Jump to content


Recommended Posts

I was looking through my list of startup programs earlier and i found one called SearchSettings.exe which i didn't recognise. After looking it up on Google it seems as though it is malware, but it is in a folder that i can't find. I already did a full scan with MBAM and it didn't find it. Any help would be appreciated.

Link to post
Share on other sites


DDS (Ver_2011-08-26.01) - NTFSx86

Internet Explorer: 8.0.6001.18928 BrowserJavaVersion: 1.6.0_29

Run by User at 17:59:35 on 2011-12-23

Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.2038.922 [GMT 0:00]


SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}


============== Running Processes ===============




C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\svchost.exe -k rpcss

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k GPSvcGroup


C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k NetworkService







C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\supserv.exe

C:\Windows\system32\svchost.exe -k imgsvc

C:\Program Files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe

C:\Windows\System32\svchost.exe -k WerSvcGroup





C:\Program Files\Launch Manager\HotkeyApp.exe

C:\Program Files\Synaptics\SynTP\SynTPStart.exe

C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

C:\Program Files\NetWorx\networx.exe

C:\Program Files\Common Files\Java\Java Update\jusched.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Users\User\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe

C:\Program Files\Windows Media Player\wmpnscfg.exe

C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

C:\Program Files\Launch Manager\WisLMSvc.exe



C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Program Files\Mozilla Firefox\firefox.exe



C:\Program Files\Mozilla Firefox\plugin-container.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe



C:\Windows\System32\svchost.exe -k swprv




============== Pseudo HJT Report ===============


uStart Page = hxxp://www.google.com/ig/redirectdomain?brand=FUJD&bmod=FUJD

mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=FUJD&bmod=FUJD

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File

BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File

BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File

uRun: [sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun

uRun: [steam] "c:\program files\steam\Steam.exe" -silent

uRun: [Octoshape Streaming Services] "c:\users\user\appdata\roaming\octoshape\octoshape streaming services\OctoshapeClient.exe" -inv:bootrun

uRun: [sony Ericsson PC Companion] "c:\program files\sony ericsson\sony ericsson pc companion\PCCompanion.exe" /Background

uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe

mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide

mRun: [igfxTray] c:\windows\system32\igfxtray.exe

mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe

mRun: [Persistence] c:\windows\system32\igfxpers.exe

mRun: [RtHDVCpl] RtHDVCpl.exe

mRun: [HotkeyApp] "c:\program files\launch manager\HotkeyApp.exe"

mRun: [synTPStart] c:\program files\synaptics\syntp\SynTPStart.exe

mRun: [NeroFilterCheck] c:\program files\common files\nero\lib\NeroCheck.exe

mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup

mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript

mRun: [CtrlVol] c:\program files\launch manager\CtrlVol.exe

mRun: [LaunchAp] c:\program files\launch manager\LaunchAp.exe

mRun: [Wbutton] c:\program files\launch manager\WButton.exe

mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"

mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"

mRun: [NetWorx] "c:\program files\networx\networx.exe" /auto

mRun: [sunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"

mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray

dRun: [fsc-reg] c:\programdata\fsc-reg\fscreg.exe

StartupFolder: c:\users\user\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE

mPolicies-system: EnableUIADesktopToggle = 0 (0x0)

IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000

IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab

DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

TCP: DhcpNameServer =

TCP: Interfaces\{02BD2FD7-5C8D-4590-ABC0-6398ABB578E0} : DhcpNameServer =

TCP: Interfaces\{C43E5CE1-3198-4171-A4D6-995C08AE545E} : DhcpNameServer =

Notify: igfxcui - igfxdev.dll

AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL


================= FIREFOX ===================


FF - ProfilePath - c:\users\user\appdata\roaming\mozilla\firefox\profiles\xhxl1e8a.default\

FF - prefs.js: browser.search.selectedEngine - Google

FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/ig

FF - prefs.js: keyword.URL - hxxp://uk.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=867034&p=

FF - component: c:\program files\avg\avg10\firefox4\components\avgssff4.dll

FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: c:\program files\microsoft silverlight\4.0.50917.0\npctrlui.dll

FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll

FF - plugin: c:\users\user\appdata\roaming\mozilla\plugins\npoctoshape.dll

FF - plugin: c:\windows\system32\tvuax\npTVUAx.dll



FF - user.js: network.cookie.cookieBehavior - 0

FF - user.js: privacy.clearOnShutdown.cookies - false

FF - user.js: security.warn_viewing_mixed - false

FF - user.js: security.warn_viewing_mixed.show_once - false

FF - user.js: security.warn_submit_insecure - false

FF - user.js: security.warn_submit_insecure.show_once - false


============= SERVICES / DRIVERS ===============


R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2010-7-13 28552]

R1 networx;networx;c:\windows\system32\drivers\networx.sys [2011-6-28 51640]

R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-12-23 366152]

R2 Sony Ericsson PC Companion download service;Sony Ericsson PC Companion download service;c:\program files\sony ericsson\sony ericsson pc companion\SupServ.exe [2010-3-23 93392]

R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-12-23 22216]

R3 WisLMSvc;WisLMSvc;c:\program files\launch manager\WisLMSvc.exe [2008-6-11 118784]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2005-8-2 32512]

S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files\sony ericsson\sony ericsson pc companion\PCCService.exe [2011-7-8 155344]

S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]


=============== Created Last 30 ================


2073-10-27 10:55:34 1835008 ----a-w- c:\program files\microsoft games\halo custom edition\haloceded.exe

2073-10-27 10:55:34 1118208 ----a-w- c:\program files\microsoft games\halo custom edition\Strings.dll

2011-12-23 13:10:40 -------- d-----w- c:\windows\pss

2011-12-23 13:00:29 22216 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-12-23 13:00:29 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2011-12-22 15:22:25 -------- d-----w- c:\program files\POWERISO

2011-12-22 14:57:20 -------- d-----w- c:\program files\Bethesda Softworks

2011-12-22 14:56:41 634880 ----a-w- c:\program files\common files\installshield\professional\runtime\0700\intel32\iKernel.dll

2011-12-22 14:56:41 57344 ----a-w- c:\program files\common files\installshield\professional\runtime\0700\intel32\ctor.dll

2011-12-22 14:56:41 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\0700\intel32\DotNetInstaller.exe

2011-12-22 14:56:41 237568 ----a-w- c:\program files\common files\installshield\professional\runtime\0700\intel32\iscript.dll

2011-12-22 14:56:41 151552 ----a-w- c:\program files\common files\installshield\professional\runtime\0700\intel32\iuser.dll

2011-12-22 14:56:38 270468 ----a-w- c:\program files\common files\installshield\professional\runtime\0700\intel32\Setup.dll

2011-12-22 14:56:38 159876 ----a-w- c:\program files\common files\installshield\professional\runtime\0700\intel32\IGdi.dll

2011-12-22 03:36:31 116736 ----a-w- c:\windows\system32\drivers\mcdbus.sys

2011-12-22 03:36:27 -------- d-----w- c:\program files\MagicDisc

2011-12-22 03:28:55 -------- d-----w- c:\users\user\appdata\roaming\DAEMON Tools Pro

2011-12-22 03:28:55 -------- d-----w- c:\programdata\DAEMON Tools Pro


==================== Find3M ====================


2011-11-15 03:50:16 112096 ----a-w- c:\windows\system32\drivers\scdemu.sys

2011-11-13 03:56:20 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2011-10-03 05:06:03 472808 ----a-w- c:\windows\system32\deployJava1.dll


============= FINISH: 18:00:33.85 ===============





DDS (Ver_2011-08-26.01)


Microsoft® Windows Vista™ Home Premium

Boot Device: \Device\HarddiskVolume2

Install Date: 08/03/2010 22:25:29

System Uptime: 23/12/2011 14:58:37 (4 hours ago)


Motherboard: FUJITSU SIEMENS | | LV1

Processor: Intel® Pentium® Dual CPU T2390 @ 1.86GHz | U2E1 | 800/mhz


==== Disk Partitions =========================


C: is FIXED (NTFS) - 93 GiB total, 2.613 GiB free.

D: is FIXED (NTFS) - 47 GiB total, 47.251 GiB free.

E: is CDROM ()

F: is CDROM ()

G: is CDROM ()


==== Disabled Device Manager Items =============


==== System Restore Points ===================


RP296: 23/12/2011 14:47:29 - Removed AVG 2012

RP297: 23/12/2011 14:51:13 - Removed AVG 2012


==== Installed Programs ======================


Activation Assistant for the 2007 Microsoft Office suites

Adobe AIR

Adobe Flash Player 10 ActiveX

Adobe Flash Player 11 Plugin

Adobe Reader X

Advertising Center

AVG PC Tuneup 2011

Big Fish Games Center (remove only)

Big Fish Games Sudoku (remove only)

Bluesoleil2.6.0.8 Release 070517

Call Of Cthulhu DCoTE

Celestia 1.6.0

Compatibility Pack for the 2007 Office system

Cradle of Rome (remove only)

DVD Flick

Gmask 1.70 English

Google Desktop

Google Earth

Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)

Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)

Intel® Graphics Media Accelerator Driver

Java Auto Updater

Java 6 Update 29

Launch Manager V1.4.9

Lexmark 640 Series

Luxor Amun Rising (remove only)

MagicDisc 2.7.106

Mahjong Towers Eternity (remove only)

Malwarebytes' Anti-Malware version

Microsoft .NET Framework 3.5 SP1

Microsoft .NET Framework 4 Client Profile

Microsoft Application Error Reporting

Microsoft Choice Guard

Microsoft Halo Custom Edition

Microsoft Office 2007 Service Pack 2 (SP2)

Microsoft Office Excel MUI (English) 2007

Microsoft Office Home and Student 2007

Microsoft Office OneNote MUI (English) 2007

Microsoft Office PowerPoint MUI (English) 2007

Microsoft Office PowerPoint Viewer 2007 (English)

Microsoft Office Proof (English) 2007

Microsoft Office Proof (French) 2007

Microsoft Office Proof (Spanish) 2007

Microsoft Office Proofing (English) 2007

Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

Microsoft Office Shared MUI (English) 2007

Microsoft Office Shared Setup Metadata MUI (English) 2007

Microsoft Office Word MUI (English) 2007

Microsoft Silverlight

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

Microsoft Works

Microsoft XML Parser

Mozilla Firefox 8.0 (x86 en-GB)


MSXML 4.0 SP2 (KB954430)

MSXML 4.0 SP2 (KB973688)

Mystery Case Files - Prime Suspects (remove only)

Nero 8 Essentials

Nero 9 Lite

Nero ControlCenter

Nero Installer

Nero Online Upgrade

Nero StartSmart


NetWorx 5.1.7

Octoshape Streaming Services

OGA Notifier 2.0.0048.0

Panda ActiveScan 2.0

Poker Superstars II (remove only)



Realtek High Definition Audio Driver


Security Update for 2007 Microsoft Office System (KB2288621)

Security Update for 2007 Microsoft Office System (KB2289158)

Security Update for 2007 Microsoft Office System (KB2344875)

Security Update for 2007 Microsoft Office System (KB2345043)

Security Update for 2007 Microsoft Office System (KB969559)

Security Update for 2007 Microsoft Office System (KB976321)

Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)

Security Update for Microsoft Office Excel 2007 (KB2345035)

Security Update for Microsoft Office InfoPath 2007 (KB979441)

Security Update for Microsoft Office PowerPoint 2007 (KB982158)

Security Update for Microsoft Office PowerPoint Viewer (KB2413381)

Security Update for Microsoft Office system 2007 (972581)

Security Update for Microsoft Office system 2007 (KB974234)

Security Update for Microsoft Office Visio Viewer 2007 (KB973709)

Security Update for Microsoft Office Word 2007 (KB2344993)

Sony Ericsson PC Companion 2.01.217


Synaptics Pointing Device Driver


Update for 2007 Microsoft Office System (KB967642)

Update for Microsoft .NET Framework 3.5 SP1 (KB963707)

Update for Microsoft Office 2007 Help for Common Features (KB963673)

Update for Microsoft Office Excel 2007 Help (KB963678)

Update for Microsoft Office OneNote 2007 (KB980729)

Update for Microsoft Office OneNote 2007 Help (KB963670)

Update for Microsoft Office Powerpoint 2007 Help (KB963669)

Update for Microsoft Office Script Editor Help (KB963671)

Update for Microsoft Office Word 2007 Help (KB963665)


Virtual Villagers (remove only)

VLC media player 1.1.11

Windows Live Call

Windows Live Communications Platform

Windows Live Essentials

Windows Live Messenger

Windows Live Sign-in Assistant

Windows Live Upload Tool

Windows Media Player Firefox Plugin

WinPcap 3.1

WinRAR archiver

XBC 5.1

Yahoo! Detect


==== Event Viewer Messages From Past Week ========


19/12/2011 21:28:46, Error: volsnap [35] - The shadow copies of volume C: were aborted because the shadow copy storage failed to grow.


==== End Of File ===========================

Link to post
Share on other sites

Look through these installed programs and verify that you recognize them all and did install them.

Uninstall any you didn't install or don't recognize.

Advertising Center <------this one

Advertising Center<------this one is suspect!

Big Fish Games Center (remove only)

Big Fish Games Sudoku (remove only)

Bluesoleil2.6.0.8 Release 070517

Call Of Cthulhu DCoTE

Celestia 1.6.0

Cradle of Rome (remove only)

DVD Flick

Gmask 1.70 English

Launch Manager V1.4.9

Luxor Amun Rising (remove only)

Mahjong Towers Eternity (remove only)

Mystery Case Files - Prime Suspects (remove only)

OGA Notifier 2.0.0048.0

Poker Superstars II (remove only)




Virtual Villagers (remove only)

WinPcap 3.1

XBC 5.1

Let me know, MrC

Link to post
Share on other sites

Hi MrCharlie, i checked through all those programs that are already installed on my computer. Every one of those programs i recognise and trust apart from 3 of them:

Advertising Center

OGA Notifier 2.0.0048.0


These are files that i also can't find.

I also tried deleting it from my add ons in IE, but once again i couldn't find it there.

Link to post
Share on other sites

I think those are OK, lets run this scanner and see what it shows:

Please download OTL from one of the links below:


http://oldtimer.geekstogo.com/OTL.com (<---renamed version)

Save it to your desktop.

Double click on the icon on your desktop.

Click the Scan All Users checkbox.

Push the Quick Scan button.

Two reports will open, copy and paste them in a reply here: (or attach them as .txt files)

OTL.txt <-- Will be opened

Extra.txt <-- Will be minimized


Link to post
Share on other sites

OTL logfile created on: 23/12/2011 20:04:17 - Run 1

OTL by OldTimer - Version Folder = C:\Users\User\Desktop

Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18928)

Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.99 Gb Total Physical Memory | 1.04 Gb Available Physical Memory | 52.43% Memory free

4.21 Gb Paging File | 2.77 Gb Available in Paging File | 65.82% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files

Drive C: | 92.70 Gb Total Space | 1.92 Gb Free Space | 2.07% Space Free | Partition Type: NTFS

Drive D: | 47.35 Gb Total Space | 47.25 Gb Free Space | 99.79% Space Free | Partition Type: NTFS

Computer Name: USER-PC | User Name: User | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users | Quick Scan

Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/12/23 20:02:41 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\User\Desktop\OTL.exe

PRC - [2011/11/10 16:12:30 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe

PRC - [2011/08/31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

PRC - [2011/05/17 12:26:20 | 002,794,496 | ---- | M] (SoftPerfect Research) -- C:\Program Files\NetWorx\networx.exe

PRC - [2010/03/23 12:59:56 | 000,093,392 | ---- | M] () -- C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\SupServ.exe

PRC - [2009/01/08 13:44:06 | 000,070,936 | ---- | M] (Octoshape ApS) -- C:\Users\User\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe

PRC - [2008/10/29 06:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe

PRC - [2008/02/29 14:13:12 | 000,307,200 | ---- | M] (Fujitsu Siemens Computers) -- C:\Program Files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe

PRC - [2007/08/17 12:40:30 | 000,102,400 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPStart.exe

PRC - [2007/07/06 09:06:52 | 004,669,440 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe

========== Modules (No Company Name) ==========

MOD - [2011/11/13 03:56:20 | 008,527,008 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32.dll

MOD - [2011/11/10 16:12:29 | 001,989,592 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll

MOD - [2011/05/01 21:08:56 | 000,484,352 | ---- | M] () -- C:\Program Files\NetWorx\sqlite.dll

MOD - [2010/06/11 20:17:18 | 000,094,208 | ---- | M] () -- C:\Program Files\NetWorx\nfapi.dll

MOD - [2010/03/15 10:28:22 | 000,141,824 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll

MOD - [2007/05/31 08:01:22 | 000,249,856 | ---- | M] () -- C:\Windows\System32\igfxTMM.dll

========== Win32 Services (SafeList) ==========

SRV - [2011/08/31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)

SRV - [2011/06/29 14:59:18 | 000,155,344 | ---- | M] (Avanquest Software) [On_Demand | Stopped] -- C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe -- (Sony Ericsson PCCompanion)

SRV - [2010/08/12 19:23:15 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)

SRV - [2010/03/23 12:59:56 | 000,093,392 | ---- | M] () [Auto | Running] -- C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\SupServ.exe -- (Sony Ericsson PC Companion download service)

SRV - [2008/02/29 14:13:12 | 000,307,200 | ---- | M] (Fujitsu Siemens Computers) [Auto | Running] -- C:\Program Files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe -- (TestHandler)

SRV - [2008/01/21 02:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)

========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | Unknown | Running] -- -- (Hotkey)

DRV - [2011/11/15 03:50:16 | 000,112,096 | ---- | M] (Power Software Ltd) [Kernel | System | Running] -- C:\Windows\System32\drivers\scdemu.sys -- (SCDEmu)

DRV - [2011/08/31 17:00:50 | 000,022,216 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)

DRV - [2011/04/15 13:12:12 | 000,051,640 | ---- | M] (NetFilterSDK.com) [Kernel | System | Running] -- C:\Windows\System32\drivers\networx.sys -- (networx)

DRV - [2009/06/30 08:37:16 | 000,028,552 | ---- | M] (Panda Security, S.L.) [File_System | Boot | Running] -- C:\Windows\system32\drivers\pavboot.sys -- (pavboot)

DRV - [2009/02/24 18:42:14 | 000,116,736 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mcdbus.sys -- (mcdbus)

DRV - [2008/04/03 12:58:46 | 000,076,688 | ---- | M] (JMicron Technology Corp.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\jraid.sys -- (JRAID)

DRV - [2007/12/19 17:45:00 | 000,170,000 | ---- | M] (AMD Technologies Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ahcix86s.sys -- (ahcix86s)

DRV - [2007/08/03 08:44:58 | 000,091,648 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)

DRV - [2007/06/18 16:03:32 | 000,737,280 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)

DRV - [2007/05/11 02:10:50 | 000,034,704 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\blueletaudio.sys -- (BlueletAudio)

DRV - [2007/05/09 00:59:40 | 000,036,496 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\btcusb.sys -- (Btcsrusb)

DRV - [2007/03/05 05:00:04 | 000,027,792 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\BlueletSCOAudio.sys -- (BlueletSCOAudio)

DRV - [2007/03/05 04:59:04 | 000,018,320 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\btnetdrv.sys -- (BT)

DRV - [2007/03/05 04:56:18 | 000,035,600 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\BTHidMgr.sys -- (BTHidMgr)

DRV - [2007/03/05 04:55:12 | 000,020,880 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\vbtenum.sys -- (BTHidEnum)

DRV - [2007/03/05 04:53:18 | 000,044,304 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\VCommMgr.sys -- (VcommMgr)

DRV - [2007/03/05 04:52:18 | 000,034,448 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\VComm.sys -- (VComm)

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain?brand=FUJD&bmod=FUJD'>http://www.google.com/ig/redirectdomain?brand=FUJD&bmod=FUJD

IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie'>http://www.google.com/ie

IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com

IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie'>http://www.google.com/ie

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-3654883410-1651815343-1435893916-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain?brand=FUJD&bmod=FUJD'>http://www.google.com/ig/redirectdomain?brand=FUJD&bmod=FUJD

IE - HKU\S-1-5-21-3654883410-1651815343-1435893916-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo"

FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=867034"

FF - prefs.js..browser.search.selectedEngine: "Google"

FF - prefs.js..browser.search.useDBForOrder: true

FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/ig"

FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6

FF - prefs.js..extensions.enabledItems: firefox@tvunetworks.com:2

FF - prefs.js..extensions.enabledItems: 5

FF - prefs.js..extensions.enabledItems: 3

FF - prefs.js..extensions.enabledItems: 1

FF - prefs.js..extensions.enabledItems: {6614d11d-d21d-b211-ae23-815234e1ebb5}:1.0.23

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24

FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:

FF - prefs.js..extensions.enabledItems: {241aae70-0022-11de-87af-0800200c9a66}:

FF - prefs.js..extensions.enabledItems: {D46E8522-6E86-44b1-A622-58C0668AD78E}:3.6.0

FF - prefs.js..extensions.enabledItems: {c8f71e5b-88f8-42a7-98bb-e4c506161de9}:0.4

FF - prefs.js..keyword.URL: "http://uk.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=867034&p="

FF - prefs.js..network.proxy.backup.ftp: ""

FF - prefs.js..network.proxy.backup.ftp_port: 3128

FF - prefs.js..network.proxy.backup.socks: ""

FF - prefs.js..network.proxy.backup.socks_port: 3128

FF - prefs.js..network.proxy.backup.ssl: ""

FF - prefs.js..network.proxy.backup.ssl_port: 3128

FF - prefs.js..network.proxy.ftp: ""

FF - prefs.js..network.proxy.ftp_port: 3128

FF - prefs.js..network.proxy.http: ""

FF - prefs.js..network.proxy.http_port: 3128

FF - prefs.js..network.proxy.share_proxy_settings: true

FF - prefs.js..network.proxy.socks: ""

FF - prefs.js..network.proxy.socks_port: 3128

FF - prefs.js..network.proxy.ssl: ""

FF - prefs.js..network.proxy.ssl_port: 3128

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()

FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)

FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.50917.0\npctrl.dll ( Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\Windows\system32\TVUAx\npTVUAx.dll (TVU networks)

FF - HKLM\Software\MozillaPlugins\@pandasecurity.com/activescan: C:\Program Files\Panda Security\ActiveScan 2.0\npwrapper.dll (Panda Security)

FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)

FF - HKCU\Software\MozillaPlugins\@octoshape.com/Octoshape Streaming Services,version=1.0: C:\Users\User\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1101262-0-npoctoshape.dll (Octoshape ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/10 16:12:31 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/18 20:48:10 | 000,000,000 | ---D | M]

[2010/03/29 00:51:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Extensions

[2011/12/23 01:32:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\xhxl1e8a.default\extensions

[2010/07/01 01:23:40 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\xhxl1e8a.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}

[2011/01/01 17:36:44 | 000,000,000 | ---D | M] (Dr.Web anti-virus link checker) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\xhxl1e8a.default\extensions\{6614d11d-d21d-b211-ae23-815234e1ebb5}

[2010/11/02 16:16:51 | 000,000,000 | ---D | M] (AmbientFox) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\xhxl1e8a.default\extensions\{c8f71e5b-88f8-42a7-98bb-e4c506161de9}

[2011/01/23 11:08:32 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\xhxl1e8a.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}(192)

[2010/11/20 22:15:30 | 000,000,000 | ---D | M] (TVU Web Player) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\xhxl1e8a.default\extensions\firefox@tvunetworks.com

[2010/03/24 10:34:04 | 000,002,456 | ---- | M] () -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\xhxl1e8a.default\searchplugins\iMeshWebSearch.xml

[2010/06/07 13:24:38 | 000,002,057 | ---- | M] () -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\xhxl1e8a.default\searchplugins\youtube-video-search.xml

[2011/11/10 16:12:36 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions

[2011/11/02 21:53:14 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}


[2011/11/10 16:12:30 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll

[2011/10/03 05:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll

[2011/10/03 15:14:20 | 000,001,538 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml

[2011/10/03 15:14:20 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml

[2011/10/03 15:14:20 | 000,000,947 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml

[2011/10/03 15:14:20 | 000,001,180 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml

[2011/10/03 15:14:20 | 000,001,135 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2006/09/18 21:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts

O1 - Hosts: localhost

O1 - Hosts: ::1 localhost

O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.

O3 - HKU\S-1-5-21-3654883410-1651815343-1435893916-1000\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.

O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)

O4 - HKLM..\Run: [CtrlVol] C:\Program Files\Launch Manager\CtrlVol.exe File not found

O4 - HKLM..\Run: [LaunchAp] C:\Program Files\Launch Manager\LaunchAp.exe File not found

O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)

O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)

O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe (Nero AG)

O4 - HKLM..\Run: [NetWorx] C:\Program Files\NetWorx\networx.exe (SoftPerfect Research)

O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)

O4 - HKLM..\Run: [synTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)

O4 - HKLM..\Run: [Wbutton] C:\Program Files\Launch Manager\WButton.exe File not found

O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)

O4 - HKU\.DEFAULT..\Run: [fsc-reg] C:\ProgramData\fsc-reg\fscreg.exe (Fujitsu Siemens Computers)

O4 - HKU\S-1-5-18..\Run: [fsc-reg] C:\ProgramData\fsc-reg\fscreg.exe (Fujitsu Siemens Computers)

O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)

O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)

O4 - HKU\S-1-5-21-3654883410-1651815343-1435893916-1000..\Run: [Octoshape Streaming Services] C:\Users\User\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe (Octoshape ApS)

O4 - HKU\S-1-5-21-3654883410-1651815343-1435893916-1000..\Run: [sony Ericsson PC Companion] C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe (Sony Ericsson)

O4 - HKU\S-1-5-21-3654883410-1651815343-1435893916-1000..\Run: [steam] "C:\Program Files\Steam\Steam.exe" -silent File not found

O7 - HKU\S-1-5-21-3654883410-1651815343-1435893916-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found

O13 - gopher Prefix: missing

O15 - HKU\S-1-5-21-3654883410-1651815343-1435893916-1000\..Trusted Ranges: GD ([http] in Local intranet)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)

O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer =

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{02BD2FD7-5C8D-4590-ABC0-6398ABB578E0}: DhcpNameServer =

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C43E5CE1-3198-4171-A4D6-995C08AE545E}: DhcpNameServer =

O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) -C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)

O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (c:\windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)

O24 - Desktop WallPaper: C:\Users\User\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg

O24 - Desktop BackupWallPaper: C:\Users\User\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2006/09/18 21:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]

O33 - MountPoints2\{4bca9014-a943-11e0-b68d-00116777cacc}\Shell - "" = AutoRun

O33 - MountPoints2\{4bca9014-a943-11e0-b68d-00116777cacc}\Shell\AutoRun\command - "" = G:\Startme.exe

O33 - MountPoints2\G\Shell - "" = AutoRun

O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\Setup.exe

O34 - HKLM BootExecute: (autocheck autochk *)

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/12/23 20:01:53 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\User\Desktop\OTL.exe

[2011/12/23 15:03:15 | 000,607,260 | R--- | C] (Swearware) -- C:\Users\User\Desktop\dds.scr

[2011/12/23 13:10:40 | 000,000,000 | ---D | C] -- C:\Windows\pss

[2011/12/23 13:00:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware

[2011/12/23 13:00:29 | 000,022,216 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys

[2011/12/23 13:00:29 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware

[2011/12/22 15:32:46 | 000,000,000 | ---D | C] -- C:\Users\User\Documents\Bethesda

[2011/12/22 15:22:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerISO

[2011/12/22 15:22:25 | 000,000,000 | ---D | C] -- C:\Program Files\POWERISO

[2011/12/22 14:57:20 | 000,000,000 | ---D | C] -- C:\Program Files\Bethesda Softworks

[2011/12/22 14:57:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bethesda Softworks

[2011/12/22 03:45:15 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MagicDisc

[2011/12/22 03:45:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MagicDisc

[2011/12/22 03:36:31 | 000,116,736 | ---- | C] (MagicISO, Inc.) -- C:\Windows\System32\drivers\mcdbus.sys

[2011/12/22 03:36:27 | 000,000,000 | ---D | C] -- C:\Program Files\MagicDisc

[2011/12/22 03:28:55 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\DAEMON Tools Pro

[2011/12/22 03:28:55 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Pro

[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/23 20:02:41 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\User\Desktop\OTL.exe

[2011/12/23 18:59:32 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0

[2011/12/23 18:59:32 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0

[2011/12/23 18:03:06 | 000,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini

[2011/12/23 15:03:16 | 000,607,260 | R--- | M] (Swearware) -- C:\Users\User\Desktop\dds.scr

[2011/12/23 14:59:00 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat

[2011/12/23 14:58:54 | 2137,448,448 | -HS- | M] () -- C:\hiberfil.sys

[2011/12/23 13:00:34 | 000,000,824 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk

[2011/12/23 12:58:00 | 000,144,896 | ---- | M] () -- C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2011/12/23 01:37:20 | 000,000,416 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{616F3064-DA7D-4CD6-864F-C62539543CED}.job

[2011/12/22 15:22:30 | 000,000,810 | ---- | M] () -- C:\Users\Public\Desktop\PowerISO.lnk

[2011/12/22 03:47:43 | 000,000,768 | ---- | M] () -- C:\Users\User\Desktop\MagicDisc.lnk

[2011/12/22 03:43:45 | 000,609,196 | ---- | M] () -- C:\Windows\System32\perfh009.dat

[2011/12/22 03:43:45 | 000,108,672 | ---- | M] () -- C:\Windows\System32\perfc009.dat

[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/23 13:00:34 | 000,000,824 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk

[2011/12/22 15:22:30 | 000,000,810 | ---- | C] () -- C:\Users\Public\Desktop\PowerISO.lnk

[2011/12/22 03:45:15 | 000,000,768 | ---- | C] () -- C:\Users\User\Desktop\MagicDisc.lnk

[2011/01/31 16:03:21 | 000,000,091 | ---- | C] () -- C:\Windows\LEXSTAT.INI

[2010/12/22 19:20:24 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini

[2010/08/10 14:52:53 | 000,000,000 | ---- | C] () -- C:\Users\User\AppData\Roaming\wklnhst.dat

[2010/06/15 16:18:42 | 000,027,503 | ---- | C] () -- C:\Users\User\AppData\Roaming\UserTile.png

[2010/04/08 17:02:18 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat

[2010/03/12 10:45:37 | 000,144,896 | ---- | C] () -- C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2010/03/10 05:04:04 | 000,106,605 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin

[2010/03/10 05:04:04 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin

[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll

[2009/08/03 15:07:42 | 000,230,768 | ---- | C] () -- C:\Windows\System32\OGAEXEC.exe

[2008/06/11 17:37:41 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll

[2008/06/11 17:34:19 | 000,910,464 | ---- | C] () -- C:\Windows\System32\igmedkrn.dll

[2008/06/11 17:34:19 | 000,249,856 | ---- | C] () -- C:\Windows\System32\igfxTMM.dll

[2008/06/11 17:34:19 | 000,204,800 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1283.dll

[2008/02/29 14:13:14 | 000,012,288 | ---- | C] () -- C:\Windows\System32\EvOnlDiag.dll

[2006/11/02 12:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat

[2006/11/02 12:47:37 | 000,296,624 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT

[2006/11/02 12:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll

[2006/11/02 10:33:01 | 000,609,196 | ---- | C] () -- C:\Windows\System32\perfh009.dat

[2006/11/02 10:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat

[2006/11/02 10:33:01 | 000,108,672 | ---- | C] () -- C:\Windows\System32\perfc009.dat

[2006/11/02 10:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat

[2006/11/02 10:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat

[2006/11/02 08:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin

[2006/11/02 08:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT

[2006/11/02 07:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini

[2006/11/02 07:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat

========== LOP Check ==========

[2010/10/22 17:53:21 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\AVG

[2011/10/12 19:03:19 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\AVG2012

[2011/12/22 03:28:55 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\DAEMON Tools Pro

[2010/09/09 00:28:17 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\DMCache

[2010/06/18 18:48:02 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\FreeAudioPack

[2010/09/09 00:29:45 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\IDM

[2010/11/01 18:05:49 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Luwe

[2010/04/16 00:12:12 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Octoshape

[2010/10/31 04:30:07 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Ogmy

[2010/06/15 16:18:41 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\PeerNetworking

[2011/04/18 12:49:26 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\TeamViewer

[2011/12/23 17:50:49 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\uTorrent

[2011/12/23 14:58:02 | 000,032,620 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

[2011/12/23 01:37:20 | 000,000,416 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{616F3064-DA7D-4CD6-864F-C62539543CED}.job

========== Purity Check ==========

========== Alternate Data Streams ==========

@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:0B4227B4

< End of report >

OTL Extras logfile created on: 23/12/2011 20:04:17 - Run 1

OTL by OldTimer - Version Folder = C:\Users\User\Desktop

Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18928)

Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.99 Gb Total Physical Memory | 1.04 Gb Available Physical Memory | 52.43% Memory free

4.21 Gb Paging File | 2.77 Gb Available in Paging File | 65.82% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files

Drive C: | 92.70 Gb Total Space | 1.92 Gb Free Space | 2.07% Space Free | Partition Type: NTFS

Drive D: | 47.35 Gb Total Space | 47.25 Gb Free Space | 99.79% Space Free | Partition Type: NTFS

Computer Name: USER-PC | User Name: User | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users | Quick Scan

Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========

========== File Associations ==========


.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)

.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)


.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========


batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)

exefile [open] -- "%1" %*

helpfile [open] -- Reg Error: Key error.

hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)

inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()

Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()

Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

"AntiVirusOverride" = 0

"AntiSpywareOverride" = 0

"FirewallOverride" = 0

"VistaSp1" = Reg Error: Unknown registry data type -- File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========


"EnableFirewall" = 1

"DisableNotifications" = 0


"EnableFirewall" = 1

"DisableNotifications" = 0


"EnableFirewall" = 1

"DisableNotifications" = 0

========== Authorized Applications List ==========

========== Vista Active Open Ports Exception List ==========


"{0637FE87-4A26-4496-A73D-5EDABCF116D1}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |

"{0B4A9C4A-62FA-4E72-AB9E-3EAE289C6B19}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |

"{13A687FA-4D9B-4908-A9EC-C6E1964BF31E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |

"{31501D4A-7C0E-44DA-9121-E2CC7EEC30C0}" = rport=139 | protocol=6 | dir=out | app=system |

"{3A7480B0-BFCD-4E74-BA21-07F6DA300B82}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |

"{3B30B1D6-3E25-46B8-A876-67730DE56395}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |

"{4845CCD0-B8EB-4791-9094-358758B92266}" = lport=445 | protocol=6 | dir=in | app=system |

"{5CB180CE-E532-4FB3-8152-07F4A38EFAED}" = lport=137 | protocol=17 | dir=in | app=system |

"{5FA981F3-DB61-4431-BC9D-E90116E23EB4}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |

"{7C4DDFD0-DE49-4E68-893D-152327CBAB57}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |

"{9EDE6C37-A52B-46F4-849E-68BF8231055E}" = lport=2869 | protocol=6 | dir=in | app=system |

"{A94E7E50-587A-458F-8DCE-E999509C14A7}" = rport=137 | protocol=17 | dir=out | app=system |

"{B3A33016-C4F0-46DD-9B44-19BDFD1590EC}" = rport=445 | protocol=6 | dir=out | app=system |

"{BE65C4E7-14E7-4423-BD3F-31AB54D67013}" = lport=139 | protocol=6 | dir=in | app=system |

"{CE434788-E6A5-42AC-9DC9-737C40F681EC}" = rport=138 | protocol=17 | dir=out | app=system |

"{D8E1EF13-AD75-4A6E-9551-8713C15B14BA}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |

"{E59F7F6D-B742-4F15-9360-016E0CF58F63}" = lport=138 | protocol=17 | dir=in | app=system |

"{E86A9DB8-FD4F-4614-AE23-97CE5C679817}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |

"{EB4B3D83-120C-430F-8A68-99F1B4403E94}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |

"{F8C5E596-AA42-4A31-8625-D89786CD2239}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========


"{00906CB8-813B-4F5A-BAE5-16C4112FF57F}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgemcx.exe |

"{06E679D6-29FE-4373-BBAA-D1C38D4E360B}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |

"{08D7DD1F-5D66-4163-9BAD-D7919E44E447}" = protocol=17 | dir=in | app=c:\program files\ivt corporation\bluesoleil\bluesoleil.exe |

"{13FB6432-63C5-45C8-9DF8-890B1214CC9B}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgdiagex.exe |

"{1871B680-10DB-454C-B86C-71035D35E56D}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgemcx.exe |

"{1BDCF26B-EF5A-420C-87C6-BA2B28DDD522}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgnsx.exe |

"{1CE9B120-3696-42BF-BCFF-1948D54A8DA1}" = protocol=6 | dir=in | app=c:\program files\ivt corporation\bluesoleil\bluesoleil.exe |

"{2DB7A5D1-AC27-47C6-8DFB-D4976F4794C5}" = protocol=17 | dir=in | app=c:\program files\steam\steam.exe |

"{452EF3CB-4D50-427B-A4D3-7AA001EB0A86}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |

"{4A8E0F60-E6F4-475F-97FB-56E7592625D4}" = protocol=6 | dir=in | app=c:\program files\steam\steam.exe |

"{4E94A918-FEC6-467D-A5A0-5B148B9DE028}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |

"{5AC6DACD-4C61-4242-8713-97E5D623F4A1}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |

"{72CDA79D-88B6-4626-8E47-6446DAFE6556}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgmfapx.exe |

"{97BC8123-347E-43EB-A030-B9FB21FADA9F}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |

"{98918094-844D-419E-A5EE-64044678DAC6}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |

"{9E1F09AE-CC25-4290-A8AD-6660CA4759F1}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |

"{A7A93381-D552-4E60-BD79-5822EF6A8A38}" = protocol=17 | dir=in | app=c:\program files\ivt corporation\bluesoleil\bluesoleil.exe |

"{AAEAC412-5DE6-454E-A667-DA2463877C91}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |

"{B0978B8B-0455-4CCB-8F1E-E0F19691CF6B}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgmfapx.exe |

"{B151A625-AA1C-4B7B-BD82-67B6229B0FA8}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgdiagex.exe |

"{B7798EC7-2DAB-487F-A7EC-D60CEB4B6D37}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |

"{BBC79E0E-32A1-44CA-B21F-83C2D6809736}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |

"{C49FF675-49C9-44CC-999F-1D97D02094B7}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgnsx.exe |

"{CB237492-9BC3-482A-83E3-93D7B1A9D31C}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |

"{CB979E82-3875-45FE-AF02-39BE1D46DECC}" = protocol=6 | dir=in | app=c:\program files\ivt corporation\bluesoleil\bluesoleil.exe |

"TCP Query User{0049F0B1-A05E-4AD6-9B6F-3E575C495A3D}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |

"TCP Query User{27170F87-9398-4F86-A839-070D06A5A22C}C:\users\user\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe" = protocol=6 | dir=in | app=c:\users\user\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe |

"TCP Query User{2F1644BC-BF82-4370-8812-4BBA916AD8DF}C:\program files\microsoft games\halo custom edition\haloce.exe" = protocol=6 | dir=in | app=c:\program files\microsoft games\halo custom edition\haloce.exe |

"TCP Query User{443E176B-D521-4118-B0C7-BEE8C21C7D7C}C:\windows\explorer.exe" = protocol=6 | dir=in | app=c:\windows\explorer.exe |

"TCP Query User{45B114AF-3C24-4744-95A6-BF79FAC0F773}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |

"TCP Query User{47FF5DF9-BE6F-4F2E-88A9-CA5C1952763F}C:\windows\explorer.exe" = protocol=6 | dir=in | app=c:\windows\explorer.exe |

"TCP Query User{93002433-75BC-4B1F-B254-F869F68C424C}C:\program files\xbc\xbc_ns.exe" = protocol=6 | dir=in | app=c:\program files\xbc\xbc_ns.exe |

"TCP Query User{B65A74F7-50BB-41DE-A964-1A4EB0FD356A}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |

"UDP Query User{09399A5F-0946-4A8C-8DB8-6587E8F7E288}C:\windows\explorer.exe" = protocol=17 | dir=in | app=c:\windows\explorer.exe |

"UDP Query User{0F49B0EF-6341-4799-B3E9-842F9E7D25C4}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |

"UDP Query User{586E0602-3360-4F16-A0DC-23E51CAB024A}C:\program files\microsoft games\halo custom edition\haloce.exe" = protocol=17 | dir=in | app=c:\program files\microsoft games\halo custom edition\haloce.exe |

"UDP Query User{59779E32-8979-42F0-A090-0FD49F65D500}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |

"UDP Query User{7B366EB4-6F08-49E9-8853-665101D5A149}C:\users\user\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe" = protocol=17 | dir=in | app=c:\users\user\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe |

"UDP Query User{C258FC9B-C126-43B9-8C12-19DC8C10251D}C:\program files\xbc\xbc_ns.exe" = protocol=17 | dir=in | app=c:\program files\xbc\xbc_ns.exe |

"UDP Query User{D2442652-7E4F-4834-A202-A65D6E79EC7F}C:\windows\explorer.exe" = protocol=17 | dir=in | app=c:\windows\explorer.exe |

"UDP Query User{EDD7C12F-8DBA-4721-B295-EF19543871CD}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========


"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam

"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool

"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT

"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java 6 Update 29

"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform

"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup

"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile

"{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}" = Google Earth

"{438BB9B4-65FE-4626-91D9-A8F57B18001D}" = Bluesoleil2.6.0.8 Release 070517

"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant

"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR

"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials

"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater

"{50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1" = AVG PC Tuneup 2011

"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml

"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites

"{67E03279-F703-408F-B4BF-46B5FC8D70CD}" = Microsoft Works

"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin

"{7748AC8C-18E3-43BB-959B-088FAEA16FB2}" = Nero StartSmart

"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable

"{86620d27-5da7-46b6-9645-d5a593f234fc}" = Nero 9 Lite

"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight

"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007

"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007

"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007

"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007

"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007

"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007

"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system

"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007

"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007

"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007

"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007

"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007

"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)

"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)

"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting

"{96AFCF8B-3C53-49A2-8456-E637021B1033}" = Nero 8 Essentials

"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

"{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X

"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0

"{B2EC4A38-B545-4A00-8214-13FE0E915E6D}" = Advertising Center

"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger

"{BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}" = Nero ControlCenter

"{C81A2FE0-3574-00A9-CED4-BDAA334CBE8E}" = Nero Online Upgrade

"{C87BC0B7-2BB8-49D1-8CE0-EB0410EF0938}" = SystemDiagnostics

"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1

"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser

"{E4406ED3-B04C-44F1-ABB4-08775B74934F}" = Call Of Cthulhu DCoTE

"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call

"{E8A80433-302B-4FF1-815D-FCC8EAC482FF}" = Nero Installer

"{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}" = Sony Ericsson PC Companion 2.01.217

"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard

"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver

"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites

"ActiveScan 2.0" = Panda ActiveScan 2.0

"Adobe AIR" = Adobe AIR

"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX

"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin

"Big Fish Games Center" = Big Fish Games Center (remove only)

"Big Fish Games Sudoku" = Big Fish Games Sudoku (remove only)

"Celestia_is1" = Celestia 1.6.0

"Cradle of Rome" = Cradle of Rome (remove only)

"DVD Flick_is1" = DVD Flick

"Gmask 1.70 English" = Gmask 1.70 English

"Google Desktop" = Google Desktop

"Halo CE" = Microsoft Halo Custom Edition

"HDMI" = Intel® Graphics Media Accelerator Driver

"HOMESTUDENTR" = Microsoft Office Home and Student 2007

"Lexmark 640 Series" = Lexmark 640 Series

"Luxor Amun Rising" = Luxor Amun Rising (remove only)

"MagicDisc 2.7.106" = MagicDisc 2.7.106

"Mahjong Towers Eternity" = Mahjong Towers Eternity (remove only)

"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version

"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1

"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile

"Mozilla Firefox 8.0 (x86 en-GB)" = Mozilla Firefox 8.0 (x86 en-GB)

"NetWorx_is1" = NetWorx 5.1.7

"Poker Superstars II" = Poker Superstars II (remove only)

"PowerISO" = PowerISO

"Recuva" = Recuva

"Steam App 400" = Portal

"SynTPDeinstKey" = Synaptics Pointing Device Driver

"Virtual Villagers" = Virtual Villagers (remove only)

"VLC media player" = VLC media player 1.1.11

"WinLiveSuite_Wave3" = Windows Live Essentials

"WinRAR archiver" = WinRAR archiver

"XBC 5.1" = XBC 5.1

"YTdetect" = Yahoo! Detect

========== HKEY_USERS Uninstall List ==========


"Octoshape Streaming Services" = Octoshape Streaming Services

========== Last 10 Event Log Errors ==========

[ Application Events ]

Error - 03/11/2011 10:07:08 | Computer Name = User-PC | Source = SideBySide | ID = 16842785

Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\wksdb.exe".


Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"

could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 03/11/2011 10:07:09 | Computer Name = User-PC | Source = SideBySide | ID = 16842785

Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\wksss.exe".


Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"

could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 03/11/2011 10:07:09 | Computer Name = User-PC | Source = SideBySide | ID = 16842785

Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\WksWP.exe".


Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"

could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 03/11/2011 12:26:25 | Computer Name = User-PC | Source = WinMgmt | ID = 10

Description =

Error - 03/11/2011 15:26:08 | Computer Name = User-PC | Source = WinMgmt | ID = 10

Description =

Error - 03/11/2011 15:26:10 | Computer Name = User-PC | Source = SideBySide | ID = 16842785

Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\WksCal.exe".


Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"

could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 03/11/2011 15:26:10 | Computer Name = User-PC | Source = SideBySide | ID = 16842785

Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\wksdb.exe".


Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"

could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 03/11/2011 15:26:10 | Computer Name = User-PC | Source = SideBySide | ID = 16842785

Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\wksss.exe".


Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"

could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 03/11/2011 15:26:10 | Computer Name = User-PC | Source = SideBySide | ID = 16842785

Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\WksWP.exe".


Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"

could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 04/11/2011 19:59:16 | Computer Name = User-PC | Source = WinMgmt | ID = 10

Description =

[ System Events ]

Error - 22/12/2011 11:25:13 | Computer Name = User-PC | Source = HTTP | ID = 15016

Description =

Error - 22/12/2011 13:45:58 | Computer Name = User-PC | Source = HTTP | ID = 15016

Description =

Error - 22/12/2011 20:54:13 | Computer Name = User-PC | Source = HTTP | ID = 15016

Description =

Error - 23/12/2011 06:54:38 | Computer Name = User-PC | Source = HTTP | ID = 15016

Description =

Error - 23/12/2011 08:37:21 | Computer Name = User-PC | Source = HTTP | ID = 15016

Description =

Error - 23/12/2011 09:03:24 | Computer Name = User-PC | Source = HTTP | ID = 15016

Description =

Error - 23/12/2011 09:25:36 | Computer Name = User-PC | Source = volsnap | ID = 393251

Description = The shadow copies of volume C: were aborted because the shadow copy

storage failed to grow.

Error - 23/12/2011 10:31:24 | Computer Name = User-PC | Source = DCOM | ID = 10010

Description =

Error - 23/12/2011 10:32:33 | Computer Name = User-PC | Source = HTTP | ID = 15016

Description =

Error - 23/12/2011 10:59:06 | Computer Name = User-PC | Source = HTTP | ID = 15016

Description =

< End of report >

Link to post
Share on other sites

Please enable hidden files/folders:



Lets clean these up.............

Please do this:


  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    DRV - File not found [Kernel | Unknown | Running] -- -- (Hotkey)
    O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O3 - HKU\S-1-5-21-3654883410-1651815343-1435893916-1000\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
    O4 - HKLM..\Run: [CtrlVol] C:\Program Files\Launch Manager\CtrlVol.exe File not found
    O4 - HKLM..\Run: [LaunchAp] C:\Program Files\Launch Manager\LaunchAp.exe File not found
    O4 - HKU\S-1-5-21-3654883410-1651815343-1435893916-1000..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent File not found


  • Then click the Run Fix button at the top
  • Let the program run unhindered, when done it will say "Fix Complete press ok to open the log"
  • Please post that log in your next reply. Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTL\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.



Please visit this webpage for download links, and instructions for running ComboFix


Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Make sure you run ComboFix from your desktop.

Please include the C:\ComboFix.txt in your next reply for further review.


Link to post
Share on other sites

All processes killed

========== OTL ==========

Error: Unable to stop service Hotkey!

Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Hotkey deleted successfully.

Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ not found.

Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.

Registry value HKEY_USERS\S-1-5-21-3654883410-1651815343-1435893916-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\CtrlVol deleted successfully.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\LaunchAp deleted successfully.

Registry value HKEY_USERS\S-1-5-21-3654883410-1651815343-1435893916-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Steam deleted successfully.

========== COMMANDS ==========


User: All Users

User: Default

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 402 bytes

->Flash cache emptied: 53632 bytes

User: Default User

User: Public

User: User

->Temp folder emptied: 143176002 bytes

->Temporary Internet Files folder emptied: 78031400 bytes

->Java cache emptied: 356279 bytes

->FireFox cache emptied: 254485197 bytes

->Flash cache emptied: 94286 bytes

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 0 bytes

%systemroot%\System32 .tmp files removed: 0 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 33752733 bytes

%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes

RecycleBin emptied: 424 bytes

Total Files Cleaned = 486.00 mb

OTL by OldTimer - Version log created on 12232011_211621

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...

ComboFix 11-12-23.01 - User 23/12/2011 21:39:39.1.2 - x86

Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.2038.1204 [GMT 0:00]

Running from: c:\users\User\Desktop\ComboFix.exe

SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}



((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))



c:\program files\WinPCap

c:\program files\WinPCap\daemon_mgm.exe

c:\program files\WinPCap\NetMonInstaller.exe

c:\program files\WinPCap\npf_mgm.exe

c:\program files\WinPCap\rpcapd.exe

c:\program files\WinPCap\Uninstall.exe







((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))






((((((((((((((((((((((((( Files Created from 2011-11-23 to 2011-12-23 )))))))))))))))))))))))))))))))



2073-10-27 10:55 . 2009-10-03 18:32 1118208 ----a-w- c:\program files\Microsoft Games\Halo Custom Edition\Strings.dll

2073-10-27 10:55 . 2009-10-03 18:32 1835008 ----a-w- c:\program files\Microsoft Games\Halo Custom Edition\haloceded.exe

2011-12-23 20:38 . 2011-12-23 20:38 -------- d-----w- C:\_OTL

2011-12-23 13:00 . 2011-12-23 13:03 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2011-12-23 13:00 . 2011-08-31 17:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-12-22 15:22 . 2011-12-22 15:22 -------- d-----w- c:\program files\POWERISO

2011-12-22 14:57 . 2011-12-22 14:57 -------- d-----w- c:\program files\Bethesda Softworks

2011-12-22 14:56 . 2002-08-05 10:46 57344 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0700\Intel32\ctor.dll

2011-12-22 14:56 . 2002-08-02 03:10 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0700\Intel32\DotNetInstaller.exe

2011-12-22 14:56 . 2002-08-02 02:20 634880 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0700\Intel32\iKernel.dll

2011-12-22 14:56 . 2002-08-02 02:20 237568 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0700\Intel32\iscript.dll

2011-12-22 14:56 . 2002-08-02 02:20 151552 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0700\Intel32\iuser.dll

2011-12-22 14:56 . 2011-12-22 14:56 270468 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0700\Intel32\Setup.dll

2011-12-22 14:56 . 2011-12-22 14:56 159876 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0700\Intel32\IGdi.dll

2011-12-22 03:36 . 2009-02-24 18:42 116736 ----a-w- c:\windows\system32\drivers\mcdbus.sys

2011-12-22 03:36 . 2011-12-22 03:47 -------- d-----w- c:\program files\MagicDisc

2011-12-22 03:28 . 2011-12-22 03:28 -------- d-----w- c:\users\User\AppData\Roaming\DAEMON Tools Pro

2011-12-22 03:28 . 2011-12-22 03:28 -------- d-----w- c:\programdata\DAEMON Tools Pro




(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))


2011-11-15 03:50 . 2011-11-15 03:50 112096 ----a-w- c:\windows\system32\drivers\scdemu.sys

2011-11-13 03:56 . 2011-05-19 19:37 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2011-10-03 05:06 . 2010-04-16 22:13 472808 ----a-w- c:\windows\system32\deployJava1.dll

2011-11-10 16:12 . 2011-05-18 20:48 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll



((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))



*Note* empty entries & legit default entries are not shown




"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]

"Octoshape Streaming Services"="c:\users\User\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" [2009-01-08 70936]

"Sony Ericsson PC Companion"="c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" [2011-07-25 433360]

"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]



"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-06-06 142104]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-06-06 154392]

"Persistence"="c:\windows\system32\igfxpers.exe" [2007-06-06 138008]

"RtHDVCpl"="RtHDVCpl.exe" [2007-07-06 4669440]

"HotkeyApp"="c:\program files\Launch Manager\HotkeyApp.exe" [2007-07-26 192512]

"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-08-17 102400]

"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]

"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-03-08 1831936]

"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-08-31 1047208]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-10 35736]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]

"NetWorx"="c:\program files\NetWorx\networx.exe" [2011-05-17 2794496]

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]

"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]



"fsc-reg"="c:\programdata\fsc-reg\fscreg.exe" [2008-01-17 511248]


c:\users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]



"EnableUIADesktopToggle"= 0 (0x0)


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]



[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]



[HKLM\~\startupfolder\C:^Users^User^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MagicDisc.lnk]

path=c:\users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk




R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [x]

R3 PsSdk30;PsSdk30;c:\windows\system32\Drivers\PsSdk30.drv [x]

R3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-06-29 155344]

R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]

S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-06-30 28552]

S1 networx;networx;c:\windows\system32\drivers\networx.sys [2011-04-15 51640]

S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152]

S2 Sony Ericsson PC Companion download service;Sony Ericsson PC Companion download service;c:\program files\Sony Ericsson\Sony Ericsson PC Companion\supserv.exe [2010-03-23 93392]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-08-31 22216]

S3 WisLMSvc;WisLMSvc;c:\program files\Launch Manager\WisLMSvc.exe [2006-11-18 118784]



[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

bthsvcs REG_MULTI_SZ BthServ


Contents of the 'Scheduled Tasks' folder


2011-12-23 c:\windows\Tasks\User_Feed_Synchronization-{616F3064-DA7D-4CD6-864F-C62539543CED}.job

- c:\windows\system32\msfeedssync.exe [2010-06-11 04:30]



------- Supplementary Scan -------


uStart Page = hxxp://www.google.com/ig/redirectdomain?brand=FUJD&bmod=FUJD

mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=FUJD&bmod=FUJD

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000

IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html

TCP: DhcpNameServer =

FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\xhxl1e8a.default\

FF - prefs.js: browser.search.selectedEngine - Google

FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/ig

FF - prefs.js: keyword.URL - hxxp://uk.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=867034&p=

FF - user.js: network.cookie.cookieBehavior - 0

FF - user.js: privacy.clearOnShutdown.cookies - false

FF - user.js: security.warn_viewing_mixed - false

FF - user.js: security.warn_viewing_mixed.show_once - false

FF - user.js: security.warn_submit_insecure - false

FF - user.js: security.warn_submit_insecure.show_once - false


- - - - ORPHANS REMOVED - - - -


HKLM-Run-Wbutton - c:\program files\Launch Manager\WButton.exe

MSConfigStartUp-SearchSettings - c:\program files\Common Files\Spigot\Search Settings\SearchSettings.exe

AddRemove-Steam App 400 - c:\program files\Steam\steam.exe

AddRemove-WinPcapInst - c:\program files\WinPcap\Uninstall.exe






catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2011-12-23 22:12

Windows 6.0.6001 Service Pack 1 NTFS


scanning hidden processes ...


scanning hidden autostart entries ...



Wbutton = c:\program files\Launch Manager\WButton.exe?????H?????????????F??X?v????????????0???$???????d???4??vG? ????????vR??v??????????????????F?4???o??u????????x???t???+?A?????????J?A???3u????|?????F?$l@?H???????????? A? ?cu????J?A?[?@??????v@???????3u??@????????


scanning hidden files ...


scan completed successfully

hidden files: 0







--------------------- LOCKED REGISTRY KEYS ---------------------



@Denied: (Full) (Everyone)

@Allowed: (Read) (RestrictedCode)







@Denied: (Full) (Everyone)

@Allowed: (Read) (RestrictedCode)





@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)




@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)



------------------------ Other Running Processes ------------------------




c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe

c:\program files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe



c:\program files\Windows Media Player\wmpnetwk.exe




Completion time: 2011-12-23 22:19:01 - machine was rebooted

ComboFix-quarantined-files.txt 2011-12-23 22:18


Pre-Run: 2,887,401,472 bytes free

Post-Run: 3,019,894,784 bytes free


- - End Of File - - D43486B2554ABF4FE90CF87D91E092FF

By the way i already had hidden folders as 'shown'.

Link to post
Share on other sites

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

4. If ComboFix wants to update.....please allow it to.


c:\program files\Common Files\Spigot

Save this as CFScript.txt, in the same location as ComboFix.exe


Refering to the picture above, drag CFScript into ComboFix.exe

CAUTION: Do not mouse-click ComboFix while it is running. It may cause it to stall.

After reboot, (in case it asks to reboot)......

Please provide the contents of the ComboFix log (C:\ComboFix.txt) in your next reply.


Link to post
Share on other sites

ComboFix 11-12-23.01 - User 24/12/2011 0:31.2.2 - x86

Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.2038.1071 [GMT 0:00]

Running from: c:\users\User\Desktop\ComboFix.exe

Command switches used :: c:\users\User\Desktop\CFScript.txt

SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}



((((((((((((((((((((((((( Files Created from 2011-11-24 to 2011-12-24 )))))))))))))))))))))))))))))))



2073-10-27 10:55 . 2009-10-03 18:32 1118208 ----a-w- c:\program files\Microsoft Games\Halo Custom Edition\Strings.dll

2073-10-27 10:55 . 2009-10-03 18:32 1835008 ----a-w- c:\program files\Microsoft Games\Halo Custom Edition\haloceded.exe

2011-12-24 00:40 . 2011-12-24 00:40 -------- d-----w- c:\users\User\AppData\Local\temp

2011-12-24 00:40 . 2011-12-24 00:40 -------- d-----w- c:\users\Default\AppData\Local\temp

2011-12-23 20:38 . 2011-12-23 20:38 -------- d-----w- C:\_OTL

2011-12-23 13:00 . 2011-12-23 13:03 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2011-12-23 13:00 . 2011-08-31 17:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-12-22 15:22 . 2011-12-22 15:22 -------- d-----w- c:\program files\POWERISO

2011-12-22 14:57 . 2011-12-22 14:57 -------- d-----w- c:\program files\Bethesda Softworks

2011-12-22 14:56 . 2002-08-05 10:46 57344 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0700\Intel32\ctor.dll

2011-12-22 14:56 . 2002-08-02 03:10 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0700\Intel32\DotNetInstaller.exe

2011-12-22 14:56 . 2002-08-02 02:20 634880 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0700\Intel32\iKernel.dll

2011-12-22 14:56 . 2002-08-02 02:20 237568 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0700\Intel32\iscript.dll

2011-12-22 14:56 . 2002-08-02 02:20 151552 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0700\Intel32\iuser.dll

2011-12-22 14:56 . 2011-12-22 14:56 270468 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0700\Intel32\Setup.dll

2011-12-22 14:56 . 2011-12-22 14:56 159876 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0700\Intel32\IGdi.dll

2011-12-22 03:36 . 2009-02-24 18:42 116736 ----a-w- c:\windows\system32\drivers\mcdbus.sys

2011-12-22 03:36 . 2011-12-22 03:47 -------- d-----w- c:\program files\MagicDisc

2011-12-22 03:28 . 2011-12-22 03:28 -------- d-----w- c:\users\User\AppData\Roaming\DAEMON Tools Pro

2011-12-22 03:28 . 2011-12-22 03:28 -------- d-----w- c:\programdata\DAEMON Tools Pro




(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))


2011-11-15 03:50 . 2011-11-15 03:50 112096 ----a-w- c:\windows\system32\drivers\scdemu.sys

2011-11-13 03:56 . 2011-05-19 19:37 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2011-10-03 05:06 . 2010-04-16 22:13 472808 ----a-w- c:\windows\system32\deployJava1.dll

2011-11-10 16:12 . 2011-05-18 20:48 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll



((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))



*Note* empty entries & legit default entries are not shown




"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]

"Octoshape Streaming Services"="c:\users\User\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" [2009-01-08 70936]

"Sony Ericsson PC Companion"="c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" [2011-07-25 433360]

"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]



"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-06-06 142104]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-06-06 154392]

"Persistence"="c:\windows\system32\igfxpers.exe" [2007-06-06 138008]

"RtHDVCpl"="RtHDVCpl.exe" [2007-07-06 4669440]

"HotkeyApp"="c:\program files\Launch Manager\HotkeyApp.exe" [2007-07-26 192512]

"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-08-17 102400]

"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]

"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-03-08 1831936]

"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-08-31 1047208]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-10 35736]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]

"NetWorx"="c:\program files\NetWorx\networx.exe" [2011-05-17 2794496]

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]

"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]



"fsc-reg"="c:\programdata\fsc-reg\fscreg.exe" [2008-01-17 511248]


c:\users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]



"EnableUIADesktopToggle"= 0 (0x0)


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]



[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]



[HKLM\~\startupfolder\C:^Users^User^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MagicDisc.lnk]

path=c:\users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk




R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [x]

R3 PsSdk30;PsSdk30;c:\windows\system32\Drivers\PsSdk30.drv [x]

R3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-06-29 155344]

R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]

S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-06-30 28552]

S1 networx;networx;c:\windows\system32\drivers\networx.sys [2011-04-15 51640]

S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152]

S2 Sony Ericsson PC Companion download service;Sony Ericsson PC Companion download service;c:\program files\Sony Ericsson\Sony Ericsson PC Companion\supserv.exe [2010-03-23 93392]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-08-31 22216]

S3 WisLMSvc;WisLMSvc;c:\program files\Launch Manager\WisLMSvc.exe [2006-11-18 118784]



[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

bthsvcs REG_MULTI_SZ BthServ


Contents of the 'Scheduled Tasks' folder


2011-12-23 c:\windows\Tasks\User_Feed_Synchronization-{616F3064-DA7D-4CD6-864F-C62539543CED}.job

- c:\windows\system32\msfeedssync.exe [2010-06-11 04:30]



------- Supplementary Scan -------


uStart Page = hxxp://www.google.com/ig/redirectdomain?brand=FUJD&bmod=FUJD

mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=FUJD&bmod=FUJD

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000

IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html

TCP: DhcpNameServer =

FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\xhxl1e8a.default\

FF - prefs.js: browser.search.selectedEngine - Google

FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/ig

FF - prefs.js: keyword.URL - hxxp://uk.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=867034&p=

FF - user.js: network.cookie.cookieBehavior - 0

FF - user.js: privacy.clearOnShutdown.cookies - false

FF - user.js: security.warn_viewing_mixed - false

FF - user.js: security.warn_viewing_mixed.show_once - false

FF - user.js: security.warn_submit_insecure - false

FF - user.js: security.warn_submit_insecure.show_once - false





catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2011-12-24 00:40

Windows 6.0.6001 Service Pack 1 NTFS


scanning hidden processes ...


scanning hidden autostart entries ...


scanning hidden files ...


scan completed successfully

hidden files: 0







--------------------- LOCKED REGISTRY KEYS ---------------------



@Denied: (Full) (Everyone)

@Allowed: (Read) (RestrictedCode)







@Denied: (Full) (Everyone)

@Allowed: (Read) (RestrictedCode)





@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)




@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)



Completion time: 2011-12-24 00:44:36

ComboFix-quarantined-files.txt 2011-12-24 00:44

ComboFix2.txt 2011-12-23 22:19


Pre-Run: 2,596,024,320 bytes free

Post-Run: 2,569,138,176 bytes free


- - End Of File - - D1F0116A99C0EF1ADA9DC0C3FDAEE673

Link to post
Share on other sites

Good :)

Please uninstall ComboFix:

Click on the Start button and then in the Search field enter combofix /uninstall

Please note that there is a space between combofix and /uninstall.

Once you have typed this in, press Enter on your Keyboard.

A Open File security warning will appear asking if you are sure you want to run ComboFix. Please click on the Run button to start the program.

ComboFix will now uninstall itself from your computer and remove any backups and quarantined files.

When it has finished you will be greeted by a dialog box stating that ComboFix has been uninstalled.

You can now delete the ComboFix.exe program from your computer.

ComboFix has now been uninstalled from your Windows Vista or Windows 7 computer.


Run OTL and hit the CleanUp button. (This will cleanup the tools and logs used including itself)

Any questions...please post back.

Take a look at My Preventive Maintenance to avoid being infected again.

Good Luck and Thanks for using the forum, MrC

Have a Good Holiday and New Year!

Link to post
Share on other sites

Glad we could help. :)

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.