trojan horse patched_c.lxt

Greetings. My brother is having a small problem with the trojan in the title and I promised I'd help him. We would both appreciate any help. Thank you in advance!

My operating system is Windows 7 Professional Version 6.1 (Build 7601: SP1)

This might not be necessary, but I added the info just in case:

The symptoms I've noticed so far are:

1. AVG Resident Shield constantly alerts me of this, especially when navigating the Task Manager:


And this, a moment ago:


Also, this is the Resident Shield detection History:


Desktop.ini entries were from when I attempted to scan with other anti virus software. AVG asked to remove them, couldn't, couldn't force remove them either and then asked for a restart. I postponed it until after finishing the scans.

Malwarebytes Anti-Malware didn't find anything related to this. It did find some other problems and fixed them.

2. Malwarebytes Anti-Malware does not want to update. I understand that it might be because of the infection.


However, I did manage to update by manually downloading (mbam-rules.exe).

3. Windows Update fails as well.


And Windows Defender seems to hate me too:


I think these are all the symptoms I noticed so far.

I've also attached DDS.txt and Attach.txt

Most posts I've read about problems similar to mine include something about DDS and some other information gathering programs. This is my first time dealing with malware this advanced and my experience with such programs is limited. Please excuse my ignorance if it becomes obvious.

Please tell me if I forgot to include anything important.

Thank you very much for your time, I appreciate it.



Hello MaxRavenclaw and :welcome:! My name is Maniac and I will be glad to help you solve your malware problem.

Please note:

  • If you are a paying customer, you have the privilege to contact the help desk at Consumer Support. If you choose this option to get help, please let me know.
  • I recommend you to keep the instructions I will be giving you so that they are available to you at any time. You can save them in a text file or print them.
  • Make sure you read all of the instructions and fixes thoroughly before continuing with them.
  • Follow my instructions strictly and don’t hesitate to stop and ask me if you have any questions.
  • Post your log files, don't attach them. Every log file should be copy/pasted in your next reply.


One or more of the identified infections is known to use a backdoor.

This allows hackers to remotely control your computer, steal critical system information and download and execute files.

I would advice you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the infection has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

Help: I Got Hacked. Now What Do I Do?

Help: I Got Hacked. Now What Do I Do? Part II

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

When Should I Format, How Should I Reinstall

We can still clean this machine but I can't guarantee that it will be 100% secure afterwards. Let me know what you decide to do. If you decide to go through with the cleanup, please proceed with the following steps.

Step 1

Please uninstall the following applications:



IMinent Toolbar

Step 2

Please download the latest version of TDSSKiller from here and save it to your Desktop.

  • Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters.
  • Put a checkmark beside loaded modules.
  • A reboot will be needed to apply the changes. Do it.
  • TDSSKiller will launch automatically after the reboot. Also your computer may seem very slow and unusable. This is normal. Give it enough time to load your background programs.
  • Then click on Change parameters in TDSSKiller.
  • Check all boxes then click OK.
  • Click the Start Scan button.
  • The scan should take no longer than 2 minutes.
  • If a suspicious object is detected, the default action will be Skip, click on Continue.
  • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
    Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.
  • A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.

Step 3

  • Launch Malwarebytes' Anti-Malware
  • Go to Update tab and select Check for Updates. If an update is found, it will download and install the latest version.
  • Go to Scanner tab and select Perform Quick Scan, then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer,please do so immediately.

In your next reply, post the following log files:

  • TDSSKiller log
  • Malwarebytes' Anti-Malware log
  • a new fresh DDS log

First of all, thank you very much for your help.

The PC in question doesn't have any sensitive information on it, and is mainly used for gaming, forums, youtube etc, nothing financial, so I'd rather not reinstall the OS or reformat everything. However, in the case that I do, should I reformat every partition, or can I reformat only the system partition?

Also, regarding Change parameters in TDSSKiller, by default, Loaded Modules and the two Aditional Options are unchecked. Should I check only Loaded Modules, or must the two Aditional Options be checked as well, like in your screenshot?

Once again, thank you for your time. I await your answer before proceeding further.

The PC in question doesn't have any sensitive information on it, and is mainly used for gaming, forums, youtube etc, nothing financial, so I'd rather not reinstall the OS or reformat everything. However, in the case that I do, should I reformat every partition, or can I reformat only the system partition?

You should reformat everything.

Also, regarding Change parameters in TDSSKiller, by default, Loaded Modules and the two Aditional Options are unchecked. Should I check only Loaded Modules, or must the two Aditional Options be checked as well, like in your screenshot?

Should be like in my screenshot, but you don't need it anymore after reformat.

I actually did the tdsskiller scan twice and it returned slightly different results... I'll post both here, although you probably only need one. It found no threats.

EDIT: TDSSKiller. was too large. I have to attach it because the forum won't allow me to post such a long reply.

However, I can't do step 3 because MBAM still doesn't want to update. I also keep getting the alerts from AVG mentioned in my first post, the one about the trojan and the one about Desktop.ini



DDS (Ver_2011-08-26.01) - NTFSAMD64

Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.5.1

Run by Max Cross at 20:30:20 on 2012-08-22

Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.8175.6142 [GMT 3:00]


AV: AVG Internet Security Business Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}

SP: AVG Internet Security Business Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

FW: AVG Firewall *Disabled* {621CC794-9486-F902-D092-0484E8EA828B}


============== Running Processes ===============



C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe



C:\Windows\system32\svchost.exe -k DcomLaunch


C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

C:\Windows\system32\svchost.exe -k RPCSS

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k NetworkService

C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe


C:\Program Files (x86)\AVG\AVG2012\avgfws.exe



C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe

C:\Program Files (x86)\Allway Sync\Bin\SyncService.exe

C:\Program Files (x86)\AVG\AVG PC Tuneup 2011\BoostSpeed.exe




C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork

C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe

C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe

C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe

C:\Windows\system32\svchost.exe -k imgsvc

C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe

C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe

C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe

C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe

C:\Program Files (x86)\AVG\AVG2012\avgemca.exe

C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe

C:\Program Files\NVIDIA Corporation\Display\nvtray.exe

C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe


C:\Program Files (x86)\Allway Sync\Bin\syncappw.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe

C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files (x86)\RMP3\RMP3.exe

C:\Users\Max Cross\AppData\Roaming\Dropbox\bin\Dropbox.exe

C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe

C:\Program Files (x86)\AVG\AVG2012\avgtray.exe

C:\Program Files (x86)\AVG Secure Search\vprot.exe

C:\Program Files (x86)\POWERISO\PWRISOVM.EXE

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe


C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Program Files\Windows Media Player\wmpnetwk.exe


C:\Program Files (x86)\Yahoo!\Messenger\ymsgr_tray.exe

C:\Users\Max Cross\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Max Cross\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Max Cross\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Max Cross\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Max Cross\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Max Cross\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Max Cross\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Max Cross\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Max Cross\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe

C:\Users\Max Cross\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe

C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe

C:\Windows\system32\svchost.exe -k WindowsMobile


"C:\Windows\SysWOW64\svchost.exe" -g no -t 3 -o http://google-updaete.com:8344/ -u E -p mkjjmlsog

C:\Program Files\Windows NT\Accessories\WORDPAD.EXE








============== Pseudo HJT Report ===============


uSearch Page =

uStart Page = hxxp://search.iminent.com/?appId=446F3829-99F7-49FC-AB05-AEC24AD66546

uSearch Bar =

uURLSearchHooks: YTNavAssistPlugin Class: {81017ea9-9aa8-4a6a-9734-7af40e7d593f} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn0\yt.dll

uURLSearchHooks: H - No File

uURLSearchHooks: ToolbarURLSearchHook Class: {ca3eb689-8f09-4026-aa10-b9534c691ce0} - C:\Program Files (x86)\Freecorder 6\tbhelper.dll

mURLSearchHooks: YTNavAssistPlugin Class: {81017ea9-9aa8-4a6a-9734-7af40e7d593f} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn0\yt.dll

mWinlogon: Userinit=userinit.exe,

BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn0\yt.dll

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll

BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll

BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll

BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - C:\Program Files (x86)\AVG Secure Search\\AVG Secure Search_toolbar.dll

BHO: IMinent WebBooster: {a09ab6eb-31b5-454c-97ec-9b294d92ee2a} - IMinent WebBooster (BHO)

BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll

BHO: TBSB00808 Class: {fcbccb87-9224-4b8d-b117-f56d924beb18} - C:\Program Files (x86)\Freecorder 6\tbcore3.dll

BHO: Yontoo Layers: {fd72061e-9fde-484d-a58a-0bab4151cad8} - Yontoo

TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - C:\Program Files (x86)\AVG Secure Search\\AVG Secure Search_toolbar.dll

TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn0\yt.dll

TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

TB: Freecorder 6: {6b34accf-1b63-4e1a-8633-461917c75544} - C:\Program Files (x86)\Freecorder 6\tbcore3.dll

uRun: [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet

uRun: [Allway Sync] "C:\Program Files (x86)\Allway Sync\Bin\syncappw.exe" -m

uRun: [Google Update] "C:\Users\Max Cross\AppData\Local\Google\Update\GoogleUpdate.exe" /c

uRun: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

uRun: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun

uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

mRun: [iAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe

mRun: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"

mRun: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"

mRun: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE -startup

mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"

mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

mRun: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start

mRun: [iminent] C:\Program Files (x86)\Iminent\Iminent.exe /warmup "F77F87E5-A6BD-4922-A530-EDF63D7E9F8C"

mRun: [iminentMessenger] C:\Program Files (x86)\Iminent\Iminent.Messengers.exe /startup

mRun: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot

mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

uExplorerRun: [Dropbox] C:\Users\Max Cross\AppData\Roaming\9DEE93.exe

StartupFolder: C:\Users\MAXCRO~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Max Cross\AppData\Roaming\Dropbox\bin\Dropbox.exe

StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\RMP3.lnk - C:\Program Files (x86)\RMP3\RMP3.exe

mPolicies-explorer: NoActiveDesktop = 1 (0x1)

mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)

mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)

mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)

mPolicies-system: EnableLUA = 0 (0x0)

mPolicies-system: EnableUIADesktopToggle = 0 (0x0)

mPolicies-system: PromptOnSecureDesktop = 0 (0x0)

IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000

IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL

LSP: mswsock.dll

DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_04-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab

TCP: DhcpNameServer =

TCP: Interfaces\{71C8C6F8-A979-4A76-8555-56CCF395F67F} : DhcpNameServer =

Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL

Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\11.2.0\ViProtocol.dll

BHO-X64: &Yahoo! Toolbar Helper: {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn0\yt.dll

BHO-X64: 0x1 - No File

BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO-X64: AcroIEHelperStub - No File

BHO-X64: RealPlayer Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll

BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll

BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File

BHO-X64: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll

BHO-X64: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\\AVG Secure Search_toolbar.dll

BHO-X64: {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} - IMinent WebBooster (BHO)

BHO-X64: IMinent WebBooster - No File

BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll

BHO-X64: TBSB00808 Class: {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files (x86)\Freecorder 6\tbcore3.dll

BHO-X64: TBSB00808 - No File

BHO-X64: {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - Yontoo

BHO-X64: Yontoo Layers - No File

TB-X64: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\\AVG Secure Search_toolbar.dll

TB-X64: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn0\yt.dll

TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

TB-X64: Freecorder 6: {6B34ACCF-1B63-4E1A-8633-461917C75544} - C:\Program Files (x86)\Freecorder 6\tbcore3.dll

mRun-x64: [iAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe

mRun-x64: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"

mRun-x64: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"

mRun-x64: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE -startup

mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"

mRun-x64: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

mRun-x64: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start

mRun-x64: [iminent] C:\Program Files (x86)\Iminent\Iminent.exe /warmup "F77F87E5-A6BD-4922-A530-EDF63D7E9F8C"

mRun-x64: [iminentMessenger] C:\Program Files (x86)\Iminent\Iminent.Messengers.exe /startup

mRun-x64: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot

mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray


============= SERVICES / DRIVERS ===============


R0 AVGIDSEH;AVGIDSEH;C:\Windows\system32\DRIVERS\AVGIDSEH.Sys --> C:\Windows\system32\DRIVERS\AVGIDSEH.Sys [?]

R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys --> C:\Windows\system32\DRIVERS\avgrkx64.sys [?]

R1 AsrAppCharger;AsrAppCharger;C:\Windows\system32\DRIVERS\AsrAppCharger.sys --> C:\Windows\system32\DRIVERS\AsrAppCharger.sys [?]

R1 Avgfwfd;AVG network filter service;C:\Windows\system32\DRIVERS\avgfwd6a.sys --> C:\Windows\system32\DRIVERS\avgfwd6a.sys [?]

R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys --> C:\Windows\system32\DRIVERS\avgldx64.sys [?]

R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys --> C:\Windows\system32\DRIVERS\avgmfx64.sys [?]

R1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys --> C:\Windows\system32\DRIVERS\avgtdia.sys [?]

R1 FNETURPX;FNETURPX;C:\Windows\system32\drivers\FNETURPX.SYS --> C:\Windows\system32\drivers\FNETURPX.SYS [?]

R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]

R2 avgfws;AVG Firewall;C:\Program Files (x86)\AVG\AVG2012\avgfws.exe [2011-11-23 2391832]

R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe [2011-10-12 4433248]

R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2011-8-2 192776]

R2 BotkindSyncService;Botkind Service;C:\Program Files (x86)\Allway Sync\Bin\SyncService.exe service --> C:\Program Files (x86)\Allway Sync\Bin\SyncService.exe service [?]

R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-6-27 2369960]

R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-3-21 13336]

R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2012-3-21 2255464]

R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [2012-2-9 31408]

R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-8-3 379496]

R2 vToolbarUpdater11.2.0;vToolbarUpdater11.2.0;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe [2012-7-10 935008]

R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys --> C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys [?]

R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys --> C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys [?]

R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\system32\DRIVERS\dtsoftbus01.sys --> C:\Windows\system32\DRIVERS\dtsoftbus01.sys [?]

R3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;C:\Windows\system32\Drivers\EtronHub3.sys --> C:\Windows\system32\Drivers\EtronHub3.sys [?]

R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;C:\Windows\system32\Drivers\EtronXHCI.sys --> C:\Windows\system32\Drivers\EtronXHCI.sys [?]

R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]

R3 MEIx64;Intel® Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]

R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys --> C:\Windows\system32\drivers\nvhda64v.sys [?]

R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]

S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-7-5 116648]

S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-8-22 655944]

S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-3 160944]

S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-15 250056]

S3 FNETTBOH_305;FNETTBOH_305;C:\Windows\system32\drivers\FNETTBOH_305.SYS --> C:\Windows\system32\drivers\FNETTBOH_305.SYS [?]

S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-7-5 116648]

S3 netr28ux;RT2870 USB Wireless LAN Card Driver for Vista;C:\Windows\system32\DRIVERS\netr28ux.sys --> C:\Windows\system32\DRIVERS\netr28ux.sys [?]

S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 20992]

S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]

S3 VSPerfDrv100;Performance Tools Driver 10.0;D:\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [2010-3-17 68440]

S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]


=============== Created Last 30 ================


2012-08-22 17:26:06 -------- d-----w- C:\Program Files (x86)\MALWAREBYTES ANTI-MALWARE

2012-08-22 10:24:03 -------- d-----w- C:\Program Files (x86)\ESET

2012-08-22 07:46:41 -------- d-----w- C:\Users\Max Cross\AppData\Roaming\Malwarebytes

2012-08-22 07:46:30 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys

2012-08-22 07:46:30 -------- d-----w- C:\ProgramData\Malwarebytes

2012-08-22 07:46:30 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware

2012-08-21 17:50:20 -------- d-----w- C:\Users\Max Cross\AppData\Roaming\rigonauts

2012-08-20 08:34:22 -------- d-----w- C:\Users\Max Cross\AppData\Local\Freecorder 6 Video

2012-08-20 08:34:17 -------- d-----w- C:\Program Files (x86)\WinPcap

2012-08-20 08:34:00 -------- d-----w- C:\Users\Max Cross\AppData\Roaming\Freecorder 6 Video

2012-08-20 08:34:00 -------- d-----w- C:\Users\Max Cross\AppData\Local\Jaksta_Technologies_Pty_L

2012-08-20 08:32:33 -------- d-----w- C:\Program Files (x86)\Applian Technologies

2012-08-20 08:32:09 -------- d-----w- C:\Program Files (x86)\Freecorder 6

2012-08-20 08:32:04 -------- d-----w- C:\Program Files (x86)\Freecorder Toolbar

2012-08-20 08:28:01 -------- d-----w- C:\Program Files (x86)\Common Files\xing shared

2012-08-15 19:37:04 9826504 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe

2012-08-14 08:25:53 -------- d-----w- C:\Windows\WindowsMobile

2012-08-14 08:09:59 3148800 ----a-w- C:\Windows\System32\win32k.sys

2012-08-14 07:55:13 184320 ----a-w- C:\Windows\System32\cryptsvc.dll

2012-08-14 07:54:47 1544704 ----a-w- C:\Windows\System32\DWrite.dll

2012-08-14 07:52:29 936960 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\ink\journal.dll

2012-08-14 07:52:29 1732096 ----a-w- C:\Program Files\Windows Journal\NBDoc.DLL

2012-08-14 07:52:29 1402880 ----a-w- C:\Program Files\Windows Journal\JNWDRV.dll

2012-08-14 07:52:29 1393664 ----a-w- C:\Program Files\Windows Journal\JNTFiltr.dll

2012-08-14 07:52:29 1367552 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll

2012-08-14 07:47:05 2622464 ----a-w- C:\Windows\System32\wucltux.dll

2012-08-14 07:47:00 99840 ----a-w- C:\Windows\System32\wudriver.dll

2012-08-14 07:46:54 36864 ----a-w- C:\Windows\System32\wuapp.exe

2012-08-14 07:46:54 186752 ----a-w- C:\Windows\System32\wuwebv.dll

2012-08-13 11:35:52 -------- d-----w- C:\Users\Max Cross\AppData\Roaming\Iminent

2012-08-13 11:35:48 -------- d-----w- C:\ProgramData\Iminent

2012-08-13 11:35:01 -------- d-----w- C:\ProgramData\Tarma Installer

2012-08-13 11:32:23 -------- d-----w- C:\Users\Max Cross\AppData\Roaming\ExpressFiles

2012-08-13 09:02:16 -------- d-----w- C:\Windows\SysWow64\spool

2012-08-13 09:02:16 -------- d-----w- C:\Users\Max Cross\AppData\Local\Sony

2012-08-13 09:02:15 -------- d-----w- C:\Program Files (x86)\Sony

2012-08-09 06:40:23 -------- d-----w- C:\VirtualDub-1.9.11

2012-08-07 08:45:46 -------- d-----w- C:\Program Files\Steam

2012-08-04 06:57:51 -------- d-----w- C:\ProgramData\REVOLT

2012-08-02 13:44:10 -------- d-----w- C:\Users\Max Cross\AppData\Local\SugarSync

2012-08-02 13:44:05 -------- d-----w- C:\Program Files (x86)\SugarSync

2012-08-01 19:11:46 -------- d-----w- C:\Program Files (x86)\Oracle


==================== Find3M ====================


2012-08-20 08:27:55 499712 ----a-w- C:\Windows\SysWow64\msvcp71.dll

2012-08-20 08:27:55 348160 ----a-w- C:\Windows\SysWow64\msvcr71.dll

2012-08-15 19:41:54 70344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

2012-08-15 19:41:54 426184 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe

2012-07-23 16:30:18 98304 ----a-w- C:\Windows\SysWow64\CmdLineExt.dll

2012-07-22 09:32:01 419840 ----a-w- C:\Windows\System32\wrap_oal.dll

2012-07-22 09:32:01 413696 ----a-w- C:\Windows\SysWow64\wrap_oal.dll

2012-07-22 09:32:01 133632 ----a-w- C:\Windows\System32\OpenAL32.dll

2012-07-22 09:32:01 110592 ----a-w- C:\Windows\SysWow64\OpenAL32.dll

2012-07-09 18:16:53 560184 ----a-w- C:\Windows\System32\drivers\sptd.sys

2012-07-09 18:12:52 178800 ----a-w- C:\Windows\SysWow64\CmdLineExt_x64.dll

2012-07-07 06:22:59 283200 ----a-w- C:\Windows\System32\drivers\dtsoftbus01.sys

2012-07-05 19:06:30 772544 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll

2012-07-05 19:06:20 687544 ----a-w- C:\Windows\SysWow64\deployJava1.dll

2012-06-11 18:02:16 71680 ----a-w- C:\Windows\System32\frapsv64.dll

2012-06-11 18:02:12 65536 ----a-w- C:\Windows\SysWow64\frapsvid.dll

2012-06-06 06:06:16 2004480 ----a-w- C:\Windows\System32\msxml6.dll

2012-06-06 06:06:16 1881600 ----a-w- C:\Windows\System32\msxml3.dll

2012-06-06 06:02:54 1133568 ----a-w- C:\Windows\System32\cdosys.dll

2012-06-06 05:05:52 1390080 ----a-w- C:\Windows\SysWow64\msxml6.dll

2012-06-06 05:05:52 1236992 ----a-w- C:\Windows\SysWow64\msxml3.dll

2012-06-06 05:03:06 805376 ----a-w- C:\Windows\SysWow64\cdosys.dll

2012-06-02 12:12:17 2311680 ----a-w- C:\Windows\System32\jscript9.dll

2012-06-02 12:05:28 1392128 ----a-w- C:\Windows\System32\wininet.dll

2012-06-02 12:04:50 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl

2012-06-02 12:01:40 173056 ----a-w- C:\Windows\System32\ieUnatt.exe

2012-06-02 11:57:08 2382848 ----a-w- C:\Windows\System32\mshtml.tlb

2012-06-02 08:33:25 1800192 ----a-w- C:\Windows\SysWow64\jscript9.dll

2012-06-02 08:25:08 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll

2012-06-02 08:25:03 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl

2012-06-02 08:20:33 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe

2012-06-02 08:16:52 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb

2012-06-02 05:50:10 458704 ----a-w- C:\Windows\System32\drivers\cng.sys

2012-06-02 05:48:16 95600 ----a-w- C:\Windows\System32\drivers\ksecdd.sys

2012-06-02 05:48:16 151920 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys

2012-06-02 05:45:31 340992 ----a-w- C:\Windows\System32\schannel.dll

2012-06-02 05:44:21 307200 ----a-w- C:\Windows\System32\ncrypt.dll

2012-06-02 04:40:42 22016 ----a-w- C:\Windows\SysWow64\secur32.dll

2012-06-02 04:40:39 225280 ----a-w- C:\Windows\SysWow64\schannel.dll

2012-06-02 04:39:10 219136 ----a-w- C:\Windows\SysWow64\ncrypt.dll

2012-06-02 04:34:09 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll


============= FINISH: 20:30:45.62 ===============






DDS (Ver_2011-08-26.01)


Microsoft Windows 7 Professional

Boot Device: \Device\HarddiskVolume1

Install Date: 20/03/2012 9:50:22 PM

System Uptime: 22/08/2012 8:17:19 PM (0 hours ago)


Motherboard: ASRock | | P67 Pro3

Processor: Intel® Core™ i5-2400 CPU @ 3.10GHz | CPUSocket | 3101/100mhz


==== Disk Partitions =========================


C: is FIXED (NTFS) - 98 GiB total, 9.268 GiB free.

D: is FIXED (NTFS) - 368 GiB total, 35.254 GiB free.

E: is CDROM ()

F: is CDROM ()

H: is CDROM ()


==== Disabled Device Manager Items =============


==== System Restore Points ===================


No restore point in system.


==== Installed Programs ======================



Adobe AIR

Adobe Community Help

Adobe Flash Player 11 ActiveX

Adobe Flash Player 11 Plugin

Adobe Media Player

Adobe Reader 9.5.2

Afterfall InSanity

Allway Sync version 12.2.3

Armies of Exigo

ASRock eXtreme Tuner v0.1.54

ASRock InstantBoot v1.26

AVG PC Tuneup 2011

AVG Security Toolbar

AVS Screen Capture version 2.0.1

AVS Update Manager 1.0

AVS Video Editor 6

AVS Video Recorder 2.4

AVS4YOU Software Navigator 1.4


Babel Rising

Batman Arkham City Game Of The Year Edition

BS.Player FREE

Buildaria 1.8.4

C&C 3: The Forgotten

Cheat Engine 6.1

CNC Fallout

Comical 0.8

Command & Conquer 3

Command & Conquer™ 3: Kane's Wrath

Command & Conquer™ Red Alert™ 3

Crystal Reports for Visual Studio

DAEMON Tools Lite

Dawn of War - Dark Crusade

Dawn Of War - Winter Assault



ESET Online Scanner v3

Etron USB3.0 Host Controller

Fable III

Flash Movie Player 1.5

Fraps (remove only)

Freecorder 6

Freecorder 6 Applications (

Freecorder 6 extension for Chrome

Gadwin PrintScreen Professional

Game Booster 3

Google Chrome

Google Toolbar for Internet Explorer

Google Update Helper


IMinent Toolbar

Intel® Management Engine Components

Intel® Rapid Storage Technology

Iron Brigade

Java Auto Updater

Java™ 6 Update 29

Java™ 7 Update 5

JavaFX 2.1.1

K-Lite Mega Codec Pack 8.8.0

LogMeIn Hamachi

Magic ISO Maker v5.5 (build 0281)

MagicDisc 2.7.106

Mal Updater 2.80

Malwarebytes Anti-Malware version

Microsoft .NET Framework 4 Multi-Targeting Pack

Microsoft Application Error Reporting

Microsoft Expression Blend 3 SDK

Microsoft Expression Blend SDK for .NET 4

Microsoft Expression Blend SDK for Silverlight 4

Microsoft Expression Encoder 4 Screen Capture Codec

Microsoft Expression Studio 4

Microsoft Expression Web 4

Microsoft Game Studios Common Redistributables Pack 1

Microsoft Games for Windows - LIVE

Microsoft Games for Windows - LIVE Redistributable

Microsoft GIF Animator

Microsoft Office Access MUI (English) 2007

Microsoft Office Access Setup Metadata MUI (English) 2007

Microsoft Office Enterprise 2007

Microsoft Office Excel MUI (English) 2007

Microsoft Office Groove MUI (English) 2007

Microsoft Office Groove Setup Metadata MUI (English) 2007

Microsoft Office InfoPath MUI (English) 2007

Microsoft Office OneNote MUI (English) 2007

Microsoft Office Outlook MUI (English) 2007

Microsoft Office PowerPoint MUI (English) 2007

Microsoft Office Proof (English) 2007

Microsoft Office Proof (French) 2007

Microsoft Office Proof (Spanish) 2007

Microsoft Office Proofing (English) 2007

Microsoft Office Publisher MUI (English) 2007

Microsoft Office Shared MUI (English) 2007

Microsoft Office Shared Setup Metadata MUI (English) 2007

Microsoft Office Word MUI (English) 2007

Microsoft Silverlight 3 SDK

Microsoft Silverlight 4 SDK

Microsoft SQL Server 2008 R2 Data-Tier Application Framework

Microsoft SQL Server 2008 R2 Data-Tier Application Project

Microsoft SQL Server 2008 R2 Management Objects

Microsoft SQL Server 2008 R2 Transact-SQL Language Service

Microsoft SQL Server Compact 3.5 SP2 ENU

Microsoft SQL Server Database Publishing Wizard 1.4

Microsoft SQL Server System CLR Types

Microsoft Sync Framework SDK v1.0 SP1

Microsoft Visual Basic PowerPacks 2.0

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219

Microsoft Visual C++ 2010 x86 Runtime - 10.0.30319

Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools

Microsoft Visual Studio 2010 Premium - ENU

Microsoft Visual Studio Macro Tools

Microsoft XML Parser

Microsoft XNA Framework Redistributable 4.0








Minecraft Cracked


MSVCRT Redists

NVIDIA 3D Vision Controller Driver


NVIDIA Stereoscopic 3D Driver




Rayman Origins


RealNetworks - Microsoft Visual C++ 2008 Runtime


Realtek Ethernet Controller Driver For Windows 7

Realtek High Definition Audio Driver

RealUpgrade 1.1

Red Faction: Guerrilla

Risen 2 Dark Waters


S.T.A.L.K.E.R. - Shadow of Chernobyl [v1.0005]


Secure Download Manager

Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)

Security Update for Microsoft .NET Framework 4 Extended (KB2487367)

Security Update for Microsoft .NET Framework 4 Extended (KB2656351)

Skype™ 5.10

Spec Ops The Line

Stalker Complete 2009


StarCraft II



Stronghold Crusader Extreme

SugarSync Manager

SWF Opener

TES V Creation Kit nosteam+steam version 1.5

The Walking Dead © 3 version 1

The Witcher 2 - Assassins of Kings Enhanced Edition

Ubisoft Game Launcher

Universe at War Earth Assault

Update for Microsoft .NET Framework 4 Client Profile (KB2468871)

Update for Microsoft .NET Framework 4 Client Profile (KB2533523)

Update for Microsoft .NET Framework 4 Client Profile (KB2600217)

Update for Microsoft .NET Framework 4 Extended (KB2468871)

Update for Microsoft .NET Framework 4 Extended (KB2533523)

Update for Microsoft .NET Framework 4 Extended (KB2600217)

Vegas Pro 11.0

Visual Studio 2008 x64 Redistributables

Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU

VLC media player 2.0.1


Winamp Detector Plug-in

WinPcap 4.1.2

World in Conflict MW Mod 2.5

World in Conflict: Soviet Assault

WPF Toolkit February 2010 (Version 3.5.50211.1)


XnView 1.98.8

Yahoo! Messenger

Yahoo! Software Update

Yahoo! Toolbar

YTD Video Downloader 3.9


==== Event Viewer Messages From Past Week ========


22/08/2012 8:19:19 PM, Error: Service Control Manager [7023] - The Function Discovery Resource Publication service terminated with the following error: %%-2147024891

22/08/2012 8:19:19 PM, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Resource Publication service which failed to start because of the following error: %%-2147024891

22/08/2012 8:17:56 PM, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.

22/08/2012 8:17:55 PM, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.

22/08/2012 8:17:53 PM, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.

22/08/2012 1:24:03 PM, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.


==== End Of File ===========================


I'd rather not reinstall the OS or reformat everything. However, in the case that I do, should I reformat every partition, or can I reformat only the system partition?

I said that in case I do, how should I do it, not that I will do it. Frankly, I'd rather fix this, if possible, without reformatting everything.

So please, if you can, help me get through this without formatting all I got.

Thank you.

This is what I need to know to make it clear whether to continue or not.

Please visit this webpage for download links, and instructions for running the tool:


* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Please post the C:\ComboFix.txt in your next reply for further review.

Note: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.

Link to post
The PC behaved strangely during the scan, and restarted a couple of time, after which I couldn't stop AVG when the scan resumed, only it's firewall. I was disconnected from the internet during the scan. Some windows did pop up during startup after the scan resumed, but it finished with no apparent problems.

ComboFix 12-08-22.03 - Max Cross 23/08/2012 18:34:55.1.4 - x64

Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.8175.6732 [GMT 3:00]

Running from: c:\users\Max Cross\Desktop\ComboFix.exe

AV: AVG Internet Security Business Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}

FW: AVG Firewall *Disabled* {621CC794-9486-F902-D092-0484E8EA828B}

SP: AVG Internet Security Business Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}



((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))




c:\users\Max Cross\AppData\Roaming\9DEE93.exe

c:\users\Max Cross\AppData\Roaming\Love

c:\users\Max Cross\AppData\Roaming\Love\mari0\mappacks\smb\1-1.txt

c:\users\Max Cross\AppData\Roaming\Love\mari0\options.txt
















Infected copy of c:\windows\system32\services.exe was found and disinfected

Restored copy from - c:\windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe



((((((((((((((((((((((((( Files Created from 2012-07-23 to 2012-08-23 )))))))))))))))))))))))))))))))



2012-08-22 18:12 . 2012-08-22 18:12 -------- d-----w- c:\users\Max Cross\AppData\Roaming\Doublefine

2012-08-22 17:26 . 2012-08-22 17:26 -------- d-----w- c:\program files (x86)\MALWAREBYTES ANTI-MALWARE

2012-08-22 10:24 . 2012-08-22 10:24 -------- d-----w- c:\program files (x86)\ESET

2012-08-22 07:46 . 2012-08-22 07:46 -------- d-----w- c:\users\Max Cross\AppData\Roaming\Malwarebytes

2012-08-22 07:46 . 2012-08-22 07:49 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2012-08-22 07:46 . 2012-08-22 07:46 -------- d-----w- c:\programdata\Malwarebytes

2012-08-22 07:46 . 2012-07-03 10:46 24904 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-08-21 17:50 . 2012-08-21 17:50 -------- d-----w- c:\users\Max Cross\AppData\Roaming\rigonauts

2012-08-20 08:34 . 2012-08-20 08:34 -------- d-----w- c:\users\Max Cross\AppData\Local\Freecorder 6 Video

2012-08-20 08:34 . 2012-08-20 08:34 -------- d-----w- c:\program files (x86)\WinPcap

2012-08-20 08:34 . 2012-08-20 08:34 -------- d-----w- c:\users\Max Cross\AppData\Roaming\Freecorder 6 Video

2012-08-20 08:34 . 2012-08-20 08:34 -------- d-----w- c:\users\Max Cross\AppData\Local\Jaksta_Technologies_Pty_L

2012-08-20 08:32 . 2012-08-20 08:32 -------- d-----w- c:\program files (x86)\Applian Technologies

2012-08-20 08:32 . 2012-08-20 08:32 -------- d-----w- c:\program files (x86)\Freecorder 6

2012-08-20 08:32 . 2012-08-20 08:32 -------- d-----w- c:\program files (x86)\Freecorder Toolbar

2012-08-20 08:28 . 2012-08-20 08:28 -------- d-----w- c:\program files (x86)\Common Files\xing shared

2012-08-20 08:27 . 2012-08-20 08:28 -------- d-----w- c:\program files (x86)\Real

2012-08-14 08:25 . 2012-08-14 08:27 -------- d-----w- c:\windows\WindowsMobile

2012-08-14 08:09 . 2012-06-12 03:08 3148800 ----a-w- c:\windows\system32\win32k.sys

2012-08-14 07:55 . 2012-04-24 05:37 184320 ----a-w- c:\windows\system32\cryptsvc.dll

2012-08-14 07:54 . 2012-03-03 06:35 1544704 ----a-w- c:\windows\system32\DWrite.dll

2012-08-14 07:52 . 2012-03-31 05:42 1732096 ----a-w- c:\program files\Windows Journal\NBDoc.DLL

2012-08-14 07:52 . 2012-03-31 05:40 1402880 ----a-w- c:\program files\Windows Journal\JNWDRV.dll

2012-08-14 07:52 . 2012-03-31 05:40 1367552 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll

2012-08-14 07:52 . 2012-03-31 05:40 1393664 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll

2012-08-14 07:52 . 2012-03-31 04:29 936960 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll

2012-08-14 07:47 . 2012-06-02 22:19 2428952 ----a-w- c:\windows\system32\wuaueng.dll

2012-08-14 07:47 . 2012-06-02 22:19 57880 ----a-w- c:\windows\system32\wuauclt.exe

2012-08-14 07:47 . 2012-06-02 22:19 44056 ----a-w- c:\windows\system32\wups2.dll

2012-08-14 07:47 . 2012-06-02 22:15 2622464 ----a-w- c:\windows\system32\wucltux.dll

2012-08-14 07:47 . 2012-06-02 22:19 38424 ----a-w- c:\windows\system32\wups.dll

2012-08-14 07:47 . 2012-06-02 22:15 99840 ----a-w- c:\windows\system32\wudriver.dll

2012-08-14 07:46 . 2012-06-02 22:19 701976 ----a-w- c:\windows\system32\wuapi.dll

2012-08-14 07:46 . 2012-06-02 12:19 186752 ----a-w- c:\windows\system32\wuwebv.dll

2012-08-14 07:46 . 2012-06-02 12:15 36864 ----a-w- c:\windows\system32\wuapp.exe

2012-08-13 11:35 . 2012-08-13 11:35 -------- d-----w- c:\users\Max Cross\AppData\Roaming\Iminent

2012-08-13 11:35 . 2012-08-13 11:35 -------- d-----w- c:\programdata\Iminent

2012-08-13 11:35 . 2012-08-13 11:35 -------- d-----w- c:\programdata\Tarma Installer

2012-08-13 11:32 . 2012-08-13 11:32 -------- d-----w- c:\users\Max Cross\AppData\Roaming\ExpressFiles

2012-08-13 09:04 . 2012-08-13 09:04 -------- d-----w- c:\programdata\Sony

2012-08-13 09:04 . 2012-08-13 09:04 -------- d-----w- c:\users\Max Cross\AppData\Roaming\Publish Providers

2012-08-13 09:02 . 2012-08-13 09:04 -------- d-----w- c:\users\Max Cross\AppData\Local\Sony

2012-08-13 09:02 . 2012-08-13 09:02 -------- d-----w- c:\windows\SysWow64\spool

2012-08-13 09:02 . 2012-08-13 09:02 -------- d-----w- c:\program files (x86)\Sony

2012-08-13 09:01 . 2012-08-13 09:04 -------- d-----w- c:\users\Max Cross\AppData\Roaming\Sony

2012-08-09 06:40 . 2012-08-09 06:40 -------- d-----w- C:\VirtualDub-1.9.11

2012-08-07 08:45 . 2012-08-07 08:45 -------- d-----w- c:\program files\Steam

2012-08-04 06:57 . 2012-08-04 06:57 -------- d-----w- c:\programdata\REVOLT

2012-08-02 13:44 . 2012-08-02 13:46 -------- d-----w- c:\users\Max Cross\AppData\Local\SugarSync

2012-08-02 13:44 . 2012-08-02 13:44 -------- d-----w- c:\program files (x86)\SugarSync

2012-08-01 19:11 . 2012-08-01 19:11 -------- d-----w- c:\program files (x86)\Oracle




(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))


2012-08-20 08:27 . 2011-08-19 07:32 499712 ----a-w- c:\windows\SysWow64\msvcp71.dll

2012-08-20 08:27 . 2011-08-19 07:32 348160 ----a-w- c:\windows\SysWow64\msvcr71.dll

2012-08-15 19:41 . 2012-04-15 19:56 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2012-08-15 19:41 . 2012-03-21 08:41 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2012-07-23 16:30 . 2012-07-23 16:30 98304 ----a-w- c:\windows\SysWow64\CmdLineExt.dll

2012-07-22 09:32 . 2012-07-21 14:23 419840 ----a-w- c:\windows\system32\wrap_oal.dll

2012-07-22 09:32 . 2012-07-21 14:23 413696 ----a-w- c:\windows\SysWow64\wrap_oal.dll

2012-07-22 09:32 . 2012-07-21 14:23 133632 ----a-w- c:\windows\system32\OpenAL32.dll

2012-07-22 09:32 . 2012-07-21 14:23 110592 ----a-w- c:\windows\SysWow64\OpenAL32.dll

2012-07-19 07:21 . 2012-07-19 07:21 15360 ----a-r- c:\users\Max Cross\AppData\Roaming\Microsoft\Installer\{DD8408E9-9421-484F-979D-DB6361E3E828}\IconDD8408E910.exe

2012-07-19 07:21 . 2012-07-19 07:21 11264 ----a-r- c:\users\Max Cross\AppData\Roaming\Microsoft\Installer\{DD8408E9-9421-484F-979D-DB6361E3E828}\IconDD8408E96.exe

2012-07-09 18:16 . 2012-07-09 18:16 560184 ----a-w- c:\windows\system32\drivers\sptd.sys

2012-07-09 18:12 . 2012-07-09 18:12 178800 ----a-w- c:\windows\SysWow64\CmdLineExt_x64.dll

2012-07-07 06:22 . 2012-07-07 06:22 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys

2012-07-05 19:06 . 2012-05-11 05:09 772544 ----a-w- c:\windows\SysWow64\npDeployJava1.dll

2012-07-05 19:06 . 2012-05-11 05:09 687544 ----a-w- c:\windows\SysWow64\deployJava1.dll

2012-07-03 00:19 . 2012-03-25 17:57 59701280 ----a-w- c:\windows\system32\MRT.exe

2012-06-11 18:02 . 2012-06-11 18:02 71680 ----a-w- c:\windows\system32\frapsv64.dll

2012-06-11 18:02 . 2012-06-11 18:02 65536 ----a-w- c:\windows\SysWow64\frapsvid.dll



((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))



*Note* empty entries & legit default entries are not shown



[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]

"{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\progra~2\Yahoo!\Companion\Installs\cpn0\yt.dll" [2012-01-12 1517368]







[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]

2012-07-10 08:07 2074208 ----a-w- c:\program files (x86)\AVG Secure Search\\AVG Secure Search_toolbar.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]

"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files (x86)\AVG Secure Search\\AVG Secure Search_toolbar.dll" [2012-07-10 2074208]

"{6B34ACCF-1B63-4E1A-8633-461917C75544}"= "c:\program files (x86)\Freecorder 6\tbcore3.dll" [2012-08-01 2711928]



[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]

[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]










2012-02-15 00:32 94208 ----a-w- c:\users\Max Cross\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll





2012-02-15 00:32 94208 ----a-w- c:\users\Max Cross\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll





2012-02-15 00:32 94208 ----a-w- c:\users\Max Cross\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll





2012-02-15 00:32 94208 ----a-w- c:\users\Max Cross\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll



"Allway Sync"="c:\program files (x86)\Allway Sync\Bin\syncappw.exe" [2012-08-16 94408]

"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-04-17 3671872]

"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2012-07-05 39408]



"IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2010-11-05 283160]

"AVG_TRAY"="c:\program files (x86)\AVG\AVG2012\avgtray.exe" [2012-01-24 2416480]

"vProt"="c:\program files (x86)\AVG Secure Search\vprot.exe" [2012-07-10 1107552]

"PWRISOVM.EXE"="c:\program files (x86)\PowerISO\PWRISOVM.EXE" [2012-02-09 312376]

"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-07-31 38872]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-11 919008]

"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-06-27 1996200]

"TkBellExe"="c:\program files (x86)\Real\RealPlayer\update\realsched.exe" [2012-08-20 296096]

"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]


c:\users\Max Cross\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dropbox.lnk - c:\users\Max Cross\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]


c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

RMP3.lnk - c:\program files (x86)\RMP3\RMP3.exe [2012-5-15 19456]



"ConsentPromptBehaviorAdmin"= 0 (0x0)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

"PromptOnSecureDesktop"= 0 (0x0)


[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]



[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG2012\avgrsa.exe /sync /restart


R2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2012\AVGIDSAgent.exe [2011-10-12 4433248]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-25 116648]

R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944]

R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-03 160944]

R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-15 250056]

R3 FNETTBOH_305;FNETTBOH_305;c:\windows\system32\drivers\FNETTBOH_305.SYS [2012-03-21 31808]

R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-25 116648]

R3 MSICDSetup;MSICDSetup;E:\CDriver64.sys [x]

R3 netr28ux;RT2870 USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr28ux.sys [2009-06-10 867328]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]

R3 VSPerfDrv100;Performance Tools Driver 10.0;d:\microsoft visual studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [2010-03-17 68440]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-03-22 1255736]

S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [2011-07-10 26704]

S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [2011-09-13 37456]

S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]

S1 AsrAppCharger;AsrAppCharger;c:\windows\system32\DRIVERS\AsrAppCharger.sys [2010-06-11 15368]

S1 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwd6a.sys [2011-05-22 48992]

S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [2011-10-07 283728]

S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [2011-08-08 46672]

S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [2011-07-10 375376]

S1 FNETURPX;FNETURPX;c:\windows\system32\drivers\FNETURPX.SYS [2012-03-21 15936]

S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]

S2 avgfws;AVG Firewall;c:\program files (x86)\AVG\AVG2012\avgfws.exe [2011-11-23 2391832]

S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2012\avgwdsvc.exe [2011-08-02 192776]

S2 BotkindSyncService;Botkind Service;c:\program files (x86)\Allway Sync\Bin\SyncService.exe service [x]

S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-06-27 2369960]

S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-05 13336]

S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-06-25 35344]

S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-08-03 2255464]

S2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [2012-02-09 31408]

S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-08-03 379496]

S2 vToolbarUpdater11.2.0;vToolbarUpdater11.2.0;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe [2012-07-10 935008]

S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [2011-07-10 120400]

S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [2011-07-10 29776]

S3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-07-07 283200]

S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys [2011-02-08 39936]

S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys [2011-02-08 64512]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904]

S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2010-10-19 56344]

S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2011-05-10 174184]

S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-06-23 344680]



Contents of the 'Scheduled Tasks' folder


2012-08-23 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-15 19:41]


2012-08-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-07-05 20:10]


2012-08-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-07-05 20:10]


2012-08-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3809980168-2150364332-903963578-1000Core.job

- c:\users\Max Cross\AppData\Local\Google\Update\GoogleUpdate.exe [2012-03-21 07:05]


2012-08-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3809980168-2150364332-903963578-1000UA.job

- c:\users\Max Cross\AppData\Local\Google\Update\GoogleUpdate.exe [2012-03-21 07:05]



--------- X64 Entries -----------






2012-02-15 00:32 97792 ----a-w- c:\users\Max Cross\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll





2012-02-15 00:32 97792 ----a-w- c:\users\Max Cross\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll





2012-02-15 00:32 97792 ----a-w- c:\users\Max Cross\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll





2012-02-15 00:32 97792 ----a-w- c:\users\Max Cross\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll





2012-07-13 05:17 463992 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll





2012-07-13 05:17 463992 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll





2012-07-13 05:17 463992 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll





2012-07-13 05:17 463992 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll



"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-07-28 11101800]

"RunDLLEntry"="c:\windows\system32\AmbRunE.dll" [2009-02-26 17920]

"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-09-16 497648]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]



------- Supplementary Scan -------


uLocal Page = c:\windows\system32\blank.htm

uStart Page = hxxp://search.iminent.com/?appId=446F3829-99F7-49FC-AB05-AEC24AD66546

mLocal Page = c:\windows\SysWOW64\blank.htm

IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000

Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\11.2.0\ViProtocol.dll


- - - - ORPHANS REMOVED - - - -


URLSearchHooks-{84FF7BD6-B47F-46F8-9130-01B2696B36CB} - (no file)

Wow6432Node-HKLM-Run-Iminent - c:\program files (x86)\Iminent\Iminent.exe

Wow6432Node-HKLM-Run-IminentMessenger - c:\program files (x86)\Iminent\Iminent.Messengers.exe





--------------------- LOCKED REGISTRY KEYS ---------------------


[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]

@Denied: (2) (LocalSystem)
























[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]

@Denied: (2) (LocalSystem)



[HKEY_USERS\S-1-5-21-3809980168-2150364332-903963578-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]

@Allowed: (Read) (RestrictedCode)





[HKEY_USERS\S-1-5-21-3809980168-2150364332-903963578-1000\Software\SecuROM\License information*]






@Denied: (A 2) (Everyone)














@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"













@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1"












@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"










@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1"












@Denied: (A 2) (Everyone)










[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]





@Denied: (Full) (Everyone)


------------------------ Other Running Processes ------------------------


c:\program files (x86)\Allway Sync\Bin\SyncService.exe

c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe

c:\program files (x86)\Yahoo!\Messenger\ymsgr_tray.exe




Completion time: 2012-08-23 18:49:31 - machine was rebooted

ComboFix-quarantined-files.txt 2012-08-23 15:49


Pre-Run: 8,678,047,744 bytes free

Post-Run: 8,518,983,680 bytes free


- - End Of File - - EF7A1BF5F65639019DA6061024FCAD8E

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

c:\program files (x86)\Freecorder 6\tbcore3.dll

c:\program files (x86)\Freecorder Toolbar

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]


Save this as CFScript.txt, in the same location as ComboFix.exe


Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

Same as before, the PC restarted twice. I'm guessing it's normal.

the log:

ComboFix 12-08-22.03 - Max Cross 23/08/2012 19:47:49.2.4 - x64

Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.8175.6482 [GMT 3:00]

Running from: c:\users\Max Cross\Desktop\ComboFix.exe

Command switches used :: c:\users\Max Cross\Desktop\CFScript.txt

AV: AVG Internet Security Business Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}

FW: AVG Firewall *Disabled* {621CC794-9486-F902-D092-0484E8EA828B}

SP: AVG Internet Security Business Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}



"c:\program files (x86)\Freecorder 6\tbcore3.dll"



((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))



c:\program files (x86)\Freecorder 6\tbcore3.dll

c:\program files (x86)\Freecorder Toolbar

c:\program files (x86)\Freecorder Toolbar\Freecorder.crx

c:\program files (x86)\Freecorder Toolbar\uninstall.chrome.exe



((((((((((((((((((((((((( Files Created from 2012-07-23 to 2012-08-23 )))))))))))))))))))))))))))))))



2012-08-23 16:51 . 2012-08-23 16:51 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp

2012-08-23 16:51 . 2012-08-23 16:51 -------- d-----w- c:\users\Default\AppData\Local\temp

2012-08-23 16:37 . 2012-08-23 16:37 -------- d-----w- C:\spre32en

2012-08-23 16:17 . 2012-08-23 16:17 -------- d-----w- c:\users\Max Cross\AppData\Roaming\SoftMaker

2012-08-23 16:16 . 2012-08-23 16:16 -------- d-----w- c:\program files (x86)\SoftMaker Viewer

2012-08-23 16:15 . 2010-09-23 11:15 98344 ----a-w- c:\windows\unTMV.exe

2012-08-22 18:12 . 2012-08-22 18:12 -------- d-----w- c:\users\Max Cross\AppData\Roaming\Doublefine

2012-08-22 17:26 . 2012-08-22 17:26 -------- d-----w- c:\program files (x86)\MALWAREBYTES ANTI-MALWARE

2012-08-22 10:24 . 2012-08-22 10:24 -------- d-----w- c:\program files (x86)\ESET

2012-08-22 07:46 . 2012-08-22 07:46 -------- d-----w- c:\users\Max Cross\AppData\Roaming\Malwarebytes

2012-08-22 07:46 . 2012-08-22 07:49 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2012-08-22 07:46 . 2012-08-22 07:46 -------- d-----w- c:\programdata\Malwarebytes

2012-08-22 07:46 . 2012-07-03 10:46 24904 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-08-21 17:50 . 2012-08-21 17:50 -------- d-----w- c:\users\Max Cross\AppData\Roaming\rigonauts

2012-08-20 08:34 . 2012-08-20 08:34 -------- d-----w- c:\users\Max Cross\AppData\Local\Freecorder 6 Video

2012-08-20 08:34 . 2012-08-20 08:34 -------- d-----w- c:\program files (x86)\WinPcap

2012-08-20 08:34 . 2012-08-20 08:34 -------- d-----w- c:\users\Max Cross\AppData\Roaming\Freecorder 6 Video

2012-08-20 08:34 . 2012-08-20 08:34 -------- d-----w- c:\users\Max Cross\AppData\Local\Jaksta_Technologies_Pty_L

2012-08-20 08:32 . 2012-08-20 08:32 -------- d-----w- c:\program files (x86)\Applian Technologies

2012-08-20 08:32 . 2012-08-23 16:50 -------- d-----w- c:\program files (x86)\Freecorder 6

2012-08-20 08:28 . 2012-08-20 08:28 -------- d-----w- c:\program files (x86)\Common Files\xing shared

2012-08-20 08:27 . 2012-08-20 08:28 -------- d-----w- c:\program files (x86)\Real

2012-08-14 08:25 . 2012-08-14 08:27 -------- d-----w- c:\windows\WindowsMobile

2012-08-14 08:09 . 2012-06-12 03:08 3148800 ----a-w- c:\windows\system32\win32k.sys

2012-08-14 07:55 . 2012-04-24 05:37 184320 ----a-w- c:\windows\system32\cryptsvc.dll

2012-08-14 07:54 . 2012-03-03 06:35 1544704 ----a-w- c:\windows\system32\DWrite.dll

2012-08-14 07:52 . 2012-03-31 05:42 1732096 ----a-w- c:\program files\Windows Journal\NBDoc.DLL

2012-08-14 07:52 . 2012-03-31 05:40 1402880 ----a-w- c:\program files\Windows Journal\JNWDRV.dll

2012-08-14 07:52 . 2012-03-31 05:40 1367552 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll

2012-08-14 07:52 . 2012-03-31 05:40 1393664 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll

2012-08-14 07:52 . 2012-03-31 04:29 936960 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll

2012-08-14 07:47 . 2012-06-02 22:19 2428952 ----a-w- c:\windows\system32\wuaueng.dll

2012-08-14 07:47 . 2012-06-02 22:19 57880 ----a-w- c:\windows\system32\wuauclt.exe

2012-08-14 07:47 . 2012-06-02 22:19 44056 ----a-w- c:\windows\system32\wups2.dll

2012-08-14 07:47 . 2012-06-02 22:15 2622464 ----a-w- c:\windows\system32\wucltux.dll

2012-08-14 07:47 . 2012-06-02 22:19 38424 ----a-w- c:\windows\system32\wups.dll

2012-08-14 07:47 . 2012-06-02 22:15 99840 ----a-w- c:\windows\system32\wudriver.dll

2012-08-14 07:46 . 2012-06-02 22:19 701976 ----a-w- c:\windows\system32\wuapi.dll

2012-08-14 07:46 . 2012-06-02 12:19 186752 ----a-w- c:\windows\system32\wuwebv.dll

2012-08-14 07:46 . 2012-06-02 12:15 36864 ----a-w- c:\windows\system32\wuapp.exe

2012-08-13 11:35 . 2012-08-13 11:35 -------- d-----w- c:\users\Max Cross\AppData\Roaming\Iminent

2012-08-13 11:35 . 2012-08-13 11:35 -------- d-----w- c:\programdata\Iminent

2012-08-13 11:35 . 2012-08-13 11:35 -------- d-----w- c:\programdata\Tarma Installer

2012-08-13 11:32 . 2012-08-13 11:32 -------- d-----w- c:\users\Max Cross\AppData\Roaming\ExpressFiles

2012-08-13 09:04 . 2012-08-13 09:04 -------- d-----w- c:\programdata\Sony

2012-08-13 09:04 . 2012-08-13 09:04 -------- d-----w- c:\users\Max Cross\AppData\Roaming\Publish Providers

2012-08-13 09:02 . 2012-08-13 09:04 -------- d-----w- c:\users\Max Cross\AppData\Local\Sony

2012-08-13 09:02 . 2012-08-13 09:02 -------- d-----w- c:\windows\SysWow64\spool

2012-08-13 09:02 . 2012-08-13 09:02 -------- d-----w- c:\program files (x86)\Sony

2012-08-13 09:01 . 2012-08-13 09:04 -------- d-----w- c:\users\Max Cross\AppData\Roaming\Sony

2012-08-09 06:40 . 2012-08-09 06:40 -------- d-----w- C:\VirtualDub-1.9.11

2012-08-07 08:45 . 2012-08-07 08:45 -------- d-----w- c:\program files\Steam

2012-08-04 06:57 . 2012-08-04 06:57 -------- d-----w- c:\programdata\REVOLT

2012-08-02 13:44 . 2012-08-02 13:46 -------- d-----w- c:\users\Max Cross\AppData\Local\SugarSync

2012-08-02 13:44 . 2012-08-02 13:44 -------- d-----w- c:\program files (x86)\SugarSync

2012-08-01 19:11 . 2012-08-01 19:11 -------- d-----w- c:\program files (x86)\Oracle




(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))


2012-08-20 08:27 . 2011-08-19 07:32 499712 ----a-w- c:\windows\SysWow64\msvcp71.dll

2012-08-20 08:27 . 2011-08-19 07:32 348160 ----a-w- c:\windows\SysWow64\msvcr71.dll

2012-08-15 19:41 . 2012-04-15 19:56 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2012-08-15 19:41 . 2012-03-21 08:41 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2012-07-23 16:30 . 2012-07-23 16:30 98304 ----a-w- c:\windows\SysWow64\CmdLineExt.dll

2012-07-22 09:32 . 2012-07-21 14:23 419840 ----a-w- c:\windows\system32\wrap_oal.dll

2012-07-22 09:32 . 2012-07-21 14:23 413696 ----a-w- c:\windows\SysWow64\wrap_oal.dll

2012-07-22 09:32 . 2012-07-21 14:23 133632 ----a-w- c:\windows\system32\OpenAL32.dll

2012-07-22 09:32 . 2012-07-21 14:23 110592 ----a-w- c:\windows\SysWow64\OpenAL32.dll

2012-07-19 07:21 . 2012-07-19 07:21 15360 ----a-r- c:\users\Max Cross\AppData\Roaming\Microsoft\Installer\{DD8408E9-9421-484F-979D-DB6361E3E828}\IconDD8408E910.exe

2012-07-19 07:21 . 2012-07-19 07:21 11264 ----a-r- c:\users\Max Cross\AppData\Roaming\Microsoft\Installer\{DD8408E9-9421-484F-979D-DB6361E3E828}\IconDD8408E96.exe

2012-07-09 18:16 . 2012-07-09 18:16 560184 ----a-w- c:\windows\system32\drivers\sptd.sys

2012-07-09 18:12 . 2012-07-09 18:12 178800 ----a-w- c:\windows\SysWow64\CmdLineExt_x64.dll

2012-07-07 06:22 . 2012-07-07 06:22 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys

2012-07-05 19:06 . 2012-05-11 05:09 772544 ----a-w- c:\windows\SysWow64\npDeployJava1.dll

2012-07-05 19:06 . 2012-05-11 05:09 687544 ----a-w- c:\windows\SysWow64\deployJava1.dll

2012-07-03 00:19 . 2012-03-25 17:57 59701280 ----a-w- c:\windows\system32\MRT.exe

2012-06-11 18:02 . 2012-06-11 18:02 71680 ----a-w- c:\windows\system32\frapsv64.dll

2012-06-11 18:02 . 2012-06-11 18:02 65536 ----a-w- c:\windows\SysWow64\frapsvid.dll



((((((((((((((((((((((((((((( SnapShot@2012-08-23_15.45.38 )))))))))))))))))))))))))))))))))))))))))


+ 2012-03-21 06:26 . 2012-08-23 15:54 48342 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin

+ 2009-07-14 05:10 . 2012-08-23 15:54 30298 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin

+ 2012-03-21 06:08 . 2012-08-23 15:54 12728 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3809980168-2150364332-903963578-1000_UserData.bin

- 2012-08-23 15:45 . 2012-08-23 15:45 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

+ 2012-08-23 16:51 . 2012-08-23 16:51 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

+ 2012-08-23 16:51 . 2012-08-23 16:51 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

- 2012-08-23 15:45 . 2012-08-23 15:45 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

- 2009-07-14 02:36 . 2012-08-23 15:38 662632 c:\windows\system32\perfh009.dat

+ 2009-07-14 02:36 . 2012-08-23 16:34 662632 c:\windows\system32\perfh009.dat

+ 2009-07-14 02:36 . 2012-08-23 16:34 122320 c:\windows\system32\perfc009.dat

- 2009-07-14 02:36 . 2012-08-23 15:38 122320 c:\windows\system32\perfc009.dat

- 2009-07-14 05:01 . 2012-08-23 15:44 390284 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

+ 2009-07-14 05:01 . 2012-08-23 16:51 390284 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))



*Note* empty entries & legit default entries are not shown



[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]

"{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\progra~2\Yahoo!\Companion\Installs\cpn0\yt.dll" [2012-01-12 1517368]







[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]

2012-07-10 08:07 2074208 ----a-w- c:\program files (x86)\AVG Secure Search\\AVG Secure Search_toolbar.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]

"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files (x86)\AVG Secure Search\\AVG Secure Search_toolbar.dll" [2012-07-10 2074208]



[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]

[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]





2012-02-15 00:32 94208 ----a-w- c:\users\Max Cross\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll





2012-02-15 00:32 94208 ----a-w- c:\users\Max Cross\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll





2012-02-15 00:32 94208 ----a-w- c:\users\Max Cross\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll





2012-02-15 00:32 94208 ----a-w- c:\users\Max Cross\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll



"Allway Sync"="c:\program files (x86)\Allway Sync\Bin\syncappw.exe" [2012-08-16 94408]

"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-04-17 3671872]

"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2012-07-05 39408]



"IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2010-11-05 283160]

"AVG_TRAY"="c:\program files (x86)\AVG\AVG2012\avgtray.exe" [2012-01-24 2416480]

"vProt"="c:\program files (x86)\AVG Secure Search\vprot.exe" [2012-07-10 1107552]

"PWRISOVM.EXE"="c:\program files (x86)\PowerISO\PWRISOVM.EXE" [2012-02-09 312376]

"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-07-31 38872]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-11 919008]

"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-06-27 1996200]

"TkBellExe"="c:\program files (x86)\Real\RealPlayer\update\realsched.exe" [2012-08-20 296096]

"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]


c:\users\Max Cross\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dropbox.lnk - c:\users\Max Cross\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]


c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

RMP3.lnk - c:\program files (x86)\RMP3\RMP3.exe [2012-5-15 19456]



"ConsentPromptBehaviorAdmin"= 0 (0x0)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

"PromptOnSecureDesktop"= 0 (0x0)


[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]



[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG2012\avgrsa.exe /sync /restart


R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-25 116648]

R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944]

R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-03 160944]

R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-15 250056]

R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-25 116648]

R3 MSICDSetup;MSICDSetup;E:\CDriver64.sys [x]

R3 netr28ux;RT2870 USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr28ux.sys [2009-06-10 867328]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]

R3 VSPerfDrv100;Performance Tools Driver 10.0;d:\microsoft visual studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [2010-03-17 68440]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-03-22 1255736]

S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [2011-07-10 26704]

S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [2011-09-13 37456]

S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]

S1 AsrAppCharger;AsrAppCharger;c:\windows\system32\DRIVERS\AsrAppCharger.sys [2010-06-11 15368]

S1 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwd6a.sys [2011-05-22 48992]

S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [2011-10-07 283728]

S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [2011-08-08 46672]

S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [2011-07-10 375376]

S1 FNETURPX;FNETURPX;c:\windows\system32\drivers\FNETURPX.SYS [2012-03-21 15936]

S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]

S2 avgfws;AVG Firewall;c:\program files (x86)\AVG\AVG2012\avgfws.exe [2011-11-23 2391832]

S2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2012\AVGIDSAgent.exe [2011-10-12 4433248]

S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2012\avgwdsvc.exe [2011-08-02 192776]

S2 BotkindSyncService;Botkind Service;c:\program files (x86)\Allway Sync\Bin\SyncService.exe service [x]

S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-06-27 2369960]

S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-05 13336]

S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-06-25 35344]

S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-08-03 2255464]

S2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [2012-02-09 31408]

S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-08-03 379496]

S2 vToolbarUpdater11.2.0;vToolbarUpdater11.2.0;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe [2012-07-10 935008]

S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [2011-07-10 120400]

S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [2011-07-10 29776]

S3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-07-07 283200]

S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys [2011-02-08 39936]

S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys [2011-02-08 64512]

S3 FNETTBOH_305;FNETTBOH_305;c:\windows\system32\drivers\FNETTBOH_305.SYS [2012-03-21 31808]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904]

S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2010-10-19 56344]

S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2011-05-10 174184]

S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-06-23 344680]



Contents of the 'Scheduled Tasks' folder


2012-08-23 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-15 19:41]


2012-08-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-07-05 20:10]


2012-08-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-07-05 20:10]


2012-08-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3809980168-2150364332-903963578-1000Core.job

- c:\users\Max Cross\AppData\Local\Google\Update\GoogleUpdate.exe [2012-03-21 07:05]


2012-08-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3809980168-2150364332-903963578-1000UA.job

- c:\users\Max Cross\AppData\Local\Google\Update\GoogleUpdate.exe [2012-03-21 07:05]



--------- X64 Entries -----------






2012-02-15 00:32 97792 ----a-w- c:\users\Max Cross\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll





2012-02-15 00:32 97792 ----a-w- c:\users\Max Cross\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll





2012-02-15 00:32 97792 ----a-w- c:\users\Max Cross\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll





2012-02-15 00:32 97792 ----a-w- c:\users\Max Cross\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll





2012-07-13 05:17 463992 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll





2012-07-13 05:17 463992 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll





2012-07-13 05:17 463992 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll





2012-07-13 05:17 463992 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll



"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-07-28 11101800]

"RunDLLEntry"="c:\windows\system32\AmbRunE.dll" [2009-02-26 17920]

"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-09-16 497648]


------- Supplementary Scan -------


uLocal Page = c:\windows\system32\blank.htm

uStart Page = hxxp://search.iminent.com/?appId=446F3829-99F7-49FC-AB05-AEC24AD66546

mLocal Page = c:\windows\SysWOW64\blank.htm

IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000

Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\11.2.0\ViProtocol.dll


- - - - ORPHANS REMOVED - - - -


AddRemove-Freecorder 6 extension for Chrome - c:\program files (x86)\Freecorder Toolbar\uninstall.chrome.exe




--------------------- LOCKED REGISTRY KEYS ---------------------


[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]

@Denied: (2) (LocalSystem)
























[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]

@Denied: (2) (LocalSystem)



[HKEY_USERS\S-1-5-21-3809980168-2150364332-903963578-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]

@Allowed: (Read) (RestrictedCode)





[HKEY_USERS\S-1-5-21-3809980168-2150364332-903963578-1000\Software\SecuROM\License information*]






@Denied: (A 2) (Everyone)














@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"













@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1"












@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"










@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1"












@Denied: (A 2) (Everyone)










[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]





@Denied: (Full) (Everyone)


------------------------ Other Running Processes ------------------------


c:\program files (x86)\Allway Sync\Bin\SyncService.exe

c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe




Completion time: 2012-08-23 19:55:54 - machine was rebooted

ComboFix-quarantined-files.txt 2012-08-23 16:55

ComboFix2.txt 2012-08-23 15:49


Pre-Run: 8,596,430,848 bytes free

Post-Run: 8,491,876,352 bytes free


- - End Of File - - 370BE0BBE21B34876F1AA2FD09599AC9

Yes, everything is alright.

Please run a free online scan with the ESET Online Scanner

Note: You will need to use Internet Explorer for this scan

  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic

Regardint the Online Scanner, must I have an internet connection during the scan? Must I shut down all other anti-malware soft like before? Must I close all programs and windows? Was the Freecorder program I recently installed to blame? Should I uninstall it?

I will run the scan as soon as you reply.

Link to post
Regardint the Online Scanner, must I have an internet connection during the scan?

Yes, you must.

Must I shut down all other anti-malware soft like before?

Yes, please.

Must I close all programs and windows?

Yes, you must.

Was the Freecorder program I recently installed to blame? Should I uninstall it?

No, the main problem was their toolbar which I already take care for it.

No, the main problem was their toolbar which I already take care for it.

I think the toolbar is an integral part of the program. So without the bar, it's pointless to keep the program, I think. But that doesn't matter, getting rid of the problem is much more important.

I found the log file in C:\Program Files (x86)\ESET\ESET Online Scanner

ESETSmartInstaller@High as CAB hook log:

OnlineScanner64.ocx - registred OK

OnlineScanner.ocx - registred OK

# version=7

# iexplore.exe=9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)

# OnlineScanner.ocx=

# api_version=3.0.2

# EOSSerial=e1ddd708fd288b4e80c1efbb6ded195e

# end=stopped

# remove_checked=false

# archives_checked=false

# unwanted_checked=true

# unsafe_checked=false

# antistealth_checked=true

# utc_time=2012-08-22 11:18:17

# local_time=2012-08-22 02:18:17 (+0200, GTB Daylight Time)

# country="United States"

# lang=1033

# osver=6.1.7601 NT Service Pack 1

# compatibility_mode=1024 16777215 100 0 13314758 13314758 0 0

# compatibility_mode=5893 16776574 66 94 12931656 97260987 0 0

# compatibility_mode=8192 67108863 100 0 94 94 0 0

# scanned=271169

# found=15

# cleaned=0

# scan_time=3159

C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application (unable to clean) 00000000000000000000000000000000 I

C:\SAFE\Oxin's Style!\3D Sexvilla 2\Binaries\fc3DSexVillaRun.DE.exe a variant of Win32/Inject.NDT trojan (unable to clean) 00000000000000000000000000000000 I

C:\SAFE\Oxin's Style!\3D Sexvilla 2\Binaries\fc3DSexVillaRun.EN.exe Win32/Inject.NDT trojan (unable to clean) 00000000000000000000000000000000 I

C:\SAFE\Oxin's Style!\Hentai3D 2\Binaries\fcHentai3DRun.DE.exe a variant of Win32/Inject.NDT trojan (unable to clean) 00000000000000000000000000000000 I

C:\SAFE\Oxin's Style!\Hentai3D 2\Binaries\fcHentai3DRun.EN.exe a variant of Win32/Inject.NDT trojan (unable to clean) 00000000000000000000000000000000 I

C:\SAFE\Oxin's Style!\VirtuallyJenna\Binaries\fcVirtuallyJennaRun.DE.exe a variant of Win32/Inject.NDT trojan (unable to clean) 00000000000000000000000000000000 I

C:\SAFE\Oxin's Style!\VirtuallyJenna\Binaries\fcVirtuallyJennaRun.EN.exe a variant of Win32/Inject.NDT trojan (unable to clean) 00000000000000000000000000000000 I

C:\SAFE\Oxin's Style!\VirtuallyJenna\Binaries\VirtuallyJenna2-054.002.exe a variant of Win32/Packed.Themida application (unable to clean) 00000000000000000000000000000000 I

C:\Users\All Users\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application (unable to clean) 00000000000000000000000000000000 I

C:\Users\Max Cross\AppData\Roaming\9DEE93.exe a variant of Win32/Injector.Autoit.AH trojan (unable to clean) 00000000000000000000000000000000 I

C:\Windows\Installer\{9bcaef9f-6f5e-fdb3-1978-f9187934e46d}\U\00000008.@ Win64/Agent.BA trojan (unable to clean) 00000000000000000000000000000000 I

C:\Windows\Installer\{9bcaef9f-6f5e-fdb3-1978-f9187934e46d}\U\000000cb.@ Win64/Conedex.B trojan (unable to clean) 00000000000000000000000000000000 I

C:\Windows\Installer\{9bcaef9f-6f5e-fdb3-1978-f9187934e46d}\U\80000000.@ Win64/Sirefef.AP trojan (unable to clean) 00000000000000000000000000000000 I

C:\Windows\Installer\{9bcaef9f-6f5e-fdb3-1978-f9187934e46d}\U\80000032.@ a variant of Win32/Sirefef.FD trojan (unable to clean) 00000000000000000000000000000000 I

D:\Fable 3\paul.dll a variant of Win32/Packed.VMProtect.AAA trojan (unable to clean) 00000000000000000000000000000000 I

# version=7

# iexplore.exe=9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)

# OnlineScanner.ocx=

# api_version=3.0.2

# EOSSerial=e1ddd708fd288b4e80c1efbb6ded195e

# end=finished

# remove_checked=true

# archives_checked=false

# unwanted_checked=true

# unsafe_checked=false

# antistealth_checked=true

# utc_time=2012-08-24 09:34:50

# local_time=2012-08-24 12:34:50 (+0200, GTB Daylight Time)

# country="United States"

# lang=1033

# osver=6.1.7601 NT Service Pack 1

# compatibility_mode=512 16777215 100 0 0 0 0 0

# compatibility_mode=1024 16777215 100 0 13481057 13481057 0 0

# compatibility_mode=5893 16776574 100 94 13097955 97427286 0 0

# compatibility_mode=8192 67108863 100 0 166393 166393 0 0

# scanned=322369

# found=15

# cleaned=15

# scan_time=3454

C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\Qoobox\Quarantine\C\Users\Max Cross\AppData\Roaming\9DEE93.exe.vir a variant of Win32/Injector.Autoit.AH trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\Qoobox\Quarantine\C\Windows\Installer\{9bcaef9f-6f5e-fdb3-1978-f9187934e46d}\U\00000008.@.vir Win64/Agent.BA trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\Qoobox\Quarantine\C\Windows\Installer\{9bcaef9f-6f5e-fdb3-1978-f9187934e46d}\U\000000cb.@.vir Win64/Conedex.B trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\Qoobox\Quarantine\C\Windows\Installer\{9bcaef9f-6f5e-fdb3-1978-f9187934e46d}\U\80000000.@.vir Win64/Sirefef.AP trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\Qoobox\Quarantine\C\Windows\Installer\{9bcaef9f-6f5e-fdb3-1978-f9187934e46d}\U\80000032.@.vir a variant of Win32/Sirefef.FD trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\Qoobox\Quarantine\C\Windows\System32\services.exe.vir Win64/Patched.A.Gen trojan (deleted - quarantined) 00000000000000000000000000000000 C

C:\SAFE\Oxin's Style!\3D Sexvilla 2\Binaries\fc3DSexVillaRun.DE.exe a variant of Win32/Inject.NDT trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\SAFE\Oxin's Style!\3D Sexvilla 2\Binaries\fc3DSexVillaRun.EN.exe Win32/Inject.NDT trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\SAFE\Oxin's Style!\Hentai3D 2\Binaries\fcHentai3DRun.DE.exe a variant of Win32/Inject.NDT trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\SAFE\Oxin's Style!\Hentai3D 2\Binaries\fcHentai3DRun.EN.exe a variant of Win32/Inject.NDT trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\SAFE\Oxin's Style!\VirtuallyJenna\Binaries\fcVirtuallyJennaRun.DE.exe a variant of Win32/Inject.NDT trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\SAFE\Oxin's Style!\VirtuallyJenna\Binaries\fcVirtuallyJennaRun.EN.exe a variant of Win32/Inject.NDT trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\SAFE\Oxin's Style!\VirtuallyJenna\Binaries\VirtuallyJenna2-054.002.exe a variant of Win32/Packed.Themida application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

D:\Fable 3\paul.dll a variant of Win32/Packed.VMProtect.AAA trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

Apparently half of the quarantined files are my bro's cracks. He has a ton of original DVDs, but I guess I understand why he would buy original hentai games, he's not the legal age yet. :)) Good thing he didn't ask our dad to fix his problem =))

But seriously now, what do I do next?

I would like to perform one last scan:

Download OTL to your Desktop

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Please tick the Scan All users. Next, click the Quick Scan button. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic.

OTL Extras logfile created on: 24/08/2012 1:30:07 PM - Run 1

OTL by OldTimer - Version Folder = C:\Users\Max Cross\Desktop

64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation

Internet Explorer (Version = 9.0.8112.16421)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: dd/MM/yyy

7.98 Gb Total Physical Memory | 5.51 Gb Available Physical Memory | 68.97% Memory free

15.96 Gb Paging File | 13.36 Gb Available in Paging File | 83.70% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

Drive C: | 97.56 Gb Total Space | 8.54 Gb Free Space | 8.76% Space Free | Partition Type: NTFS

Drive D: | 368.10 Gb Total Space | 36.69 Gb Free Space | 9.97% Space Free | Partition Type: NTFS

Computer Name: MAXCROSS-PC | User Name: Max Cross | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans

Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========

========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

.txt[@ = txtfile] -- Reg Error: Key error. File not found


.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

.txt [@ = txtfile] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

exefile [open] -- "%1" %*

helpfile [open] -- Reg Error: Key error.

htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)

inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)

InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)

InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

txtfile [open] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()

Directory [browse with XnView] -- "C:\Program Files (x86)\XnView\xnview.exe" "%1" (XnView, http://www.xnview.com)

Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()

Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [explore] -- Reg Error: Value error.

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)


batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)

exefile [open] -- "%1" %*

helpfile [open] -- Reg Error: Key error.

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

txtfile [open] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()

Directory [browse with XnView] -- "C:\Program Files (x86)\XnView\xnview.exe" "%1" (XnView, http://www.xnview.com)

Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()

Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [explore] -- Reg Error: Value error.

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"cval" = 1

"FirewallDisableNotify" = 0

"AntiVirusDisableNotify" = 0

"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]

"AntiVirusOverride" = 0

"AntiSpywareOverride" = 0

"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]

"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]





"DisableNotifications" = 0

"EnableFirewall" = 0


"DisableNotifications" = 0

"EnableFirewall" = 0



"DisableNotifications" = 0

"EnableFirewall" = 0

========== Authorized Applications List ==========



========== Vista Active Open Ports Exception List ==========


"{0294BB2F-6178-459D-8C46-8D1C40D6AD6B}" = rport=445 | protocol=6 | dir=out | app=system |

"{057550CC-1C7E-4C7B-A2F8-3A8DDC978C8C}" = lport=138 | protocol=17 | dir=in | app=system |

"{08E024BB-596A-4DFF-A430-159062EB67CE}" = lport=10243 | protocol=6 | dir=in | app=system |

"{19A5737B-0BEE-43C8-BCD3-3CC714AA4FD3}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |

"{25B9D31D-64EC-44F5-900B-17177C3E5D3C}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |

"{295EF879-34FC-4A05-A484-51AA1443280E}" = lport=445 | protocol=6 | dir=in | app=system |

"{2FA65B31-3A9D-4C20-AFC6-469495F0EF44}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |

"{4084E937-EAAA-47EE-9520-7BE7CE434C09}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |

"{4BF5EB07-06A2-40E2-B5B6-244EF5C49A0F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |

"{5456EA1E-AF45-48BD-9C96-AB99A6CCF1D9}" = lport=139 | protocol=6 | dir=in | app=system |

"{6364B77A-8796-4078-B3CC-5963A3E70B4F}" = rport=139 | protocol=6 | dir=out | app=system |

"{6EFD3216-D4DB-448C-81DA-E8838C66FFD2}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |

"{7C7BD74E-D59D-40F9-8481-A74C4729E9DD}" = rport=138 | protocol=17 | dir=out | app=system |

"{86444BB3-291D-4D31-A046-BB4AA3243C28}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |

"{AF8150A9-8B4A-4262-900E-D368942052B3}" = lport=2869 | protocol=6 | dir=in | app=system |

"{BE10AB93-C4A6-464B-BE93-069E778BFF99}" = rport=10243 | protocol=6 | dir=out | app=system |

"{C232D951-55E7-4D04-9346-F88A07FC0B22}" = lport=137 | protocol=17 | dir=in | app=system |

"{C428A183-FD79-40B5-990D-895328F43AC8}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |

"{CF0676E6-E2EC-438A-9741-7029DEBD00CE}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |

"{F534D21D-02A4-4E48-A237-A3745ED5E6D3}" = rport=137 | protocol=17 | dir=out | app=system |

"{F9C1EEE5-72B7-40C6-BC7C-64E9DF7DEB39}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========


"{003C7A18-60D9-4C89-94D8-DE42C1AA1D76}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |

"{02A4D600-582A-4C14-ADFE-C125CF0CB18F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |

"{1473D86F-6F04-46A3-9153-CD04272511DC}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |

"{4849799C-D8E9-4360-8F9A-6B5F2BCC7EA4}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |

"{56E808A1-BFD0-4B79-B567-B9FA848D697F}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |

"{61FB8AD2-C831-45AB-9DFB-D685C3A8300D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |

"{62F27534-2769-4D2F-B42F-E96E62F64F44}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |

"{65901CFC-D156-4C8F-90EA-C26D256CA195}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |

"{68F6992D-6E9D-4F14-88EC-3E0B8BEC7EFF}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |

"{8642AF85-31DC-4BB3-8E9D-1E478C224084}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |

"{A5589677-56C4-46C1-A86B-1F0B5425786F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |

"{AB3FBA72-52C3-4476-9A38-230DBE05659B}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |

"{BC7833D1-AE4B-4CAB-BDD5-6EA587E5C763}" = protocol=6 | dir=out | app=system |

"{CE504808-152F-4073-8BB9-0F8E7C4D30C6}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |

"{D3648D1D-2BA3-4973-9B7E-EDC907B6E342}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |

"{E8715BB0-E132-4617-B344-62E03BFE2C1C}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |

"{E926E57D-011D-4F63-BCC5-FFCFDC28D091}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |

"{EFA98652-B437-42AA-B7D3-EFFD71ED4ECD}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |

"{F7DCF881-DB9D-4779-8D1C-CCCBAC7C73FF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

OTL logfile created on: 24/08/2012 1:30:07 PM - Run 1

OTL by OldTimer - Version Folder = C:\Users\Max Cross\Desktop

64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation

Internet Explorer (Version = 9.0.8112.16421)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: dd/MM/yyy

7.98 Gb Total Physical Memory | 5.51 Gb Available Physical Memory | 68.97% Memory free

15.96 Gb Paging File | 13.36 Gb Available in Paging File | 83.70% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

Drive C: | 97.56 Gb Total Space | 8.54 Gb Free Space | 8.76% Space Free | Partition Type: NTFS

Drive D: | 368.10 Gb Total Space | 36.69 Gb Free Space | 9.97% Space Free | Partition Type: NTFS

Computer Name: MAXCROSS-PC | User Name: Max Cross | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans

Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

[2012/08/23 19:15:57 | 000,098,344 | ---- | C] () -- C:\Windows\unTMV.exe

[2012/08/23 18:33:25 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe

[2012/08/23 18:33:25 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe

[2012/08/23 18:33:25 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe

[2012/08/23 18:33:25 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe

[2012/08/23 18:33:25 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe

[2012/08/14 11:25:59 | 000,002,419 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Mobile Device Center.lnk

[2012/08/13 14:35:44 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\extensions.sqlite

[2012/08/13 14:35:41 | 000,000,620 | ---- | C] () -- C:\Windows\SysWow64\InstallUtil.InstallLog

[2012/08/12 20:45:18 | 000,010,248 | ---- | C] () -- C:\Users\Max Cross\AppData\Roaming\fk1xxx.e2ts

[2012/08/02 16:44:08 | 000,001,962 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SugarSync Manager.lnk

[2012/07/25 16:01:16 | 000,002,081 | ---- | C] () -- C:\ProgramData\ENG.2012-07.pl.nicolasgames_B05A5A11-F525-40DF-AE67-58228603B921.swidtag

[2012/07/21 21:11:54 | 000,000,067 | ---- | C] () -- C:\Windows\lz_scm.ini

[2012/07/03 12:05:32 | 000,002,315 | ---- | C] () -- C:\Users\Max Cross\AppData\Local\recently-used.xbel

[2012/05/23 21:06:30 | 000,029,696 | ---- | C] () -- C:\Users\Max Cross\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2012/05/23 09:17:32 | 000,650,752 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll

[2012/05/23 09:17:32 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll

[2012/05/23 09:17:32 | 000,216,064 | ---- | C] ( ) -- C:\Windows\SysWow64\lagarith.dll

[2012/05/23 09:17:31 | 000,079,872 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll

[2012/05/06 14:31:10 | 000,026,185 | ---- | C] () -- C:\Windows\scunin.dat

[2012/04/30 12:17:24 | 000,001,025 | ---- | C] () -- C:\Windows\SysWow64\sysprs7.dll

[2012/04/30 12:17:23 | 000,000,205 | ---- | C] () -- C:\Windows\SysWow64\lsprst7.dll

[2012/04/06 19:15:22 | 000,000,193 | ---- | C] () -- C:\Windows\WORDPAD.INI

[2012/03/24 20:04:52 | 000,007,606 | ---- | C] () -- C:\Users\Max Cross\AppData\Local\Resmon.ResmonCfg

[2012/03/23 20:09:03 | 000,036,892 | ---- | C] () -- C:\Windows\SysWow64\bassmod.dll

[2012/03/22 17:03:38 | 000,000,799 | ---- | C] () -- C:\Users\Max Cross\AppData\Roaming\MPQEditor.ini

[2012/03/22 16:18:52 | 000,000,040 | ---- | C] () -- C:\ProgramData\ra3.ini

[2012/03/22 15:23:24 | 000,777,148 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI

[2012/03/21 11:28:12 | 000,175,616 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll

[2011/08/03 04:31:54 | 000,311,912 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe

OK. I reinstalled MBAM but still no update posible. I get the same error.

I also have a couple of more questions, if I may.

1. Should I check Delete Quarantine Files on ESET before closing?

2. Could you explain please a little about what actually did the programs I ran? I'm curious what fixed what, what files were deleted and which were cleaned. Of course, if it takes too much time, it's not necessary. You spent enough time as it is helping me. Even so, I would be thankful if you would tell me if other files that the ones ESET quarantined were deleted. My brother has been inquiring about this for a while. So a short report would be welcome, if possible.

3. I still have $AVG and $RECYCLE.BIN folders on my two partitions... what's up with those?

I presume that TDSSKiller only scanned and reported, since it found no threats. DDS only scanned. And ESET Scanned and fixed. But I'm not sure about ComboFix, I'm guessing it also fixed stuff. It must have fixed the main problem when I launched it with that script you posted.

In any case, both me and my brother appreciated the time you spent with us (actually, me, he didn't do a thing) fixing this problem. We couldn't have done it without you. Thank you.

1. Should I check Delete Quarantine Files on ESET before closing?

No, you shouldn't for now.

2. Could you explain please a little about what actually did the programs I ran? I'm curious what fixed what, what files were deleted and which were cleaned. Of course, if it takes too much time, it's not necessary. You spent enough time as it is helping me. Even so, I would be thankful if you would tell me if other files that the ones ESET quarantined were deleted. My brother has been inquiring about this for a while. So a short report would be welcome, if possible.

These questions require answers and pretty much details. If you want to get them to sign up for training:


What was found from ESET Online Scanner was removed successfully. In other tools, depends on me.

I still have $AVG and $RECYCLE.BIN folders on my two partitions... what's up with those?

One folder belongs to the AVG Security Software, the other to your Windows. These folders are hidden by default when complete will not see them anymore.

Please try to re-install Malwarebytes' Anti-Malware and try again.

Please try to re-install Malwarebytes' Anti-Malware and try again.

The first time, I installed MBAM over itself, it didn't work. This time, I uninstalled it first, then installed it again. Still getting the same error.

P.S. So, with the exception of the files quarantined by ESET Online Scanner, were there any other files deleted on this PC? Did TDSSKiller or ComboFix or OTL delete anything?

Link to post
  • Download and run mbam-clean.exe from here
  • It will ask to restart your computer, please allow it to do so very important
  • After the computer restarts, temporarily disable your Anti-Virus and install the latest version of Malwarebytes' Anti-Malware from here

    • Note: You will need to reactivate the program using the license you were sent via email if using the Pro version
    • Launch the program and set the Protection and Registration. Then go to the UPDATE tab if not done during installation and check for updates.
      Restart the computer again and verify that MBAM is in the task tray if using the Pro version. Now setup any file exclusions as may be required in your Anti-Virus/Internet-Security/Firewall applications and restart your Anti-Virus/Internet-Security applications. You may use the guides posted in the FAQ's here or ask and we'll explain how to do it.

Ok, my most humble appologies, but it turned out that it was the AVG Firewall that was stopping the update. I finally managed to update with the firewall down. Normally, AVG asks if I want to allow something through or not, this time it did not. MBAM is finally able to update... as long as the firewall is down. When I put it back up, it gives me the same error.

Yeah... MBAM was blocked in the firewall for some reason, I'm going to have to ask my brother about why it was, but problem fixed. MBAM is up and running with no further problems. I'll check Windows Update after posting this.

Anyways, what do I do with the files ESET moved to the Qoobox folder in C?

And what's with all the new folders in C? I've got Config.Msi, MSOCache, PrefLogs, Recovery and I don't remember them being here before. Every folder but PrefLogs also has a "lock" on it's icon.

Link to post
