Jump to content

Can anyone help me clean up my comp? (if it needs it)...


Recommended Posts

Hi Guys

My computer isn't slowing down or acting weird but I have seen some toolbars in Firefox which when I try and uninstall they don't go away so just wondering if I might need to clean it up a bit.

I downloaded and ran a quick scan with Malwarebytes and it found nothing. I attach my hijackthis log and would be happy if someone could look at it for me and just may be recommend anything that needs to be done (if anything does need to be done).

Thank you

Christian

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 16:54:13, on 23/04/2012

Platform: Windows 7 SP1 (WinNT 6.00.3505)

MSIE: Internet Explorer v9.00 (9.00.8112.16421)

Boot mode: Normal

Running processes:

C:\Windows\System32\spool\drivers\x64\3\WrtMon.exe

C:\Windows\System32\spool\drivers\x64\3\WrtProc.exe

C:\Program Files (x86)\Plustek\Plustek OpticBook 3800\book express.exe

C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe

C:\Program Files (x86)\ABBYY FineReader 11\Bonus.ScreenshotReader.exe

C:\Program Files (x86)\Mindjet\MindManager 10\MmReminderService.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Program Files (x86)\OLYMPUS\DeviceDetector\DeviceDetector4.exe

C:\Program Files (x86)\iTunes\iTunesHelper.exe

C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE

C:\Program Files (x86)\Mozilla Firefox\firefox.exe

C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe

C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.co.uk

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?affID=109980&babsrc=HP_ss&mntrId=d8a31185000000000000d0df9a8d65b5

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

F2 - REG:system.ini: UserInit=userinit.exe

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: CmjBrowserHelperObject Object - {6FE6A929-59D1-4763-91AD-29B61CFFB35B} - C:\Program Files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll

O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WIA6EB~1\Datamngr\ToolBar\searchqudtx.dll (file missing)

O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

O3 - Toolbar: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WIA6EB~1\Datamngr\ToolBar\searchqudtx.dll (file missing)

O3 - Toolbar: (no name) - !{98889811-442D-49dd-99D7-DC866BE87DBC} - (no file)

O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [bCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices

O4 - HKLM\..\Run: [KeNotify] "C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe" LPCM

O4 - HKLM\..\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe hwSetUP

O4 - HKLM\..\Run: [bonus.SSR.FR11] "C:\Program Files (x86)\ABBYY FineReader 11\Bonus.ScreenshotReader.exe" /autorun

O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [MMReminderService] C:\Program Files (x86)\Mindjet\MindManager 10\MMReminderService.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent

O4 - HKCU\..\Run: [Xvid] C:\Program Files (x86)\Xvid\CheckUpdate.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Christian Ronchetti\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')

O4 - .DEFAULT User Startup: TaskBar.vbs (User 'Default user')

O4 - Startup: Colour Explorer 9,0.lnk = C:\Program Files (x86)\MicrolinkPC\CXLOADER.exe

O4 - Startup: OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE

O4 - Global Startup: Book Pavilion (Plustek OpticBook 3800).lnk = ?

O4 - Global Startup: Device Detector 4.lnk = C:\Program Files (x86)\OLYMPUS\DeviceDetector\DeviceDetector4.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000

O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105

O8 - Extra context menu item: Send Image To MindManager - res://C:\Program Files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll/201

O8 - Extra context menu item: Send Link To MindManager - res://C:\Program Files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll/203

O8 - Extra context menu item: Send Page To MindManager - res://C:\Program Files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll/204

O8 - Extra context menu item: Send Text To MindManager - res://C:\Program Files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll/202

O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll

O9 - Extra button: Send to Mindjet MindManager - {2F72393D-2472-4F82-B600-ED77F354B7FF} - C:\Program Files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll

O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - http://88.247.210.37:81/activex/AMC.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL

O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL

O20 - AppInit_DLLs:

O23 - Service: ABBYY FineReader 11 PE Licensing Service (ABBYY.Licensing.FineReader.Professional.11.0) - ABBYY - C:\Program Files (x86)\ABBYY FineReader 11\NetworkLicenseServer.exe

O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) - ABBYY - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe

O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe

O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: Olympus DVR Service - OLYMPUS IMAGING CORP. - C:\Program Files (x86)\Common Files\Olympus Shared\DeviceManager\olydvrsv.exe

O23 - Service: PACE License Services (PaceLicenseDServices) - PACE Anti-Piracy, Inc. - C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe

O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe

O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe

O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)

O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--

End of file - 13054 bytes

Link to post
Share on other sites

Welcome to the forum, please start at the link below:

http://forums.malwar...?showtopic=9573

Post back the 2 logs.

<====><====><====><====><====><====><====><====>

Next.......

Please remove any usb or external drives from the computer before you run this scan!

Please download and run RogueKiller.

For Windows XP, double-click to start.

For Vista or Windows 7, do a right-click on the program, select Run as Administrator to start, & when prompted Allow to run.

Click Scan to scan the system (don't run any other options)

Post back the report.

What's the name of the tool bars that you're talking about?

MrC

Link to post
Share on other sites

.

DDS (Ver_2011-08-26.01) - NTFSAMD64

Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_31

Run by Christian Ronchetti at 20:07:36 on 2012-04-23

Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.4004.1665 [GMT 1:00]

.

AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}

SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

============== Running Processes ===============

.

C:\Windows\system32\wininit.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\svchost.exe -k RPCSS

C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Program Files (x86)\ABBYY FineReader 11\NetworkLicenseServer.exe

C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe

C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe

C:\Windows\system32\svchost.exe -k imgsvc

C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Windows\system32\taskhost.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Windows\System32\igfxtray.exe

C:\Windows\System32\hkcmd.exe

C:\Windows\System32\igfxpers.exe

C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe

C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe

C:\Windows\System32\spool\drivers\x64\3\WrtMon.exe

C:\Program Files\Synaptics\SynTP\SynTPHelper.exe

C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe

C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe

C:\Program Files\Microsoft Security Client\msseces.exe

C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE

C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatcher.exe

C:\Windows\System32\spool\drivers\x64\3\WrtProc.exe

C:\Program Files (x86)\Plustek\Plustek OpticBook 3800\book express.exe

C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe

C:\Program Files (x86)\ABBYY FineReader 11\Bonus.ScreenshotReader.exe

C:\Program Files (x86)\Mindjet\MindManager 10\MmReminderService.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Program Files (x86)\OLYMPUS\DeviceDetector\DeviceDetector4.exe

C:\Program Files (x86)\iTunes\iTunesHelper.exe

C:\Windows\system32\igfxext.exe

C:\Windows\system32\igfxsrvc.exe

C:\Windows\system32\SearchIndexer.exe

C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE

C:\Windows\splwow64.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Program Files (x86)\Nero\Update\NASvc.exe

C:\Program Files (x86)\Mozilla Firefox\firefox.exe

C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe

C:\Windows\system32\DllHost.exe

C:\Windows\system32\calc.exe

C:\Windows\system32\SearchProtocolHost.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Windows\system32\DllHost.exe

C:\Windows\system32\DllHost.exe

C:\Windows\SysWOW64\cmd.exe

C:\Windows\system32\conhost.exe

C:\Windows\SysWOW64\cscript.exe

C:\Windows\system32\wbem\wmiprvse.exe

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://search.babylon.com/?affID=109980&babsrc=HP_ss&mntrId=d8a31185000000000000d0df9a8d65b5

uDefault_Page_URL = hxxp://www.google.co.uk

uInternet Settings,ProxyOverride = *.local

mWinlogon: Userinit=userinit.exe

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO: CmjBrowserHelperObject Object: {6fe6a929-59d1-4763-91ad-29b61cffb35b} - C:\Program Files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll

BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL

BHO: Java Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll

BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WIA6EB~1\Datamngr\ToolBar\searchqudtx.dll

BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

TB: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WIA6EB~1\Datamngr\ToolBar\searchqudtx.dll

TB: !{98889811-442D-49dd-99D7-DC866BE87DBC} - No File

uRun: [Xvid] C:\Program Files (x86)\Xvid\CheckUpdate.exe

uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background

uRun: [Facebook Update] "C:\Users\Christian Ronchetti\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver

mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

mRun: [bCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices

mRun: [KeNotify] "C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe" LPCM

mRun: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe hwSetUP

mRun: [bonus.SSR.FR11] "C:\Program Files (x86)\ABBYY FineReader 11\Bonus.ScreenshotReader.exe" /autorun

mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"

mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime

mRun: [MMReminderService] C:\Program Files (x86)\Mindjet\MindManager 10\MMReminderService.exe

mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"

mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

mRunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent

StartupFolder: C:\Users\CHRIST~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\COLOUR~1.LNK - C:\Program Files (x86)\MicrolinkPC\CXLOADER.exe

StartupFolder: C:\Users\CHRIST~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ONENOT~1.LNK - C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE

StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BOOKPA~1.LNK - C:\Program Files (x86)\Plustek\Plustek OpticBook 3800\book express.exe

StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\DEVICE~1.LNK - C:\Program Files (x86)\OLYMPUS\DeviceDetector\DeviceDetector4.exe

mPolicies-explorer: NoActiveDesktop = 1 (0x1)

mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)

mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)

mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)

mPolicies-system: EnableUIADesktopToggle = 0 (0x0)

IE:

IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000

IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105

IE: Send Image To MindManager - C:\Program Files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll/201

IE: Send Link To MindManager - C:\Program Files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll/203

IE: Send Page To MindManager - C:\Program Files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll/204

IE: Send Text To MindManager - C:\Program Files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll/202

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll

IE: {2F72393D-2472-4F82-B600-ED77F354B7FF} - {6FE6A929-59D1-4763-91AD-29B61CFFB35B} - C:\Program Files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll

IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab

DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://88.247.210.37:81/activex/AMC.cab

TCP: DhcpNameServer = 192.168.0.1

TCP: Interfaces\{9D90092F-353F-44BC-BAD7-EAA0BE47863B} : DhcpNameServer = 192.168.0.1

TCP: Interfaces\{9D90092F-353F-44BC-BAD7-EAA0BE47863B}\25F63756D6162797242716E6368623 : DhcpNameServer = 213.120.234.6 194.72.0.98

TCP: Interfaces\{9D90092F-353F-44BC-BAD7-EAA0BE47863B}\2656C6B696E6334353A616E6 : DhcpNameServer = 192.168.2.1

Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL

AppInit_DLLs:

SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL

mASetup: {90EF4A5E-85DB-4825-96F5-1AB93C2A8EEB} - C:\Program Files (x86)\Mindjet\MindManager 10\sys\MmInternetExplorerActiveSetup.vbs

BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO-X64: AcroIEHelperStub - No File

BHO-X64: CmjBrowserHelperObject Object: {6FE6A929-59D1-4763-91AD-29B61CFFB35B} - C:\Program Files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll

BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL

BHO-X64: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll

BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO-X64: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WIA6EB~1\Datamngr\ToolBar\searchqudtx.dll

BHO-X64: Searchqu Toolbar - No File

BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL

BHO-X64: URLRedirectionBHO - No File

BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

TB-X64: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WIA6EB~1\Datamngr\ToolBar\searchqudtx.dll

mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

mRun-x64: [bCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices

mRun-x64: [KeNotify] "C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe" LPCM

mRun-x64: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe hwSetUP

mRun-x64: [bonus.SSR.FR11] "C:\Program Files (x86)\ABBYY FineReader 11\Bonus.ScreenshotReader.exe" /autorun

mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"

mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime

mRun-x64: [MMReminderService] C:\Program Files (x86)\Mindjet\MindManager 10\MMReminderService.exe

mRun-x64: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"

mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

mRunOnce-x64: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent

AppInit_DLLs-X64:

SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL

.

================= FIREFOX ===================

.

FF - ProfilePath - C:\Users\Christian Ronchetti\AppData\Roaming\Mozilla\Firefox\Profiles\xd6r04iw.default\

FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)

FF - prefs.js: browser.startup.homepage - hxxp://www.searchqu.com/102

FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=100&systemid=102&sr=0&q=

FF - prefs.js: network.proxy.type - 0

FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npdeployJava1.dll

FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll

FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrlui.dll

FF - plugin: C:\Users\Christian Ronchetti\AppData\Local\Facebook\Messenger\2.0.4478.0\npFbDesktopPlugin.dll

FF - plugin: C:\Users\Christian Ronchetti\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll

FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_233.dll

.

---- FIREFOX POLICIES ----

FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109980

FF - user.js: extensions.BabylonToolbar_i.babExt -

FF - user.js: extensions.BabylonToolbar_i.srcExt - ss

FF - user.js: extensions.BabylonToolbar_i.id - d8a31185000000000000d0df9a8d65b5

FF - user.js: extensions.BabylonToolbar_i.hardId - d8a31185000000000000d0df9a8d65b5

FF - user.js: extensions.BabylonToolbar_i.instlDay - 15445

FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1721:11:17

FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon

FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar

FF - user.js: extensions.BabylonToolbar_i.aflt - babsst

FF - user.js: extensions.BabylonToolbar_i.smplGrp - none

FF - user.js: extensions.BabylonToolbar_i.tlbrId - base

FF - user.js: extensions.BabylonToolbar_i.instlRef - sst

.

============= SERVICES / DRIVERS ===============

.

R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]

R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]

R2 ABBYY.Licensing.FineReader.Professional.11.0;ABBYY FineReader 11 PE Licensing Service;C:\Program Files (x86)\ABBYY FineReader 11\NetworkLicenseServer.exe [2011-8-3 819976]

R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-5-14 759048]

R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928]

R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-4-23 654408]

R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2010-5-4 503080]

R2 PaceLicenseDServices;PACE License Services;C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe [2011-7-9 2932224]

R3 CeKbFilter;CeKbFilter;C:\Windows\system32\DRIVERS\CeKbFilter.sys --> C:\Windows\system32\DRIVERS\CeKbFilter.sys [?]

R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]

R3 MEIx64;Intel® Management Engine Interface;C:\Windows\system32\drivers\HECIx64.sys --> C:\Windows\system32\drivers\HECIx64.sys [?]

R3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\system32\DRIVERS\MpNWMon.sys --> C:\Windows\system32\DRIVERS\MpNWMon.sys [?]

R3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]

R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-4-27 288272]

R3 PGEffect;Pangu effect driver;C:\Windows\system32\DRIVERS\pgeffect.sys --> C:\Windows\system32\DRIVERS\pgeffect.sys [?]

R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]

S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-2-29 158856]

S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-15 253088]

S3 FwLnk;FwLnk Driver;C:\Windows\system32\drivers\FwLnk.sys --> C:\Windows\system32\drivers\FwLnk.sys [?]

S3 ggflt;SEMC USB Flash Driver Filter;C:\Windows\system32\DRIVERS\ggflt.sys --> C:\Windows\system32\DRIVERS\ggflt.sys [?]

S3 Impcd;Impcd;C:\Windows\system32\drivers\Impcd.sys --> C:\Windows\system32\drivers\Impcd.sys [?]

S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-6-12 31125880]

S3 Netaapl;Apple Mobile Device Ethernet Service;C:\Windows\system32\DRIVERS\netaapl64.sys --> C:\Windows\system32\DRIVERS\netaapl64.sys [?]

S3 Olympus DVR Service;Olympus DVR Service;C:\Program Files (x86)\Common Files\Olympus Shared\DeviceManager\olydvrsv.exe [2011-5-10 176128]

S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]

S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\system32\Drivers\RtsUStor.sys --> C:\Windows\system32\Drivers\RtsUStor.sys [?]

S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]

S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?]

S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]

S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]

.

=============== Created Last 30 ================

.

2012-04-23 15:49:31 388096 ----a-r- C:\Users\Christian Ronchetti\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2012-04-23 15:49:31 -------- d-----w- C:\Program Files (x86)\Trend Micro

2012-04-23 15:41:04 -------- d-----w- C:\Users\Christian Ronchetti\AppData\Roaming\Malwarebytes

2012-04-23 15:40:47 -------- d-----w- C:\ProgramData\Malwarebytes

2012-04-23 15:40:46 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys

2012-04-23 15:40:46 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware

2012-04-23 15:25:05 -------- d-----w- C:\Users\Christian Ronchetti\AppData\Local\{FC570FC9-D91B-41A7-92D7-AA9C62FAA823}

2012-04-23 15:24:53 -------- d-----w- C:\Users\Christian Ronchetti\AppData\Local\{471142C4-FC30-4DE8-AA8D-9B44DCC119C1}

2012-04-23 14:50:44 8917360 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{01CCA537-C00B-40A3-9978-A594718D95F0}\mpengine.dll

2012-04-23 14:48:02 2382848 ----a-w- C:\Windows\System32\mshtml.tlb

2012-04-23 14:48:01 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb

2012-04-23 14:48:00 304640 ----a-w- C:\Program Files\Internet Explorer\IEShims.dll

2012-04-23 14:48:00 174392 ----a-w- C:\Program Files\Internet Explorer\sqmapi.dll

2012-04-23 14:48:00 141112 ----a-w- C:\Program Files (x86)\Internet Explorer\sqmapi.dll

2012-04-23 14:45:22 5559152 ----a-w- C:\Windows\System32\ntoskrnl.exe

2012-04-23 14:45:22 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe

2012-04-23 14:45:21 3913072 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe

2012-04-23 14:36:22 81408 ----a-w- C:\Windows\System32\imagehlp.dll

2012-04-23 14:36:22 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys

2012-04-23 14:36:22 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll

2012-04-23 14:36:21 5120 ----a-w- C:\Windows\SysWow64\wmi.dll

2012-04-23 14:36:21 5120 ----a-w- C:\Windows\System32\wmi.dll

2012-04-23 14:36:21 220672 ----a-w- C:\Windows\System32\wintrust.dll

2012-04-23 14:36:21 172544 ----a-w- C:\Windows\SysWow64\wintrust.dll

2012-04-23 14:19:59 -------- d-----w- C:\Users\Christian Ronchetti\AppData\Local\{51C258B7-DC86-488C-8E39-E21C1ED78BB2}

2012-04-23 14:19:47 -------- d-----w- C:\Users\Christian Ronchetti\AppData\Local\{CC5FC9CE-D138-49D6-A3B9-BB103A229B86}

2012-04-19 13:39:44 -------- d-----w- C:\Users\Christian Ronchetti\AppData\Local\{E50630EE-25AF-4F32-8553-E18B61EFEC26}

2012-04-19 13:39:31 -------- d-----w- C:\Users\Christian Ronchetti\AppData\Local\{49AB086C-ECFE-4248-8BA1-900FE5164080}

2012-04-19 13:23:36 -------- d-----w- C:\Windows\XSxS

2012-04-18 12:42:33 -------- d-----w- C:\Program Files\iPod

2012-04-18 12:42:32 -------- d-----w- C:\Program Files\iTunes

2012-04-15 20:18:09 -------- d-----w- C:\Program Files (x86)\fbphotozoom

2012-04-15 20:11:03 -------- d-----w- C:\Users\Christian Ronchetti\AppData\Local\Babylon

2012-04-15 20:11:02 -------- d-----w- C:\Users\Christian Ronchetti\AppData\Roaming\Babylon

2012-04-15 20:11:02 -------- d-----w- C:\ProgramData\Babylon

2012-04-15 19:54:21 -------- d-----w- C:\Users\Christian Ronchetti\AppData\Local\{9C107A08-3E3B-4A2C-9F87-9F9DFCB8CEEC}

2012-04-15 19:54:08 -------- d-----w- C:\Users\Christian Ronchetti\AppData\Local\{FA5DE11A-E444-486C-AA8F-92A11139F3E3}

2012-04-15 19:51:02 -------- d-----w- C:\ProgramData\PACE

2012-04-15 19:51:00 -------- d-----w- C:\Program Files (x86)\Common Files\PACE

2012-04-15 19:50:55 -------- d-----w- C:\ProgramData\Antares

2012-04-15 15:43:14 -------- d-----w- C:\ProgramData\PACE Anti-Piracy

2012-04-15 15:43:13 -------- d-----w- C:\Users\Christian Ronchetti\AppData\Roaming\PACE Anti-Piracy

2012-04-15 15:43:13 -------- d-----w- C:\Users\Christian Ronchetti\AppData\Local\PACE Anti-Piracy

2012-04-15 15:43:13 -------- d-----w- C:\Program Files (x86)\Common Files\PACE Anti-Piracy

2012-04-15 15:42:54 -------- d-----w- C:\Users\Christian Ronchetti\AppData\Local\{536C29FF-1601-44D0-9ABF-4D23B111962C}

2012-04-15 15:42:42 -------- d-----w- C:\Users\Christian Ronchetti\AppData\Local\{8D3DF2E0-D125-4C69-B01E-CDB5F174DEB6}

2012-04-15 14:48:08 -------- d-----w- C:\Program Files (x86)\Antares Audio Technologies

2012-04-15 13:48:51 -------- d-----w- C:\Program Files (x86)\Ffmpeg For Audacity

2012-04-15 13:09:32 -------- d-----w- C:\Windows\Freecorder Toolbar

2012-04-15 12:14:30 -------- d-----w- C:\Program Files (x86)\Lame For Audacity

2012-04-15 11:33:35 -------- d-----w- C:\Users\Christian Ronchetti\AppData\Roaming\Antares

2012-04-15 10:33:34 -------- d-----w- C:\Program Files (x86)\Audacity

2012-04-15 10:20:14 8766112 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe

2012-04-15 09:53:14 -------- d-----w- C:\Users\Christian Ronchetti\AppData\Local\TechSmith

2012-04-15 09:45:51 418464 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe

2012-04-15 09:32:48 411480 ----a-w- C:\Windows\SysWow64\tsccvid.dll

2012-04-15 09:32:47 -------- d-----w- C:\Windows\SysWow64\QuickTime

2012-04-15 09:32:09 -------- d-----w- C:\Program Files (x86)\Common Files\TechSmith Shared

2012-04-13 03:17:59 -------- d-----w- C:\Users\Christian Ronchetti\AppData\Local\{EE26926E-92BD-4BF1-BE33-C6D6EAAE52F4}

2012-04-12 09:44:26 -------- d-----w- C:\Users\Christian Ronchetti\AppData\Local\{9E3491EF-F091-4F3C-BC2E-214F1D1890A4}

2012-04-11 21:44:14 -------- d-----w- C:\Users\Christian Ronchetti\AppData\Local\{C190C0A1-5A75-43A7-AA60-805F0ACD9376}

2012-04-11 10:15:17 27176 ----a-w- C:\Windows\System32\drivers\ggsemc.sys

2012-04-11 10:15:17 1490656 ----a-w- C:\Windows\System32\WdfCoInstaller01007.dll

2012-04-11 10:15:17 13352 ----a-w- C:\Windows\System32\drivers\ggflt.sys

2012-04-11 10:14:44 -------- d-----w- C:\ProgramData\Sony Ericsson

2012-04-11 10:14:38 -------- d-----w- C:\Program Files (x86)\Sony Ericsson

2012-04-11 10:14:12 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll

2012-04-11 08:31:00 -------- d-----w- C:\Users\Christian Ronchetti\AppData\Local\{12F7C193-6347-4DDC-93AC-1573B166D3CA}

2012-04-10 14:14:52 -------- d-----w- C:\Users\Christian Ronchetti\AppData\Local\{59E8BB12-DE1E-4F91-893E-F5B146622E18}

2012-04-09 20:24:16 -------- d-----w- C:\Users\Christian Ronchetti\AppData\Local\{9DD84786-521D-493F-874C-3846B72DAF86}

2012-04-09 08:24:04 -------- d-----w- C:\Users\Christian Ronchetti\AppData\Local\{1D59E881-6D4A-4365-897C-9B0B3F0EE6F7}

2012-04-08 15:32:20 -------- d-----w- C:\Users\Christian Ronchetti\AppData\Local\{F4D610C0-7603-4D1A-8010-07A3CAA16526}

2012-04-05 14:05:01 -------- d-----w- C:\Users\Christian Ronchetti\AppData\Roaming\AVS4YOU

2012-04-05 14:02:39 -------- d-----w- C:\Program Files (x86)\Common Files\AVSMedia

2012-04-05 14:02:38 24576 ----a-w- C:\Windows\SysWow64\msxml3a.dll

2012-04-05 14:02:38 -------- d-----w- C:\ProgramData\AVS4YOU

2012-04-05 14:02:38 -------- d-----w- C:\Program Files (x86)\AVS4YOU

2012-04-04 05:53:56 182160 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\nppdf32.dll

2012-04-04 02:51:07 -------- d-----w- C:\Program Files (x86)\Reincubate

2012-04-04 01:35:19 -------- d-----w- C:\Users\Christian Ronchetti\AppData\Local\Apple_Inc

2012-04-04 01:34:34 -------- d-----w- C:\Program Files (x86)\iPhone Configuration Utility

2012-04-03 10:11:24 -------- d-----w- C:\Users\Christian Ronchetti\AppData\Local\{F5190AE2-8273-4699-BFC2-0F8D121B83A3}

2012-04-02 15:59:28 -------- d-----w- C:\Users\Christian Ronchetti\AppData\Local\{4FD26976-032E-4438-92AA-8A684052D39D}

2012-04-02 03:59:16 -------- d-----w- C:\Users\Christian Ronchetti\AppData\Local\{83709D4A-52B1-48B4-9970-6779AB567A77}

2012-04-01 11:31:02 -------- d-----w- C:\Users\Christian Ronchetti\AppData\Local\{544A8C05-15D0-40D9-8B94-36DE32D4F1FA}

.

==================== Find3M ====================

.

2012-04-15 10:20:47 70304 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

2012-02-28 06:56:48 2311168 ----a-w- C:\Windows\System32\jscript9.dll

2012-02-28 06:49:56 1390080 ----a-w- C:\Windows\System32\wininet.dll

2012-02-28 06:48:57 1493504 ----a-w- C:\Windows\System32\inetcpl.cpl

2012-02-28 01:18:55 1799168 ----a-w- C:\Windows\SysWow64\jscript9.dll

2012-02-28 01:11:21 1427456 ----a-w- C:\Windows\SysWow64\inetcpl.cpl

2012-02-28 01:11:07 1127424 ----a-w- C:\Windows\SysWow64\wininet.dll

2012-02-17 06:38:26 1031680 ----a-w- C:\Windows\System32\rdpcore.dll

2012-02-17 05:34:22 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll

2012-02-17 04:58:24 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys

2012-02-17 04:57:32 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys

2012-02-15 11:01:50 52736 ----a-w- C:\Windows\System32\drivers\usbaapl64.sys

2012-02-15 11:01:50 4547944 ----a-w- C:\Windows\System32\usbaaplrc.dll

2012-02-14 11:09:44 1070352 ----a-w- C:\Windows\SysWow64\MSCOMCTL.OCX

2012-02-10 06:36:07 1544192 ----a-w- C:\Windows\System32\DWrite.dll

2012-02-10 05:38:43 1077248 ----a-w- C:\Windows\SysWow64\DWrite.dll

2012-02-03 04:34:34 3145728 ----a-w- C:\Windows\System32\win32k.sys

2012-01-31 12:44:20 279656 ------w- C:\Windows\System32\MpSigStub.exe

2012-01-25 06:38:39 77312 ----a-w- C:\Windows\System32\rdpwsx.dll

2012-01-25 06:38:38 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll

2012-01-25 06:33:30 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe

.

============= FINISH: 20:08:17.90 ===============

.

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.

IF REQUESTED, ZIP IT UP & ATTACH IT

.

DDS (Ver_2011-08-26.01)

.

Microsoft Windows 7 Home Premium

Boot Device: \Device\HarddiskVolume1

Install Date: 01/12/2011 12:50:39

System Uptime: 23/04/2012 16:22:17 (4 hours ago)

.

Motherboard: TOSHIBA | | PWWHA

Processor: Intel® Core i3-2310M CPU @ 2.10GHz | CPU 1 | 882/100mhz

.

==== Disk Partitions =========================

.

C: is FIXED (NTFS) - 75 GiB total, 29.231 GiB free.

D: is FIXED (NTFS) - 391 GiB total, 323.423 GiB free.

E: is CDROM ()

.

==== Disabled Device Manager Items =============

.

==== System Restore Points ===================

.

RP81: 22/04/2012 05:55:45 - Windows Update

RP82: 23/04/2012 15:31:05 - Windows Update

RP83: 23/04/2012 16:26:51 - Removed Interlok driver setup x64.

RP84: 23/04/2012 16:48:12 - Installed HiJackThis

.

==== Installed Programs ======================

.

ABBYY FineReader 11

ABBYY FineReader 9.0 Sprint

Adobe Reader X (10.1.3)

Adobe Shockwave Player 11.6

Antares Auto-Tune Evo VST

Apple Application Support

Apple Software Update

µTorrent

Audacity 1.3.14 (Unicode)

Auto-Tune EFX VST

Camtasia Studio 7

Canon iP4900 series User Registration

Canon My Printer

Colour Explorer 9,0

D3DX10

Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition

Facebook Messenger 2.0.4478.0

Facebook Video Calling 1.2.0.159

FFmpeg v0.6.2 for Audacity

GIMP 2.6.11

HiJackThis

IBM SPSS Statistics 19

iPhone Backup Extractor

iPhone Configuration Utility

Java Auto Updater

Java 6 Update 31

jZip

LAME v3.99.3 (for Windows)

Malwarebytes Anti-Malware version 1.61.0.1400

MatchWare MindView 4.0

Microsoft Office 2010 Service Pack 1 (SP1)

Microsoft Office Access MUI (English) 2010

Microsoft Office Access Setup Metadata MUI (English) 2010

Microsoft Office Excel MUI (English) 2010

Microsoft Office Groove MUI (English) 2010

Microsoft Office InfoPath MUI (English) 2010

Microsoft Office OneNote MUI (English) 2010

Microsoft Office Outlook MUI (English) 2010

Microsoft Office PowerPoint MUI (English) 2010

Microsoft Office Professional Plus 2010

Microsoft Office Proof (English) 2010

Microsoft Office Proof (French) 2010

Microsoft Office Proof (Spanish) 2010

Microsoft Office Proofing (English) 2010

Microsoft Office Publisher MUI (English) 2010

Microsoft Office Shared MUI (English) 2010

Microsoft Office Shared Setup Metadata MUI (English) 2010

Microsoft Office Word MUI (English) 2010

Microsoft Silverlight

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319

Mindjet MindManager 2012

Mozilla Firefox 11.0 (x86 en-GB)

MSVCRT

MSXML 4.0 SP2 (KB954430)

MSXML 4.0 SP2 (KB973688)

Nero Burning ROM 10

Nero BurningROM 10 Help (CHM)

Nero BurnRights 10

Nero BurnRights 10 Help (CHM)

Nero Control Center 10

Nero ControlCenter 10 Help (CHM)

Nero Core Components 10

Nero Update

Olympus Sonority

Plustek OpticBook 3800

Presto! ImageFolio 4

Presto! PageManager 7.23

QuickTime

Realtek High Definition Audio Driver

Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)

Security Update for Microsoft Office 2010 (KB2553091)

Security Update for Microsoft Office 2010 (KB2553096)

Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition

Security Update for Microsoft Office 2010 (KB2598039) 32-Bit Edition

Security Update for Microsoft PowerPoint 2010 (KB2553185) 32-Bit Edition

Security Update for Microsoft SharePoint Workspace 2010 (KB2566445)

Security Update for Microsoft Visio Viewer 2010 (KB2597170) 32-Bit Edition

Skype™ 5.8

swMSM

TOSHIBA Assist

TOSHIBA Face Recognition

TOSHIBA Flash Cards Support Utility

TOSHIBA Hardware Setup

TOSHIBA Value Added Package

TOSHIBA Web Camera Application

Update for Microsoft .NET Framework 4 Client Profile (KB2468871)

Update for Microsoft .NET Framework 4 Client Profile (KB2533523)

Update for Microsoft .NET Framework 4 Client Profile (KB2600217)

Update for Microsoft Excel 2010 (KB2553439) 32-Bit Edition

Update for Microsoft Office 2010 (KB2553065)

Update for Microsoft Office 2010 (KB2553092)

Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition

Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition

Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition

Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition

Update for Microsoft Office 2010 (KB2553385) 32-Bit Edition

Update for Microsoft Office 2010 (KB2566458)

Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition

Update for Microsoft Office 2010 (KB2597091) 32-Bit Edition

Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition

Update for Microsoft Outlook 2010 (KB2553248) 32-Bit Edition

Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition

Utility Common Driver

VST Bridge 1.1

Windows Live Communications Platform

Windows Live Essentials

Windows Live Installer

Windows Live Messenger

Windows Live Photo Common

Windows Live PIMT Platform

Windows Live SOXE

Windows Live SOXE Definitions

Windows Live UX Platform

Windows Live UX Platform Language Pack

WMPTagSupportExtender

Xvid Video Codec

youtubetomp3.org ver. 1.0

.

==== Event Viewer Messages From Past Week ========

.

23/04/2012 08:06:02, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.

22/04/2012 05:44:26, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Netman service.

18/04/2012 22:13:00, Error: ACPI [13] - : The embedded controller (EC) did not respond within the specified timeout period. This may indicate that there is an error in the EC hardware or firmware or that the BIOS is accessing the EC incorrectly. You should check with your computer manufacturer for an upgraded BIOS. In some situations, this error may cause the computer to function incorrectly.

.

==== End Of File ===========================

RogueKiller V7.3.3 [04/22/2012] by Tigzy

mail: tigzyRK<at>gmail<dot>com

Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/

Blog: http://tigzyrk.blogspot.com

Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version

Started in : Normal mode

User: Christian Ronchetti [Admin rights]

Mode: Scan -- Date: 04/23/2012 20:12:45

¤¤¤ Bad processes: 0 ¤¤¤

¤¤¤ Registry Entries: 2 ¤¤¤

[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND

[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver: [NOT LOADED] ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤

¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: TOSHIBA MK5075GSX +++++

--- User ---

[MBR] a2742854001c4d7785a9c038e6cc02a8

[bSP] 35b1ce54f3458b0da221017b70a9409f : Windows 7 MBR Code

Partition table:

0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 76800 Mo

1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 157288448 | Size: 400138 Mo

User = LL1 ... OK!

User = LL2 ... OK!

Finished : << RKreport[1].txt >>

RKreport[1].txt

I think its called babylon toolbar ....

thanks

Link to post
Share on other sites

OK, I see it...but we have to run a different program to delete it:

Please download and run ComboFix.

The most important things to remember when running it is to disable all your malware programs and run Combofix from your desktop.

Please visit this webpage for download links, and instructions for running ComboFix

http://www.bleepingc...to-use-combofix

Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Information on disabling your malware programs can be found Here.

Make sure you run ComboFix from your desktop.

Please include the C:\ComboFix.txt in your next reply for further review.

Note:

If you get the message Illegal operation attempted on registry key that has been marked for deletion. after you run ComboFix....please reboot the computer, this should resolve the problem. You may have to do this several times if needed.

MrC

Link to post
Share on other sites

ComboFix 12-04-23.02 - Christian Ronchetti 23/04/2012 21:34:57.1.4 - x64

Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.4004.1334 [GMT 1:00]

Running from: c:\users\Christian Ronchetti\Desktop\ComboFix.exe

AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}

SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\programdata\xp

c:\programdata\xp\EBLib.dll

c:\programdata\xp\TPwSav.sys

c:\windows\system32\Thumbs.db

c:\windows\XSxS

D:\install.exe

.

.

((((((((((((((((((((((((( Files Created from 2012-03-23 to 2012-04-23 )))))))))))))))))))))))))))))))

.

.

2012-04-23 15:49 . 2012-04-23 15:49 388096 ----a-r- c:\users\Christian Ronchetti\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2012-04-23 15:49 . 2012-04-23 15:49 -------- d-----w- c:\program files (x86)\Trend Micro

2012-04-23 15:41 . 2012-04-23 15:41 -------- d-----w- c:\users\Christian Ronchetti\AppData\Roaming\Malwarebytes

2012-04-23 15:40 . 2012-04-23 15:40 -------- d-----w- c:\programdata\Malwarebytes

2012-04-23 15:40 . 2012-04-23 15:40 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2012-04-23 15:40 . 2012-04-04 14:56 24904 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-04-23 14:50 . 2012-04-13 08:46 8917360 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{01CCA537-C00B-40A3-9978-A594718D95F0}\mpengine.dll

2012-04-23 14:48 . 2012-02-28 06:42 2382848 ----a-w- c:\windows\system32\mshtml.tlb

2012-04-23 14:48 . 2012-02-28 01:03 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb

2012-04-23 14:48 . 2012-02-28 07:37 174392 ----a-w- c:\program files\Internet Explorer\sqmapi.dll

2012-04-23 14:48 . 2012-02-28 06:47 304640 ----a-w- c:\program files\Internet Explorer\IEShims.dll

2012-04-23 14:48 . 2012-02-28 01:58 141112 ----a-w- c:\program files (x86)\Internet Explorer\sqmapi.dll

2012-04-23 14:45 . 2012-03-06 06:53 5559152 ----a-w- c:\windows\system32\ntoskrnl.exe

2012-04-23 14:45 . 2012-03-06 05:59 3968368 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe

2012-04-23 14:45 . 2012-03-06 05:59 3913072 ----a-w- c:\windows\SysWow64\ntoskrnl.exe

2012-04-23 14:36 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys

2012-04-23 14:36 . 2012-03-01 06:33 81408 ----a-w- c:\windows\system32\imagehlp.dll

2012-04-23 14:36 . 2012-03-01 05:33 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll

2012-04-23 14:36 . 2012-03-01 06:38 220672 ----a-w- c:\windows\system32\wintrust.dll

2012-04-23 14:36 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll

2012-04-23 14:36 . 2012-03-01 05:37 172544 ----a-w- c:\windows\SysWow64\wintrust.dll

2012-04-23 14:36 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll

2012-04-18 12:42 . 2012-04-18 12:42 -------- d-----w- c:\program files\iPod

2012-04-18 12:42 . 2012-04-18 12:43 -------- d-----w- c:\program files\iTunes

2012-04-15 20:18 . 2012-04-15 20:18 -------- d-----w- c:\program files (x86)\fbphotozoom

2012-04-15 20:11 . 2012-04-15 20:11 237 ----a-w- C:\user.js

2012-04-15 20:11 . 2012-04-15 20:11 -------- d-----w- c:\users\Christian Ronchetti\AppData\Local\Babylon

2012-04-15 20:11 . 2012-04-15 20:11 -------- d-----w- c:\users\Christian Ronchetti\AppData\Roaming\Babylon

2012-04-15 20:11 . 2012-04-15 20:11 -------- d-----w- c:\programdata\Babylon

2012-04-15 19:51 . 2012-04-15 19:51 -------- d-----w- c:\programdata\PACE

2012-04-15 19:51 . 2012-04-15 19:51 -------- d-----w- c:\program files (x86)\Common Files\PACE

2012-04-15 19:50 . 2012-04-15 19:50 -------- d-----w- c:\programdata\Antares

2012-04-15 15:43 . 2012-04-15 15:43 -------- d-----w- c:\programdata\PACE Anti-Piracy

2012-04-15 15:43 . 2012-04-15 15:44 -------- d-----w- c:\users\Christian Ronchetti\AppData\Local\PACE Anti-Piracy

2012-04-15 15:43 . 2012-04-15 15:43 -------- d-----w- c:\users\Christian Ronchetti\AppData\Roaming\PACE Anti-Piracy

2012-04-15 15:43 . 2012-04-15 15:43 -------- d-----w- c:\program files (x86)\Common Files\PACE Anti-Piracy

2012-04-15 14:48 . 2012-04-15 19:50 -------- d-----w- c:\program files (x86)\Antares Audio Technologies

2012-04-15 13:48 . 2012-04-15 13:48 -------- d-----w- c:\program files (x86)\Ffmpeg For Audacity

2012-04-15 13:09 . 2012-04-15 13:09 -------- d-----w- c:\windows\Freecorder Toolbar

2012-04-15 12:14 . 2012-04-15 12:14 -------- d-----w- c:\program files (x86)\Lame For Audacity

2012-04-15 11:33 . 2012-04-15 14:56 -------- d-----w- c:\users\Christian Ronchetti\AppData\Roaming\Antares

2012-04-15 10:33 . 2012-04-15 10:33 -------- d-----w- c:\program files (x86)\Audacity

2012-04-15 10:20 . 2012-04-15 10:20 8766112 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe

2012-04-15 09:53 . 2012-04-15 09:53 -------- d-----w- c:\users\Christian Ronchetti\AppData\Local\TechSmith

2012-04-15 09:45 . 2012-04-15 10:20 418464 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2012-04-15 09:32 . 2010-03-04 16:27 411480 ----a-w- c:\windows\SysWow64\tsccvid.dll

2012-04-15 09:32 . 2012-04-15 09:32 -------- d-----w- c:\windows\SysWow64\QuickTime

2012-04-15 09:32 . 2012-04-15 09:32 -------- d-----w- c:\program files (x86)\Common Files\TechSmith Shared

2012-04-15 09:32 . 2012-04-15 09:32 -------- d-----w- c:\programdata\TechSmith

2012-04-15 09:32 . 2012-04-15 09:32 -------- d-----w- c:\program files (x86)\TechSmith

2012-04-11 10:15 . 2012-04-11 10:15 27176 ----a-w- c:\windows\system32\drivers\ggsemc.sys

2012-04-11 10:15 . 2012-04-11 10:15 1490656 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll

2012-04-11 10:15 . 2012-04-11 10:15 13352 ----a-w- c:\windows\system32\drivers\ggflt.sys

2012-04-11 10:14 . 2012-04-23 14:38 -------- d-----w- c:\programdata\Sony Ericsson

2012-04-11 10:14 . 2012-04-23 14:38 -------- d-----w- c:\program files (x86)\Sony Ericsson

2012-04-11 10:14 . 2012-04-11 10:14 -------- d-----w- c:\program files (x86)\Common Files\Java

2012-04-11 10:14 . 2012-04-11 10:13 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll

2012-04-11 10:13 . 2012-04-11 10:13 -------- d-----w- c:\program files (x86)\Java

2012-04-05 14:05 . 2012-04-05 14:05 -------- d-----w- c:\users\Christian Ronchetti\AppData\Roaming\AVS4YOU

2012-04-05 14:02 . 2012-04-23 14:35 -------- d-----w- c:\program files (x86)\Common Files\AVSMedia

2012-04-05 14:02 . 2012-04-23 14:35 -------- d-----w- c:\program files (x86)\AVS4YOU

2012-04-05 14:02 . 2012-04-05 14:05 -------- d-----w- c:\programdata\AVS4YOU

2012-04-05 14:02 . 2011-08-22 15:32 24576 ----a-w- c:\windows\SysWow64\msxml3a.dll

2012-04-04 05:53 . 2012-04-04 05:53 182160 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll

2012-04-04 02:51 . 2012-04-04 02:51 -------- d-----w- c:\program files (x86)\Reincubate

2012-04-04 01:35 . 2012-04-04 01:35 -------- d-----w- c:\users\Christian Ronchetti\AppData\Local\Apple_Inc

2012-04-04 01:34 . 2012-04-04 01:34 -------- d-----w- c:\program files (x86)\iPhone Configuration Utility

2012-03-30 19:01 . 2012-03-30 19:01 -------- d-----w- c:\program files (x86)\Common Files\Skype

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-04-15 10:20 . 2011-12-01 14:05 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2012-04-13 08:46 . 2011-12-14 10:29 8917360 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll

2012-03-01 23:55 . 2012-03-01 23:55 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe

2012-03-01 23:55 . 2012-03-01 23:55 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe

2012-03-01 23:55 . 2012-03-01 23:55 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll

2012-03-01 23:55 . 2012-03-01 23:55 161792 ----a-w- c:\windows\SysWow64\msls31.dll

2012-03-01 23:55 . 2012-03-01 23:55 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll

2012-03-01 23:55 . 2012-03-01 23:55 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll

2012-03-01 23:55 . 2012-03-01 23:55 74752 ----a-w- c:\windows\SysWow64\iesetup.dll

2012-03-01 23:55 . 2012-03-01 23:55 63488 ----a-w- c:\windows\SysWow64\tdc.ocx

2012-03-01 23:55 . 2012-03-01 23:55 367104 ----a-w- c:\windows\SysWow64\html.iec

2012-03-01 23:55 . 2012-03-01 23:55 420864 ----a-w- c:\windows\SysWow64\vbscript.dll

2012-03-01 23:55 . 2012-03-01 23:55 35840 ----a-w- c:\windows\SysWow64\imgutil.dll

2012-03-01 23:55 . 2012-03-01 23:55 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll

2012-03-01 23:55 . 2012-03-01 23:55 152064 ----a-w- c:\windows\SysWow64\wextract.exe

2012-03-01 23:55 . 2012-03-01 23:55 150528 ----a-w- c:\windows\SysWow64\iexpress.exe

2012-03-01 23:55 . 2012-03-01 23:55 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe

2012-03-01 23:55 . 2012-03-01 23:55 11776 ----a-w- c:\windows\SysWow64\mshta.exe

2012-03-01 23:55 . 2012-03-01 23:55 101888 ----a-w- c:\windows\SysWow64\admparse.dll

2012-03-01 23:55 . 2012-03-01 23:55 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe

2012-03-01 23:55 . 2012-03-01 23:55 222208 ----a-w- c:\windows\system32\msls31.dll

2012-03-01 23:55 . 2012-03-01 23:55 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe

2012-03-01 23:55 . 2012-03-01 23:55 85504 ----a-w- c:\windows\system32\iesetup.dll

2012-03-01 23:55 . 2012-03-01 23:55 76800 ----a-w- c:\windows\system32\tdc.ocx

2012-03-01 23:55 . 2012-03-01 23:55 49664 ----a-w- c:\windows\system32\imgutil.dll

2012-03-01 23:55 . 2012-03-01 23:55 48640 ----a-w- c:\windows\system32\mshtmler.dll

2012-03-01 23:55 . 2012-03-01 23:55 448512 ----a-w- c:\windows\system32\html.iec

2012-03-01 23:55 . 2012-03-01 23:55 173056 ----a-w- c:\windows\system32\ieUnatt.exe

2012-03-01 23:55 . 2012-03-01 23:55 135168 ----a-w- c:\windows\system32\IEAdvpack.dll

2012-03-01 23:55 . 2012-03-01 23:55 12288 ----a-w- c:\windows\system32\mshta.exe

2012-03-01 23:55 . 2012-03-01 23:55 114176 ----a-w- c:\windows\system32\admparse.dll

2012-03-01 23:55 . 2012-03-01 23:55 111616 ----a-w- c:\windows\system32\iesysprep.dll

2012-03-01 23:55 . 2012-03-01 23:55 603648 ----a-w- c:\windows\system32\vbscript.dll

2012-03-01 23:55 . 2012-03-01 23:55 30720 ----a-w- c:\windows\system32\licmgr10.dll

2012-03-01 23:55 . 2012-03-01 23:55 165888 ----a-w- c:\windows\system32\iexpress.exe

2012-03-01 23:55 . 2012-03-01 23:55 160256 ----a-w- c:\windows\system32\wextract.exe

2012-02-17 06:38 . 2012-03-14 17:04 1031680 ----a-w- c:\windows\system32\rdpcore.dll

2012-02-17 05:34 . 2012-03-14 17:04 826880 ----a-w- c:\windows\SysWow64\rdpcore.dll

2012-02-17 04:58 . 2012-03-14 17:04 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys

2012-02-17 04:57 . 2012-03-14 17:04 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys

2012-02-15 11:01 . 2012-02-15 11:01 52736 ----a-w- c:\windows\system32\drivers\usbaapl64.sys

2012-02-15 11:01 . 2012-02-15 11:01 4547944 ----a-w- c:\windows\system32\usbaaplrc.dll

2012-02-14 11:09 . 2012-02-14 11:09 1070352 ----a-w- c:\windows\SysWow64\MSCOMCTL.OCX

2012-02-11 02:24 . 2012-02-11 02:25 927800 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{AEF04F1F-1395-41E9-9CFF-6142BD87F2B8}\gapaengine.dll

2012-02-10 06:36 . 2012-03-14 17:07 1544192 ----a-w- c:\windows\system32\DWrite.dll

2012-02-10 05:38 . 2012-03-14 17:07 1077248 ----a-w- c:\windows\SysWow64\DWrite.dll

2012-02-08 07:13 . 2012-03-01 23:59 8643640 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll

2012-02-03 04:34 . 2012-03-14 17:07 3145728 ----a-w- c:\windows\system32\win32k.sys

2012-01-31 12:44 . 2010-11-21 03:27 279656 ------w- c:\windows\system32\MpSigStub.exe

2012-01-25 06:38 . 2012-03-14 17:05 77312 ----a-w- c:\windows\system32\rdpwsx.dll

2012-01-25 06:38 . 2012-03-14 17:05 149504 ----a-w- c:\windows\system32\rdpcorekmts.dll

2012-01-25 06:33 . 2012-03-14 17:05 9216 ----a-w- c:\windows\system32\rdrmemptylst.exe

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Xvid"="c:\program files (x86)\Xvid\CheckUpdate.exe" [2011-01-17 8192]

"Facebook Update"="c:\users\Christian Ronchetti\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-04-11 137536]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]

"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]

"KeNotify"="c:\program files (x86)\TOSHIBA\Utilities\KeNotify.exe" [2010-08-16 34160]

"HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2010-03-04 423936]

"Bonus.SSR.FR11"="c:\program files (x86)\ABBYY FineReader 11\Bonus.ScreenshotReader.exe" [2011-08-09 911112]

"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]

"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]

"MMReminderService"="c:\program files (x86)\Mindjet\MindManager 10\MMReminderService.exe" [2012-02-27 38248]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]

"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-03-27 421736]

"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]

.

c:\users\Christian Ronchetti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Colour Explorer 9,0.lnk - c:\program files (x86)\MicrolinkPC\CXLOADER.exe [2011-12-1 72192]

OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE [2010-12-21 227712]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

Book Pavilion (Plustek OpticBook 3800).lnk - c:\program files (x86)\Plustek\Plustek OpticBook 3800\book express.exe [2011-12-1 475136]

Device Detector 4.lnk - c:\program files (x86)\OLYMPUS\DeviceDetector\DeviceDetector4.exe [2009-12-1 402832]

.

c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

TaskBar.vbs [2009-8-12 1797]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]

"aux"=wdmaud.drv

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

@="Service"

.

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-02-29 158856]

R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-15 253088]

R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [x]

R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [x]

R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [x]

R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880]

R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]

R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys [x]

R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]

R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]

R3 Olympus DVR Service;Olympus DVR Service;c:\program files (x86)\Common Files\Olympus Shared\DeviceManager\olydvrsv.exe [2011-05-10 176128]

R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]

R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]

R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]

R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]

S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]

S2 ABBYY.Licensing.FineReader.Professional.11.0;ABBYY FineReader 11 PE Licensing Service;c:\program files (x86)\ABBYY FineReader 11\NetworkLicenseServer.exe [2011-08-03 819976]

S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]

S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]

S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]

S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-05-04 503080]

S2 PaceLicenseDServices;PACE License Services;c:\program files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe [2011-07-09 2932224]

S3 CeKbFilter;CeKbFilter;c:\windows\system32\DRIVERS\CeKbFilter.sys [x]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]

S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\drivers\HECIx64.sys [x]

S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x]

S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]

.

.

--- Other Services/Drivers In Memory ---

.

*NewlyCreated* - WS2IFSL

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{90EF4A5E-85DB-4825-96F5-1AB93C2A8EEB}]

2012-02-27 04:49 1409 ----a-r- c:\program files (x86)\Mindjet\MindManager 10\sys\MmInternetExplorerActiveSetup.vbs

.

Contents of the 'Scheduled Tasks' folder

.

2012-04-23 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-15 10:20]

.

2012-04-22 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-201949659-3598620656-673553719-1000Core.job

- c:\users\Christian Ronchetti\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-01-19 08:36]

.

2012-04-23 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-201949659-3598620656-673553719-1000UA.job

- c:\users\Christian Ronchetti\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-01-19 08:36]

.

.

--------- x86-64 -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-04-07 167256]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-04-07 391000]

"Persistence"="c:\windows\system32\igfxpers.exe" [2011-04-07 418136]

"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-02-11 11776104]

"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-01-18 2188904]

"TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376]

"WrtMon.exe"="c:\windows\system32\spool\drivers\x64\3\WrtMon.exe" [2007-07-18 20480]

"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736]

"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2011-03-15 2779024]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"LoadAppInit_DLLs"=0x1

.

------- Supplementary Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

uStart Page = hxxp://search.babylon.com/?affID=109980&babsrc=HP_ss&mntrId=d8a31185000000000000d0df9a8d65b5

mLocal Page = c:\windows\SysWOW64\blank.htm

uInternet Settings,ProxyOverride = *.local

IE:

IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000

IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105

IE: Send Image To MindManager - c:\program files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll/201

IE: Send Link To MindManager - c:\program files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll/203

IE: Send Page To MindManager - c:\program files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll/204

IE: Send Text To MindManager - c:\program files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll/202

TCP: DhcpNameServer = 192.168.0.1

DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://88.247.210.37:81/activex/AMC.cab

FF - ProfilePath - c:\users\Christian Ronchetti\AppData\Roaming\Mozilla\Firefox\Profiles\xd6r04iw.default\

FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)

FF - prefs.js: browser.startup.homepage - hxxp://www.searchqu.com/102

FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=100&systemid=102&sr=0&q=

FF - prefs.js: network.proxy.type - 0

FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109980

FF - user.js: extensions.BabylonToolbar_i.babExt -

FF - user.js: extensions.BabylonToolbar_i.srcExt - ss

FF - user.js: extensions.BabylonToolbar_i.id - d8a31185000000000000d0df9a8d65b5

FF - user.js: extensions.BabylonToolbar_i.hardId - d8a31185000000000000d0df9a8d65b5

FF - user.js: extensions.BabylonToolbar_i.instlDay - 15445

FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1721:11

FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon

FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar

FF - user.js: extensions.BabylonToolbar_i.aflt - babsst

FF - user.js: extensions.BabylonToolbar_i.smplGrp - none

FF - user.js: extensions.BabylonToolbar_i.tlbrId - base

FF - user.js: extensions.BabylonToolbar_i.instlRef - sst

.

- - - - ORPHANS REMOVED - - - -

.

Toolbar-Locked - (no file)

Toolbar-10 - (no file)

Toolbar-Locked - (no file)

Toolbar-10 - (no file)

HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe

HKLM-Run-TPwrMain - c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE

HKLM-Run-TCrdMain - c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe

HKLM-Run-TOSHIBA Face Recognition - c:\program files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe

AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe

AddRemove-Colour Explorer 9,0 - c:\windows\system32\SpoonUninstall.exe

.

.

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_233_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_233_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.11"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]

@Denied: (A) (Everyone)

"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]

@Denied: (A) (Everyone)

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]

"Key"="ActionsPane3"

"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

------------------------ Other Running Processes ------------------------

.

c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

.

**************************************************************************

.

Completion time: 2012-04-23 21:46:29 - machine was rebooted

ComboFix-quarantined-files.txt 2012-04-23 20:46

.

Pre-Run: 31,077,609,472 bytes free

Post-Run: 32,278,523,904 bytes free

.

- - End Of File - - A8E813620D0E3385834FEDF9DC7771E8

Link to post
Share on other sites

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

4. If ComboFix wants to update.....please allow it to.

DDS::

uStart Page = hxxp://search.babylon.com/?affID=109980&babsrc=HP_ss&mntrId=d8a31185000000000000d0df9a8d65b5

BHO: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WIA6EB~1\Datamngr\ToolBar\searchqudtx.dll

TB: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WIA6EB~1\Datamngr\ToolBar\searchqudtx.dll

TB: !{98889811-442D-49dd-99D7-DC866BE87DBC} - No File

BHO-X64: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WIA6EB~1\Datamngr\ToolBar\searchqudtx.dll

BHO-X64: Searchqu Toolbar - No File

BHO-X64: URLRedirectionBHO - No File

TB-X64: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WIA6EB~1\Datamngr\ToolBar\searchqudtx.dll

FF - prefs.js: browser.startup.homepage - hxxp://www.searchqu.com/102

FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109980

FF - user.js: extensions.BabylonToolbar_i.babExt -

FF - user.js: extensions.BabylonToolbar_i.srcExt - ss

FF - user.js: extensions.BabylonToolbar_i.id - d8a31185000000000000d0df9a8d65b5

FF - user.js: extensions.BabylonToolbar_i.hardId - d8a31185000000000000d0df9a8d65b5

FF - user.js: extensions.BabylonToolbar_i.instlDay - 15445

FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1721:11:17

FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon

FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar

FF - user.js: extensions.BabylonToolbar_i.aflt - babsst

FF - user.js: extensions.BabylonToolbar_i.smplGrp - none

FF - user.js: extensions.BabylonToolbar_i.tlbrId - base

FF - user.js: extensions.BabylonToolbar_i.instlRef - sst

2012-04-15 20:11:03 -------- d-----w- C:\Users\Christian Ronchetti\AppData\Local\Babylon

2012-04-15 20:11:02 -------- d-----w- C:\Users\Christian Ronchetti\AppData\Roaming\Babylon

2012-04-15 20:11:02 -------- d-----w- C:\ProgramData\Babylon

Firefox::

FF - ProfilePath - c:\users\Christian Ronchetti\AppData\Roaming\Mozilla\Firefox\Profiles\xd6r04iw.default\

FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)

FF - prefs.js: browser.startup.homepage - hxxp://www.searchqu.com/102

Save this as CFScript.txt, in the same location as ComboFix.exe

CFScript.gif

Refering to the picture above, drag CFScript into ComboFix.exe

CAUTION: Do not mouse-click ComboFix while it is running. It may cause it to stall.

After reboot, (in case it asks to reboot)......

Please provide the contents of the ComboFix log (C:\ComboFix.txt) in your next reply.

MrC

Link to post
Share on other sites

ComboFix 12-04-23.02 - Christian Ronchetti 23/04/2012 23:00:20.2.4 - x64

Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.4004.2671 [GMT 1:00]

Running from: c:\users\Christian Ronchetti\Desktop\ComboFix.exe

Command switches used :: c:\users\Christian Ronchetti\Desktop\CFScript.txt

AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}

SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

((((((((((((((((((((((((( Files Created from 2012-03-23 to 2012-04-23 )))))))))))))))))))))))))))))))

.

.

2012-04-23 22:05 . 2012-04-23 22:05 -------- d-----w- c:\users\Default\AppData\Local\temp

2012-04-23 15:49 . 2012-04-23 15:49 388096 ----a-r- c:\users\Christian Ronchetti\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2012-04-23 15:49 . 2012-04-23 15:49 -------- d-----w- c:\program files (x86)\Trend Micro

2012-04-23 15:41 . 2012-04-23 15:41 -------- d-----w- c:\users\Christian Ronchetti\AppData\Roaming\Malwarebytes

2012-04-23 15:40 . 2012-04-23 15:40 -------- d-----w- c:\programdata\Malwarebytes

2012-04-23 15:40 . 2012-04-23 15:40 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2012-04-23 15:40 . 2012-04-04 14:56 24904 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-04-23 14:50 . 2012-04-13 08:46 8917360 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{01CCA537-C00B-40A3-9978-A594718D95F0}\mpengine.dll

2012-04-23 14:48 . 2012-02-28 06:42 2382848 ----a-w- c:\windows\system32\mshtml.tlb

2012-04-23 14:48 . 2012-02-28 01:03 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb

2012-04-23 14:48 . 2012-02-28 07:37 174392 ----a-w- c:\program files\Internet Explorer\sqmapi.dll

2012-04-23 14:48 . 2012-02-28 06:47 304640 ----a-w- c:\program files\Internet Explorer\IEShims.dll

2012-04-23 14:48 . 2012-02-28 01:58 141112 ----a-w- c:\program files (x86)\Internet Explorer\sqmapi.dll

2012-04-23 14:45 . 2012-03-06 06:53 5559152 ----a-w- c:\windows\system32\ntoskrnl.exe

2012-04-23 14:45 . 2012-03-06 05:59 3968368 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe

2012-04-23 14:45 . 2012-03-06 05:59 3913072 ----a-w- c:\windows\SysWow64\ntoskrnl.exe

2012-04-23 14:36 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys

2012-04-23 14:36 . 2012-03-01 06:33 81408 ----a-w- c:\windows\system32\imagehlp.dll

2012-04-23 14:36 . 2012-03-01 05:33 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll

2012-04-23 14:36 . 2012-03-01 06:38 220672 ----a-w- c:\windows\system32\wintrust.dll

2012-04-23 14:36 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll

2012-04-23 14:36 . 2012-03-01 05:37 172544 ----a-w- c:\windows\SysWow64\wintrust.dll

2012-04-23 14:36 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll

2012-04-18 12:42 . 2012-04-18 12:42 -------- d-----w- c:\program files\iPod

2012-04-18 12:42 . 2012-04-18 12:43 -------- d-----w- c:\program files\iTunes

2012-04-15 20:18 . 2012-04-15 20:18 -------- d-----w- c:\program files (x86)\fbphotozoom

2012-04-15 20:11 . 2012-04-15 20:11 237 ----a-w- C:\user.js

2012-04-15 20:11 . 2012-04-15 20:11 -------- d-----w- c:\users\Christian Ronchetti\AppData\Local\Babylon

2012-04-15 20:11 . 2012-04-15 20:11 -------- d-----w- c:\users\Christian Ronchetti\AppData\Roaming\Babylon

2012-04-15 20:11 . 2012-04-15 20:11 -------- d-----w- c:\programdata\Babylon

2012-04-15 19:51 . 2012-04-15 19:51 -------- d-----w- c:\programdata\PACE

2012-04-15 19:51 . 2012-04-15 19:51 -------- d-----w- c:\program files (x86)\Common Files\PACE

2012-04-15 19:50 . 2012-04-15 19:50 -------- d-----w- c:\programdata\Antares

2012-04-15 15:43 . 2012-04-15 15:43 -------- d-----w- c:\programdata\PACE Anti-Piracy

2012-04-15 15:43 . 2012-04-15 15:44 -------- d-----w- c:\users\Christian Ronchetti\AppData\Local\PACE Anti-Piracy

2012-04-15 15:43 . 2012-04-15 15:43 -------- d-----w- c:\users\Christian Ronchetti\AppData\Roaming\PACE Anti-Piracy

2012-04-15 15:43 . 2012-04-15 15:43 -------- d-----w- c:\program files (x86)\Common Files\PACE Anti-Piracy

2012-04-15 14:48 . 2012-04-15 19:50 -------- d-----w- c:\program files (x86)\Antares Audio Technologies

2012-04-15 13:48 . 2012-04-15 13:48 -------- d-----w- c:\program files (x86)\Ffmpeg For Audacity

2012-04-15 13:09 . 2012-04-15 13:09 -------- d-----w- c:\windows\Freecorder Toolbar

2012-04-15 12:14 . 2012-04-15 12:14 -------- d-----w- c:\program files (x86)\Lame For Audacity

2012-04-15 11:33 . 2012-04-15 14:56 -------- d-----w- c:\users\Christian Ronchetti\AppData\Roaming\Antares

2012-04-15 10:33 . 2012-04-15 10:33 -------- d-----w- c:\program files (x86)\Audacity

2012-04-15 10:20 . 2012-04-15 10:20 8766112 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe

2012-04-15 09:53 . 2012-04-15 09:53 -------- d-----w- c:\users\Christian Ronchetti\AppData\Local\TechSmith

2012-04-15 09:45 . 2012-04-15 10:20 418464 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2012-04-15 09:32 . 2010-03-04 16:27 411480 ----a-w- c:\windows\SysWow64\tsccvid.dll

2012-04-15 09:32 . 2012-04-15 09:32 -------- d-----w- c:\windows\SysWow64\QuickTime

2012-04-15 09:32 . 2012-04-15 09:32 -------- d-----w- c:\program files (x86)\Common Files\TechSmith Shared

2012-04-15 09:32 . 2012-04-15 09:32 -------- d-----w- c:\programdata\TechSmith

2012-04-15 09:32 . 2012-04-15 09:32 -------- d-----w- c:\program files (x86)\TechSmith

2012-04-11 10:15 . 2012-04-11 10:15 27176 ----a-w- c:\windows\system32\drivers\ggsemc.sys

2012-04-11 10:15 . 2012-04-11 10:15 1490656 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll

2012-04-11 10:15 . 2012-04-11 10:15 13352 ----a-w- c:\windows\system32\drivers\ggflt.sys

2012-04-11 10:14 . 2012-04-23 14:38 -------- d-----w- c:\programdata\Sony Ericsson

2012-04-11 10:14 . 2012-04-23 14:38 -------- d-----w- c:\program files (x86)\Sony Ericsson

2012-04-11 10:14 . 2012-04-11 10:14 -------- d-----w- c:\program files (x86)\Common Files\Java

2012-04-11 10:14 . 2012-04-11 10:13 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll

2012-04-11 10:13 . 2012-04-11 10:13 -------- d-----w- c:\program files (x86)\Java

2012-04-05 14:05 . 2012-04-05 14:05 -------- d-----w- c:\users\Christian Ronchetti\AppData\Roaming\AVS4YOU

2012-04-05 14:02 . 2012-04-23 14:35 -------- d-----w- c:\program files (x86)\Common Files\AVSMedia

2012-04-05 14:02 . 2012-04-23 14:35 -------- d-----w- c:\program files (x86)\AVS4YOU

2012-04-05 14:02 . 2012-04-05 14:05 -------- d-----w- c:\programdata\AVS4YOU

2012-04-05 14:02 . 2011-08-22 15:32 24576 ----a-w- c:\windows\SysWow64\msxml3a.dll

2012-04-04 05:53 . 2012-04-04 05:53 182160 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll

2012-04-04 02:51 . 2012-04-04 02:51 -------- d-----w- c:\program files (x86)\Reincubate

2012-04-04 01:35 . 2012-04-04 01:35 -------- d-----w- c:\users\Christian Ronchetti\AppData\Local\Apple_Inc

2012-04-04 01:34 . 2012-04-04 01:34 -------- d-----w- c:\program files (x86)\iPhone Configuration Utility

2012-03-30 19:01 . 2012-03-30 19:01 -------- d-----w- c:\program files (x86)\Common Files\Skype

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-04-15 10:20 . 2011-12-01 14:05 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2012-04-13 08:46 . 2011-12-14 10:29 8917360 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll

2012-03-01 23:55 . 2012-03-01 23:55 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe

2012-03-01 23:55 . 2012-03-01 23:55 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe

2012-03-01 23:55 . 2012-03-01 23:55 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll

2012-03-01 23:55 . 2012-03-01 23:55 161792 ----a-w- c:\windows\SysWow64\msls31.dll

2012-03-01 23:55 . 2012-03-01 23:55 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll

2012-03-01 23:55 . 2012-03-01 23:55 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll

2012-03-01 23:55 . 2012-03-01 23:55 74752 ----a-w- c:\windows\SysWow64\iesetup.dll

2012-03-01 23:55 . 2012-03-01 23:55 63488 ----a-w- c:\windows\SysWow64\tdc.ocx

2012-03-01 23:55 . 2012-03-01 23:55 367104 ----a-w- c:\windows\SysWow64\html.iec

2012-03-01 23:55 . 2012-03-01 23:55 420864 ----a-w- c:\windows\SysWow64\vbscript.dll

2012-03-01 23:55 . 2012-03-01 23:55 35840 ----a-w- c:\windows\SysWow64\imgutil.dll

2012-03-01 23:55 . 2012-03-01 23:55 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll

2012-03-01 23:55 . 2012-03-01 23:55 152064 ----a-w- c:\windows\SysWow64\wextract.exe

2012-03-01 23:55 . 2012-03-01 23:55 150528 ----a-w- c:\windows\SysWow64\iexpress.exe

2012-03-01 23:55 . 2012-03-01 23:55 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe

2012-03-01 23:55 . 2012-03-01 23:55 11776 ----a-w- c:\windows\SysWow64\mshta.exe

2012-03-01 23:55 . 2012-03-01 23:55 101888 ----a-w- c:\windows\SysWow64\admparse.dll

2012-03-01 23:55 . 2012-03-01 23:55 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe

2012-03-01 23:55 . 2012-03-01 23:55 222208 ----a-w- c:\windows\system32\msls31.dll

2012-03-01 23:55 . 2012-03-01 23:55 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe

2012-03-01 23:55 . 2012-03-01 23:55 85504 ----a-w- c:\windows\system32\iesetup.dll

2012-03-01 23:55 . 2012-03-01 23:55 76800 ----a-w- c:\windows\system32\tdc.ocx

2012-03-01 23:55 . 2012-03-01 23:55 49664 ----a-w- c:\windows\system32\imgutil.dll

2012-03-01 23:55 . 2012-03-01 23:55 48640 ----a-w- c:\windows\system32\mshtmler.dll

2012-03-01 23:55 . 2012-03-01 23:55 448512 ----a-w- c:\windows\system32\html.iec

2012-03-01 23:55 . 2012-03-01 23:55 173056 ----a-w- c:\windows\system32\ieUnatt.exe

2012-03-01 23:55 . 2012-03-01 23:55 135168 ----a-w- c:\windows\system32\IEAdvpack.dll

2012-03-01 23:55 . 2012-03-01 23:55 12288 ----a-w- c:\windows\system32\mshta.exe

2012-03-01 23:55 . 2012-03-01 23:55 114176 ----a-w- c:\windows\system32\admparse.dll

2012-03-01 23:55 . 2012-03-01 23:55 111616 ----a-w- c:\windows\system32\iesysprep.dll

2012-03-01 23:55 . 2012-03-01 23:55 603648 ----a-w- c:\windows\system32\vbscript.dll

2012-03-01 23:55 . 2012-03-01 23:55 30720 ----a-w- c:\windows\system32\licmgr10.dll

2012-03-01 23:55 . 2012-03-01 23:55 165888 ----a-w- c:\windows\system32\iexpress.exe

2012-03-01 23:55 . 2012-03-01 23:55 160256 ----a-w- c:\windows\system32\wextract.exe

2012-02-17 06:38 . 2012-03-14 17:04 1031680 ----a-w- c:\windows\system32\rdpcore.dll

2012-02-17 05:34 . 2012-03-14 17:04 826880 ----a-w- c:\windows\SysWow64\rdpcore.dll

2012-02-17 04:58 . 2012-03-14 17:04 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys

2012-02-17 04:57 . 2012-03-14 17:04 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys

2012-02-15 11:01 . 2012-02-15 11:01 52736 ----a-w- c:\windows\system32\drivers\usbaapl64.sys

2012-02-15 11:01 . 2012-02-15 11:01 4547944 ----a-w- c:\windows\system32\usbaaplrc.dll

2012-02-14 11:09 . 2012-02-14 11:09 1070352 ----a-w- c:\windows\SysWow64\MSCOMCTL.OCX

2012-02-11 02:24 . 2012-02-11 02:25 927800 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{AEF04F1F-1395-41E9-9CFF-6142BD87F2B8}\gapaengine.dll

2012-02-10 06:36 . 2012-03-14 17:07 1544192 ----a-w- c:\windows\system32\DWrite.dll

2012-02-10 05:38 . 2012-03-14 17:07 1077248 ----a-w- c:\windows\SysWow64\DWrite.dll

2012-02-08 07:13 . 2012-03-01 23:59 8643640 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll

2012-02-03 04:34 . 2012-03-14 17:07 3145728 ----a-w- c:\windows\system32\win32k.sys

2012-01-31 12:44 . 2010-11-21 03:27 279656 ------w- c:\windows\system32\MpSigStub.exe

2012-01-25 06:38 . 2012-03-14 17:05 77312 ----a-w- c:\windows\system32\rdpwsx.dll

2012-01-25 06:38 . 2012-03-14 17:05 149504 ----a-w- c:\windows\system32\rdpcorekmts.dll

2012-01-25 06:33 . 2012-03-14 17:05 9216 ----a-w- c:\windows\system32\rdrmemptylst.exe

.

.

((((((((((((((((((((((((((((( SnapShot@2012-04-23_20.42.01 )))))))))))))))))))))))))))))))))))))))))

.

+ 2010-11-21 03:09 . 2012-04-23 21:19 24650 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin

+ 2009-07-14 05:10 . 2012-04-23 21:19 30458 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin

+ 2009-07-14 04:46 . 2012-04-23 20:49 92944 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat

+ 2011-12-02 08:16 . 2012-04-23 21:19 4706 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-201949659-3598620656-673553719-1000_UserData.bin

- 2012-04-23 20:41 . 2012-04-23 20:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

+ 2012-04-23 22:06 . 2012-04-23 22:06 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

+ 2012-04-23 22:06 . 2012-04-23 22:06 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

- 2012-04-23 20:41 . 2012-04-23 20:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

- 2009-07-14 02:36 . 2012-04-23 20:30 630560 c:\windows\system32\perfh009.dat

+ 2009-07-14 02:36 . 2012-04-23 21:22 630560 c:\windows\system32\perfh009.dat

- 2009-07-14 02:36 . 2012-04-23 20:30 111612 c:\windows\system32\perfc009.dat

+ 2009-07-14 02:36 . 2012-04-23 21:22 111612 c:\windows\system32\perfc009.dat

+ 2009-07-14 05:01 . 2012-04-23 22:05 390296 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

- 2009-07-14 05:01 . 2012-04-23 20:40 390296 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

+ 2012-01-27 23:40 . 2012-04-23 22:05 25963472 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-201949659-3598620656-673553719-1000-8192.dat

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Xvid"="c:\program files (x86)\Xvid\CheckUpdate.exe" [2011-01-17 8192]

"Facebook Update"="c:\users\Christian Ronchetti\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-04-11 137536]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]

"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]

"KeNotify"="c:\program files (x86)\TOSHIBA\Utilities\KeNotify.exe" [2010-08-16 34160]

"HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2010-03-04 423936]

"Bonus.SSR.FR11"="c:\program files (x86)\ABBYY FineReader 11\Bonus.ScreenshotReader.exe" [2011-08-09 911112]

"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]

"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]

"MMReminderService"="c:\program files (x86)\Mindjet\MindManager 10\MMReminderService.exe" [2012-02-27 38248]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]

"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-03-27 421736]

"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]

.

c:\users\Christian Ronchetti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Colour Explorer 9,0.lnk - c:\program files (x86)\MicrolinkPC\CXLOADER.exe [2011-12-1 72192]

OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE [2010-12-21 227712]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

Book Pavilion (Plustek OpticBook 3800).lnk - c:\program files (x86)\Plustek\Plustek OpticBook 3800\book express.exe [2011-12-1 475136]

Device Detector 4.lnk - c:\program files (x86)\OLYMPUS\DeviceDetector\DeviceDetector4.exe [2009-12-1 402832]

.

c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

TaskBar.vbs [2009-8-12 1797]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]

"aux"=wdmaud.drv

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

@="Service"

.

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-02-29 158856]

R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-15 253088]

R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [x]

R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [x]

R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [x]

R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880]

R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]

R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys [x]

R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]

R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]

R3 Olympus DVR Service;Olympus DVR Service;c:\program files (x86)\Common Files\Olympus Shared\DeviceManager\olydvrsv.exe [2011-05-10 176128]

R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]

R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]

R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]

R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]

S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]

S2 ABBYY.Licensing.FineReader.Professional.11.0;ABBYY FineReader 11 PE Licensing Service;c:\program files (x86)\ABBYY FineReader 11\NetworkLicenseServer.exe [2011-08-03 819976]

S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]

S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]

S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]

S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-05-04 503080]

S2 PaceLicenseDServices;PACE License Services;c:\program files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe [2011-07-09 2932224]

S3 CeKbFilter;CeKbFilter;c:\windows\system32\DRIVERS\CeKbFilter.sys [x]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]

S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\drivers\HECIx64.sys [x]

S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x]

S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]

.

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{90EF4A5E-85DB-4825-96F5-1AB93C2A8EEB}]

2012-02-27 04:49 1409 ----a-r- c:\program files (x86)\Mindjet\MindManager 10\sys\MmInternetExplorerActiveSetup.vbs

.

Contents of the 'Scheduled Tasks' folder

.

2012-04-23 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-15 10:20]

.

2012-04-22 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-201949659-3598620656-673553719-1000Core.job

- c:\users\Christian Ronchetti\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-01-19 08:36]

.

2012-04-23 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-201949659-3598620656-673553719-1000UA.job

- c:\users\Christian Ronchetti\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-01-19 08:36]

.

.

--------- x86-64 -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [bU]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-04-07 167256]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-04-07 391000]

"Persistence"="c:\windows\system32\igfxpers.exe" [2011-04-07 418136]

"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-02-11 11776104]

"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-01-18 2188904]

"TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376]

"WrtMon.exe"="c:\windows\system32\spool\drivers\x64\3\WrtMon.exe" [2007-07-18 20480]

"TPwrMain"="c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE" [bU]

"TCrdMain"="c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe" [bU]

"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736]

"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2011-03-15 2779024]

"TOSHIBA Face Recognition"="c:\program files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe" [bU]

.

------- Supplementary Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

mLocal Page = c:\windows\SysWOW64\blank.htm

uInternet Settings,ProxyOverride = *.local

IE:

IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000

IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105

IE: Send Image To MindManager - c:\program files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll/201

IE: Send Link To MindManager - c:\program files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll/203

IE: Send Page To MindManager - c:\program files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll/204

IE: Send Text To MindManager - c:\program files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll/202

TCP: DhcpNameServer = 192.168.0.1

DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://88.247.210.37:81/activex/AMC.cab

FF - ProfilePath - c:\users\Christian Ronchetti\AppData\Roaming\Mozilla\Firefox\Profiles\xd6r04iw.default\

FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=100&systemid=102&sr=0&q=

FF - prefs.js: network.proxy.type - 0

FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109980

FF - user.js: extensions.BabylonToolbar_i.babExt -

FF - user.js: extensions.BabylonToolbar_i.srcExt - ss

FF - user.js: extensions.BabylonToolbar_i.id - d8a31185000000000000d0df9a8d65b5

FF - user.js: extensions.BabylonToolbar_i.hardId - d8a31185000000000000d0df9a8d65b5

FF - user.js: extensions.BabylonToolbar_i.instlDay - 15445

FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1721:11

FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon

FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar

FF - user.js: extensions.BabylonToolbar_i.aflt - babsst

FF - user.js: extensions.BabylonToolbar_i.smplGrp - none

FF - user.js: extensions.BabylonToolbar_i.tlbrId - base

FF - user.js: extensions.BabylonToolbar_i.instlRef - sst

.

- - - - ORPHANS REMOVED - - - -

.

Toolbar-Locked - (no file)

Toolbar-10 - (no file)

.

.

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_233_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_233_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.11"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]

@Denied: (A) (Everyone)

"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]

@Denied: (A) (Everyone)

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]

"Key"="ActionsPane3"

"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

------------------------ Other Running Processes ------------------------

.

c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

.

**************************************************************************

.

Completion time: 2012-04-23 23:10:54 - machine was rebooted

ComboFix-quarantined-files.txt 2012-04-23 22:10

ComboFix2.txt 2012-04-23 20:46

.

Pre-Run: 32,217,776,128 bytes free

Post-Run: 32,137,740,288 bytes free

.

- - End Of File - - 6E98D091A07B836BBB94CE1FAD3DD5BF

Link to post
Share on other sites

Looks like I didn't create the script correctly, we have to run it again.

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

4. If ComboFix wants to update.....please allow it to.

File::

c:\users\Christian Ronchetti\AppData\Local\Babylon

c:\users\Christian Ronchetti\AppData\Roaming\Babylon

c:\programdata\Babylon

Firefox::

FF - ProfilePath - c:\users\Christian Ronchetti\AppData\Roaming\Mozilla\Firefox\Profiles\xd6r04iw.default\

FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109980

FF - user.js: extensions.BabylonToolbar_i.babExt -

FF - user.js: extensions.BabylonToolbar_i.srcExt - ss

FF - user.js: extensions.BabylonToolbar_i.id - d8a31185000000000000d0df9a8d65b5

FF - user.js: extensions.BabylonToolbar_i.hardId - d8a31185000000000000d0df9a8d65b5

FF - user.js: extensions.BabylonToolbar_i.instlDay - 15445

FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1721:11

FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon

FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar

FF - user.js: extensions.BabylonToolbar_i.aflt - babsst

FF - user.js: extensions.BabylonToolbar_i.smplGrp - none

FF - user.js: extensions.BabylonToolbar_i.tlbrId - base

FF - user.js: extensions.BabylonToolbar_i.instlRef - sst

Save this as CFScript.txt, in the same location as ComboFix.exe

CFScript.gif

Refering to the picture above, drag CFScript into ComboFix.exe

CAUTION: Do not mouse-click ComboFix while it is running. It may cause it to stall.

After reboot, (in case it asks to reboot)......

Please provide the contents of the ComboFix log (C:\ComboFix.txt) in your next reply.

MrC

Link to post
Share on other sites

ComboFix 12-04-23.02 - Christian Ronchetti 24/04/2012 9:25.3.4 - x64

Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.4004.2568 [GMT 1:00]

Running from: c:\users\Christian Ronchetti\Desktop\ComboFix.exe

Command switches used :: c:\users\Christian Ronchetti\Desktop\CFScript.txt

AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}

SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

FILE ::

"c:\programdata\Babylon"

"c:\users\Christian Ronchetti\AppData\Local\Babylon"

"c:\users\Christian Ronchetti\AppData\Roaming\Babylon"

.

.

((((((((((((((((((((((((( Files Created from 2012-03-24 to 2012-04-24 )))))))))))))))))))))))))))))))

.

.

2012-04-24 08:30 . 2012-04-24 08:30 -------- d-----w- c:\users\Default\AppData\Local\temp

2012-04-23 15:49 . 2012-04-23 15:49 388096 ----a-r- c:\users\Christian Ronchetti\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2012-04-23 15:49 . 2012-04-23 15:49 -------- d-----w- c:\program files (x86)\Trend Micro

2012-04-23 15:41 . 2012-04-23 15:41 -------- d-----w- c:\users\Christian Ronchetti\AppData\Roaming\Malwarebytes

2012-04-23 15:40 . 2012-04-23 15:40 -------- d-----w- c:\programdata\Malwarebytes

2012-04-23 15:40 . 2012-04-23 15:40 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2012-04-23 15:40 . 2012-04-04 14:56 24904 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-04-23 14:50 . 2012-04-13 08:46 8917360 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{01CCA537-C00B-40A3-9978-A594718D95F0}\mpengine.dll

2012-04-23 14:48 . 2012-02-28 06:42 2382848 ----a-w- c:\windows\system32\mshtml.tlb

2012-04-23 14:48 . 2012-02-28 01:03 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb

2012-04-23 14:48 . 2012-02-28 07:37 174392 ----a-w- c:\program files\Internet Explorer\sqmapi.dll

2012-04-23 14:48 . 2012-02-28 06:47 304640 ----a-w- c:\program files\Internet Explorer\IEShims.dll

2012-04-23 14:48 . 2012-02-28 01:58 141112 ----a-w- c:\program files (x86)\Internet Explorer\sqmapi.dll

2012-04-23 14:45 . 2012-03-06 06:53 5559152 ----a-w- c:\windows\system32\ntoskrnl.exe

2012-04-23 14:45 . 2012-03-06 05:59 3968368 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe

2012-04-23 14:45 . 2012-03-06 05:59 3913072 ----a-w- c:\windows\SysWow64\ntoskrnl.exe

2012-04-23 14:36 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys

2012-04-23 14:36 . 2012-03-01 06:33 81408 ----a-w- c:\windows\system32\imagehlp.dll

2012-04-23 14:36 . 2012-03-01 05:33 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll

2012-04-23 14:36 . 2012-03-01 06:38 220672 ----a-w- c:\windows\system32\wintrust.dll

2012-04-23 14:36 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll

2012-04-23 14:36 . 2012-03-01 05:37 172544 ----a-w- c:\windows\SysWow64\wintrust.dll

2012-04-23 14:36 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll

2012-04-18 12:42 . 2012-04-18 12:42 -------- d-----w- c:\program files\iPod

2012-04-18 12:42 . 2012-04-18 12:43 -------- d-----w- c:\program files\iTunes

2012-04-15 20:18 . 2012-04-15 20:18 -------- d-----w- c:\program files (x86)\fbphotozoom

2012-04-15 20:11 . 2012-04-15 20:11 237 ----a-w- C:\user.js

2012-04-15 20:11 . 2012-04-15 20:11 -------- d-----w- c:\users\Christian Ronchetti\AppData\Local\Babylon

2012-04-15 20:11 . 2012-04-15 20:11 -------- d-----w- c:\users\Christian Ronchetti\AppData\Roaming\Babylon

2012-04-15 20:11 . 2012-04-15 20:11 -------- d-----w- c:\programdata\Babylon

2012-04-15 19:51 . 2012-04-15 19:51 -------- d-----w- c:\programdata\PACE

2012-04-15 19:51 . 2012-04-15 19:51 -------- d-----w- c:\program files (x86)\Common Files\PACE

2012-04-15 19:50 . 2012-04-15 19:50 -------- d-----w- c:\programdata\Antares

2012-04-15 15:43 . 2012-04-15 15:43 -------- d-----w- c:\programdata\PACE Anti-Piracy

2012-04-15 15:43 . 2012-04-15 15:44 -------- d-----w- c:\users\Christian Ronchetti\AppData\Local\PACE Anti-Piracy

2012-04-15 15:43 . 2012-04-15 15:43 -------- d-----w- c:\users\Christian Ronchetti\AppData\Roaming\PACE Anti-Piracy

2012-04-15 15:43 . 2012-04-15 15:43 -------- d-----w- c:\program files (x86)\Common Files\PACE Anti-Piracy

2012-04-15 14:48 . 2012-04-15 19:50 -------- d-----w- c:\program files (x86)\Antares Audio Technologies

2012-04-15 13:48 . 2012-04-15 13:48 -------- d-----w- c:\program files (x86)\Ffmpeg For Audacity

2012-04-15 13:09 . 2012-04-15 13:09 -------- d-----w- c:\windows\Freecorder Toolbar

2012-04-15 12:14 . 2012-04-15 12:14 -------- d-----w- c:\program files (x86)\Lame For Audacity

2012-04-15 11:33 . 2012-04-15 14:56 -------- d-----w- c:\users\Christian Ronchetti\AppData\Roaming\Antares

2012-04-15 10:33 . 2012-04-15 10:33 -------- d-----w- c:\program files (x86)\Audacity

2012-04-15 10:20 . 2012-04-15 10:20 8766112 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe

2012-04-15 09:53 . 2012-04-15 09:53 -------- d-----w- c:\users\Christian Ronchetti\AppData\Local\TechSmith

2012-04-15 09:45 . 2012-04-15 10:20 418464 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2012-04-15 09:32 . 2010-03-04 16:27 411480 ----a-w- c:\windows\SysWow64\tsccvid.dll

2012-04-15 09:32 . 2012-04-15 09:32 -------- d-----w- c:\windows\SysWow64\QuickTime

2012-04-15 09:32 . 2012-04-15 09:32 -------- d-----w- c:\program files (x86)\Common Files\TechSmith Shared

2012-04-15 09:32 . 2012-04-15 09:32 -------- d-----w- c:\programdata\TechSmith

2012-04-15 09:32 . 2012-04-15 09:32 -------- d-----w- c:\program files (x86)\TechSmith

2012-04-11 10:15 . 2012-04-11 10:15 27176 ----a-w- c:\windows\system32\drivers\ggsemc.sys

2012-04-11 10:15 . 2012-04-11 10:15 1490656 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll

2012-04-11 10:15 . 2012-04-11 10:15 13352 ----a-w- c:\windows\system32\drivers\ggflt.sys

2012-04-11 10:14 . 2012-04-23 14:38 -------- d-----w- c:\programdata\Sony Ericsson

2012-04-11 10:14 . 2012-04-23 14:38 -------- d-----w- c:\program files (x86)\Sony Ericsson

2012-04-11 10:14 . 2012-04-11 10:14 -------- d-----w- c:\program files (x86)\Common Files\Java

2012-04-11 10:14 . 2012-04-11 10:13 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll

2012-04-11 10:13 . 2012-04-11 10:13 -------- d-----w- c:\program files (x86)\Java

2012-04-05 14:05 . 2012-04-05 14:05 -------- d-----w- c:\users\Christian Ronchetti\AppData\Roaming\AVS4YOU

2012-04-05 14:02 . 2012-04-23 14:35 -------- d-----w- c:\program files (x86)\Common Files\AVSMedia

2012-04-05 14:02 . 2012-04-23 14:35 -------- d-----w- c:\program files (x86)\AVS4YOU

2012-04-05 14:02 . 2012-04-05 14:05 -------- d-----w- c:\programdata\AVS4YOU

2012-04-05 14:02 . 2011-08-22 15:32 24576 ----a-w- c:\windows\SysWow64\msxml3a.dll

2012-04-04 05:53 . 2012-04-04 05:53 182160 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll

2012-04-04 02:51 . 2012-04-04 02:51 -------- d-----w- c:\program files (x86)\Reincubate

2012-04-04 01:35 . 2012-04-04 01:35 -------- d-----w- c:\users\Christian Ronchetti\AppData\Local\Apple_Inc

2012-04-04 01:34 . 2012-04-04 01:34 -------- d-----w- c:\program files (x86)\iPhone Configuration Utility

2012-03-30 19:01 . 2012-03-30 19:01 -------- d-----w- c:\program files (x86)\Common Files\Skype

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-04-15 10:20 . 2011-12-01 14:05 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2012-04-13 08:46 . 2011-12-14 10:29 8917360 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll

2012-03-01 23:55 . 2012-03-01 23:55 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe

2012-03-01 23:55 . 2012-03-01 23:55 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe

2012-03-01 23:55 . 2012-03-01 23:55 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll

2012-03-01 23:55 . 2012-03-01 23:55 161792 ----a-w- c:\windows\SysWow64\msls31.dll

2012-03-01 23:55 . 2012-03-01 23:55 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll

2012-03-01 23:55 . 2012-03-01 23:55 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll

2012-03-01 23:55 . 2012-03-01 23:55 74752 ----a-w- c:\windows\SysWow64\iesetup.dll

2012-03-01 23:55 . 2012-03-01 23:55 63488 ----a-w- c:\windows\SysWow64\tdc.ocx

2012-03-01 23:55 . 2012-03-01 23:55 367104 ----a-w- c:\windows\SysWow64\html.iec

2012-03-01 23:55 . 2012-03-01 23:55 420864 ----a-w- c:\windows\SysWow64\vbscript.dll

2012-03-01 23:55 . 2012-03-01 23:55 35840 ----a-w- c:\windows\SysWow64\imgutil.dll

2012-03-01 23:55 . 2012-03-01 23:55 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll

2012-03-01 23:55 . 2012-03-01 23:55 152064 ----a-w- c:\windows\SysWow64\wextract.exe

2012-03-01 23:55 . 2012-03-01 23:55 150528 ----a-w- c:\windows\SysWow64\iexpress.exe

2012-03-01 23:55 . 2012-03-01 23:55 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe

2012-03-01 23:55 . 2012-03-01 23:55 11776 ----a-w- c:\windows\SysWow64\mshta.exe

2012-03-01 23:55 . 2012-03-01 23:55 101888 ----a-w- c:\windows\SysWow64\admparse.dll

2012-03-01 23:55 . 2012-03-01 23:55 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe

2012-03-01 23:55 . 2012-03-01 23:55 222208 ----a-w- c:\windows\system32\msls31.dll

2012-03-01 23:55 . 2012-03-01 23:55 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe

2012-03-01 23:55 . 2012-03-01 23:55 85504 ----a-w- c:\windows\system32\iesetup.dll

2012-03-01 23:55 . 2012-03-01 23:55 76800 ----a-w- c:\windows\system32\tdc.ocx

2012-03-01 23:55 . 2012-03-01 23:55 49664 ----a-w- c:\windows\system32\imgutil.dll

2012-03-01 23:55 . 2012-03-01 23:55 48640 ----a-w- c:\windows\system32\mshtmler.dll

2012-03-01 23:55 . 2012-03-01 23:55 448512 ----a-w- c:\windows\system32\html.iec

2012-03-01 23:55 . 2012-03-01 23:55 173056 ----a-w- c:\windows\system32\ieUnatt.exe

2012-03-01 23:55 . 2012-03-01 23:55 135168 ----a-w- c:\windows\system32\IEAdvpack.dll

2012-03-01 23:55 . 2012-03-01 23:55 12288 ----a-w- c:\windows\system32\mshta.exe

2012-03-01 23:55 . 2012-03-01 23:55 114176 ----a-w- c:\windows\system32\admparse.dll

2012-03-01 23:55 . 2012-03-01 23:55 111616 ----a-w- c:\windows\system32\iesysprep.dll

2012-03-01 23:55 . 2012-03-01 23:55 603648 ----a-w- c:\windows\system32\vbscript.dll

2012-03-01 23:55 . 2012-03-01 23:55 30720 ----a-w- c:\windows\system32\licmgr10.dll

2012-03-01 23:55 . 2012-03-01 23:55 165888 ----a-w- c:\windows\system32\iexpress.exe

2012-03-01 23:55 . 2012-03-01 23:55 160256 ----a-w- c:\windows\system32\wextract.exe

2012-02-17 06:38 . 2012-03-14 17:04 1031680 ----a-w- c:\windows\system32\rdpcore.dll

2012-02-17 05:34 . 2012-03-14 17:04 826880 ----a-w- c:\windows\SysWow64\rdpcore.dll

2012-02-17 04:58 . 2012-03-14 17:04 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys

2012-02-17 04:57 . 2012-03-14 17:04 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys

2012-02-15 11:01 . 2012-02-15 11:01 52736 ----a-w- c:\windows\system32\drivers\usbaapl64.sys

2012-02-15 11:01 . 2012-02-15 11:01 4547944 ----a-w- c:\windows\system32\usbaaplrc.dll

2012-02-14 11:09 . 2012-02-14 11:09 1070352 ----a-w- c:\windows\SysWow64\MSCOMCTL.OCX

2012-02-11 02:24 . 2012-02-11 02:25 927800 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{AEF04F1F-1395-41E9-9CFF-6142BD87F2B8}\gapaengine.dll

2012-02-10 06:36 . 2012-03-14 17:07 1544192 ----a-w- c:\windows\system32\DWrite.dll

2012-02-10 05:38 . 2012-03-14 17:07 1077248 ----a-w- c:\windows\SysWow64\DWrite.dll

2012-02-08 07:13 . 2012-03-01 23:59 8643640 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll

2012-02-03 04:34 . 2012-03-14 17:07 3145728 ----a-w- c:\windows\system32\win32k.sys

2012-01-31 12:44 . 2010-11-21 03:27 279656 ------w- c:\windows\system32\MpSigStub.exe

.

.

((((((((((((((((((((((((((((( SnapShot@2012-04-23_20.42.01 )))))))))))))))))))))))))))))))))))))))))

.

+ 2010-11-21 03:09 . 2012-04-23 22:16 27760 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin

+ 2009-07-14 05:10 . 2012-04-23 22:16 30490 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin

+ 2009-07-14 04:46 . 2012-04-23 20:49 92944 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat

+ 2011-12-02 08:16 . 2012-04-23 22:16 5400 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-201949659-3598620656-673553719-1000_UserData.bin

- 2012-04-23 20:41 . 2012-04-23 20:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

+ 2012-04-24 08:31 . 2012-04-24 08:31 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

+ 2012-04-24 08:31 . 2012-04-24 08:31 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

- 2012-04-23 20:41 . 2012-04-23 20:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

+ 2011-12-14 11:08 . 2012-04-24 08:05 219266 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin

- 2009-07-14 02:36 . 2012-04-23 20:30 630560 c:\windows\system32\perfh009.dat

+ 2009-07-14 02:36 . 2012-04-24 08:07 630560 c:\windows\system32\perfh009.dat

+ 2009-07-14 02:36 . 2012-04-24 08:07 111612 c:\windows\system32\perfc009.dat

- 2009-07-14 02:36 . 2012-04-23 20:30 111612 c:\windows\system32\perfc009.dat

- 2009-07-14 05:01 . 2012-04-23 20:40 390296 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

+ 2009-07-14 05:01 . 2012-04-24 08:30 390296 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

+ 2012-01-27 23:40 . 2012-04-24 08:30 25963472 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-201949659-3598620656-673553719-1000-8192.dat

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Xvid"="c:\program files (x86)\Xvid\CheckUpdate.exe" [2011-01-17 8192]

"Facebook Update"="c:\users\Christian Ronchetti\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-04-11 137536]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]

"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]

"KeNotify"="c:\program files (x86)\TOSHIBA\Utilities\KeNotify.exe" [2010-08-16 34160]

"HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2010-03-04 423936]

"Bonus.SSR.FR11"="c:\program files (x86)\ABBYY FineReader 11\Bonus.ScreenshotReader.exe" [2011-08-09 911112]

"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]

"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]

"MMReminderService"="c:\program files (x86)\Mindjet\MindManager 10\MMReminderService.exe" [2012-02-27 38248]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]

"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-03-27 421736]

"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]

.

c:\users\Christian Ronchetti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Colour Explorer 9,0.lnk - c:\program files (x86)\MicrolinkPC\CXLOADER.exe [2011-12-1 72192]

OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE [2010-12-21 227712]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

Book Pavilion (Plustek OpticBook 3800).lnk - c:\program files (x86)\Plustek\Plustek OpticBook 3800\book express.exe [2011-12-1 475136]

Device Detector 4.lnk - c:\program files (x86)\OLYMPUS\DeviceDetector\DeviceDetector4.exe [2009-12-1 402832]

.

c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

TaskBar.vbs [2009-8-12 1797]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]

"aux"=wdmaud.drv

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

@="Service"

.

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-02-29 158856]

R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-15 253088]

R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [x]

R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [x]

R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [x]

R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880]

R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]

R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys [x]

R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]

R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]

R3 Olympus DVR Service;Olympus DVR Service;c:\program files (x86)\Common Files\Olympus Shared\DeviceManager\olydvrsv.exe [2011-05-10 176128]

R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]

R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]

R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]

R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]

S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]

S2 ABBYY.Licensing.FineReader.Professional.11.0;ABBYY FineReader 11 PE Licensing Service;c:\program files (x86)\ABBYY FineReader 11\NetworkLicenseServer.exe [2011-08-03 819976]

S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]

S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]

S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]

S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-05-04 503080]

S2 PaceLicenseDServices;PACE License Services;c:\program files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe [2011-07-09 2932224]

S3 CeKbFilter;CeKbFilter;c:\windows\system32\DRIVERS\CeKbFilter.sys [x]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]

S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\drivers\HECIx64.sys [x]

S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x]

S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]

.

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{90EF4A5E-85DB-4825-96F5-1AB93C2A8EEB}]

2012-02-27 04:49 1409 ----a-r- c:\program files (x86)\Mindjet\MindManager 10\sys\MmInternetExplorerActiveSetup.vbs

.

Contents of the 'Scheduled Tasks' folder

.

2012-04-24 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-15 10:20]

.

2012-04-22 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-201949659-3598620656-673553719-1000Core.job

- c:\users\Christian Ronchetti\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-01-19 08:36]

.

2012-04-24 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-201949659-3598620656-673553719-1000UA.job

- c:\users\Christian Ronchetti\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-01-19 08:36]

.

.

--------- x86-64 -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [bU]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-04-07 167256]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-04-07 391000]

"Persistence"="c:\windows\system32\igfxpers.exe" [2011-04-07 418136]

"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-02-11 11776104]

"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-01-18 2188904]

"TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376]

"WrtMon.exe"="c:\windows\system32\spool\drivers\x64\3\WrtMon.exe" [2007-07-18 20480]

"TPwrMain"="c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE" [bU]

"TCrdMain"="c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe" [bU]

"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736]

"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2011-03-15 2779024]

"TOSHIBA Face Recognition"="c:\program files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe" [bU]

.

------- Supplementary Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

mLocal Page = c:\windows\SysWOW64\blank.htm

uInternet Settings,ProxyOverride = *.local

IE:

IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000

IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105

IE: Send Image To MindManager - c:\program files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll/201

IE: Send Link To MindManager - c:\program files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll/203

IE: Send Page To MindManager - c:\program files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll/204

IE: Send Text To MindManager - c:\program files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll/202

TCP: DhcpNameServer = 192.168.0.1

DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://88.247.210.37:81/activex/AMC.cab

FF - ProfilePath - c:\users\Christian Ronchetti\AppData\Roaming\Mozilla\Firefox\Profiles\xd6r04iw.default\

FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=100&systemid=102&sr=0&q=

FF - prefs.js: network.proxy.type - 0

.

- - - - ORPHANS REMOVED - - - -

.

Toolbar-Locked - (no file)

Toolbar-10 - (no file)

.

.

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_233_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_233_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.11"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]

@Denied: (A) (Everyone)

"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]

@Denied: (A) (Everyone)

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]

"Key"="ActionsPane3"

"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

------------------------ Other Running Processes ------------------------

.

c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

.

**************************************************************************

.

Completion time: 2012-04-24 09:37:43 - machine was rebooted

ComboFix-quarantined-files.txt 2012-04-24 08:37

ComboFix2.txt 2012-04-23 22:10

ComboFix3.txt 2012-04-23 20:46

.

Pre-Run: 31,251,025,920 bytes free

Post-Run: 30,933,848,064 bytes free

.

- - End Of File - - 0A8A0BEE4905E4EA9A871BF79314682C

Link to post
Share on other sites

These are still there:

c:\users\Christian Ronchetti\AppData\Local\Babylon

c:\users\Christian Ronchetti\AppData\Roaming\Babylon

c:\programdata\Babylon

Please download OTL from one of the links below:

http://oldtimer.geekstogo.com/OTL.exe

http://oldtimer.geekstogo.com/OTL.com (<---renamed version)

Save it to your desktop.

Please do this:

Run OTL

  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :Files
    c:\users\Christian Ronchetti\AppData\Local\Babylon
    c:\users\Christian Ronchetti\AppData\Roaming\Babylon
    c:\programdata\Babylon

    :Commands
    [EMPTYJAVA]
    [emptytemp]


  • Then click the Run Fix button at the top
  • Let the program run unhindered, when done it will say "Fix Complete press ok to open the log"
  • Please post that log in your next reply. Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTL\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

MrC

Link to post
Share on other sites

All processes killed

========== FILES ==========

c:\users\Christian Ronchetti\AppData\Local\Babylon\Setup\HtmlScreens folder moved successfully.

c:\users\Christian Ronchetti\AppData\Local\Babylon\Setup folder moved successfully.

c:\users\Christian Ronchetti\AppData\Local\Babylon folder moved successfully.

c:\users\Christian Ronchetti\AppData\Roaming\Babylon folder moved successfully.

c:\programdata\Babylon folder moved successfully.

========== COMMANDS ==========

[EMPTYJAVA]

User: All Users

User: Christian Ronchetti

->Java cache emptied: 1668922 bytes

User: Default

User: Default User

User: Public

Total Java Files Cleaned = 2.00 mb

[EMPTYTEMP]

User: All Users

User: Christian Ronchetti

->Temp folder emptied: 1396499 bytes

->Temporary Internet Files folder emptied: 232101048 bytes

->Java cache emptied: 0 bytes

->FireFox cache emptied: 843562887 bytes

->Flash cache emptied: 54399 bytes

User: Default

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 67 bytes

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

User: Public

->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 0 bytes

%systemroot%\System32 .tmp files removed: 0 bytes

%systemroot%\System32 (64bit) .tmp files removed: 0 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 5382 bytes

%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 8852515 bytes

RecycleBin emptied: 173366 bytes

Total Files Cleaned = 1,036.00 mb

OTL by OldTimer - Version 3.2.41.0 log created on 04242012_160029

Files\Folders moved on Reboot...

C:\Users\Christian Ronchetti\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

C:\Users\Christian Ronchetti\AppData\Local\Temp\FXSTIFFDebugLogFile.txt moved successfully.

File\Folder C:\Users\Christian Ronchetti\AppData\Local\Temp\~DF9440BC389CC26475.TMP not found!

File\Folder C:\Users\Christian Ronchetti\AppData\Local\Temp\~DFD42A3BE77194A535.TMP not found!

C:\Users\Christian Ronchetti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF{51F19FF3-F46D-4D35-93A2-6C77FBF84B9D}.tmp moved successfully.

File\Folder C:\Users\Christian Ronchetti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{22A9F03C-9401-4317-85A0-DFD8D73B7972}.tmp not found!

File\Folder C:\Users\Christian Ronchetti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{3667AD41-21E2-4EF8-8622-CA5199A8A9A8}.tmp not found!

File\Folder C:\Users\Christian Ronchetti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{638CA098-80CA-412A-AD68-A3FF9816B60F}.tmp not found!

File\Folder C:\Users\Christian Ronchetti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{67C8AAF6-5605-486D-8AE7-29AFB770C8F1}.tmp not found!

File\Folder C:\Users\Christian Ronchetti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{67EFC7E0-93E2-4B88-9ED5-624458C24C0D}.tmp not found!

File\Folder C:\Users\Christian Ronchetti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{7BA094C4-7624-4347-88F9-DC85F924D99A}.tmp not found!

File\Folder C:\Users\Christian Ronchetti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{82B5C8AE-7FBA-4C3B-A95F-8090C62F71EB}.tmp not found!

File\Folder C:\Users\Christian Ronchetti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{8757664D-FCA6-47F5-9CE2-DD6F610FCC9A}.tmp not found!

File\Folder C:\Users\Christian Ronchetti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{96F67295-C64B-47FD-92FB-483335B94D27}.tmp not found!

File\Folder C:\Users\Christian Ronchetti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{BB0DAB89-846E-4705-987C-C9853EF4AEA6}.tmp not found!

File\Folder C:\Users\Christian Ronchetti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\26027963.jpeg not found!

File\Folder C:\Users\Christian Ronchetti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\C5289C08.jpeg not found!

Registry entries deleted on Reboot...

Link to post
Share on other sites

Please download SystemLook from the links below and save it to your Desktop.

http://jpshortstuff....temLook_x64.exe

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:

    :filefind
    *Babylon*
    *Searchqu*

    :folderfind
    *Babylon*
    *Searchqu*

    :regfind
    Babylon
    Searchqu


  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.

Note: The log can also be found on your Desktop entitled SystemLook.txt

-----------------------------------------

Then run OTL

Click the Scan All Users checkbox.

Push the Quick Scan button.

The scan will take about 10 minutes...depends on your hard drive size.

Two reports will open, copy and paste them in a reply here: (or attach them as .txt files)

OTL.txt <-- Will be opened

Extra.txt <-- Will be minimized

MrC

Link to post
Share on other sites

SystemLook 30.07.11 by jpshortstuff

Log created at 16:19 on 26/04/2012 by Christian Ronchetti

Administrator - Elevation successful

========== filefind ==========

Searching for "*Babylon*"

C:\Program Files (x86)\MatchWare\MindView 4.0\mmc\01.Clipart\06.Arts & Architecture\05.Wonders of the ancient world\hanging gardens of babylon.ini --a---- 463 bytes [20:24 19/04/2010] [20:24 19/04/2010] F7B8E7402647374840FEEB0142CA090C

C:\Program Files (x86)\MatchWare\MindView 4.0\mmc\01.Clipart\06.Arts & Architecture\05.Wonders of the ancient world\Hanging Gardens of Babylon.png --a---- 97333 bytes [09:18 23/09/2005] [09:18 23/09/2005] 9A0B8EB47E72401F3FE6D852B9CB6191

C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml --a---- 2313 bytes [20:11 15/04/2012] [20:11 15/04/2012] E3AE8EEB0B934350F95695B12B3B70D5

C:\_OTL\MovedFiles\04242012_160029\c_users\Christian Ronchetti\AppData\Local\Babylon\Setup\Babylon.dat --a---- 12848 bytes [20:11 15/04/2012] [14:03 01/04/2012] ADBB6A655AE518830BA1AFEFDB84668F

Searching for "*Searchqu*"

No files found.

========== folderfind ==========

Searching for "*Babylon*"

C:\_OTL\MovedFiles\04242012_160029\c_programdata\Babylon d------ [20:11 15/04/2012]

C:\_OTL\MovedFiles\04242012_160029\c_users\Christian Ronchetti\AppData\Local\Babylon d------ [20:11 15/04/2012]

C:\_OTL\MovedFiles\04242012_160029\c_users\Christian Ronchetti\AppData\Roaming\Babylon d------ [20:11 15/04/2012]

Searching for "*Searchqu*"

C:\Users\Christian Ronchetti\AppData\LocalLow\searchquband d------ [13:11 15/04/2012]

========== regfind ==========

Searching for "Babylon"

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}]

"DisplayName"="Search the web (Babylon)"

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}]

"URL"="http://search.babylon.com/?q={searchTerms}&affID=109980&babsrc=SP_ss&mntrId=d8a31185000000000000d0df9a8d65b5"'>http://search.babylon.com/?q={searchTerms}&affID=109980&babsrc=SP_ss&mntrId=d8a31185000000000000d0df9a8d65b5"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B}]

@="Babylon toolbar helper"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B}\InprocServer32]

@="C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E46C8196-B634-44a1-AF6E-957C64278AB1}\InprocServer32]

@="C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Babylon]

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Babylon\Babylon Client]

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\MyBabylonTB_RASAPI32]

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\MyBabylonTB_RASMANCS]

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B}]

@="Babylon toolbar helper"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B}\InprocServer32]

@="C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{E46C8196-B634-44a1-AF6E-957C64278AB1}\InprocServer32]

@="C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll"

[HKEY_USERS\S-1-5-21-201949659-3598620656-673553719-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}]

"DisplayName"="Search the web (Babylon)"

[HKEY_USERS\S-1-5-21-201949659-3598620656-673553719-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}]

"URL"="http://search.babylon.com/?q={searchTerms}&affID=109980&babsrc=SP_ss&mntrId=d8a31185000000000000d0df9a8d65b5"'>http://search.babylon.com/?q={searchTerms}&affID=109980&babsrc=SP_ss&mntrId=d8a31185000000000000d0df9a8d65b5"

Searching for "Searchqu"

[HKEY_CURRENT_USER\Software\AppDataLow\Software\searchqutoolbar]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}]

"SuggestionsURL_JSON"="http://www.searchqu.com/suggest.php?src=ieb&appid=100&systemid=102&qu={searchTerms}&ft=json"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}]

@="ISearchQueryHelper"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}]

@="ISearchQueryHelper"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}]

"SuggestionsURL_JSON"="http://www.searchqu.com/suggest.php?src=ieb&appid=100&systemid=102&qu={searchTerms}&ft=json"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}]

"SuggestionsURL_JSON"="http://www.searchqu.com/suggest.php?src=ieb&appid=100&systemid=102&qu={searchTerms}&ft=json"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Searchqu Toolbar uninstall_RASAPI32]

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Searchqu Toolbar uninstall_RASMANCS]

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SearchquMediaBar_RASAPI32]

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SearchquMediaBar_RASMANCS]

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}]

@="ISearchQueryHelper"

[HKEY_USERS\S-1-5-21-201949659-3598620656-673553719-1000\Software\AppDataLow\Software\searchqutoolbar]

[HKEY_USERS\S-1-5-21-201949659-3598620656-673553719-1000\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}]

"SuggestionsURL_JSON"="http://www.searchqu.com/suggest.php?src=ieb&appid=100&systemid=102&qu={searchTerms}&ft=json"

-= EOF =-

OTL logfile created on: 26/04/2012 16:22:36 - Run 1

OTL by OldTimer - Version 3.2.41.0 Folder = C:\Users\Christian Ronchetti\Desktop

64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation

Internet Explorer (Version = 9.0.8112.16421)

Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.91 Gb Total Physical Memory | 1.13 Gb Available Physical Memory | 28.98% Memory free

7.82 Gb Paging File | 4.62 Gb Available in Paging File | 59.08% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

Drive C: | 75.00 Gb Total Space | 28.28 Gb Free Space | 37.71% Space Free | Partition Type: NTFS

Drive D: | 390.76 Gb Total Space | 321.60 Gb Free Space | 82.30% Space Free | Partition Type: NTFS

Computer Name: WIN-6VAR1135O14 | User Name: Christian Ronchetti | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans

Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - File not found --

PRC - [2012/04/24 15:59:19 | 000,594,944 | ---- | M] (OldTimer Tools) -- C:\Users\Christian Ronchetti\Desktop\OTL.exe

PRC - [2012/04/04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

PRC - [2012/04/04 15:56:38 | 000,462,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

PRC - [2012/03/23 10:41:03 | 000,924,600 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe

PRC - [2012/03/16 10:20:10 | 000,553,472 | ---- | M] () -- C:\Program Files (x86)\youtubetomp3.org-1.0\youtubetomp3.exe

PRC - [2012/02/27 05:52:20 | 000,038,248 | ---- | M] (Mindjet) -- C:\Program Files (x86)\Mindjet\MindManager 10\MmReminderService.exe

PRC - [2012/02/15 11:32:12 | 000,055,144 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe

PRC - [2012/01/03 14:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

PRC - [2011/08/09 13:58:22 | 000,911,112 | ---- | M] (ABBYY.) -- C:\Program Files (x86)\ABBYY FineReader 11\Bonus.ScreenshotReader.exe

PRC - [2011/08/03 19:02:17 | 000,819,976 | ---- | M] (ABBYY) -- C:\Program Files (x86)\ABBYY FineReader 11\NetworkLicenseServer.exe

PRC - [2011/07/09 02:36:12 | 002,932,224 | ---- | M] (PACE Anti-Piracy, Inc.) -- C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe

PRC - [2011/03/31 16:53:26 | 000,475,136 | ---- | M] (plustek) -- C:\Program Files (x86)\Plustek\Plustek OpticBook 3800\book express.exe

PRC - [2010/08/16 11:54:50 | 000,034,160 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe

PRC - [2010/05/04 13:07:22 | 000,503,080 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Update\NASvc.exe

PRC - [2009/12/01 18:24:44 | 000,402,832 | ---- | M] (OLYMPUS IMAGING CORP.) -- C:\Program Files (x86)\OLYMPUS\DeviceDetector\DeviceDetector4.exe

PRC - [2009/05/14 18:07:14 | 000,759,048 | ---- | M] (ABBYY) -- C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe

========== Modules (No Company Name) ==========

MOD - [2012/04/15 10:45:50 | 008,797,344 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_233.dll

MOD - [2012/04/11 11:13:56 | 000,008,192 | ---- | M] () -- C:\Program Files (x86)\Java\jre6\bin\jp2native.dll

MOD - [2012/03/23 10:41:03 | 001,969,080 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll

MOD - [2012/03/16 10:20:10 | 000,553,472 | ---- | M] () -- C:\Program Files (x86)\youtubetomp3.org-1.0\youtubetomp3.exe

MOD - [2012/02/27 05:51:34 | 000,151,376 | ---- | M] () -- C:\Program Files (x86)\Mindjet\MindManager 10\zlib.dll

MOD - [2011/12/12 11:20:28 | 002,552,320 | ---- | M] () -- C:\Program Files (x86)\youtubetomp3.org-1.0\QtCore4.dll

MOD - [2011/12/12 11:20:26 | 009,869,824 | ---- | M] () -- C:\Program Files (x86)\youtubetomp3.org-1.0\QtGui4.dll

MOD - [2011/12/12 11:20:26 | 001,215,488 | ---- | M] () -- C:\Program Files (x86)\youtubetomp3.org-1.0\QtNetwork4.dll

MOD - [2011/12/12 11:20:14 | 000,043,008 | ---- | M] () -- C:\Program Files (x86)\youtubetomp3.org-1.0\libgcc_s_dw2-1.dll

MOD - [2011/12/12 11:20:14 | 000,011,362 | ---- | M] () -- C:\Program Files (x86)\youtubetomp3.org-1.0\mingwm10.dll

MOD - [2011/06/24 23:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll

MOD - [2011/06/24 23:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll

MOD - [2011/04/12 12:42:54 | 000,901,120 | ---- | M] () -- C:\Program Files (x86)\Plustek\Plustek OpticBook 3800\Scanapi.dll

MOD - [2011/04/11 19:01:52 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\Plustek\Plustek OpticBook 3800\ScanAdvanced.dll

MOD - [2011/03/29 16:42:02 | 000,053,248 | ---- | M] () -- C:\Program Files (x86)\Plustek\Plustek OpticBook 3800\Prndriver.dll

MOD - [2011/03/17 01:11:16 | 004,297,568 | ---- | M] () -- C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF

MOD - [2010/10/20 16:45:26 | 008,801,120 | ---- | M] () -- C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll

MOD - [2009/10/28 18:11:46 | 001,019,904 | ---- | M] () -- C:\Program Files (x86)\Plustek\Plustek OpticBook 3800\bmp2tiff.dll

MOD - [2008/09/18 13:23:58 | 000,024,576 | ---- | M] () -- C:\Program Files (x86)\Plustek\Plustek OpticBook 3800\FineReader.dll

MOD - [2008/08/14 14:43:54 | 000,606,208 | ---- | M] () -- C:\Program Files (x86)\Plustek\Plustek OpticBook 3800\bmp2pdf.dll

MOD - [2008/08/12 13:15:30 | 000,548,864 | ---- | M] () -- C:\Program Files (x86)\Plustek\Plustek OpticBook 3800\dxbmp2j2k.dll

MOD - [2008/08/12 13:15:26 | 001,073,152 | ---- | M] () -- C:\Program Files (x86)\Plustek\Plustek OpticBook 3800\dxMal2PDF.dll

MOD - [2007/08/08 13:08:02 | 000,036,864 | ---- | M] () -- C:\Program Files (x86)\Plustek\Plustek OpticBook 3800\MaxReader.dll

MOD - [2007/06/26 18:08:24 | 000,040,960 | ---- | M] () -- C:\Program Files (x86)\Plustek\Plustek OpticBook 3800\DetectSession.dll

MOD - [2006/05/15 16:24:18 | 000,122,938 | ---- | M] () -- C:\Program Files (x86)\Common Files\iMpacct\CommonFunc.dll

MOD - [2005/09/21 15:37:36 | 000,073,728 | ---- | M] () -- C:\Program Files (x86)\Plustek\Plustek OpticBook 3800\Copy Utility.dll

========== Win32 Services (SafeList) ==========

SRV:64bit: - [2011/04/27 18:21:18 | 000,288,272 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe -- (NisSrv)

SRV:64bit: - [2011/04/27 18:21:18 | 000,012,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)

SRV:64bit: - [2010/12/09 18:45:26 | 000,489,384 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe -- (TosCoSrv)

SRV:64bit: - [2009/07/14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)

SRV - [2012/04/15 11:20:48 | 000,253,088 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)

SRV - [2012/04/04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)

SRV - [2012/02/29 09:16:46 | 000,158,856 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)

SRV - [2012/01/03 14:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)

SRV - [2011/08/03 19:02:17 | 000,819,976 | ---- | M] (ABBYY) [Auto | Running] -- C:\Program Files (x86)\ABBYY FineReader 11\NetworkLicenseServer.exe -- (ABBYY.Licensing.FineReader.Professional.11.0)

SRV - [2011/07/09 02:36:12 | 002,932,224 | ---- | M] (PACE Anti-Piracy, Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe -- (PaceLicenseDServices)

SRV - [2011/05/10 10:35:10 | 000,176,128 | ---- | M] (OLYMPUS IMAGING CORP.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Olympus Shared\DeviceManager\olydvrsv.exe -- (Olympus DVR Service)

SRV - [2010/05/04 13:07:22 | 000,503,080 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate) @C:\Program Files (x86)

SRV - [2010/03/18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)

SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)

SRV - [2009/05/14 18:07:14 | 000,759,048 | ---- | M] (ABBYY) [Auto | Running] -- C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe -- (ABBYY.Licensing.FineReader.Sprint.9.0)

========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/04/11 11:15:17 | 000,027,176 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ggsemc.sys -- (ggsemc)

DRV:64bit: - [2012/04/11 11:15:17 | 000,013,352 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ggflt.sys -- (ggflt)

DRV:64bit: - [2012/04/04 15:56:40 | 000,024,904 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)

DRV:64bit: - [2012/03/01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)

DRV:64bit: - [2012/02/15 12:01:50 | 000,052,736 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)

DRV:64bit: - [2011/12/01 15:41:01 | 000,020,592 | ---- | M] (Compal Electronics, INC.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CeKbFilter.sys -- (CeKbFilter)

DRV:64bit: - [2011/08/02 18:38:44 | 000,022,528 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netaapl64.sys -- (Netaapl)

DRV:64bit: - [2011/06/10 06:34:52 | 000,539,240 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)

DRV:64bit: - [2011/05/24 16:24:20 | 002,750,464 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)

DRV:64bit: - [2011/04/27 16:25:24 | 000,084,864 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)

DRV:64bit: - [2011/04/04 20:10:14 | 012,262,624 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)

DRV:64bit: - [2011/03/11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)

DRV:64bit: - [2011/03/11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)

DRV:64bit: - [2011/02/08 20:07:00 | 000,038,096 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\PGEffect.sys -- (PGEffect)

DRV:64bit: - [2011/01/12 17:51:44 | 000,439,320 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)

DRV:64bit: - [2010/12/17 09:06:32 | 001,404,464 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)

DRV:64bit: - [2010/11/21 04:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)

DRV:64bit: - [2010/11/21 04:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)

DRV:64bit: - [2010/11/21 04:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)

DRV:64bit: - [2010/10/19 16:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) Intel®

DRV:64bit: - [2010/07/20 17:43:22 | 000,247,400 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR)

DRV:64bit: - [2010/03/22 11:55:20 | 000,046,192 | ---- | M] (COMPAL ELECTRONIC INC.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\LPCFilter.sys -- (LPCFilter)

DRV:64bit: - [2010/02/26 16:32:12 | 000,158,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)

DRV:64bit: - [2009/07/14 16:31:18 | 000,026,840 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\TVALZ_O.SYS -- (TVALZ)

DRV:64bit: - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)

DRV:64bit: - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)

DRV:64bit: - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)

DRV:64bit: - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)

DRV:64bit: - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)

DRV:64bit: - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)

DRV:64bit: - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)

DRV:64bit: - [2009/05/18 14:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)

DRV:64bit: - [2006/11/19 22:11:06 | 000,008,704 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\FwLnk.sys -- (FwLnk)

DRV - [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}

IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=100&systemid=102&sr=0&q={searchTerms}

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}

IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=100&systemid=102&sr=0&q={searchTerms}

IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-201949659-3598620656-673553719-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp

IE - HKU\S-1-5-21-201949659-3598620656-673553719-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-GB

IE - HKU\S-1-5-21-201949659-3598620656-673553719-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = E4 6A A0 71 EA 22 CD 01 [binary data]

IE - HKU\S-1-5-21-201949659-3598620656-673553719-1000\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}

IE - HKU\S-1-5-21-201949659-3598620656-673553719-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC

IE - HKU\S-1-5-21-201949659-3598620656-673553719-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=109980&babsrc=SP_ss&mntrId=d8a31185000000000000d0df9a8d65b5

IE - HKU\S-1-5-21-201949659-3598620656-673553719-1000\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=100&systemid=102&sr=0&q={searchTerms}

IE - HKU\S-1-5-21-201949659-3598620656-673553719-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-201949659-3598620656-673553719-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"

FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"

FF - prefs.js..browser.search.order.2: "Google"

FF - prefs.js..keyword.URL: "http://dts.search-results.com/sr?src=ffb&appid=100&systemid=102&sr=0&q="

FF - prefs.js..network.proxy.no_proxies_on: "*.local"

FF - prefs.js..network.proxy.type: 0

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_2_202_233.dll File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_233.dll ()

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)

FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found

FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()

FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found

FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Christian Ronchetti\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)

FF - HKCU\Software\MozillaPlugins\facebook.com/fbDesktopPlugin: C:\Users\Christian Ronchetti\AppData\Local\Facebook\Messenger\2.0.4478.0\npFbDesktopPlugin.dll (Facebook, Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/03/23 10:41:04 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2012/04/23 15:39:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian Ronchetti\AppData\Roaming\Mozilla\Extensions

[2012/04/26 07:36:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian Ronchetti\AppData\Roaming\Mozilla\Firefox\Profiles\xd6r04iw.default\extensions

[2012/04/26 07:36:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian Ronchetti\AppData\Roaming\Mozilla\Firefox\Profiles\xd6r04iw.default\extensions\staged

[2012/02/02 15:44:03 | 000,000,000 | ---D | M] ("Update Service") -- C:\Users\Christian Ronchetti\AppData\Roaming\Mozilla\Firefox\Profiles\xd6r04iw.default\extensions\updater@foxstart.com

[2012/03/23 09:57:40 | 000,002,519 | ---- | M] () -- C:\Users\Christian Ronchetti\AppData\Roaming\Mozilla\Firefox\Profiles\xd6r04iw.default\searchplugins\Search_Results.xml

[2012/04/23 15:39:14 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions

[2012/04/11 11:14:14 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}

[2012/01/29 16:32:10 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\distribution\extensions

[2012/01/29 16:32:10 | 000,000,000 | ---D | M] ("Update Service") -- C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\updater@foxstart.com

() (No name found) -- C:\USERS\CHRISTIAN RONCHETTI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XD6R04IW.DEFAULT\EXTENSIONS\FBPHOTOZOOM@INSTALLDADDY.COM.XPI

[2012/03/23 10:41:04 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll

[2012/03/12 23:05:47 | 000,001,538 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml

[2012/04/15 21:11:03 | 000,002,313 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml

[2012/03/12 23:05:47 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml

[2012/03/12 23:05:47 | 000,000,947 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml

[2012/03/12 23:05:47 | 000,001,180 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml

[2012/03/23 09:57:40 | 000,002,519 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\Search_Results.xml

[2012/03/12 23:05:46 | 000,001,135 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2012/04/24 09:33:51 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2:64bit: - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)

O2 - BHO: (CmjBrowserHelperObject Object) - {6FE6A929-59D1-4763-91AD-29B61CFFB35B} - C:\Program Files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll (Mindjet)

O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)

O3:64bit: - HKLM\..\Toolbar: (no name) - !{98889811-442D-49dd-99D7-DC866BE87DBC} - No CLSID value found.

O3 - HKLM\..\Toolbar: (no name) - !{98889811-442D-49dd-99D7-DC866BE87DBC} - No CLSID value found.

O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.

O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.

O4:64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)

O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)

O4:64bit: - HKLM..\Run: [igfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)

O4:64bit: - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)

O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)

O4:64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)

O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)

O4:64bit: - HKLM..\Run: [TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)

O4:64bit: - HKLM..\Run: [TOSHIBA Face Recognition] C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatcher.exe (TOSHIBA Corporation)

O4:64bit: - HKLM..\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation)

O4:64bit: - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)

O4:64bit: - HKLM..\Run: [WrtMon.exe] C:\Windows\SysNative\spool\drivers\x64\3\WrtMon.exe ()

O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)

O4 - HKLM..\Run: [bonus.SSR.FR11] C:\Program Files (x86)\ABBYY FineReader 11\Bonus.ScreenshotReader.exe (ABBYY.)

O4 - HKLM..\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe (TOSHIBA Electronics, Inc.)

O4 - HKLM..\Run: [KeNotify] C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe (TOSHIBA CORPORATION)

O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)

O4 - HKLM..\Run: [MMReminderService] C:\Program Files (x86)\Mindjet\MindManager 10\MmReminderService.exe (Mindjet)

O4 - HKU\S-1-5-21-201949659-3598620656-673553719-1000..\Run: [Facebook Update] C:\Users\Christian Ronchetti\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)

O4 - HKU\S-1-5-21-201949659-3598620656-673553719-1000..\Run: [Xvid] C:\Program Files (x86)\Xvid\CheckUpdate.exe ()

O4 - Startup: C:\Users\Christian Ronchetti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Colour Explorer 9,0.lnk = C:\Program Files (x86)\MicrolinkPC\CXLOADER.exe (MicrolinkPC)

O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TaskBar.vbs ()

O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TaskBar.vbs ()

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3

O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-21-201949659-3598620656-673553719-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-21-201949659-3598620656-673553719-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-21-201949659-3598620656-673553719-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O8:64bit: - Extra context menu item: Send Image To MindManager - C:\Program Files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll (Mindjet)

O8:64bit: - Extra context menu item: Send Link To MindManager - C:\Program Files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll (Mindjet)

O8:64bit: - Extra context menu item: Send Page To MindManager - C:\Program Files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll (Mindjet)

O8:64bit: - Extra context menu item: Send Text To MindManager - C:\Program Files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll (Mindjet)

O8 - Extra context menu item: Send Image To MindManager - C:\Program Files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll (Mindjet)

O8 - Extra context menu item: Send Link To MindManager - C:\Program Files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll (Mindjet)

O8 - Extra context menu item: Send Page To MindManager - C:\Program Files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll (Mindjet)

O8 - Extra context menu item: Send Text To MindManager - C:\Program Files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll (Mindjet)

O9 - Extra Button: Send to Mindjet MindManager - {2F72393D-2472-4F82-B600-ED77F354B7FF} - C:\Program Files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll (Mindjet)

O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)

O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab (Java Plug-in 10.1.0)

O16:64bit: - DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab (Java Plug-in 1.7.0_01)

O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab (Java Plug-in 1.7.0_01)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)

O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)

O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} http://88.247.210.37:81/activex/AMC.cab (Reg Error: Key error.)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9D90092F-353F-44BC-BAD7-EAA0BE47863B}: DhcpNameServer = 192.168.0.1

O18:64bit: - Protocol\Handler\livecall - No CLSID value found

O18:64bit: - Protocol\Handler\ms-help - No CLSID value found

O18:64bit: - Protocol\Handler\msnim - No CLSID value found

O18:64bit: - Protocol\Handler\skype4com - No CLSID value found

O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)

O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found

O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)

O32 - HKLM CDRom: AutoRun - 1

O34 - HKLM BootExecute: (autocheck autochk *)

O35:64bit: - HKLM\..comfile [open] -- "%1" %*

O35:64bit: - HKLM\..exefile [open] -- "%1" %*

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*

O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*

O37 - HKLM\...com [@ = ComFile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/04/26 16:01:28 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\AppData\Roaming\SuperPump

[2012/04/26 15:38:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NokiaFREE Calculator

[2012/04/25 14:08:39 | 000,000,000 | ---D | C] -- C:\Windows\XSxS

[2012/04/25 14:08:39 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\Desktop\Photoshop

[2012/04/24 16:00:29 | 000,000,000 | ---D | C] -- C:\_OTL

[2012/04/24 15:59:34 | 000,594,944 | ---- | C] (OldTimer Tools) -- C:\Users\Christian Ronchetti\Desktop\OTL.exe

[2012/04/24 14:24:11 | 000,000,000 | ---D | C] -- C:\Windows\Sun

[2012/04/24 09:55:09 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN

[2012/04/24 09:37:45 | 000,000,000 | ---D | C] -- C:\Windows\temp

[2012/04/23 21:33:21 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe

[2012/04/23 21:33:21 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe

[2012/04/23 21:33:20 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe

[2012/04/23 21:33:10 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT

[2012/04/23 21:33:05 | 000,000,000 | ---D | C] -- C:\Qoobox

[2012/04/23 21:32:46 | 004,473,179 | R--- | C] (Swearware) -- C:\Users\Christian Ronchetti\Desktop\ComboFix.exe

[2012/04/23 20:12:28 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\Desktop\RK_Quarantine

[2012/04/23 16:49:32 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis

[2012/04/23 16:49:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro

[2012/04/23 16:41:04 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\AppData\Roaming\Malwarebytes

[2012/04/23 16:40:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware

[2012/04/23 16:40:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes

[2012/04/23 16:40:46 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys

[2012/04/23 16:40:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware

[2012/04/23 16:25:05 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\AppData\Local\{FC570FC9-D91B-41A7-92D7-AA9C62FAA823}

[2012/04/23 16:24:53 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\AppData\Local\{471142C4-FC30-4DE8-AA8D-9B44DCC119C1}

[2012/04/23 15:20:06 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\Desktop\tattoo

[2012/04/23 15:19:59 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\AppData\Local\{51C258B7-DC86-488C-8E39-E21C1ED78BB2}

[2012/04/23 15:19:47 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\AppData\Local\{CC5FC9CE-D138-49D6-A3B9-BB103A229B86}

[2012/04/19 14:39:44 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\AppData\Local\{E50630EE-25AF-4F32-8553-E18B61EFEC26}

[2012/04/19 14:39:31 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\AppData\Local\{49AB086C-ECFE-4248-8BA1-900FE5164080}

[2012/04/18 13:43:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes

[2012/04/18 13:42:33 | 000,000,000 | ---D | C] -- C:\Program Files\iPod

[2012/04/18 13:42:32 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes

[2012/04/15 21:18:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\fbphotozoom

[2012/04/15 20:54:21 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\AppData\Local\{9C107A08-3E3B-4A2C-9F87-9F9DFCB8CEEC}

[2012/04/15 20:54:08 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\AppData\Local\{FA5DE11A-E444-486C-AA8F-92A11139F3E3}

[2012/04/15 20:51:02 | 000,000,000 | ---D | C] -- C:\ProgramData\PACE

[2012/04/15 20:51:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PACE

[2012/04/15 20:50:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Antares

[2012/04/15 16:43:14 | 000,000,000 | ---D | C] -- C:\ProgramData\PACE Anti-Piracy

[2012/04/15 16:43:13 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\AppData\Roaming\PACE Anti-Piracy

[2012/04/15 16:43:13 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\AppData\Local\PACE Anti-Piracy

[2012/04/15 16:43:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PACE Anti-Piracy

[2012/04/15 16:42:54 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\AppData\Local\{536C29FF-1601-44D0-9ABF-4D23B111962C}

[2012/04/15 16:42:42 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\AppData\Local\{8D3DF2E0-D125-4C69-B01E-CDB5F174DEB6}

[2012/04/15 15:56:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antares Audio Technologies

[2012/04/15 15:48:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Antares Audio Technologies

[2012/04/15 14:48:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ffmpeg For Audacity

[2012/04/15 14:09:32 | 000,000,000 | ---D | C] -- C:\Windows\Freecorder Toolbar

[2012/04/15 13:14:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Lame For Audacity

[2012/04/15 13:13:01 | 000,000,000 | ---D | C] -- D:\Users\Christian Ronchetti\Documents\Music!

[2012/04/15 12:33:35 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\AppData\Roaming\Antares

[2012/04/15 11:33:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Audacity

[2012/04/15 10:53:14 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\AppData\Local\TechSmith

[2012/04/15 10:33:06 | 000,000,000 | R--D | C] -- C:\Users\Christian Ronchetti\Documents

[2012/04/15 10:32:48 | 000,411,480 | ---- | C] (TechSmith Corporation) -- C:\Windows\SysWow64\tsccvid.dll

[2012/04/15 10:32:47 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\QuickTime

[2012/04/15 10:32:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Camtasia Studio 7

[2012/04/15 10:32:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\TechSmith Shared

[2012/04/15 10:32:07 | 000,000,000 | ---D | C] -- C:\ProgramData\TechSmith

[2012/04/15 10:32:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TechSmith

[2012/04/13 04:17:59 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\AppData\Local\{EE26926E-92BD-4BF1-BE33-C6D6EAAE52F4}

[2012/04/12 10:44:26 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\AppData\Local\{9E3491EF-F091-4F3C-BC2E-214F1D1890A4}

[2012/04/12 10:01:35 | 000,000,000 | ---D | C] -- D:\Users\Christian Ronchetti\Documents\Outlook Files

[2012/04/11 22:44:14 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\AppData\Local\{C190C0A1-5A75-43A7-AA60-805F0ACD9376}

[2012/04/11 11:15:17 | 000,027,176 | ---- | C] (Sony Ericsson Mobile Communications) -- C:\Windows\SysNative\drivers\ggsemc.sys

[2012/04/11 11:15:17 | 000,013,352 | ---- | C] (Sony Ericsson Mobile Communications) -- C:\Windows\SysNative\drivers\ggflt.sys

[2012/04/11 11:14:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Sony Ericsson

[2012/04/11 11:14:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sony Ericsson

[2012/04/11 11:14:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun

[2012/04/11 11:14:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java

[2012/04/11 11:13:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java

[2012/04/11 09:37:05 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Facebook

[2012/04/11 09:31:00 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\AppData\Local\{12F7C193-6347-4DDC-93AC-1573B166D3CA}

[2012/04/10 15:14:52 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\AppData\Local\{59E8BB12-DE1E-4F91-893E-F5B146622E18}

[2012/04/09 21:24:16 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\AppData\Local\{9DD84786-521D-493F-874C-3846B72DAF86}

[2012/04/09 09:24:04 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\AppData\Local\{1D59E881-6D4A-4365-897C-9B0B3F0EE6F7}

[2012/04/08 16:32:20 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\AppData\Local\{F4D610C0-7603-4D1A-8010-07A3CAA16526}

[2012/04/05 15:05:01 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\AppData\Roaming\AVS4YOU

[2012/04/05 15:02:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\AVSMedia

[2012/04/05 15:02:38 | 000,000,000 | ---D | C] -- C:\ProgramData\AVS4YOU

[2012/04/05 15:02:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVS4YOU

[2012/04/04 03:51:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reincubate

[2012/04/04 03:51:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Reincubate

[2012/04/04 03:48:41 | 000,000,000 | ---D | C] -- D:\Users\Christian Ronchetti\Documents\Backup files

[2012/04/04 02:35:19 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\AppData\Local\Apple_Inc

[2012/04/04 02:34:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iPhone Configuration Utility

[2012/04/04 02:34:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iPhone Configuration Utility

[2012/04/03 11:11:24 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\AppData\Local\{F5190AE2-8273-4699-BFC2-0F8D121B83A3}

[2012/04/02 16:59:28 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\AppData\Local\{4FD26976-032E-4438-92AA-8A684052D39D}

[2012/04/02 04:59:16 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\AppData\Local\{83709D4A-52B1-48B4-9970-6779AB567A77}

[2012/04/01 12:31:02 | 000,000,000 | ---D | C] -- C:\Users\Christian Ronchetti\AppData\Local\{544A8C05-15D0-40D9-8B94-36DE32D4F1FA}

[2012/03/30 20:01:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype

[2012/03/30 20:01:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype

========== Files - Modified Within 30 Days ==========

[2012/04/26 16:20:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job

[2012/04/26 16:17:40 | 000,165,376 | ---- | M] () -- C:\Users\Christian Ronchetti\Desktop\SystemLook_x64.exe

[2012/04/26 15:41:01 | 000,000,984 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-201949659-3598620656-673553719-1000UA.job

[2012/04/26 15:25:21 | 000,729,688 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI

[2012/04/26 15:25:21 | 000,630,560 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat

[2012/04/26 15:25:21 | 000,111,612 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat

[2012/04/26 15:23:31 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat

[2012/04/26 10:36:13 | 000,000,962 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-201949659-3598620656-673553719-1000Core.job

[2012/04/25 10:58:34 | 000,021,872 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

[2012/04/25 10:58:34 | 000,021,872 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

[2012/04/25 10:39:09 | 000,000,004 | ---- | M] () -- C:\Users\Christian Ronchetti\youtubetomp3.org.save

[2012/04/24 17:59:30 | 000,000,148 | ---- | M] () -- C:\Users\Christian Ronchetti\webct_upload_applet.properties

[2012/04/24 16:03:28 | 3148,685,312 | -HS- | M] () -- C:\hiberfil.sys

[2012/04/24 15:59:19 | 000,594,944 | ---- | M] (OldTimer Tools) -- C:\Users\Christian Ronchetti\Desktop\OTL.exe

[2012/04/24 09:33:51 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts

[2012/04/23 21:32:30 | 004,473,179 | R--- | M] (Swearware) -- C:\Users\Christian Ronchetti\Desktop\ComboFix.exe

[2012/04/23 20:06:18 | 000,001,431 | ---- | M] () -- C:\Users\Christian Ronchetti\Desktop\dds - Shortcut.lnk

[2012/04/23 16:40:50 | 000,001,120 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

[2012/04/23 16:23:37 | 000,416,744 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT

[2012/04/22 16:16:44 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_netaapl64_01009.Wdf

[2012/04/18 13:43:29 | 000,001,794 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk

[2012/04/15 21:11:18 | 000,000,237 | ---- | M] () -- C:\user.js

[2012/04/15 10:42:23 | 000,005,632 | ---- | M] () -- C:\Users\Christian Ronchetti\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2012/04/11 11:23:53 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_ggsemc_01007.Wdf

[2012/04/11 11:23:53 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_ggflt_01007.Wdf

[2012/04/11 11:15:17 | 000,027,176 | ---- | M] (Sony Ericsson Mobile Communications) -- C:\Windows\SysNative\drivers\ggsemc.sys

[2012/04/11 11:15:17 | 000,013,352 | ---- | M] (Sony Ericsson Mobile Communications) -- C:\Windows\SysNative\drivers\ggflt.sys

[2012/04/04 15:56:40 | 000,024,904 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys

========== Files Created - No Company Name ==========

[2012/04/26 16:18:39 | 000,165,376 | ---- | C] () -- C:\Users\Christian Ronchetti\Desktop\SystemLook_x64.exe

[2012/04/24 17:59:30 | 000,000,148 | ---- | C] () -- C:\Users\Christian Ronchetti\webct_upload_applet.properties

[2012/04/23 21:33:21 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe

[2012/04/23 21:33:21 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe

[2012/04/23 21:33:21 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe

[2012/04/23 21:33:20 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe

[2012/04/23 21:33:20 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe

[2012/04/23 20:06:18 | 000,001,431 | ---- | C] () -- C:\Users\Christian Ronchetti\Desktop\dds - Shortcut.lnk

[2012/04/23 16:40:50 | 000,001,120 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

[2012/04/22 16:16:44 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_netaapl64_01009.Wdf

[2012/04/18 13:43:29 | 000,001,794 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk

[2012/04/15 21:11:18 | 000,000,237 | ---- | C] () -- C:\user.js

[2012/04/15 10:45:52 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job

[2012/04/15 10:38:58 | 000,005,632 | ---- | C] () -- C:\Users\Christian Ronchetti\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2012/04/11 11:23:53 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_ggsemc_01007.Wdf

[2012/04/11 11:23:53 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_ggflt_01007.Wdf

[2012/03/22 19:25:46 | 002,255,360 | ---- | C] () -- C:\Windows\SysWow64\libavcodec.dll

[2012/03/22 19:25:46 | 000,395,776 | ---- | C] () -- C:\Windows\SysWow64\libmplayer.dll

[2012/03/22 19:25:46 | 000,262,144 | ---- | C] () -- C:\Windows\SysWow64\TomsMoComp_ff.dll

[2012/03/22 19:25:46 | 000,112,640 | ---- | C] () -- C:\Windows\SysWow64\libmpeg2_ff.dll

[2012/03/22 09:24:26 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll

[2012/01/14 14:02:35 | 000,001,025 | ---- | C] () -- C:\Windows\SysWow64\sysprs7.dll

[2012/01/14 14:02:35 | 000,000,205 | ---- | C] () -- C:\Windows\SysWow64\lsprst7.dll

[2011/12/29 23:14:09 | 000,645,632 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll

[2011/12/29 23:14:09 | 000,240,640 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll

[2011/12/01 22:07:39 | 000,066,856 | ---- | C] () -- C:\Windows\SysWow64\SynTPEnhPS.dll

[2011/12/01 22:06:16 | 000,963,116 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin

[2011/12/01 22:06:16 | 000,216,876 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin

[2011/12/01 22:06:15 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin

[2011/12/01 15:51:35 | 000,722,802 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI

[2011/12/01 15:48:14 | 000,000,246 | ---- | C] () -- C:\Windows\B6FU.ini

[2011/12/01 15:48:09 | 000,000,104 | ---- | C] () -- C:\Windows\iris.ini

[2011/12/01 15:45:06 | 000,001,881 | ---- | C] () -- C:\Windows\if42le.ini

[2011/12/01 15:45:06 | 000,000,317 | ---- | C] () -- C:\Windows\Pexplore.ini

[2011/12/01 15:18:33 | 000,000,294 | ---- | C] () -- C:\Windows\Support.ini

[2011/12/01 15:12:59 | 000,131,584 | ---- | C] () -- C:\Windows\SysWow64\SpoonUninstall.exe

[2011/12/01 15:12:59 | 000,000,809 | ---- | C] () -- C:\Windows\SysWow64\SpoonUninstall-Colour Explorer 9,0.dat

========== LOP Check ==========

[2012/04/15 15:56:58 | 000,000,000 | ---D | M] -- C:\Users\Christian Ronchetti\AppData\Roaming\Antares

[2011/12/01 14:55:45 | 000,000,000 | ---D | M] -- C:\Users\Christian Ronchetti\AppData\Roaming\Appinstaller_2

[2012/04/22 12:07:56 | 000,000,000 | ---D | M] -- C:\Users\Christian Ronchetti\AppData\Roaming\Audacity

[2012/01/14 14:09:08 | 000,000,000 | ---D | M] -- C:\Users\Christian Ronchetti\AppData\Roaming\Eclipse

[2012/03/22 23:02:26 | 000,000,000 | ---D | M] -- C:\Users\Christian Ronchetti\AppData\Roaming\gtk-2.0

[2011/12/01 16:10:27 | 000,000,000 | ---D | M] -- C:\Users\Christian Ronchetti\AppData\Roaming\MatchWare

[2012/02/19 16:26:22 | 000,000,000 | ---D | M] -- C:\Users\Christian Ronchetti\AppData\Roaming\MusicNet

[2012/04/15 16:43:14 | 000,000,000 | ---D | M] -- C:\Users\Christian Ronchetti\AppData\Roaming\PACE Anti-Piracy

[2012/04/26 16:01:29 | 000,000,000 | ---D | M] -- C:\Users\Christian Ronchetti\AppData\Roaming\SuperPump

[2011/12/01 15:48:06 | 000,000,000 | ---D | M] -- C:\Users\Christian Ronchetti\AppData\Roaming\toshiba

[2012/04/26 16:01:32 | 000,000,000 | ---D | M] -- C:\Users\Christian Ronchetti\AppData\Roaming\uTorrent

[2011/12/01 15:40:45 | 000,000,000 | ---D | M] -- C:\Users\Christian Ronchetti\AppData\Roaming\WinBatch

[2012/04/26 10:36:13 | 000,000,962 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-201949659-3598620656-673553719-1000Core.job

[2012/04/26 15:41:01 | 000,000,984 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-201949659-3598620656-673553719-1000UA.job

[2009/07/14 06:08:49 | 000,009,816 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========

========== Alternate Data Streams ==========

@Alternate Data Stream - 1303 bytes -> C:\ProgramData\Microsoft:bq15DsCsG2npjGOuNVfFqTBhCbY

@Alternate Data Stream - 1213 bytes -> C:\ProgramData\Microsoft:eGTjNfB5lfhtWRA529d69TJcMPRBA

< End of report >

OTL Extras logfile created on: 26/04/2012 16:22:36 - Run 1

OTL by OldTimer - Version 3.2.41.0 Folder = C:\Users\Christian Ronchetti\Desktop

64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation

Internet Explorer (Version = 9.0.8112.16421)

Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.91 Gb Total Physical Memory | 1.13 Gb Available Physical Memory | 28.98% Memory free

7.82 Gb Paging File | 4.62 Gb Available in Paging File | 59.08% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

Drive C: | 75.00 Gb Total Space | 28.28 Gb Free Space | 37.71% Space Free | Partition Type: NTFS

Drive D: | 390.76 Gb Total Space | 321.60 Gb Free Space | 82.30% Space Free | Partition Type: NTFS

Computer Name: WIN-6VAR1135O14 | User Name: Christian Ronchetti | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans

Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========

========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-201949659-3598620656-673553719-1000\SOFTWARE\Classes\<extension>]

.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

exefile [open] -- "%1" %*

helpfile [open] -- Reg Error: Key error.

htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)

inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)

InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)

InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [explore] -- Reg Error: Value error.

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)

exefile [open] -- "%1" %*

helpfile [open] -- Reg Error: Key error.

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [explore] -- Reg Error: Value error.

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"cval" = 1

"FirewallDisableNotify" = 0

"AntiVirusDisableNotify" = 0

"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]

"AntiVirusOverride" = 0

"AntiSpywareOverride" = 0

"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"FirewallDisableNotify" = 0

"AntiVirusDisableNotify" = 0

"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]

"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

"EnableFirewall" = 1

"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"EnableFirewall" = 1

"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]

"EnableFirewall" = 1

"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware

"{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package

"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP4900_series" = Canon iP4900 series Printer Driver

"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector

"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant

"{26A24AE4-039D-4CA4-87B4-2F86417001FF}" = Java 7 Update 1 (64-bit)

"{42738DB0-FC3E-4672-A99B-9372F5696E30}" = Microsoft Security Client

"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour

"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010

"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010

"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010

"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting

"{B8AD779A-82DA-4365-A7D0-AD3DCFC55CFF}" = Apple Mobile Device Support

"{CF8FFD12-602B-422D-AF1D-511B411E7632}" = iTunes

"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile

"{F67FA545-D8E5-4209-86B1-AEE045D1003F}" = TOSHIBA Face Recognition

"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit

"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit

"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile

"Microsoft Security Client" = Microsoft Security Essentials

"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{03D57353-071B-4D21-982A-CC35C962A7C4}" = Mindjet MindManager 2012

"{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package

"{06C43FAA-7226-41EF-A05E-9AE0AA849FFE}" = IBM SPSS Statistics 19

"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer

"{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}" = Utility Common Driver

"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319

"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions

"{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10

"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java 6 Update 31

"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger

"{3671EC4B-1A7B-4EB7-A47B-7E70020C7058}" = MatchWare MindView 4.0

"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis

"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater

"{523B2B1B-D8DB-4B41-90FF-C4D799E2758A}" = Nero ControlCenter 10 Help (CHM)

"{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup

"{53FA9A9F-3C19-4D43-AD6B-DEF365D469BA}" = Camtasia Studio 7

"{555868C6-49FB-484F-BB43-8980651A1B00}" = Nero BurnRights 10 Help (CHM)

"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack

"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM

"{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support Utility

"{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update

"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE

"{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10

"{6F3C8901-EBD3-470D-87F8-AC210F6E5E02}" = TOSHIBA Web Camera Application

"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable

"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable

"{783033B0-D8E6-11D5-9293-0050BA073EEC}" = Presto! ImageFolio 4

"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update

"{7A5D731D-B4B3-490E-B339-75685712BAAB}" = Nero Burning ROM 10

"{7AEBFFF0-15A1-48A9-88F3-06604486C7C9}" = WMPTagSupportExtender

"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime

"{7CAC6A44-C3DE-4153-ACA6-7524602C789E}" = Facebook Video Calling 1.2.0.159

"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable

"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform

"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight

"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT

"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010

"{90140000-0015-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010

"{90140000-0016-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010

"{90140000-0018-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010

"{90140000-0019-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010

"{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010

"{90140000-001B-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010

"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010

"{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUSR_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010

"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUSR_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-002A-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010

"{90140000-002C-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010

"{90140000-0044-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010

"{90140000-006E-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010

"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010

"{90140000-00BA-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010

"{90140000-0115-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-0116-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010

"{90140000-0117-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010

"{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{943CFD7D-5336-47AF-9418-E02473A5A517}" = Nero BurnRights 10

"{99D5EF59-CF6F-4030-901B-4DDDB7F99403}" = Presto! PageManager 7.23

"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

"{9B6B24BE-80E7-46C4-9FA5-B167D5E0F345}" = Nero BurningROM 10 Help (CHM)

"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

"{A10B9E4E-9C40-4491-A3E1-C2B53DAB03C1}" = Facebook Messenger 2.0.4478.0

"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common

"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.3)

"{BAF227A2-E214-49E3-9137-94A300EA85BA}" = iPhone Configuration Utility

"{BFE5EE53-FB9C-4E32-B652-A85C55E1F081}" = Olympus Sonority

"{C2A276E3-154E-44DC-AAF1-FFDD7FD30E35}" = TOSHIBA Assist

"{CCF89E7D-8BFC-4B3C-8C9C-8C4E9EF8BA45}" = Auto-Tune EFX VST

"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform

"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common

"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform

"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10

"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger

"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support

"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.8

"{F1100000-0007-0000-0001-074957833700}" = ABBYY FineReader 11

"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver

"{F88AB834-AE45-4EE2-88D4-7F2A50ECB5DF}" = Plustek OpticBook 3800

"{F9000000-0018-0000-0000-074957833700}" = ABBYY FineReader 9.0 Sprint

"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials

"{FE83F463-7E61-4B18-9FA0-B94B90A0B6B9}" = Nero Burning ROM 10

"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022

"{FFF74EC9-1FF4-4456-99E3-4F05129F4FAB}" = Antares Auto-Tune Evo VST

"ABBYY FineReader 9.0 Sprint" = ABBYY FineReader 9.0 Sprint

"Adobe Shockwave Player" = Adobe Shockwave Player 11.6

"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.14 (Unicode)

"Canon iP4900 series User Registration" = Canon iP4900 series User Registration

"CanonMyPrinter" = Canon My Printer

"Colour Explorer 9,0" = Colour Explorer 9,0

"FFmpeg for Audacity_is1" = FFmpeg v0.6.2 for Audacity

"InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package

"InstallShield_{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}" = Utility Common Driver

"InstallShield_{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup

"InstallShield_{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support Utility

"InstallShield_{6F3C8901-EBD3-470D-87F8-AC210F6E5E02}" = TOSHIBA Web Camera Application

"InstallShield_{F67FA545-D8E5-4209-86B1-AEE045D1003F}" = TOSHIBA Face Recognition

"iPhoneBackupExtractor" = iPhone Backup Extractor

"jZip" = jZip

"LAME_is1" = LAME v3.99.3 (for Windows)

"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400

"Mozilla Firefox 11.0 (x86 en-GB)" = Mozilla Firefox 11.0 (x86 en-GB)

"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010

"uTorrent" = µTorrent

"VST Bridge_is1" = VST Bridge 1.1

"WinGimp-2.0_is1" = GIMP 2.6.11

"WinLiveSuite" = Windows Live Essentials

"Xvid Video Codec 1.3.2" = Xvid Video Codec

"youtubetomp3.org" = youtubetomp3.org ver. 1.0

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >

Link to post
Share on other sites

OK, download and unzip the attached file

Then right click on Fix.reg and choose "Run as Administrator"

Allow it to merge into the registry

--------------------

Next......

Run OTL

  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    O3:64bit: - HKLM\..\Toolbar: (no name) - !{98889811-442D-49dd-99D7-DC866BE87DBC} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - !{98889811-442D-49dd-99D7-DC866BE87DBC} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    [2012/04/15 21:11:03 | 000,002,313 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
    FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
    FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
    IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}
    IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
    IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}: "URL" = http://dts.search-re...q={searchTerms}
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
    IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}: "URL" = http://dts.search-re...q={searchTerms}
    IE - HKU\S-1-5-21-201949659-3598620656-673553719-1000\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
    IE - HKU\S-1-5-21-201949659-3598620656-673553719-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylo...000d0df9a8d65b5
    IE - HKU\S-1-5-21-201949659-3598620656-673553719-1000\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}: "URL" = http://dts.search-re...q={searchTerms}
    IE - HKU\S-1-5-21-201949659-3598620656-673553719-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
    :Files
    C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml
    C:\Users\Christian Ronchetti\AppData\LocalLow\searchquband
    C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll

    :Commands
    [EMPTYJAVA]
    [emptytemp]


  • Then click the Run Fix button at the top
  • Let the program run unhindered, when done it will say "Fix Complete press ok to open the log"
  • Please post that log in your next reply. Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTL\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Reboot and let me know how it is, MrC

Link to post
Share on other sites

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.