Here is the log from HitmanPro (it didn't give me an option to save to an .xml, simply gave me a 'save log' option.
Code:
HitmanPro 3.7.0.185
www.hitmanpro.com
Computer name . . . . : ADMıN-PC
Windows . . . . . . . : 6.1.1.7601.X64/8
User name . . . . . . : admın-pc\admın
UAC . . . . . . . . . : Disabled
License . . . . . . . : Trial (30 days left)
Scan date . . . . . . : 2013-01-12 02:20:00
Scan mode . . . . . . : Normal
Scan duration . . . . : 3m 53s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : No
Threats . . . . . . . : 4
Traces . . . . . . . : 129
Objects scanned . . . : 1,428,449
Files scanned . . . . : 16,835
Remnants scanned . . : 512,374 files / 899,240 keys
Malware _____________________________________________________________________
C:\Users\admın\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7M6IU78Z\libpdcurses[1].dll -> Quarantined
Size . . . . . . . : 87,054 bytes
Age . . . . . . . : 1.1 days (2013-01-11 00:02:32)
Entropy . . . . . : 6.5
SHA-256 . . . . . : 94995B0560D2CCDA7951252397EB152B499454746B75D03479BBFA551DEF41E4
> Ikarus . . . . . . : Trojan-PWS.Keylogger!IK
Fuzzy . . . . . . : 108.0
C:\Users\admın\AppData\Local\Temp\libpdcurses.dll -> Quarantined
Size . . . . . . . : 87,054 bytes
Age . . . . . . . : 1.1 days (2013-01-11 00:02:32)
Entropy . . . . . : 6.5
SHA-256 . . . . . : 94995B0560D2CCDA7951252397EB152B499454746B75D03479BBFA551DEF41E4
> Ikarus . . . . . . : Trojan-PWS.Keylogger!IK
Fuzzy . . . . . . : 114.0
C:\Users\admın\Downloads\AngryBirdsStarWars\Patch\angry.birds.all-patch.offline.v1.3.exe -> Quarantined
Size . . . . . . . : 70,656 bytes
Age . . . . . . . : 60.5 days (2012-11-12 14:12:19)
Entropy . . . . . : 7.9
SHA-256 . . . . . : 72F98D7F31000B4CA8197B0DFB94E5254F0E7F3A7423B75A6C684EE833507A2F
> Ikarus . . . . . . : Trojan.Win32.Spy!IK
Fuzzy . . . . . . : 114.0
C:\Users\admın\Downloads\Antares Autotune Evo VST RTAS v6.0.9 PROPER -AiR\setup.exe -> Quarantined
Size . . . . . . . : 4,938,752 bytes
Age . . . . . . . : 195.4 days (2012-06-30 17:35:21)
Entropy . . . . . : 8.0
SHA-256 . . . . . : 9A5CED4D63CF26F01D3B88E3F1062A8CA72DEEC4A52249557868853FF5C53199
Description . . . :
Version . . . . . : 0.0.0.0
Copyright . . . . :
> Ikarus . . . . . . : Trojan-Downloader.Win32.Delf!IK
Fuzzy . . . . . . : 109.0
Suspicious files ____________________________________________________________
C:\Users\admın\AppData\Local\Temp\svchost.exe -> Quarantined
Size . . . . . . . : 370,702 bytes
Age . . . . . . . : 1.1 days (2013-01-11 00:02:31)
Entropy . . . . . : 6.4
SHA-256 . . . . . : BE795C17358B01204E090B57A4E775BA65220191E8201BD2A1B784320D10C3AE
Source URL . . . . : hxxp://1v401.chickenkiller.com/v4/cgminer.exe
Running processes : 3544
Fuzzy . . . . . . : 27.0
Program is impersonating a common Windows system file. This is typical for malware.
The file is downloaded from the Internet to this computer.
Program is running but currently exposes no human-computer interface (GUI).
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Time indicates that the file appeared recently on this computer.
The file is in use by one or more active processes.
Potential Unwanted Programs _________________________________________________
C:\Program Files (x86)\BabylonToolbar\ (Babylon)
C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\ (Babylon)
C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\ (Babylon)
C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarApp.dll (Babylon)
Size . . . . . . . : 330,240 bytes
Age . . . . . . . : 194.6 days (2012-07-01 12:27:38)
Entropy . . . . . : 6.3
SHA-256 . . . . . : 52CAA8C32555E05191FED8187D74B20C916F44789693CC0B70D7BB09783844ED
Product . . . . . : Babylon Toolbar
Publisher . . . . : Babylon Ltd.
Description
Version . . . . . : 1.4.35.0
Copyright . . . . : (c) Babylon Ltd. All rights reserved.
Fuzzy . . . . . . : 0.0
C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarsrv.exe (Babylon)
Size . . . . . . . : 347,648 bytes
Age . . . . . . . : 194.6 days (2012-07-01 12:27:39)
Entropy . . . . . : 6.3
SHA-256 . . . . . : 27F90D20668D9CA40555C086A5123240022DA0097EE0B3EE766D8FCFCE078EF8
Product . . . . . : Babylon Toolbar
Publisher . . . . : Babylon Ltd.
Description
Version . . . . . : 1.4.35.0
Copyright . . . . : (c) Babylon Ltd. All rights reserved.
Fuzzy . . . . . . : 0.0
C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\ (Babylon)
C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll (Babylon)
Size . . . . . . . : 270,960 bytes
Age . . . . . . . : 194.6 days (2012-07-01 12:27:38)
Entropy . . . . . : 6.3
SHA-256 . . . . . : AC6AB10609C702F2ACEDC58E83AFD5E4BD9855071DE8A39CEF31D314F10A09B1
Product . . . . . : Babylon Toolbar
Publisher . . . . : Babylon BHO
Description
Version . . . . . : 1.4.35.0
Copyright . . . . : (c) Babylon Ltd. All rights reserved.
RSA Key Size . . . : 2048
Authenticode . . . : Valid
Fuzzy . . . . . . : -7.0
C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\uninstall.exe (Babylon)
Size . . . . . . . : 82,870 bytes
Age . . . . . . . : 194.6 days (2012-07-01 12:27:39)
Entropy . . . . . : 7.6
SHA-256 . . . . . : CD7D3E9D725511770BC29F27EC73D6D875B5F423896E3A5AF44482B8BD3BCB22
Product . . . . . : BabylonToolbar
Publisher . . . . : BabylonToolbar
Version . . . . . : 1.5.3.17
Fuzzy . . . . . . : 8.0
C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\BabylonTB.xpi (Babylon)
C:\Users\admin\AppData\LocalLow\BabylonToolbar\ (Babylon)
C:\Users\admın\AppData\Roaming\Babylon\ (Babylon)
C:\Users\admın\AppData\Roaming\Babylon\log_file.txt (Babylon)
C:\Users\admın\AppData\Roaming\BabylonToolbar\ (Babylon)
C:\Users\admın\AppData\Roaming\BabylonToolbar\CR\ (Babylon)
C:\Users\admın\AppData\Roaming\BabylonToolbar\CR\BabylonChrome1.crx (Babylon)
C:\Users\admın\AppData\Roaming\BabylonToolbar\CR\BUSolution.dll (Babylon)
Size . . . . . . . : 514,048 bytes
Age . . . . . . . : 194.6 days (2012-07-01 12:27:56)
Entropy . . . . . : 6.3
SHA-256 . . . . . : B5AF65918FD8D3C8847E86438D67F1136646033911EE48E6D717C0F2349E8BE7
Product . . . . . : BU Dynamic Link Library
Description . . . : BU Dynamic Link Library
Version . . . . . : 2.0.0.2
Copyright . . . . : Copyright (C) 1997-2012
Fuzzy . . . . . . : -7.0
C:\Users\admın\AppData\Roaming\BabylonToolbar\FF\ (Babylon)
C:\Users\admın\AppData\Roaming\BabylonToolbar\FF\BUSolution.dll (Babylon)
Size . . . . . . . : 514,048 bytes
Age . . . . . . . : 194.6 days (2012-07-01 12:27:56)
Entropy . . . . . : 6.3
SHA-256 . . . . . : B5AF65918FD8D3C8847E86438D67F1136646033911EE48E6D717C0F2349E8BE7
Product . . . . . : BU Dynamic Link Library
Description . . . : BU Dynamic Link Library
Version . . . . . : 2.0.0.2
Copyright . . . . : Copyright (C) 1997-2012
Fuzzy . . . . . . : -7.0
C:\Users\admın\AppData\Roaming\BabylonToolbar\IE\ (Babylon)
C:\Users\admın\AppData\Roaming\BabylonToolbar\IE\BUSolution.dll (Babylon)
Size . . . . . . . : 514,048 bytes
Age . . . . . . . : 194.6 days (2012-07-01 12:27:56)
Entropy . . . . . : 6.3
SHA-256 . . . . . : B5AF65918FD8D3C8847E86438D67F1136646033911EE48E6D717C0F2349E8BE7
Product . . . . . : BU Dynamic Link Library
Description . . . : BU Dynamic Link Library
Version . . . . . : 2.0.0.2
Copyright . . . . : Copyright (C) 1997-2012
Fuzzy . . . . . . : -7.0
C:\Users\admın\AppData\Roaming\BabylonToolbar\Shared\ (Babylon)
C:\Users\admın\AppData\Roaming\BabylonToolbar\Shared\BabyTBConf.ini (Babylon)
C:\Users\admın\AppData\Roaming\BabylonToolbar\Shared\BUSolution.dll (Babylon)
Size . . . . . . . : 514,048 bytes
Age . . . . . . . : 194.6 days (2012-07-01 12:27:56)
Entropy . . . . . : 6.3
SHA-256 . . . . . : B5AF65918FD8D3C8847E86438D67F1136646033911EE48E6D717C0F2349E8BE7
Product . . . . . : BU Dynamic Link Library
Description . . . : BU Dynamic Link Library
Version . . . . . : 2.0.0.2
Copyright . . . . : Copyright (C) 1997-2012
Fuzzy . . . . . . : -7.0
C:\Users\admın\AppData\Roaming\BabylonToolbar\Shared\sign (Babylon)
HKLM\SOFTWARE\Classes\AppID\escort.DLL\ (Funmoods)
HKLM\SOFTWARE\Classes\AppID\escortApp.DLL\ (Funmoods)
HKLM\SOFTWARE\Classes\AppID\escortEng.DLL\ (Funmoods)
HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL\ (Funmoods)
HKLM\SOFTWARE\Classes\AppID\esrv.EXE\ (Funmoods)
HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}\ (Funmoods)
HKLM\SOFTWARE\Classes\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1}\ (Babylon)
HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}\ (Funmoods)
HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}\ (Funmoods)
HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\ (Babylon)
HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}\ (Funmoods)
HKLM\SOFTWARE\Classes\b\ (Babylon)
HKLM\SOFTWARE\Classes\Babylon.dskBnd.1\ (Babylon)
HKLM\SOFTWARE\Classes\Babylon.dskBnd\ (Babylon)
HKLM\SOFTWARE\Classes\bbylnApp.appCore.1\ (Babylon)
HKLM\SOFTWARE\Classes\bbylnApp.appCore\ (Babylon)
HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1\ (Babylon)
HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr\ (Babylon)
HKLM\SOFTWARE\Classes\escort.escortIEPane.1\ (Funmoods)
HKLM\SOFTWARE\Classes\escort.escortIEPane\ (Funmoods)
HKLM\SOFTWARE\Classes\esrv.BabylonESrvc.1\ (Babylon)
HKLM\SOFTWARE\Classes\esrv.BabylonESrvc\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}\ (Babylon)
HKLM\SOFTWARE\Classes\Prod.cap\ (Claro)
HKLM\SOFTWARE\Classes\TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1}\ (Babylon)
HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}\ (Funmoods)
HKLM\SOFTWARE\Classes\TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70}\ (Babylon)
HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}\ (Funmoods)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\escort.DLL\ (Funmoods)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\escortApp.DLL\ (Funmoods)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\escortEng.DLL\ (Funmoods)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\escorTlbr.DLL\ (Funmoods)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\esrv.EXE\ (Funmoods)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}\ (Funmoods)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}\ (Funmoods)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}\ (Funmoods)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}\ (Funmoods)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{291BCCC1-6890-484a-89D3-318C928DAC1B}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{B8276A94-891D-453C-9FF3-715C042A2575}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{FFB9ADCB-8C79-4C29-81D3-74D46A93D370}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{706D4A4B-184A-4434-B331-296B07493D2D}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}\ (Funmoods)
HKLM\SOFTWARE\Classes\Wow6432Node\TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}\ (Funmoods)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4B2468513CA2D6943A1A233CD3F88CE7\ (Claro)
HKLM\SOFTWARE\Wow6432Node\Babylon\ (Babylon)
HKLM\SOFTWARE\Wow6432Node\BabylonToolbar\ (Babylon)
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\ (Babylon)
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8375D9C8-634F-4ECB-8CF5-C7416BA5D542}\ (Babylon)
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\BabylonToolbar\ (Babylon)
HKU\S-1-5-21-3655514959-12179107-2567171075-1000\Software\BabylonToolbar\ (Babylon)
HKU\S-1-5-21-3655514959-12179107-2567171075-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{98889811-442D-49DD-99D7-DC866BE87DBC} (Claro)
HKU\S-1-5-21-3655514959-12179107-2567171075-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ (Babylon)
HKU\S-1-5-21-3655514959-12179107-2567171075-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B}\ (Babylon)
HKU\S-1-5-21-3655514959-12179107-2567171075-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC}\ (Babylon)
Cookies _____________________________________________________________________
C:\Users\admın\AppData\Roaming\Microsoft\Windows\Cookies\6LEWKBGR.txt
C:\Users\admın\AppData\Roaming\Microsoft\Windows\Cookies\6YSVKKPM.txt
C:\Users\admın\AppData\Roaming\Microsoft\Windows\Cookies\8RL7MQSM.txt
C:\Users\admın\AppData\Roaming\Microsoft\Windows\Cookies\admın@ads.ad4game[2].txt
C:\Users\admın\AppData\Roaming\Microsoft\Windows\Cookies\admın@atdmt[1].txt
C:\Users\admın\AppData\Roaming\Microsoft\Windows\Cookies\admın@c.atdmt[2].txt
C:\Users\admın\AppData\Roaming\Microsoft\Windows\Cookies\admın@serving-sys[1].txt
C:\Users\admın\AppData\Roaming\Microsoft\Windows\Cookies\BH13MTX4.txt
C:\Users\admın\AppData\Roaming\Microsoft\Windows\Cookies\ES7NQ8F9.txt
C:\Users\admın\AppData\Roaming\Microsoft\Windows\Cookies\FUAOWWGM.txt
C:\Users\admın\AppData\Roaming\Microsoft\Windows\Cookies\I4TVPD4E.txt
C:\Users\admın\AppData\Roaming\Microsoft\Windows\Cookies\KE30C9Z2.txt
C:\Users\admın\AppData\Roaming\Microsoft\Windows\Cookies\WAPQO0U0.txt