TechSpot

MSE says I have 4 sirefefs

Solved
By 1ronnie1
Sep 25, 2012
  1. 1ronnie1

    1ronnie1 TS Rookie Topic Starter Posts: 27

    ========== FireFox ==========

    FF - prefs.js..browser.search.selectedEngine: "Google"
    FF - prefs.js..browser.startup.homepage: "http://my.yahoo.com/"


    FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_265.dll File not found
    FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
    FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
    FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files (x86)\Virtual Earth 3D\ [2010/10/12 13:35:45 | 000,000,000 | ---D | M]
    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
    FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
    FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
    FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files (x86)\Virtual Earth 3D\ [2010/10/12 13:35:45 | 000,000,000 | ---D | M]
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=13: C:\Program Files (x86)\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll File not found
    FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.69: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll File not found
    FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.69: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll File not found
    FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.69: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll File not found
    FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files (x86)\Viewpoint\Viewpoint Media Player\npViewpoint.dll File not found
    FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Bluesman\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Bluesman\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

    64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\WEB ASSISTANT\FIREFOX [2012/06/24 21:14:33 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2009/12/25 09:20:36 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files (x86)\AVG\AVG8\Toolbar\Firefox\avg@igeared
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files (x86)\Real\RealPlayer\browserrecord
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\Program Files\Web Assistant\Firefox [2012/06/24 21:14:33 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/09/15 13:50:56 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/08/17 10:23:18 | 000,000,000 | ---D | M]
    FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2009/12/25 09:20:36 | 000,000,000 | ---D | M]
    FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{699C5557-0574-11E2-8271-B8AC6F996F26}: C:\Users\Bluesman\AppData\Local\{699C5557-0574-11E2-8271-B8AC6F996F26}\ [2012/09/23 07:47:17 | 000,000,000 | ---D | M]

    [2009/12/26 11:40:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Extensions
    [2012/09/21 11:38:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\cmzlwot0.Rich\extensions
    [2012/06/24 21:14:43 | 000,000,000 | ---D | M] (incredibar.com) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\cmzlwot0.Rich\extensions\ffxtlbr@incredibar.com
    [2012/06/24 21:14:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\f8iip4f0.default\extensions
    [2009/12/26 11:33:53 | 000,000,000 | ---D | M] (Adblock) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\f8iip4f0.default\extensions\{34274bf4-1d97-a289-e984-17e546307e4f}
    [2009/12/26 11:33:53 | 000,000,000 | ---D | M] (Bandwidth Tester) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\f8iip4f0.default\extensions\{7C06F9C2-B0D0-47b4-93B8-116C919084BA}
    [2009/12/26 11:33:53 | 000,000,000 | ---D | M] (Firefox (default)) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\f8iip4f0.default\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    [2009/12/26 11:33:53 | 000,000,000 | ---D | M] (AutoForm) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\f8iip4f0.default\extensions\{fa908322-0757-4eb2-9427-dca5567ac7a7}
    [2009/12/26 11:33:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\f8iip4f0.default\extensions\{fb0cbf5b-695b-4322-8b49-5dedbfb946fc}
    [2012/06/24 21:14:42 | 000,000,000 | ---D | M] (incredibar.com) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\f8iip4f0.default\extensions\ffxtlbr@incredibar.com
    [2009/12/26 11:33:52 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\f8iip4f0.default\extensions\temp
    [2009/12/26 11:33:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\z15kh4bz.default\extensions
    [2009/12/26 11:33:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\z15kh4bz.default\extensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}
    [2009/12/26 11:33:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\z15kh4bz.default\extensions\{dc0fa13d-3daf-73ec-e852-912722c85309}
    [2009/12/26 11:33:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\z15kh4bz.default\extensions\{f35b2da4-cece-d4e8-0bad-ccd1df7ee17a}
    [2012/07/06 13:19:24 | 000,148,816 | ---- | M] () (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\cmzlwot0.Rich\extensions\autofillForms@blueimp.net.xpi
    [2012/07/02 08:26:45 | 002,265,909 | ---- | M] () (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\cmzlwot0.Rich\extensions\firefox@tvunetworks.com.xpi
    [2012/07/02 08:22:38 | 000,020,591 | ---- | M] () (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\cmzlwot0.Rich\extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi
    [2012/07/02 08:20:11 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
    [2010/12/18 21:23:15 | 000,000,000 | ---D | M] (Babylon) -- C:\Program Files (x86)\Mozilla Firefox\extensions\ffxtlbr@babylon.com
    [2012/09/23 07:47:17 | 000,000,000 | ---D | M] (Mozilla Safe Browsing) -- C:\USERS\BLUESMAN\APPDATA\LOCAL\{699C5557-0574-11E2-8271-B8AC6F996F26}
    [2012/09/15 13:50:56 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
    [2011/04/14 14:01:38 | 000,024,376 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\mozilla firefox\components\Scriptff.dll
    [2011/11/10 06:54:13 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
    [2010/12/18 21:11:31 | 000,002,226 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
    [2012/09/15 13:50:54 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
    [2012/02/20 18:03:28 | 000,002,024 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\McSiteAdvisor.xml
    [2012/09/15 13:50:54 | 000,002,253 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

    ========== Chrome ==========

    CHR - default_search_provider: ()
    CHR - default_search_provider: search_url =
    CHR - default_search_provider: suggest_url =
    CHR - homepage: http://mystart.incredibar.com/mb161?a=6PQBuVHlh7&I=26
    CHR - Extension: No name found = C:\Users\Bluesman\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.40.135.1_0\

    O1 HOSTS File: ([2012/09/26 13:50:08 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
    O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
    O2 - BHO: (Freecorder Toolbar) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files (x86)\Freecorder\tbFree.dll (Conduit Ltd.)
    O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
    O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
    O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
    O3 - HKLM\..\Toolbar: (Freecorder Toolbar) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files (x86)\Freecorder\tbFree.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
    O3 - HKU\S-1-5-21-4292630620-794784561-241906710-1000\..\Toolbar\WebBrowser: (Freecorder Toolbar) - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - C:\Program Files (x86)\Freecorder\tbFree.dll (Conduit Ltd.)
    O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
    O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
    O4:64bit: - HKLM..\Run: [IntelliPoint] c:\Program Files\Microsoft Device Center\ipoint.exe (Microsoft Corporation)
    O4:64bit: - HKLM..\Run: [IntelliType Pro] c:\Program Files\Microsoft Device Center\itype.exe (Microsoft Corporation)
    O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
    O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
    O4:64bit: - HKLM..\Run: [ProfilerU] C:\Program Files\Saitek\SD6\Software\ProfilerU.exe (Saitek)
    O4:64bit: - HKLM..\Run: [SaiMfd] C:\Program Files\Saitek\SD6\Software\SaiMfd.exe (Saitek)
    O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
    O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
    O4 - HKLM..\Run: [DigidesignMMERefresh] C:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe (Avid, Inc. All rights reserved.)
    O4 - HKLM..\Run: [Freecorder FLV Service] C:\Program Files (x86)\Freecorder\FLVSrvc.exe (Applian Technologies, Inc.)
    O4 - HKLM..\Run: [Mobile Connectivity Suite] C:\Program Files (x86)\HTC\HTC Sync\Application Launcher\Application Launcher.exe (Teleca Sweden AB)
    O4 - HKLM..\Run: [NortonOnlineBackupReminder] C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe (Symantec Corporation)
    O4 - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
    O4 - HKU\S-1-5-21-4292630620-794784561-241906710-1000..\Run: [PhotoshopElements8SyncAgent] C:\Program Files (x86)\Adobe\Elements Organizer 8.0\ElementsOrganizerSyncAgent.exe (Adobe Systems Incorporated)
    O4 - Startup: C:\Users\Bluesman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Bluesman\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
    O4 - Startup: C:\Users\Bluesman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Mozilla Firefox.lnk = C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
    O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
    O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
    O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-4292630620-794784561-241906710-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-4292630620-794784561-241906710-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-21-4292630620-794784561-241906710-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O15 - HKU\S-1-5-21-4292630620-794784561-241906710-1000\..Trusted Domains: ([]msn in Computer)
    O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab (Java Plug-in 10.5.0)
    O16:64bit: - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab (Java Plug-in 1.6.0_14)
    O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab (Java Plug-in 10.5.0)
    O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab (QuickTime Object)
    O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab (StagingUI Object)
    O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://oas.support.microsoft.com/ActiveX/MSDcode.cab (Microsoft Data Collection Control)
    O16 - DPF: {0DB074F0-617E-4EE9-912C-2965CF2AA5A4} http://download.microsoft.com/download/f/0/2/f02b515c-7076-4cee-bc08-fd6fea594578/VirtualEarth3D.cab (Reg Error: Key error.)
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://active.macromedia.com/director/cabs/sw.cab (Reg Error: Key error.)
    O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} http://protect.microsoft.com/security/protect/wsa/shared/CAB/x86/msSecAdv.cab?1102267634347 (MSSecurityAdvisor Class)
    O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab (Reg Error: Key error.)
    O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB (Reg Error: Key error.)
    O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab (MSN Games – Buddy Invite)
    O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc.cab (Office Update Installation Engine)
    O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} http://dl.tvunetworks.com/TVUAx.cab (CTVUAxCtrl Object)
    O16 - DPF: {4FAE30E1-EE9C-477D-8D06-BF8D3429B60F} https://www.webiqonline.com/WebIQ/bin/WebIQ.cab (Reg Error: Key error.)
    O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab (ZonePAChat Object)
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1102266753391 (WUWebControl Class)
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1147379248038 (Reg Error: Key error.)
    O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab (GMNRev Class)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 10.5.1)
    O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
    O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} http://69.177.83.150/activex/AxisCamControl.cab (CamImage Class)
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab (MSN Games - Installer)
    O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-31-0.cab (EPUImageControl Class)
    O16 - DPF: {CAC181B0-4D70-402D-B571-C596A47D0CE0} http://zone.msn.com/bingame/zpagames/zpa_pool.cab56649.cab (CBankshotZoneCtrl Class)
    O16 - DPF: {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.4.2/jinstall-1_4_2_06-windows-i586.cab (Java Plug-in 1.4.2_06)
    O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab (Java Plug-in 1.5.0_04)
    O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Java Plug-in 1.5.0_06)
    O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab (Java Plug-in 1.5.0_09)
    O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab (Java Plug-in 1.5.0_10)
    O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab (Java Plug-in 1.5.0_11)
    O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab (Java Plug-in 1.6.0_01)
    O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02)
    O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Java Plug-in 1.6.0_03)
    O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
    O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
    O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 10.5.1)
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
    O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} http://zone.msn.com/binframework/v10/StProxy.cab55579.cab (MSN Games – Game Communicator)
    O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} http://avptcam.uconn.edu/activex/AMC.cab (AxisMediaControlEmb Class)
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab (PopCapLoader Object)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
    O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB (Reg Error: Key error.)
    O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
    O16 - DPF: Yahoo! Poker http://download.games.yahoo.com/games/clients/y/pt1_x.cab (Reg Error: Key error.)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 156.154.119.11 156.154.129.11
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{61228E68-0127-43F1-8400-0DF616A8938F}: DhcpNameServer = 156.154.119.11 156.154.129.11
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A8355ABA-5B16-474E-B856-3B41D981710F}: DhcpNameServer = 156.154.119.11 156.154.129.11
    O18:64bit: - Protocol\Handler\gopher - No CLSID value found
    O18:64bit: - Protocol\Handler\livecall - No CLSID value found
    O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
    O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
    O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
    O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
    O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
    O18:64bit: - Protocol\Handler\msnim - No CLSID value found
    O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
    O18:64bit: - Protocol\Handler\sysimage - No CLSID value found
    O18:64bit: - Protocol\Handler\wia - No CLSID value found
    O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
    O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
    O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\Windows\SysWOW64\wiascr.dll File not found
    O18:64bit: - Protocol\Filter\lzdhtml - No CLSID value found
    O18 - Protocol\Filter\lzdhtml - No CLSID value found
    O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
    O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
    O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\Windows\SysWOW64\ExplorerFrame.dll (Microsoft Corporation)
    O24 - Desktop WallPaper: C:\Users\Bluesman\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O24 - Desktop BackupWallPaper: C:\Users\Bluesman\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
    O32 - HKLM CDRom: AutoRun - 1
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35:64bit: - HKLM\..comfile [open] -- "%1" %*
    O35:64bit: - HKLM\..exefile [open] -- "%1" %*
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
    O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
    O37 - HKLM\...com [@ = ComFile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*
    O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
    O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
    O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

    ========== Files/Folders - Created Within 30 Days ==========

    [2012/09/26 14:24:39 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Bluesman\Desktop\OTL.exe
    [2012/09/26 13:59:45 | 000,000,000 | ---D | C] -- C:\Users\NetworkService\AppData\Local\temp
    [2012/09/26 13:59:45 | 000,000,000 | ---D | C] -- C:\Users\LocalService\AppData\Local\temp
    [2012/09/26 13:50:14 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
    [2012/09/26 13:42:20 | 000,000,000 | ---D | C] -- C:\Windows\temp
    [2012/09/26 13:28:21 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
    [2012/09/26 13:28:21 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
    [2012/09/26 13:28:21 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
    [2012/09/26 13:20:38 | 000,000,000 | ---D | C] -- C:\Qoobox
    [2012/09/26 13:20:04 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
    [2012/09/26 13:14:24 | 004,757,076 | R--- | C] (Swearware) -- C:\Users\Bluesman\Desktop\ComboFix.exe
    [2012/09/26 06:31:50 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\Bluesman\Desktop\aswMBR.exe
    [2012/09/26 06:20:29 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\Desktop\RK_Quarantine
    [2012/09/26 01:27:27 | 000,000,000 | ---D | C] -- C:\FRST
    [2012/09/25 17:31:29 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 USB DVD Download Tool
    [2012/09/25 05:43:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
    [2012/09/25 05:43:03 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
    [2012/09/25 05:43:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
    [2012/09/25 05:42:03 | 010,524,080 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Bluesman\Desktop\mbam-setup-1.65.0.1400.exe
    [2012/09/25 05:35:27 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Roaming\Malwarebytes
    [2012/09/25 05:35:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
    [2012/09/25 05:28:26 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{968259CE-CF08-41BC-94BE-2FDAB779FE06}
    [2012/09/24 15:37:35 | 002,212,440 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Bluesman\Desktop\TDSSKiller.exe
    [2012/09/24 15:37:35 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\Desktop\tdsskiller
    [2012/09/24 14:26:42 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{6735502A-4CFA-4455-8859-6F91ABA096F3}
    [2012/09/23 19:44:11 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{D8E63098-088A-4EAF-A65F-5605B3AF8164}
    [2012/09/23 08:22:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client
    [2012/09/23 08:22:12 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
    [2012/09/23 07:52:07 | 000,000,000 | -HSD | C] -- C:\Windows\SysWow64\%APPDATA%
    [2012/09/23 07:47:17 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{699C5557-0574-11E2-8271-B8AC6F996F26}
    [2012/09/20 12:53:32 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{844A71EC-7437-43BF-84B3-D03643DF0F5F}
    [2012/09/19 12:46:46 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{0F5B6F81-50DF-4FBC-9C75-A63D7445ACF6}
    [2012/09/16 04:09:36 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{ADE0C4BA-3661-4C42-B54B-C062DAD95CCC}
    [2012/09/15 16:04:09 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group
    [2012/09/15 16:03:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard
    [2012/09/15 14:29:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SystemRequirementsLab
    [2012/09/15 14:29:09 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Roaming\SystemRequirementsLab
    [2012/09/15 10:13:26 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
    [2012/09/15 10:10:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Steam
    [2012/09/15 10:10:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
    [2012/09/15 10:10:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Steam
    [2012/09/15 10:04:25 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{C517D045-4AB9-4A87-99AE-232699B81B41}
    [2012/09/14 12:54:59 | 000,255,352 | ---- | C] (Audible, Inc.) -- C:\Windows\SysWow64\awrdscdc.ax
    [2012/09/14 12:54:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AudibleManager
    [2012/09/14 12:54:45 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Audible
    [2012/09/14 12:54:45 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\Documents\Audible
    [2012/09/14 12:54:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Audible
    [2012/09/14 11:45:19 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{17A2073C-C4B4-42EF-A3DD-41854554AF43}
    [2012/09/13 14:37:41 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{A8459B45-BD30-4F96-8429-8F7CE5FDAE7F}
    [2012/09/13 13:38:09 | 000,604,672 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\stapi64.dll
    [2012/09/13 13:37:27 | 012,350,464 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\idtcpl64.cpl
    [2012/09/13 13:37:27 | 000,564,224 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\idt64mp1.exe
    [2012/09/13 13:37:27 | 000,456,192 | ---- | C] (IDT, Inc.) -- C:\Windows\sttray64.exe
    [2012/09/13 13:37:26 | 003,738,112 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\stlang64.dll
    [2012/09/13 13:35:33 | 000,000,000 | ---D | C] -- C:\Program Files\IDT
    [2012/09/13 10:46:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Mouse and Keyboard Center
    [2012/09/13 10:45:54 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Device Center
    [2012/09/11 14:20:17 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{467F4BB2-FF87-42ED-ACFA-54B14AA518EB}
    [2012/09/10 13:33:31 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{A8FC8CF5-54BF-4C66-8084-29901FB5F97A}
    [2012/09/09 08:36:36 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{9298516F-C007-4518-85C5-0A6869298A60}
    [2012/09/08 10:55:44 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{DDAB4F53-E743-4F8C-B3D4-91C31D564C0A}
    [2012/09/07 13:33:01 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{EB402655-03EE-4595-ADDD-CF4B66C57A6A}
    [2012/09/05 12:33:15 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{EE70D068-5A23-4462-974B-D945F751C6FF}
    [2012/09/04 13:25:25 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{A8B55E16-14EE-43DE-B8F4-D0D2C3015A5B}
    [2012/09/03 20:02:17 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{0569FBA8-3704-4C42-AC57-F4D1059AE728}
    [2012/08/31 11:55:12 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{FA24B57A-518F-4599-8128-9C8FF5C0B0D7}
    [2012/08/30 09:38:37 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{FEB68387-36A9-4B5B-9902-59FDC13B18E3}
    [2012/08/29 12:56:54 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{8F7A452B-E58E-4B17-9EE2-68B3FAB59969}
    [4 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
    [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
    [1 C:\*.tmp files -> C:\*.tmp -> ]
     
  2. 1ronnie1

    1ronnie1 TS Rookie Topic Starter Posts: 27

    ========== Files - Modified Within 30 Days ==========

    [2012/09/26 14:24:42 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Bluesman\Desktop\OTL.exe
    [2012/09/26 14:15:02 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2012/09/26 14:14:39 | 000,023,248 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    [2012/09/26 14:14:39 | 000,023,248 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    [2012/09/26 14:10:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
    [2012/09/26 14:08:20 | 000,000,222 | ---- | M] () -- C:\ProgramData\hpqp.ini
    [2012/09/26 14:07:53 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2012/09/26 14:07:15 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2012/09/26 14:07:07 | 3144,880,128 | -HS- | M] () -- C:\hiberfil.sys
    [2012/09/26 13:58:41 | 000,000,920 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4292630620-794784561-241906710-1000UA.job
    [2012/09/26 13:50:08 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
    [2012/09/26 13:14:39 | 004,757,076 | R--- | M] (Swearware) -- C:\Users\Bluesman\Desktop\ComboFix.exe
    [2012/09/26 06:44:10 | 000,000,512 | ---- | M] () -- C:\Users\Bluesman\Desktop\MBR.dat
    [2012/09/26 06:32:04 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\Bluesman\Desktop\aswMBR.exe
    [2012/09/26 06:20:17 | 001,391,616 | ---- | M] () -- C:\Users\Bluesman\Desktop\RogueKiller.exe
    [2012/09/25 17:31:29 | 000,002,536 | ---- | M] () -- C:\Users\Bluesman\Desktop\Windows 7 USB DVD Download Tool.lnk
    [2012/09/25 06:52:23 | 000,302,592 | ---- | M] () -- C:\Users\Bluesman\Desktop\99um94iv.exe
    [2012/09/25 05:43:04 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    [2012/09/25 05:42:04 | 010,524,080 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Bluesman\Desktop\mbam-setup-1.65.0.1400.exe
    [2012/09/24 16:27:04 | 000,729,706 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
    [2012/09/24 16:27:04 | 000,626,540 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
    [2012/09/24 16:27:04 | 000,107,784 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
    [2012/09/23 19:25:49 | 000,000,346 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForBluesman.job
    [2012/09/23 08:23:02 | 000,013,125 | ---- | M] () -- C:\Users\Bluesman\Desktop\Downloads.lnk
    [2012/09/23 08:22:29 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
    [2012/09/23 08:22:18 | 000,743,856 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
    [2012/09/23 07:58:00 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4292630620-794784561-241906710-1000Core.job
    [2012/09/17 19:25:14 | 002,212,440 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Bluesman\Desktop\TDSSKiller.exe
    [2012/09/15 14:37:46 | 000,015,150 | ---- | M] () -- C:\Windows\SysNative\results.xml
    [2012/09/15 13:50:57 | 000,002,044 | ---- | M] () -- C:\Users\Bluesman\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
    [2012/09/15 10:10:47 | 000,000,917 | ---- | M] () -- C:\Users\Public\Desktop\Steam.lnk
    [2012/09/14 12:55:05 | 000,001,965 | ---- | M] () -- C:\Users\Bluesman\Desktop\Audible Manager.lnk
    [2012/09/14 12:54:59 | 000,255,352 | ---- | M] (Audible, Inc.) -- C:\Windows\SysWow64\awrdscdc.ax
    [2012/09/11 14:55:07 | 000,000,449 | ---- | M] () -- C:\Users\Bluesman\Desktop\CD Drive - Shortcut.lnk
    [2012/09/07 17:04:46 | 000,025,928 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
    [2012/09/05 13:31:36 | 000,002,305 | ---- | M] () -- C:\Users\Bluesman\.budgetrc
    [2012/09/05 13:31:36 | 000,002,120 | ---- | M] () -- C:\Users\Bluesman\Documents\Budget.bgt
    [2012/09/02 05:51:35 | 000,000,489 | ---- | M] () -- C:\Users\Bluesman\Desktop\Power Options - Shortcut.lnk
    [4 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
    [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
    [1 C:\*.tmp files -> C:\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2012/09/26 13:28:21 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
    [2012/09/26 13:28:21 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
    [2012/09/26 13:28:21 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
    [2012/09/26 13:28:21 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
    [2012/09/26 13:28:21 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
    [2012/09/26 06:44:10 | 000,000,512 | ---- | C] () -- C:\Users\Bluesman\Desktop\MBR.dat
    [2012/09/26 06:20:16 | 001,391,616 | ---- | C] () -- C:\Users\Bluesman\Desktop\RogueKiller.exe
    [2012/09/25 17:31:29 | 000,002,536 | ---- | C] () -- C:\Users\Bluesman\Desktop\Windows 7 USB DVD Download Tool.lnk
    [2012/09/25 06:52:22 | 000,302,592 | ---- | C] () -- C:\Users\Bluesman\Desktop\99um94iv.exe
    [2012/09/25 05:43:04 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    [2012/09/23 08:23:02 | 000,013,125 | ---- | C] () -- C:\Users\Bluesman\Desktop\Downloads.lnk
    [2012/09/23 08:22:24 | 000,001,915 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
    [2012/09/15 16:36:12 | 000,001,945 | ---- | C] () -- C:\Windows\epplauncher.mif
    [2012/09/15 16:34:54 | 000,743,856 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
    [2012/09/15 10:10:47 | 000,000,917 | ---- | C] () -- C:\Users\Public\Desktop\Steam.lnk
    [2012/09/14 12:55:05 | 000,001,965 | ---- | C] () -- C:\Users\Bluesman\Desktop\Audible Manager.lnk
    [2012/09/11 14:55:07 | 000,000,449 | ---- | C] () -- C:\Users\Bluesman\Desktop\CD Drive - Shortcut.lnk
    [2012/09/02 05:51:35 | 000,000,489 | ---- | C] () -- C:\Users\Bluesman\Desktop\Power Options - Shortcut.lnk
    [2012/02/05 07:48:56 | 000,007,605 | ---- | C] () -- C:\Users\Bluesman\AppData\Local\Resmon.ResmonCfg
    [2011/10/15 11:58:23 | 000,002,305 | ---- | C] () -- C:\Users\Bluesman\.budgetrc
    [2011/02/10 14:40:41 | 000,217,088 | ---- | C] () -- C:\Windows\SysWow64\qtmlClient.dll
    [2010/12/23 16:39:10 | 000,000,088 | ---- | C] () -- C:\Windows\diug3002hd.dat
    [2010/12/21 14:06:23 | 000,141,138 | ---- | C] () -- C:\Windows\hpwins27.dat
    [2010/12/21 14:06:23 | 000,000,385 | ---- | C] () -- C:\Windows\hpwmdl27.dat
    [2010/11/28 18:51:59 | 000,000,286 | ---- | C] () -- C:\Windows\reimage.ini
    [2010/11/14 13:54:08 | 000,000,709 | ---- | C] () -- C:\Program Files (x86)\GameEXE.gms
    [2010/11/09 12:28:34 | 000,000,526 | ---- | C] () -- C:\Windows\eReg.dat
    [2010/07/19 18:56:18 | 003,229,546 | ---- | C] () -- C:\Program Files\YouTubeDownloaderSetup256.exe
    [2010/03/02 13:07:04 | 000,000,998 | ---- | C] () -- C:\ProgramData\ss.ini
    [2009/12/25 17:23:05 | 000,001,842 | ---- | C] () -- C:\Users\Bluesman\AppData\Roaming\wklnhst.dat
    [2009/09/25 04:51:44 | 000,000,222 | ---- | C] () -- C:\ProgramData\hpqp.ini
    [2009/07/01 12:57:01 | 001,574,616 | -H-- | C] () -- C:\Users\Bluesman\AppData\Local\IconCache (1).db
    [2009/02/08 17:29:58 | 006,815,744 | ---- | C] () -- C:\Users\Bluesman\ntuser (1).dat
    [2007/11/24 11:13:11 | 000,000,127 | ---- | C] () -- C:\Users\Bluesman\AppData\Local\fusioncache.dat
    [2006/04/22 17:43:37 | 000,002,146 | ---- | C] () -- C:\ProgramData\QTSBandwidthCache
    [2005/03/06 08:01:46 | 000,132,608 | ---- | C] () -- C:\Users\Bluesman\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2004/12/12 06:00:19 | 000,002,098 | ---- | C] () -- C:\Users\Bluesman\plugin131_04.trace
    [2004/12/05 15:40:47 | 000,000,994 | ---- | C] () -- C:\Users\Bluesman\AppData\Local\FASTWiz.html
    [2004/12/05 14:42:50 | 000,023,592 | ---- | C] () -- C:\Users\Bluesman\AppData\Local\GDIPFONTCACHEV1 (1).DAT
    [2004/12/05 12:18:18 | 000,000,278 | -HS- | C] () -- C:\Users\Bluesman\ntuser (1).ini

    ========== ZeroAccess Check ==========

    [2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

    [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

    [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

    [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

    [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
    "" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 01:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Apartment

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
    "" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 00:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Apartment

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
    "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 21:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Free

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
    "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 08:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Free

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
    "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 21:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Both

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
    "" = %systemroot%\SysWow64\wbem\wbemess.dll

    ========== LOP Check ==========

    [2009/12/26 11:38:26 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\Amazon
    [2010/12/18 21:23:08 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\Babylon
    [2011/05/15 12:51:41 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\ChessBase
    [2010/01/15 13:38:54 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\COWON
    [2012/07/20 13:06:16 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\Digidesign
    [2012/09/26 14:08:21 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\Dropbox
    [2009/12/26 11:38:27 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\FIFA2003CC
    [2010/08/01 19:15:31 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\flightgear.org
    [2010/08/01 17:13:12 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\fltk.org
    [2009/12/27 10:08:06 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\Gamelab
    [2010/11/05 11:41:26 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\GARMIN
    [2009/12/26 11:38:27 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\GetRightToGo
    [2009/12/26 11:40:04 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\Home Budget For Dummies
    [2009/12/26 11:40:04 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\ICQ
    [2008/05/09 14:32:38 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\ieSpell
    [2009/12/26 11:40:04 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\InterVideo
    [2010/04/03 19:38:24 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\iWin
    [2009/12/26 11:40:07 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\Leadertech
    [2010/12/05 20:11:46 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\Ludia
    [2009/12/26 11:41:17 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\Obsidium
    [2009/12/26 11:41:17 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\OLYMPUS
    [2012/04/27 12:48:33 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\Out of the Park Developments
    [2011/02/10 15:28:25 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\PACE Anti-Piracy
    [2009/12/26 11:41:51 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\RCP 4
    [2009/12/26 11:41:51 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\RCP 5
    [2009/12/26 17:32:44 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\Spearit
    [2009/12/26 11:42:34 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\Sports Interactive
    [2011/07/24 08:16:46 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\Stentec
    [2010/08/02 06:02:14 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\Subversion
    [2012/09/15 14:29:09 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\SystemRequirementsLab
    [2011/03/21 08:17:55 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\Teleca
    [2009/12/25 17:23:05 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\Template
    [2010/03/13 19:50:31 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\UNBALANCE
    [2009/12/26 11:49:33 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\Viewpoint
    [2009/12/26 11:49:35 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\WeatherBug
    [2010/09/19 20:05:53 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\WildTangent
    [2010/10/21 14:03:15 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\Windows Live Writer
    [2009/12/26 11:49:35 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\XM Satellite Radio
    [2009/12/26 17:32:44 | 000,000,000 | ---D | M] -- C:\Users\Christine\AppData\Roaming\Spearit
    [2012/02/20 15:29:38 | 000,000,000 | ---D | M] -- C:\Users\Christine\AppData\Roaming\Teleca
    [2009/12/26 17:32:44 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\Spearit
    [2009/12/26 17:32:44 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\Spearit

    ========== Purity Check ==========



    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 930 bytes -> C:\ProgramData\Microsoft:qndnqNjnujLMh9q0f44UAoplO
    @Alternate Data Stream - 1154 bytes -> C:\ProgramData\Microsoft:p4HXp9bdgPtyRsHckoAU
    @Alternate Data Stream - 1151 bytes -> C:\ProgramData\Microsoft:pIDIoXAt1lFHWnPZNwVOVmM
    @Alternate Data Stream - 1143 bytes -> C:\ProgramData\Microsoft:4o0deNYGV1WKxL9xvDSZJCf
    @Alternate Data Stream - 1099 bytes -> C:\ProgramData\Microsoft:VxEDQco0jg8iSZokjVOAOrfMkzMa
    @Alternate Data Stream - 1042 bytes -> C:\Users\Bluesman\AppData\Local\sds1i34IVairK:SRhb0OWSTCFtytU3lEJVXm

    < End of report >
     
  3. Broni

    Broni Malware Annihilator Posts: 47,616   +267

    Run OTL
    • Under the Custom Scans/Fixes box at the bottom, paste in the following

      Code:
      :OTL
      DRV:64bit: - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys -- (esgiguard)
      O15 - HKU\S-1-5-21-4292630620-794784561-241906710-1000\..Trusted Domains: ([]msn in Computer)
      O16 - DPF: {0DB074F0-617E-4EE9-912C-2965CF2AA5A4} http://download.microsoft.com/download/f/0/2/f02b515c-7076-4cee-bc08-fd6fea594578/VirtualEarth3D.cab (Reg Error: Key error.)
      O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://active.macromedia.com/director/cabs/sw.cab (Reg Error: Key error.)
      O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab (Reg Error: Key error.)
      O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB (Reg Error: Key error.)
      O16 - DPF: {4FAE30E1-EE9C-477D-8D06-BF8D3429B60F} https://www.webiqonline.com/WebIQ/bin/WebIQ.cab (Reg Error: Key error.)
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1147379248038 (Reg Error: Key error.)
      O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
      O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
      O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
      O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB (Reg Error: Key error.)
      O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
      O16 - DPF: Yahoo! Poker http://download.games.yahoo.com/games/clients/y/pt1_x.cab (Reg Error: Key error.)
      O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\Windows\SysWOW64\wiascr.dll File not found
      O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
      [2012/09/26 01:27:27 | 000,000,000 | ---D | C] -- C:\FRST
      [2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
      
      [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
      
      [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
      
      [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
      
      [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
      
      [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
      "" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 01:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
      "ThreadingModel" = Apartment
      
      [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
      "" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 00:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
      "ThreadingModel" = Apartment
      
      [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
      "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 21:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
      "ThreadingModel" = Free
      
      [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
      "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 08:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
      "ThreadingModel" = Free
      
      [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
      "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 21:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
      "ThreadingModel" = Both
      
      [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
      "" = %systemroot%\SysWow64\wbem\wbemess.dll
      [2009/12/26 11:49:33 | 000,000,000 | ---D | M] -- C:\Users\Bluesman\AppData\Roaming\Viewpoint
      @Alternate Data Stream - 930 bytes -> C:\ProgramData\Microsoft:qndnqNjnujLMh9q0f44UAoplO
      @Alternate Data Stream - 1154 bytes -> C:\ProgramData\Microsoft:p4HXp9bdgPtyRsHckoAU
      @Alternate Data Stream - 1151 bytes -> C:\ProgramData\Microsoft:pIDIoXAt1lFHWnPZNwVOVmM
      @Alternate Data Stream - 1143 bytes -> C:\ProgramData\Microsoft:4o0deNYGV1WKxL9xvDSZJCf
      @Alternate Data Stream - 1099 bytes -> C:\ProgramData\Microsoft:VxEDQco0jg8iSZokjVOAOrfMkzMa
      @Alternate Data Stream - 1042 bytes -> C:\Users\Bluesman\AppData\Local\sds1i34IVairK:SRhb0OWSTCFtytU3lEJVXm
      
      :Commands
      [purity]
      [emptytemp]
      [emptyjava]
      [emptyflash]
      [Reboot]
      
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.

    NOTE. If for any reason OTL stalls (most likely at "killing processes..." step) run the fix from safe mode.

    ===================================

    Last scans...

    1. Download Security Check from HERE, and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

      NOTE SecurityCheck may produce some false warning(s), so leave the results reading to me.

    2. Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
    • Make sure the following options are checked:
      • Internet Services
      • Windows Firewall
      • System Restore
      • Security Center
      • Windows Update
      • Windows Defender
    • Press "Scan".
    • It will create a log (FSS.txt) in the same directory the tool is run.
    • Please copy and paste the log to your reply.

    3. Please download AdwCleaner by Xplode onto your desktop.
    • Close all open programs and internet browsers.
    • Double click on adwcleaner.exe to run the tool.
    • Click on Delete.
    • Confirm each time with Ok.
    • Your computer will be rebooted automatically. A text file will open after the restart.
    • Please post the contents of that logfile with your next reply.
    • You can find the logfile at C:\AdwCleaner[S1].txt as well.

    Next...

    • Double click on adwcleaner.exe to run the tool.
    • Click on Uninstall.
    • Confirm with yes.

    4. Download Temp File Cleaner (TFC)
    Alternate download: http://www.itxassociates.com/OT-Tools/TFC.exe
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.

    5. Please run a free online scan with the ESET Online Scanner

    • Disable your antivirus program
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • Accept any security warnings from your browser.
    • Check Scan archives
    • Click Start
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, click on List of found threats
    • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • NOTE. If Eset won't find any threats, it won't produce any log.
     
  4. 1ronnie1

    1ronnie1 TS Rookie Topic Starter Posts: 27

    All processes killed
    ========== OTL ==========
    Service esgiguard stopped successfully!
    Service esgiguard deleted successfully!
    File C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys not found.
    Registry value HKEY_USERS\S-1-5-21-4292630620-794784561-241906710-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\\ deleted successfully.
    Starting removal of ActiveX control {0DB074F0-617E-4EE9-912C-2965CF2AA5A4}
    C:\WINDOWS\Downloaded Program Files\VE3DInstall.inf not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{0DB074F0-617E-4EE9-912C-2965CF2AA5A4}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0DB074F0-617E-4EE9-912C-2965CF2AA5A4}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{0DB074F0-617E-4EE9-912C-2965CF2AA5A4}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0DB074F0-617E-4EE9-912C-2965CF2AA5A4}\ not found.
    Starting removal of ActiveX control {166B1BCA-3F9C-11CF-8075-444553540000}
    C:\WINDOWS\Downloaded Program Files\erma.inf not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{166B1BCA-3F9C-11CF-8075-444553540000}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{166B1BCA-3F9C-11CF-8075-444553540000}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{166B1BCA-3F9C-11CF-8075-444553540000}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{166B1BCA-3F9C-11CF-8075-444553540000}\ not found.
    Starting removal of ActiveX control {233C1507-6A77-46A4-9443-F871F945D258}
    C:\WINDOWS\Downloaded Program Files\swdir.inf not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{233C1507-6A77-46A4-9443-F871F945D258}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{233C1507-6A77-46A4-9443-F871F945D258}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{233C1507-6A77-46A4-9443-F871F945D258}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{233C1507-6A77-46A4-9443-F871F945D258}\ not found.
    Starting removal of ActiveX control {33564D57-0000-0010-8000-00AA00389B71}
    C:\WINDOWS\Downloaded Program Files\WMV9VCM.inf not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{33564D57-0000-0010-8000-00AA00389B71}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{33564D57-0000-0010-8000-00AA00389B71}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{33564D57-0000-0010-8000-00AA00389B71}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{33564D57-0000-0010-8000-00AA00389B71}\ not found.
    Starting removal of ActiveX control {4FAE30E1-EE9C-477D-8D06-BF8D3429B60F}
    C:\WINDOWS\Downloaded Program Files\WebIQ.inf not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{4FAE30E1-EE9C-477D-8D06-BF8D3429B60F}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4FAE30E1-EE9C-477D-8D06-BF8D3429B60F}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{4FAE30E1-EE9C-477D-8D06-BF8D3429B60F}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4FAE30E1-EE9C-477D-8D06-BF8D3429B60F}\ not found.
    Starting removal of ActiveX control {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
    C:\WINDOWS\Downloaded Program Files\muweb.inf not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}\ not found.
    Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
    C:\WINDOWS\Downloaded Program Files\erma.inf not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
    Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
    C:\Windows\Downloaded Program Files\gp.inf not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    File Animation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab not found.
    Starting removal of ActiveX control DirectAnimation Java Classes
    Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\DirectAnimation Java Classes\DownloadInformation\\INF .
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\DirectAnimation Java Classes\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\DirectAnimation Java Classes\ not found.
    Starting removal of ActiveX control Garmin Communicator Plug-In
    Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Garmin Communicator Plug-In\DownloadInformation\\INF .
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Garmin Communicator Plug-In\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Garmin Communicator Plug-In\ not found.
    File oft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab not found.
    Starting removal of ActiveX control Microsoft XML Parser for Java
    Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\DownloadInformation\\INF .
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Microsoft XML Parser for Java\ not found.
    Starting removal of ActiveX control Yahoo! Poker
    Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Yahoo! Poker\DownloadInformation\\INF .
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Yahoo! Poker\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Yahoo! Poker\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wia\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE}\ deleted successfully.
    File {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\Windows\SysWOW64\wiascr.dll File not found not found.
    Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{AEB6717E-7E19-11d0-97EE-00C04FD91972} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\ not found.
    C:\FRST\Quarantine\$c9e709fff391860c25d75ea7dc9c281b folder moved successfully.
    Folder move failed. C:\FRST\Quarantine scheduled to be moved on reboot.
    C:\FRST\Logs folder moved successfully.
    C:\FRST\Hives folder moved successfully.
    C:\FRST folder moved successfully.
    C:\Windows\assembly\Desktop.ini moved successfully.
    File EY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 not found.
    File EY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] not found.
    File EY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 not found.
    File EY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] not found.
    File EY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 not found.
    File EY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] not found.
    Folder EY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64\ not found.
    Folder EY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]\ not found.
    Folder EY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64\ not found.
    Folder EY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]\ not found.
    C:\Users\Bluesman\AppData\Roaming\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_03 folder moved successfully.
    C:\Users\Bluesman\AppData\Roaming\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_02 folder moved successfully.
    C:\Users\Bluesman\AppData\Roaming\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_01 folder moved successfully.
    C:\Users\Bluesman\AppData\Roaming\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_00 folder moved successfully.
    C:\Users\Bluesman\AppData\Roaming\Viewpoint\Viewpoint Media Player\Resources folder moved successfully.
    C:\Users\Bluesman\AppData\Roaming\Viewpoint\Viewpoint Media Player folder moved successfully.
    C:\Users\Bluesman\AppData\Roaming\Viewpoint folder moved successfully.
    ADS C:\ProgramData\Microsoft:qndnqNjnujLMh9q0f44UAoplO deleted successfully.
    ADS C:\ProgramData\Microsoft:p4HXp9bdgPtyRsHckoAU deleted successfully.
    ADS C:\ProgramData\Microsoft:pIDIoXAt1lFHWnPZNwVOVmM deleted successfully.
    ADS C:\ProgramData\Microsoft:4o0deNYGV1WKxL9xvDSZJCf deleted successfully.
    ADS C:\ProgramData\Microsoft:VxEDQco0jg8iSZokjVOAOrfMkzMa deleted successfully.
    ADS C:\Users\Bluesman\AppData\Local\sds1i34IVairK:SRhb0OWSTCFtytU3lEJVXm deleted successfully.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: AppData
    ->Temp folder emptied: 0 bytes

    User: Bluesman
    ->Temp folder emptied: 10551 bytes
    ->Temporary Internet Files folder emptied: 4263445236 bytes
    ->Java cache emptied: 141476363 bytes
    ->FireFox cache emptied: 80197774 bytes
    ->Google Chrome cache emptied: 387096509 bytes
    ->Flash cache emptied: 1876682 bytes

    User: Christine
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 304923 bytes
    ->Java cache emptied: 591 bytes
    ->FireFox cache emptied: 15981273 bytes
    ->Flash cache emptied: 45208 bytes

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 67 bytes
    ->Flash cache emptied: 41044 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: LocalService
    ->Temp folder emptied: 0 bytes

    User: NetworkService
    ->Temp folder emptied: 0 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 1714252 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 20968 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67496 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 4,666.00 mb


    [EMPTYJAVA]

    User: All Users

    User: AppData

    User: Bluesman
    ->Java cache emptied: 0 bytes

    User: Christine
    ->Java cache emptied: 0 bytes

    User: Default

    User: Default User

    User: LocalService

    User: NetworkService

    User: Public

    Total Java Files Cleaned = 0.00 mb


    [EMPTYFLASH]

    User: All Users

    User: AppData

    User: Bluesman
    ->Flash cache emptied: 0 bytes

    User: Christine
    ->Flash cache emptied: 0 bytes

    User: Default
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Flash cache emptied: 0 bytes

    User: LocalService

    User: NetworkService

    User: Public

    Total Flash Files Cleaned = 0.00 mb


    OTL by OldTimer - Version 3.2.68.0 log created on 09262012_145527

    Files\Folders moved on Reboot...
    File\Folder C:\FRST\Quarantine not found!
    C:\Users\Bluesman\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

    PendingFileRenameOperations files...

    Registry entries deleted on Reboot...
     
  5. 1ronnie1

    1ronnie1 TS Rookie Topic Starter Posts: 27

    Results of screen317's Security Check version 0.99.51
    Windows 7 Service Pack 1 x64 (UAC is enabled)
    Internet Explorer 9
    ``````````````Antivirus/Firewall Check:``````````````
    Windows Firewall Enabled!
    Microsoft Security Essentials
    Antivirus up to date!
    `````````Anti-malware/Other Utilities Check:`````````
    Spybot - Search & Destroy
    Malwarebytes Anti-Malware version 1.65.0.1400
    JavaFX 2.1.1
    Java(TM) 6 Update 30
    Java(TM) 7 Update 5
    Java version out of Date!
    Adobe Flash Player 11.4.402.265
    Adobe Reader 9 Adobe Reader out of Date!
    Mozilla Firefox (15.0.1)
    Google Chrome 21.0.1180.83
    Google Chrome 21.0.1180.89
    ````````Process Check: objlist.exe by Laurent````````
    Microsoft Security Essentials msseces.exe
    Windows Defender MSMpEng.exe
    `````````````````System Health check`````````````````
    Total Fragmentation on Drive C: 7%
    ````````````````````End of Log``````````````````````
     
  6. 1ronnie1

    1ronnie1 TS Rookie Topic Starter Posts: 27

    Farbar Service Scanner Version: 19-09-2012
    Ran by Bluesman (administrator) on 26-09-2012 at 15:16:44
    Running from "C:\Users\Bluesman\Desktop"
    Windows 7 Home Premium Service Pack 1 (X64)
    Boot Mode: Normal
    ****************************************************************

    Internet Services:
    ============

    Connection Status:
    ==============
    Localhost is accessible.
    LAN connected.
    Google IP is accessible.
    Google.com is accessible.
    Yahoo IP is accessible.
    Yahoo.com is accessible.


    Windows Firewall:
    =============

    Firewall Disabled Policy:
    ==================


    System Restore:
    ============

    System Restore Disabled Policy:
    ========================


    Action Center:
    ============

    Windows Update:
    ============

    Windows Autoupdate Disabled Policy:
    ============================


    Windows Defender:
    ==============
    WinDefend Service is not running. Checking service configuration:
    The start type of WinDefend service is set to Demand. The default start type is Auto.
    The ImagePath of WinDefend service is OK.
    The ServiceDll of WinDefend service is OK.


    Windows Defender Disabled Policy:
    ==========================
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
    "DisableAntiSpyware"=DWORD:1


    Other Services:
    ==============


    File Check:
    ========
    C:\Windows\System32\nsisvc.dll => MD5 is legit
    C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
    C:\Windows\System32\dhcpcore.dll => MD5 is legit
    C:\Windows\System32\drivers\afd.sys => MD5 is legit
    C:\Windows\System32\drivers\tdx.sys => MD5 is legit
    C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
    C:\Windows\System32\dnsrslvr.dll => MD5 is legit
    C:\Windows\System32\mpssvc.dll => MD5 is legit
    C:\Windows\System32\bfe.dll => MD5 is legit
    C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
    C:\Windows\System32\SDRSVC.dll => MD5 is legit
    C:\Windows\System32\vssvc.exe => MD5 is legit
    C:\Windows\System32\wscsvc.dll => MD5 is legit
    C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
    C:\Windows\System32\wuaueng.dll => MD5 is legit
    C:\Windows\System32\qmgr.dll => MD5 is legit
    C:\Windows\System32\es.dll => MD5 is legit
    C:\Windows\System32\cryptsvc.dll => MD5 is legit
    C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\System32\rpcss.dll => MD5 is legit


    **** End of log ****
     
  7. 1ronnie1

    1ronnie1 TS Rookie Topic Starter Posts: 27

    # AdwCleaner v2.003 - Logfile created 09/26/2012 at 15:19:29
    # Updated 23/09/2012 by Xplode
    # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
    # User : Bluesman - BLUESMAN-PC
    # Boot Mode : Normal
    # Running from : C:\Users\Bluesman\Desktop\adwcleaner.exe
    # Option [Delete]


    ***** [Services] *****

    Stopped & Deleted : Web Assistant Updater

    ***** [Files / Folders] *****

    File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml
    File Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk
    File Deleted : C:\user.js
    File Deleted : C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\cmzlwot0.Rich\searchplugins\MyStart Search.xml
    Folder Deleted : C:\Program Files (x86)\Babylon
    Folder Deleted : C:\Program Files (x86)\BabylonToolbar
    Folder Deleted : C:\Program Files (x86)\Conduit
    Folder Deleted : C:\Program Files (x86)\Freecorder
    Folder Deleted : C:\Program Files (x86)\Ilivid
    Folder Deleted : C:\Program Files\Web Assistant
    Folder Deleted : C:\ProgramData\Babylon
    Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Babylon
    Folder Deleted : C:\ProgramData\Trymedia
    Folder Deleted : C:\ProgramData\Viewpoint
    Folder Deleted : C:\Users\Bluesman\AppData\Local\Babylon
    Folder Deleted : C:\Users\Bluesman\AppData\LocalLow\Conduit
    Folder Deleted : C:\Users\Bluesman\AppData\LocalLow\Freecorder
    Folder Deleted : C:\Users\Bluesman\AppData\Roaming\Babylon
    Folder Deleted : C:\Users\Bluesman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freecorder
    Folder Deleted : C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\cmzlwot0.Rich\extensions\ffxtlbr@incredibar.com
    Folder Deleted : C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\f8iip4f0.default\extensions\ffxtlbr@incredibar.com
    Folder Deleted : C:\Users\Christine\AppData\LocalLow\Conduit
    Folder Deleted : C:\Users\Christine\AppData\LocalLow\Freecorder
    Folder Deleted : C:\Windows\Freecorder

    ***** [Registry] *****

    Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
    Key Deleted : HKCU\Software\AppDataLow\Software\Freecorder
    Key Deleted : HKCU\Software\AppDataLow\Toolbar
    Key Deleted : HKCU\Software\Ask&Record
    Key Deleted : HKCU\Software\Conduit
    Key Deleted : HKCU\Software\Headlight
    Key Deleted : HKCU\Software\IM
    Key Deleted : HKCU\Software\ImInstaller
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1392B8D2-5C05-419F-A8F6-B9F15A596612}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{03F998B2-0E00-11D3-A498-00104B6EB52E}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1392B8D2-5C05-419F-A8F6-B9F15A596612}
    Key Deleted : HKCU\Software\Softonic
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B}
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{CFE8AAFD-A0F3-4329-84E9-6B679EC93EC2}
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\Extension.DLL
    Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane
    Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
    Key Deleted : HKLM\SOFTWARE\Classes\esrv.IncredibarESrvc
    Key Deleted : HKLM\SOFTWARE\Classes\esrv.IncredibarESrvc.1
    Key Deleted : HKLM\SOFTWARE\Classes\I
    Key Deleted : HKLM\SOFTWARE\Classes\IncredibarApp.appCore
    Key Deleted : HKLM\SOFTWARE\Classes\IncredibarApp.appCore.1
    Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT1060933
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{48C9C8B0-A546-46C1-A81F-47A31E623E9D}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{CFE8AAFD-A0F3-4329-84E9-6B679EC93EC2}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
    Key Deleted : HKLM\Software\Conduit
    Key Deleted : HKLM\Software\Freecorder
    Key Deleted : HKLM\Software\Freeze.com
    Key Deleted : HKLM\Software\ImInstaller
    Key Deleted : HKLM\Software\incredibar.com
    Key Deleted : HKLM\Software\MetaStream
    Key Deleted : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{03F998B2-0E00-11D3-A498-00104B6EB52E}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASAPI32
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASMANCS
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\mywebsearch bar uninstall
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{03F998B2-0E00-11D3-A498-00104B6EB52E}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E57F2472-04C3-43BF-B464-EC443B809E07}
    Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@viewpoint.com/VMP
    Key Deleted : HKLM\Software\Web Assistant
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{1392B8D2-5C05-419F-A8F6-B9F15A596612}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{761F6A83-F007-49E4-8EAC-CDB6808EF06F}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{97D69524-BB57-4185-9C7F-5F05593B771A}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{C01315C7-B4E2-4864-B43D-5FAFC414D179}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{C1545464-C77C-4130-A572-1C619E2895FE}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E57F2472-04C3-43BF-B464-EC443B809E07}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{ED0E67AD-926C-4008-87E5-03CF72AA2A7E}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{EF7FEC6D-451B-4452-9D26-7E10C6B5DB6E}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{22B0769F-794B-4422-AC84-47B123C8986D}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{255E0B2A-D747-4EEF-B7CE-159D73A3656D}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{28ED590D-F5ED-4E05-A87F-1D759F1C6169}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{45D5B93F-E2ED-4AF2-915E-DCDDBDA8C33C}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{771B99AB-636F-4A11-9039-8DFEB927B061}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A8321AA2-2227-40C7-8525-6C2F4E1B0EBE}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{AA41A731-6814-4A70-A6F1-C0A20FBBFBD5}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{ABBB8A9E-D8AF-40D1-94BE-5175077465FC}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{BF737694-56F6-46FA-9FDC-FA99A5B25FAD}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{CFCD164E-8AC9-478E-9ECC-B616A932016C}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D5961CC0-B442-4567-8030-67E241EF4CC2}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E450067F-1C93-41A7-928E-07E5C2EEC680}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{F977D9F2-4BDC-44A6-B508-7C0284C61EED}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{74C36554-31F0-49DD-8857-ED6A64DF45BE}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1392B8D2-5C05-419F-A8F6-B9F15A596612}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Freecorder Toolbar
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\incredibar
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{22B0769F-794B-4422-AC84-47B123C8986D}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{255E0B2A-D747-4EEF-B7CE-159D73A3656D}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{28ED590D-F5ED-4E05-A87F-1D759F1C6169}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{45D5B93F-E2ED-4AF2-915E-DCDDBDA8C33C}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{771B99AB-636F-4A11-9039-8DFEB927B061}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A8321AA2-2227-40C7-8525-6C2F4E1B0EBE}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AA41A731-6814-4A70-A6F1-C0A20FBBFBD5}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ABBB8A9E-D8AF-40D1-94BE-5175077465FC}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BF737694-56F6-46FA-9FDC-FA99A5B25FAD}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{CFCD164E-8AC9-478E-9ECC-B616A932016C}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D5961CC0-B442-4567-8030-67E241EF4CC2}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E450067F-1C93-41A7-928E-07E5C2EEC680}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F977D9F2-4BDC-44A6-B508-7C0284C61EED}
    Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1
    Key Deleted : HKLM\SOFTWARE\Web Assistant
    Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{1392B8D2-5C05-419F-A8F6-B9F15A596612}]
    Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{1392B8D2-5C05-419F-A8F6-B9F15A596612}]
    Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{1392B8D2-5C05-419F-A8F6-B9F15A596612}]
    Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}]
    Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{1392B8D2-5C05-419F-A8F6-B9F15A596612}]

    ***** [Internet Browsers] *****

    -\\ Internet Explorer v9.0.8112.16421

    Restored : [HKCU\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
    Restored : [HKCU\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
    Restored : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
    Restored : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
    Restored : [HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
    Restored : [HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
    Restored : [HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]

    -\\ Mozilla Firefox v15.0.1 (en-US)

    Profile name : default
    File : C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\f8iip4f0.default\prefs.js

    C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\f8iip4f0.default\user.js ... Deleted !

    [OK] File is clean.

    Profile name : Rich [Profil par défaut]
    File : C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\cmzlwot0.Rich\prefs.js

    C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\cmzlwot0.Rich\user.js ... Deleted !

    Deleted : user_pref("extensions.incredibar_i.aflt", "orgnl");
    Deleted : user_pref("extensions.incredibar_i.dfltLng", "");
    Deleted : user_pref("extensions.incredibar_i.did", "10643");
    Deleted : user_pref("extensions.incredibar_i.excTlbr", false);
    Deleted : user_pref("extensions.incredibar_i.id", "80c00424000000000000001e64809d93");
    Deleted : user_pref("extensions.incredibar_i.installerproductid", "26");
    Deleted : user_pref("extensions.incredibar_i.instlDay", "15516");
    Deleted : user_pref("extensions.incredibar_i.instlRef", "");
    Deleted : user_pref("extensions.incredibar_i.ms_url_id", "");
    Deleted : user_pref("extensions.incredibar_i.newTab", false);
    Deleted : user_pref("extensions.incredibar_i.ppd", "1");
    Deleted : user_pref("extensions.incredibar_i.prdct", "incredibar");
    Deleted : user_pref("extensions.incredibar_i.productid", "26");
    Deleted : user_pref("extensions.incredibar_i.prtnrId", "Incredibar");
    Deleted : user_pref("extensions.incredibar_i.smplGrp", "none");
    Deleted : user_pref("extensions.incredibar_i.tlbrId", "base");
    Deleted : user_pref("extensions.incredibar_i.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6PQBuVHlh7&loc=IB[...]
    Deleted : user_pref("extensions.incredibar_i.upn2", "6PQBuVHlh7");
    Deleted : user_pref("extensions.incredibar_i.upn2n", "92543118567216433");
    Deleted : user_pref("extensions.incredibar_i.vrsn", "1.5.11.14");
    Deleted : user_pref("extensions.incredibar_i.vrsnTs", "1.5.11.1421:14:43");
    Deleted : user_pref("extensions.incredibar_i.vrsni", "1.5.11.14");

    Profile name : default
    File : C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\slul7tep.default\prefs.js

    Deleted : user_pref("extensions.newAddons", "ffxtlbr@babylon.com");

    -\\ Google Chrome v21.0.1180.89

    File : C:\Users\Bluesman\AppData\Local\Google\Chrome\User Data\Default\Preferences

    [OK] File is clean.

    *************************

    AdwCleaner[S1].txt - [13760 octets] - [26/09/2012 15:19:29]

    ########## EOF - C:\AdwCleaner[S1].txt - [13821 octets] ##########
     
  8. 1ronnie1

    1ronnie1 TS Rookie Topic Starter Posts: 27

    C:\Program Files (x86)\Laplink\PCmover\ThirdParty\registrybooster.exe a variant of Win32/RegistryBooster application
    C:\Qoobox\Quarantine\C\Users\Bluesman\AppData\Roaming\casrt.dll.vir a variant of Win32/Medfos.DT trojan
    C:\Users\Bluesman\AppData\Local\Downloaded Installations\{D5D6261A-38A4-4559-8195-8655505D1F7C}\PCmover Professional.msi a variant of Win32/RegistryBooster application
    C:\Users\Bluesman\Documents\My Downloads\Setup_FreeConverter.exe Win32/Toolbar.Widgi application
    C:\Users\Bluesman\Downloads\cnet_BudgetCalendar_exe.exe a variant of Win32/InstallCore.D application
    C:\Users\Public\Downloads\JEOPARDY_Setup-dm[2].exe a variant of Win32/Adware.Trymedia.A application
    C:\Windows\Installer\c017ae.msi a variant of Win32/RegistryBooster application
    C:\_OTL\MovedFiles\09262012_145527\C_\FRST\Quarantine\dridl.dll a variant of Win32/Medfos.DV trojan
     
  9. Broni

    Broni Malware Annihilator Posts: 47,616   +267

    Update Adobe Reader

    You can download it from http://www.adobe.com/products/acrobat/readstep2.html
    After installing the latest Adobe Reader, uninstall all previous versions (if present).
    Note. If you already have Adobe Photoshop® Album Starter Edition installed or do not wish to have it installed UNcheck the box which says Also Download Adobe Photoshop® Album Starter Edition.

    Alternatively, you can uninstall Adobe Reader (33.5 MB), download and install Foxit PDF Reader(3.5MB) from HERE.
    It's a much smaller file to download and uses a lot less resources than Adobe Reader.
    Note: When installing FoxitReader, make sure to UN-check any pre-checked toolbar, or any other garbage.

    ============================

    1. Update your Java version here: http://www.java.com/en/download/installed.jsp

    Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

    Note 2: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

    2. Now, we need to remove old Java version and its remnants...

    Download JavaRa to your desktop and unzip it.
    • Run JavaRa.exe (Vista users! Right click on JavaRa.exe, click Run As Administrator), pick the language of your choice and click Select. Then click Remove Older Versions.
    • Accept any prompts.
    • Do NOT post JavaRa log.
    ==============================

    Your computer is clean [​IMG]

    1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

    Run OTL

    • Under the Custom Scans/Fixes box at the bottom, paste in the following:

    Code:
    :OTL
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [emptyjava]
    [CLEARALLRESTOREPOINTS]
    [Reboot]
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Post resulting log.

    2. Now, we'll remove all tools, we used during our cleaning process

    Clean up with OTL:

    • Double-click OTL.exe to start the program.
    • Close all other programs apart from OTL as this step will require a reboot
    • On the OTL main screen, press the CLEANUP button
    • Say Yes to the prompt and then allow the program to reboot your computer.

    If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

    3. Make sure, Windows Updates are current.

    4. If any trojans, rootkits or bootkits were listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    7. Run Temporary File Cleaner (TFC) weekly.

    8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    10. (Windows XP only) Run defrag at your convenience.

    11. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

    12. Read:
    How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html
    Simple and easy ways to keep your computer safe and secure on the Internet: http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/

    13. Please, let me know, how your computer is doing.
     
  10. 1ronnie1

    1ronnie1 TS Rookie Topic Starter Posts: 27

    All processes killed
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: AppData
    ->Temp folder emptied: 0 bytes

    User: Bluesman
    ->Temp folder emptied: 1098276 bytes
    ->Temporary Internet Files folder emptied: 540067 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 28538515 bytes
    ->Google Chrome cache emptied: 0 bytes
    ->Flash cache emptied: 492 bytes

    User: Christine
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: LocalService
    ->Temp folder emptied: 0 bytes

    User: NetworkService
    ->Temp folder emptied: 0 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 2336 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 29.00 mb


    [EMPTYFLASH]

    User: All Users

    User: AppData

    User: Bluesman
    ->Flash cache emptied: 0 bytes

    User: Christine
    ->Flash cache emptied: 0 bytes

    User: Default
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Flash cache emptied: 0 bytes

    User: LocalService

    User: NetworkService

    User: Public

    Total Flash Files Cleaned = 0.00 mb


    [EMPTYJAVA]

    User: All Users

    User: AppData

    User: Bluesman
    ->Java cache emptied: 0 bytes

    User: Christine
    ->Java cache emptied: 0 bytes

    User: Default

    User: Default User

    User: LocalService

    User: NetworkService

    User: Public

    Total Java Files Cleaned = 0.00 mb

    System Restore Service not available.

    OTL by OldTimer - Version 3.2.68.0 log created on 09262012_193820

    Files\Folders moved on Reboot...
    C:\Users\Bluesman\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

    PendingFileRenameOperations files...

    Registry entries deleted on Reboot...
     
  11. Broni

    Broni Malware Annihilator Posts: 47,616   +267

    The issue seems to be resolved.
     
     


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.