomorrow.

    All processes killed
    ========== OTL ==========
    C:\Users\Pradeep\AppData\Roaming\date moved successfully.
    C:\Users\Pradeep\AppData\Roaming\evf9 moved successfully.
    C:\Windows\assembly\Desktop.ini moved successfully.
    File EY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 not found.
    File EY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] not found.
    File EY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 not found.
    File EY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] not found.
    File EY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 not found.
    File EY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] not found.
    Folder EY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64\ not found.
    Folder EY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]\ not found.
    Folder EY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64\ not found.
    Folder EY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]\ not found.
    ADS C:\ProgramData\TEMP:A303874F deleted successfully.
    ========== SERVICES/DRIVERS ==========
    ========== REGISTRY ==========
    ========== FILES ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 56475 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Pradeep
    ->Temp folder emptied: 71931 bytes
    ->Temporary Internet Files folder emptied: 70991391 bytes
    ->Java cache emptied: 1619280 bytes
    ->Google Chrome cache emptied: 47369126 bytes
    ->Flash cache emptied: 57353 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 698 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 36030824 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 149.00 mb


    [EMPTYJAVA]

    User: All Users

    User: Default

    User: Default User

    User: Pradeep
    ->Java cache emptied: 0 bytes

    User: Public

    Total Java Files Cleaned = 0.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Default
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Flash cache emptied: 0 bytes

    User: Pradeep
    ->Flash cache emptied: 0 bytes

    User: Public

    Total Flash Files Cleaned = 0.00 mb


    OTL by OldTimer - Version 3.2.69.0 log created on 10212012_233021
    Files\Folders moved on Reboot...
    File\Folder C:\Users\Pradeep\AppData\Local\Temp\Low\~DF3F48A6596742BC29.TMP not found!
    File\Folder C:\Users\Pradeep\AppData\Local\Temp\Low\~DF74E1A83E4B1580FB.TMP not found!
    C:\Users\Pradeep\AppData\Local\Temp\Low\~DFB74B12916334CD2F.TMP moved successfully.
    C:\Users\Pradeep\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZQ8GHCB0\B6957617[1].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZQ8GHCB0\ping[3].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZQ8GHCB0\ping[4].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZQ8GHCB0\rt[3].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZQ8GHCB0\r[2].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\NB25QDD0\918[2].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\NB25QDD0\page-2[1].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\NB25QDD0\ping[3].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\NB25QDD0\ping[4].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\NB25QDD0\rt[3].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\NB25QDD0\rt[4].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BMNPX4HS\billboard[1].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BMNPX4HS\partner[2].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BMNPX4HS\partner[3].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BMNPX4HS\ping[4].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BMNPX4HS\rsa[1].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BMNPX4HS\rt[6].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BMNPX4HS\r[1].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\93OH316V\net[2].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\93OH316V\ptj[3].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\93OH316V\rt[6].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully.
    PendingFileRenameOperations files...
    Registry entries deleted on Reboot...
  10. Pete26 Newcomer, in training Posts: 30

    Results of screen317's Security Check version 0.99.53
    Windows 7 Service Pack 1 x64 (UAC is enabled)
    Internet Explorer 9
    ``````````````Antivirus/Firewall Check:``````````````
    Windows Firewall Enabled!
    Norton 360
    WMI entry may not exist for antivirus; attempting automatic update.
    `````````Anti-malware/Other Utilities Check:`````````
    Malwarebytes Anti-Malware version 1.65.1.1000
    Java(TM) 6 Update 7
    Java version out of Date!
    Adobe Flash Player 9 Flash Player out of Date!
    Adobe Reader X (10.1.4)
    Google Chrome 21.0.1180.83
    Google Chrome 21.0.1180.89
    Google Chrome 22.0.1229.79
    Google Chrome 22.0.1229.92
    Google Chrome 22.0.1229.94
    ````````Process Check: objlist.exe by Laurent````````
    Norton ccSvcHst.exe
    `````````````````System Health check`````````````````
    Total Fragmentation on Drive C: 7%
    ````````````````````End of Log``````````````````````
  11. Pete26 Newcomer, in training Posts: 30

    Farbar Service Scanner Version: 19-10-2012
    Ran by Pradeep (administrator) on 22-10-2012 at 07:15:20
    Running from "C:\Users\Pradeep\Desktop"
    Microsoft Windows 7 Ultimate Service Pack 1 (X64)
    Boot Mode: Normal
    ****************************************************************
    Internet Services:
    ============
    Connection Status:
    ==============
    Localhost is accessible.
    LAN connected.
    Google IP is accessible.
    Google.com is accessible.
    Yahoo IP is accessible.
    Yahoo.com is accessible.

    Windows Firewall:
    =============
    Firewall Disabled Policy:
    ==================

    System Restore:
    ============
    System Restore Disabled Policy:
    ========================

    Action Center:
    ============
    Windows Update:
    ============
    Windows Autoupdate Disabled Policy:
    ============================

    Windows Defender:
    ==============
    WinDefend Service is not running. Checking service configuration:
    The start type of WinDefend service is set to Demand. The default start type is Auto.
    The ImagePath of WinDefend service is OK.
    The ServiceDll of WinDefend service is OK.

    Windows Defender Disabled Policy:
    ==========================
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
    "DisableAntiSpyware"=DWORD:1

    Other Services:
    ==============

    File Check:
    ========
    C:\Windows\System32\nsisvc.dll => MD5 is legit
    C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
    C:\Windows\System32\dhcpcore.dll => MD5 is legit
    C:\Windows\System32\drivers\afd.sys => MD5 is legit
    C:\Windows\System32\drivers\tdx.sys => MD5 is legit
    C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
    C:\Windows\System32\dnsrslvr.dll => MD5 is legit
    C:\Windows\System32\mpssvc.dll => MD5 is legit
    C:\Windows\System32\bfe.dll => MD5 is legit
    C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
    C:\Windows\System32\SDRSVC.dll => MD5 is legit
    C:\Windows\System32\vssvc.exe => MD5 is legit
    C:\Windows\System32\wscsvc.dll => MD5 is legit
    C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
    C:\Windows\System32\wuaueng.dll => MD5 is legit
    C:\Windows\System32\qmgr.dll => MD5 is legit
    C:\Windows\System32\es.dll => MD5 is legit
    C:\Windows\System32\cryptsvc.dll => MD5 is legit
    C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\System32\rpcss.dll => MD5 is legit

    **** End of log ****
  12. Pete26 Newcomer, in training Posts: 30

    # AdwCleaner v2.005 - Logfile created 10/22/2012 at 07:21:34
    # Updated 14/10/2012 by Xplode
    # Operating system : Windows 7 Ultimate Service Pack 1 (64 bits)
    # User : Pradeep - PRADEEPS-PC
    # Boot Mode : Normal
    # Running from : C:\Users\Pradeep\Desktop\adwcleaner.exe
    # Option [Delete]

    ***** [Services] *****

    ***** [Files / Folders] *****
    Folder Deleted : C:\Program Files (x86)\Free Offers from Freeze.com
    Folder Deleted : C:\ProgramData\{B49A644A-1076-4A3D-B124-DAA7862F2318}
    Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ilivid
    Folder Deleted : C:\Users\Pradeep\AppData\Local\Ilivid Player
    ***** [Registry] *****
    Key Deleted : HKCU\Software\ilivid
    Key Deleted : HKCU\Software\Softonic
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    Key Deleted : HKLM\Software\Freeze.com
    Key Deleted : HKLM\Software\ilivid
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASAPI32
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASMANCS
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ilivid
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    ***** [Internet Browsers] *****
    -\\ Internet Explorer v9.0.8112.16421
    [OK] Registry is clean.
    -\\ Google Chrome v22.0.1229.94
    File : C:\Users\Pradeep\AppData\Local\Google\Chrome\User Data\Default\Preferences
    [OK] File is clean.
    *************************
    AdwCleaner[S1].txt - [1685 octets] - [22/10/2012 07:21:35]
    ########## EOF - C:\AdwCleaner[S1].txt - [1745 octets] ##########
  13. Pete26 Newcomer, in training Posts: 30

    TFC cleaner was run as per your instructions and ran successfully.

    Getting "cannot get updates. Is proxy configured?" message when trying to run ESET Online Scanner and it will not progress further. Please advise...
  14. Broni Malware Annihilator Posts: 40,051   +187

    Try different browser.
  15. Pete26 Newcomer, in training Posts: 30

    Ran ESET through Google Chrome. haa...it took a lot of time. Attached below is the log.

    C:\Qoobox\Quarantine\C\Users\Pradeep\Videos\iLividSetupV1.exe.vir Win32/Toolbar.SearchSuite application cleaned by deleting - quarantined
    C:\TDSSKiller_Quarantine\20.10.2012_17.56.15\mbr0000\tdlfs0000\tsk0000.dta a variant of Win32/Olmarik.AYI trojan cleaned by deleting - quarantined
    C:\TDSSKiller_Quarantine\20.10.2012_17.56.15\mbr0000\tdlfs0000\tsk0001.dta a variant of Win64/Olmarik.AM trojan cleaned by deleting - quarantined
    C:\TDSSKiller_Quarantine\20.10.2012_17.56.15\mbr0000\tdlfs0000\tsk0004.dta a variant of Win32/Rootkit.Kryptik.OX trojan cleaned by deleting - quarantined
    C:\TDSSKiller_Quarantine\20.10.2012_17.56.15\mbr0000\tdlfs0000\tsk0005.dta Win64/Olmarik.AN trojan cleaned by deleting - quarantined
    C:\TDSSKiller_Quarantine\20.10.2012_17.56.15\mbr0000\tdlfs0000\tsk0009.dta Win32/Olmarik.AFK trojan cleaned by deleting - quarantined
    C:\TDSSKiller_Quarantine\20.10.2012_17.56.15\mbr0000\tdlfs0000\tsk0010.dta Win64/Olmarik.AK trojan cleaned by deleting - quarantined
    C:\Users\Pradeep\Videos\utorrent_movies_download_jatt_and_juliet_720rip_hd.exe Win32/BundleInstaller application cleaned by deleting - quarantined
  16. Broni Malware Annihilator Posts: 40,051   +187

    Update Adobe Flash Player
    Download the Latest Adobe Flash for Firefox and IE Without Any Extras: http://www.404techsupport.com/2010/...-flash-for-firefox-and-ie-without-any-extras/

    ==============================

    1. Update your Java version here: http://www.java.com/en/download/installed.jsp

    Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

    Note 2: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

    2. Now, we need to remove old Java version and its remnants...

    Download JavaRa to your desktop and unzip it.
    • Run JavaRa.exe (Vista users! Right click on JavaRa.exe, click Run As Administrator), pick the language of your choice and click Select. Then click Remove Older Versions.
    • Accept any prompts.
    • Do NOT post JavaRa log.

    ================================

    Your computer is clean [IMG]

    1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

    Run OTL

    • Under the Custom Scans/Fixes box at the bottom, paste in the following:

    Code:
    :OTL
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [emptyjava]
    [CLEARALLRESTOREPOINTS]
    [Reboot]
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Post resulting log.

    2. Now, we'll remove all tools, we used during our cleaning process

    Clean up with OTL:

    • Double-click OTL.exe to start the program.
    • Close all other programs apart from OTL as this step will require a reboot
    • On the OTL main screen, press the CLEANUP button
    • Say Yes to the prompt and then allow the program to reboot your computer.

    If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

    3. Make sure, Windows Updates are current.

    4. If any trojans, rootkits or bootkits were listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    7. Run Temporary File Cleaner (TFC) weekly.

    8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    10. (Windows XP only) Run defrag at your convenience.

    11. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

    12. Read:
    How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html
    Simple and easy ways to keep your computer safe and secure on the Internet: http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/

    13. Please, let me know, how your computer is doing.
  17. Pete26 Newcomer, in training Posts: 30

    All processes killed
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Pradeep
    ->Temp folder emptied: 1534824 bytes
    ->Temporary Internet Files folder emptied: 18689110 bytes
    ->Java cache emptied: 1834 bytes
    ->Google Chrome cache emptied: 10817978 bytes
    ->Flash cache emptied: 492 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 1396 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 30.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Default
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Flash cache emptied: 0 bytes

    User: Pradeep
    ->Flash cache emptied: 0 bytes

    User: Public

    Total Flash Files Cleaned = 0.00 mb


    [EMPTYJAVA]

    User: All Users

    User: Default

    User: Default User

    User: Pradeep
    ->Java cache emptied: 0 bytes

    User: Public

    Total Java Files Cleaned = 0.00 mb

    Restore point Set: OTL Restore Point

    OTL by OldTimer - Version 3.2.69.0 log created on 10232012_183706
    Files\Folders moved on Reboot...
    C:\Users\Pradeep\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
    C:\Users\Pradeep\AppData\Local\Temp\~DFF4E1B5BE58939583.TMP moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YDLD95JN\aclk[1].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YDLD95JN\aclk[2].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YDLD95JN\ping[1].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YDLD95JN\rt[1].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RS63WKKE\billboard[1].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RS63WKKE\DocumentDotWrite[1].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RS63WKKE\net[1].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RS63WKKE\page-2[1].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RS63WKKE\ping[1].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RS63WKKE\ptj[1].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RS63WKKE\rt[1].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RS63WKKE\sta[1].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R871FJRA\91[1].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R871FJRA\partner[1].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R871FJRA\partner[2].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R871FJRA\ping[1].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R871FJRA\ping[2].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R871FJRA\rt[1].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R871FJRA\rt[2].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R871FJRA\r[1].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R871FJRA\sta[1].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R871FJRA\sta[2].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\N17MP8D1\bizo_multi[1].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\N17MP8D1\ptj[1].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\N17MP8D1\rsa[1].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\N17MP8D1\sta[1].htm moved successfully.
    PendingFileRenameOperations files...
    Registry entries deleted on Reboot...
  18. Pete26 Newcomer, in training Posts: 30

    Hi there,
    Just wanted to provide you with an update on the macine.
    It is running perfectly fine now. No issues...
    Thanks for all your help!! You guys simply rock!!

    One small question: when trying to download WOT, I am getting the error message that it can be installed on IE vesion 6.0 or later. I have IE 9.0, not sure why this message is coming...
  19. Broni Malware Annihilator Posts: 40,051   +187

    It won't let you install it?
  20. Pete26 Newcomer, in training Posts: 30

    Correct...it would just give an error message that the set up has ended prematurely due to an error.