dslreports logo
site
    All Forums Hot Topics Gallery
spc
Search Topic:
uniqs
3
share rss forum feed

Carcassonne

join:2012-11-26
11000
reply to LoPhatPhuud

Re: [Malware] Starburn software problem -Virus/malware?

I have done both those things and I am not given that option. I just get a list of 12 previously search items


Carcassonne

join:2012-11-26
11000

sorry should have said I have never noticed Skysearch coming up


Carcassonne

join:2012-11-26
11000

Ok - I uninstalled Utorrent
No utorrentControl v2 toolbar
No A youtube Downloader
When I tried to remove Yontoo I got the message:
C:\Document~\ALLUSE~1\APPLIC~1\TarmaInstaller\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\setup.dat
Error2 while loading archive: The system cannot find the specified file
While trying to get rid of Skywebsearch I noticed that A Youtube downloader was enabled again despite my having previously disabled it – I do not seem to be able to remove it.
OTL Scan results:
OTL logfile created on: 27/11/2012 19:00:53 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\annas\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.99 Gb Total Physical Memory | 1.34 Gb Available Physical Memory | 67.20% Memory free
7.81 Gb Paging File | 7.34 Gb Available in Paging File | 93.92% Paging File free
Paging file location(s): C:\pagefile.sys 3057 3057D:\pagef [Binary data over 200 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.82 Gb Total Space | 25.41 Gb Free Space | 36.40% Space Free | Partition Type: NTFS
Drive D: | 68.36 Gb Total Space | 61.50 Gb Free Space | 89.97% Space Free | Partition Type: NTFS
Drive E: | 195.31 Gb Total Space | 50.71 Gb Free Space | 25.96% Space Free | Partition Type: NTFS
Drive F: | 202.09 Gb Total Space | 26.30 Gb Free Space | 13.02% Space Free | Partition Type: NTFS
Drive G: | 10.53 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive H: | 3.66 Gb Total Space | 1.42 Gb Free Space | 38.95% Space Free | Partition Type: FAT32
Drive Z: | 465.76 Gb Total Space | 196.29 Gb Free Space | 42.14% Space Free | Partition Type: NTFS

Computer Name: DELL | User Name: annas | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2012/11/26 17:41:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\OTL.exe
PRC - [2012/10/30 23:50:59 | 004,297,136 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2012/10/30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2012/09/29 19:54:26 | 000,766,536 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012/09/29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/09/29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/09/24 22:12:59 | 000,161,768 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe
PRC - [2012/09/13 00:46:52 | 000,026,008 | ---- | M] (Uniblue Systems Ltd) -- C:\Program Files\Uniblue\SpeedUpMyPC\spmonitor.exe
PRC - [2012/09/12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2012/08/10 13:13:05 | 000,079,872 | ---- | M] (SanDisk Corporation) -- C:\Documents and Settings\annas\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe
PRC - [2012/07/08 13:39:22 | 000,026,016 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
PRC - [2012/03/14 04:48:58 | 003,051,619 | ---- | M] (Logitech Inc.) -- C:\Program Files\Squeezebox\SqueezeTray.exe
PRC - [2009/05/21 09:55:32 | 000,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2008/09/10 16:22:32 | 000,229,648 | ---- | M] (Uniblue) -- C:\Program Files\Uniblue\DiskRescue\UBDiskRescueSrv.exe
PRC - [2008/08/13 17:32:40 | 000,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2008/04/14 01:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/06/05 13:20:32 | 000,177,704 | ---- | M] () -- C:\WINDOWS\system32\PSIService.exe
PRC - [2007/03/15 11:09:36 | 000,460,784 | ---- | M] (Gteko Ltd.) -- C:\Program Files\DellSupport\DSAgnt.exe
PRC - [2005/09/29 04:02:26 | 000,491,520 | ---- | M] ( ) -- C:\WINDOWS\system32\dlcfcoms.exe

[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2012/11/27 13:40:20 | 000,024,701 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\93e7e3d6030f426844228042348210cf\Service.dll
MOD - [2012/11/27 13:40:18 | 000,184,414 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\bd5179a413bc0c4b82eedc22c6cab101\re.dll
MOD - [2012/11/27 13:40:14 | 000,053,340 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\de446fdd1ae335c7d2b9e62bb8cdf765\B.dll
MOD - [2012/11/27 13:40:13 | 000,094,334 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\eb138ef0e4282611dbf485a302784646\LibYAML.dll
MOD - [2012/11/27 13:40:12 | 000,061,540 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\e56c61f7248672819579325af3387035\POSIX.dll
MOD - [2012/11/27 13:40:11 | 000,024,676 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\32785c19dc6898fbbbf06f3b776edd08\Fcntl.dll
MOD - [2012/11/27 13:40:09 | 000,082,033 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\df1ba73f49c38cbbc7a11c779c3506d2\OLE.dll
MOD - [2012/11/27 13:40:07 | 000,020,590 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\5ffd05b2cbd58528e56519784ca9c869\Hostname.dll
MOD - [2012/11/27 13:40:06 | 000,036,964 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\f233f63b6654362865c7577442edb9e3\Win32.dll
MOD - [2012/11/27 13:40:05 | 000,020,576 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\31638f63e39b38d3e250a9a57cb9d1c5\Cwd.dll
MOD - [2012/11/27 13:40:03 | 000,082,048 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\3a7ccbf8181ee5a145227a6dfce3594c\WinError.dll
MOD - [2012/11/27 13:40:02 | 000,118,918 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\eaeabd54205de2f10c00aea80bbf0d83\Registry.dll
MOD - [2012/11/27 13:40:01 | 000,020,601 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\4461f48e31bde5c56b31b973b773de09\List.dll
MOD - [2012/11/27 13:40:00 | 000,028,779 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\60ff464e01c2cd5526dbdad5a125081d\Dumper.dll
MOD - [2012/11/27 13:39:59 | 000,024,701 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\d10c2c06ba2044cccc247c4315f5c7d3\Process.dll
MOD - [2012/11/27 13:39:58 | 000,032,878 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\7ef0d901bf4203fbcf7a0fff0e82aa5f\Encode.dll
MOD - [2012/11/27 13:39:56 | 000,024,679 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\c5cce8d16a1bd48692b421dcf46d3396\Util.dll
MOD - [2012/11/27 13:39:43 | 000,028,774 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\d1e7c33431cd8713f2ce3582829a8b14\Socket.dll
MOD - [2012/11/27 09:19:43 | 002,034,176 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\12112700\algo.dll
MOD - [2012/11/24 00:17:52 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\d35b50eb6bb7b1bfb6592419d9feba47\System.Xml.ni.dll
MOD - [2012/11/24 00:14:12 | 007,977,472 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\90ad0c96693527ae685ff40019bb33b0\System.ni.dll
MOD - [2012/11/24 00:13:55 | 011,492,352 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\3add69b075f3da012fb97ce00cd795c0\mscorlib.ni.dll
MOD - [2007/09/20 18:34:58 | 000,129,024 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2007/06/27 15:21:20 | 000,086,016 | ---- | M] () -- F:\Downloads\Free Download Manager\FUM\fumshext.dll
MOD - [2007/06/05 13:20:32 | 000,177,704 | ---- | M] () -- C:\WINDOWS\system32\PSIService.exe
MOD - [2005/09/29 03:02:18 | 000,114,688 | ---- | M] () -- C:\WINDOWS\system32\spool\drivers\w32x86\3\dlcfflib.dll
MOD - [2005/09/29 03:02:16 | 000,479,232 | ---- | M] () -- C:\WINDOWS\system32\spool\drivers\w32x86\3\dlcfhpec.dll
MOD - [2005/08/26 07:43:48 | 000,065,536 | ---- | M] () -- C:\WINDOWS\system32\spool\drivers\w32x86\3\dlcfcfg.dll

[color=#E56717]========== Services (SafeList) ==========[/color]

SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - File not found [Auto | Stopped] -- -- (EasyBoxApache)
SRV - [2012/11/24 16:11:09 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/10/30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2012/10/09 17:30:34 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/09/29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/09/29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012/09/24 22:12:59 | 000,161,768 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2012/09/12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012/07/13 12:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/03/14 04:49:48 | 014,057,569 | ---- | M] (Logitech Inc.) [Auto | Stopped] -- C:\Program Files\Squeezebox\server\SqueezeSvr.exe -- (squeezesvc)
SRV - [2011/06/13 22:09:22 | 000,267,568 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Fix it Center\Matsvc.exe -- (MatSvc)
SRV - [2011/03/16 09:42:06 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2010/02/17 18:21:24 | 000,245,760 | ---- | M] (SMServer) [On_Demand | Stopped] -- C:\WINDOWS\system32\snmvtsvc.exe -- (SMServer)
SRV - [2008/11/19 15:30:07 | 000,016,680 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe -- (GoToAssist)
SRV - [2008/09/10 16:22:32 | 000,229,648 | ---- | M] (Uniblue) [Auto | Running] -- C:\Program Files\Uniblue\DiskRescue\UBDiskRescueSrv.exe -- (Uniblue DiskRescue)
SRV - [2008/08/13 17:32:40 | 000,201,968 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_dellsupportcenter)
SRV - [2007/06/05 13:20:32 | 000,177,704 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\PSIService.exe -- (ProtexisLicensing)
SRV - [2007/03/07 15:47:46 | 000,076,848 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\DellSupport\brkrsvc.exe -- (DSBrokerService)
SRV - [2005/09/29 04:02:26 | 000,491,520 | ---- | M] ( ) [On_Demand | Running] -- C:\WINDOWS\system32\dlcfcoms.exe -- (dlcf_device)

[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (wanatw)
DRV - File not found [Kernel | Boot | Stopped] -- -- (tclondrv)
DRV - File not found [Kernel | Boot | Stopped] -- -- (szkg)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (mcdbus)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2012/10/30 23:51:58 | 000,738,504 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2012/10/30 23:51:58 | 000,361,032 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2012/10/30 23:51:58 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2012/10/30 23:51:58 | 000,035,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (AswRdr)
DRV - [2012/10/30 23:51:57 | 000,097,608 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2012/10/30 23:51:56 | 000,025,256 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2012/10/30 23:51:56 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2012/09/29 19:54:26 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(5).sys -- (WsAudio_DeviceS(5)
DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(4).sys -- (WsAudio_DeviceS(4)
DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(3).sys -- (WsAudio_DeviceS(3)
DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(2).sys -- (WsAudio_DeviceS(2)
DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(1).sys -- (WsAudio_DeviceS(1)
DRV - [2012/01/05 00:01:54 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\taphss.sys -- (taphss)
DRV - [2010/02/18 07:57:18 | 000,023,096 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\TucbAudio.sys -- (TucbAudio)
DRV - [2010/02/16 11:44:26 | 000,037,920 | ---- | M] (RapidSolution Software AG) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tbhsd.sys -- (tbhsd)
DRV - [2008/09/16 18:09:24 | 000,030,080 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RKHit.sys -- (RkHit)
DRV - [2008/05/22 14:06:01 | 000,027,136 | ---- | M] (NCH Swift Sound) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nchssvad.sys -- (NCHSSVAD)
DRV - [2007/02/25 12:10:48 | 000,005,376 | --S- | M] (Gteko Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\dsunidrv.sys -- (dsunidrv)
DRV - [2006/10/05 16:07:28 | 000,004,736 | ---- | M] (Gteko Ltd.) [Kernel | On_Demand | Running] -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys -- (DSproct)
DRV - [2006/10/03 14:06:38 | 000,022,656 | R--- | M] (Guillemot Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\camfilt.sys -- (camfilt)
DRV - [2006/09/29 10:12:00 | 000,274,816 | ---- | M] (Guillemont Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BLvid.sys -- (APL531)
DRV - [2005/11/16 21:36:00 | 001,047,816 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2004/08/03 22:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139)

[color=#E56717]========== Standard Registry (SafeList) ==========[/color]

[color=#E56717]========== Internet Explorer ==========[/color]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com/?crg=3.1010000.10011&barid={3944DCAE-EE02-11E1-996B-00C12606FC20}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\..\URLSearchHook: {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software)
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\..\URLSearchHook: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software)
IE - HKCU\..\URLSearchHook: {da21bd13-ca22-42e3-a071-98f08f1ca1e7} - SOFTWARE\Classes\CLSID\{da21bd13-ca22-42e3-a071-98f08f1ca1e7}\InprocServer32 File not found
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
IE - HKCU\..\SearchScopes\{420efb88-346f-4cb5-bbb1-cfd5efad5439}: "URL" = http://apype.com/results.php?q={searchTerms}
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3220468
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.search.defaultenginename: "Custom search"
FF - prefs.js..browser.search.selectedEngine: "Custom search"
FF - prefs.js..browser.startup.homepage: "http://apype.com"
FF - prefs.js..extensions.enabledAddons: %7B20a82645-c095-46ed-80e3-08825760534b%7D:0.0.0
FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:7.0.1474
FF - prefs.js..extensions.enabledAddons: %7Be001c731-5e37-4538-a5cb-8168736a2360%7D:0.9.9.119
FF - prefs.js..keyword.URL: "http://apype.com/results.php?q="
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Program Files\DNA\plugins\npbtdna.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1483: C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{0153E448-190B-4987-BDE1-F256CADA672F}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012/11/25 18:27:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/11/24 20:02:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/11/24 20:02:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012/10/13 17:10:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2012/10/13 17:09:50 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\14xRm@skywebsearch.com: C:\DOCUME~1\annas\A Youtube Downloader Free.xpi [2012/09/27 17:40:26 | 000,046,060 | ---- | M] ()

[2012/07/09 09:10:50 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Extensions
[2010/08/26 19:05:36 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012/07/09 09:10:50 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Extensions\songbird@songbirdnest.com
[2012/11/25 22:13:55 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Profiles\4zdzkxi8.default-1353843710664\extensions
[2012/11/25 22:13:55 | 000,000,000 | ---D | M] (Bitdefender QuickScan) -- C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Profiles\4zdzkxi8.default-1353843710664\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2012/11/24 20:22:49 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/11/25 18:27:15 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2009/09/01 21:58:53 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2012/11/24 16:11:10 | 000,262,112 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/09/05 17:35:28 | 000,129,176 | ---- | M] (RealPlayer) -- C:\Program Files\mozilla firefox\plugins\nprpplugin.dll
[2012/11/24 17:07:33 | 000,002,261 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\Custom search.xml

O1 HOSTS File: ([2012/01/30 17:35:54 | 000,000,822 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (uTorrentControl_v2 Toolbar) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (A Youtube Downloader Free) - {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (uTorrentControl_v2 Toolbar) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (A Youtube Downloader Free) - {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software)
O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentControl_v2 Toolbar) - {7473B6BD-4691-4744-A82B-7854EB3D70B6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [DLCFCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCFtime.DLL ()
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [LanceurEasyBox] "C:\Program Files\EasyBox\EasyBox.exe" -AutoStart File not found
O4 - HKCU..\Run: [RegistryBooster] "C:\Program Files\Uniblue\RegistryBooster\launcher.exe" delay 20000 File not found
O4 - HKCU..\Run: [SansaDispatch] C:\Documents and Settings\annas\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
O4 - HKCU..\Run: [SpeedUpMyPC] C:\Program Files\Uniblue\SpeedUpMyPC\launcher.exe (Uniblue Systems Ltd)
O4 - HKCU..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED File not found
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Media Server Tray Tool.lnk = C:\Program Files\Squeezebox\SqueezeTray.exe (Logitech Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Philips GoGear VIBE Device Manager.lnk = C:\Program Files\Philips\GoGear VIBE Device Manager\GoGear_Vibe_DeviceManager.exe (Philips)
O4 - Startup: C:\Documents and Settings\annas\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\annas\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Subscribe with ArchosLink - Reg Error: Value error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: gouv.fr ([www.impots] http in Trusted sites)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} http://eic.lgservice.com/DjvuViewer/DjVuControl-6.1.4.cab (DjVuCtl Class)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1144743462484 (WUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.27.40.241 212.27.40.240
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7C338859-52A3-49F6-AED7-DBFF78ABE174}: DhcpNameServer = 212.27.40.241 212.27.40.240
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7C338859-52A3-49F6-AED7-DBFF78ABE174}: NameServer = 8.8.8.8,8.8.8.4
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FE60E668-8D91-4FCF-A5B3-C0421F29144F}: NameServer = 212.27.53.252,212.27.54.252
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\application/x-internet-signup {A173B69A-1F9B-4823-9FDA-412F641E65D6} - Reg Error: Value error. File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Desktop Background.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Desktop Background.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 04:43:04 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2006/09/14 11:31:11 | 000,000,030 | R--- | M] () - G:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{5bd8fb02-d866-11e0-9845-00c12606fc20}\Shell - "" = AutoRun
O33 - MountPoints2\{5bd8fb02-d866-11e0-9845-00c12606fc20}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{5bd8fb02-d866-11e0-9845-00c12606fc20}\Shell\AutoRun\command - "" = I:\SafeStick.exe
O33 - MountPoints2\{715c34c2-d645-11e1-9941-00c12606fc20}\Shell - "" = AutoRun
O33 - MountPoints2\{715c34c2-d645-11e1-9941-00c12606fc20}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{715c34c2-d645-11e1-9941-00c12606fc20}\Shell\AutoRun\command - "" = H:\PMCsetup.exe
O33 - MountPoints2\{e90fc898-c743-11e1-992f-00c12606fc20}\Shell - "" = AutoRun
O33 - MountPoints2\{e90fc898-c743-11e1-992f-00c12606fc20}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{e90fc898-c743-11e1-992f-00c12606fc20}\Shell\AutoRun\command - "" = H:\PMCsetup.exe
O34 - HKLM BootExecute: (autocheck autochk /k:E *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2012/11/27 10:14:40 | 002,213,976 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\annas\Desktop\tdsskiller.exe
[2012/11/26 18:09:08 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012/11/26 17:50:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Desktop\Virus nov2012
[2012/11/26 17:40:47 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\OTL.exe
[2012/11/26 14:25:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/11/26 14:24:53 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012/11/26 13:52:17 | 000,448,512 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\TFC.exe
[2012/11/26 10:46:22 | 000,000,000 | -H-D | C] -- C:\Program Files\WindowsUpdate
[2012/11/26 10:26:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\ParetoLogic
[2012/11/26 10:25:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2012/11/26 10:01:09 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012/11/25 23:41:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Local Settings\Application Data\FixItCenter
[2012/11/25 23:10:55 | 000,000,000 | ---D | C] -- C:\WINDOWS\MATS
[2012/11/25 23:10:53 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Fix it Center
[2012/11/25 23:09:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows PowerShell 1.0
[2012/11/25 23:09:15 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\windowspowershell
[2012/11/25 22:36:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\DriverCure
[2012/11/25 22:36:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\PC Utility Kit
[2012/11/25 22:36:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Start Menu\Programs\PC Utility Kit
[2012/11/25 22:36:12 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Utility Kit
[2012/11/25 22:36:08 | 000,000,000 | ---D | C] -- C:\Program Files\PC Utility Kit
[2012/11/25 22:36:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PC Utility Kit
[2012/11/25 22:14:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\QuickScan
[2012/11/25 18:27:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus
[2012/11/25 18:27:50 | 000,361,032 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2012/11/25 18:27:50 | 000,021,256 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2012/11/25 18:27:46 | 000,035,928 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2012/11/25 18:27:45 | 000,054,232 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2012/11/25 18:27:44 | 000,738,504 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2012/11/25 18:27:42 | 000,097,608 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2012/11/25 18:27:42 | 000,089,752 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2012/11/25 18:27:41 | 000,025,256 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2012/11/25 18:26:53 | 000,041,224 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2012/11/25 18:26:51 | 000,227,648 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2012/11/25 18:26:11 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2012/11/25 18:26:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2012/11/25 12:41:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Desktop\Old Firefox Data
[2012/11/24 20:22:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Local Settings\Application Data\PCHealth
[2012/11/24 20:21:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Start Menu\Programs\HomePlayer
[2012/11/24 20:21:02 | 000,000,000 | ---D | C] -- C:\Program Files\HomePlayer
[2012/11/24 20:20:34 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrentControl_v2
[2012/11/24 17:40:42 | 000,237,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MpSigStub.exe
[2012/11/24 17:26:03 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012/11/24 16:11:01 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2012/11/23 23:19:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Local Settings\Application Data\uTorrentControl_v2
[2012/11/23 14:04:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\Malwarebytes
[2012/11/23 14:04:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012/11/23 14:04:20 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/11/15 19:28:39 | 000,000,000 | ---D | C] -- C:\Program Files\HomePlayer(2)
[2012/09/27 17:40:26 | 000,447,488 | ---- | C] (HotSummerWind Software) -- C:\Documents and Settings\annas\A Youtube Downloader Free.dll

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2012/11/27 18:30:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/11/27 18:27:00 | 000,000,314 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2012/11/27 18:00:00 | 000,000,456 | ---- | M] () -- C:\WINDOWS\tasks\PC Utility Kit Registration3.job
[2012/11/27 15:14:00 | 000,000,580 | -H-- | M] () -- C:\WINDOWS\tasks\DataUpload.job
[2012/11/27 13:48:09 | 000,000,384 | -H-- | M] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012/11/27 13:38:38 | 000,000,616 | -H-- | M] () -- C:\WINDOWS\tasks\ConfigExec.job
[2012/11/27 13:38:38 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-459166176-3624373595-3541044804-1006.job
[2012/11/27 13:38:27 | 000,000,264 | ---- | M] () -- C:\WINDOWS\tasks\RegistryBooster.job
[2012/11/27 13:38:27 | 000,000,256 | ---- | M] () -- C:\WINDOWS\tasks\SpeedUpMyPC.job
[2012/11/27 13:37:51 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/11/27 10:14:49 | 002,213,976 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\annas\Desktop\tdsskiller.exe
[2012/11/27 09:43:52 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/11/26 21:30:10 | 000,001,623 | ---- | M] () -- C:\scu.dat
[2012/11/26 17:58:09 | 000,856,731 | ---- | M] () -- C:\Documents and Settings\annas\Desktop\SecurityCheck.exe
[2012/11/26 17:41:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\OTL.exe
[2012/11/26 14:25:07 | 000,000,802 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/26 13:52:25 | 000,448,512 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\TFC.exe
[2012/11/25 23:17:27 | 000,000,736 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Fix it Center.lnk
[2012/11/25 22:37:27 | 000,001,478 | ---- | M] () -- C:\Documents and Settings\annas\Application Data\Microsoft\Internet Explorer\Quick Launch\Media Center.lnk
[2012/11/25 22:36:19 | 000,000,911 | ---- | M] () -- C:\Documents and Settings\annas\Desktop\PC Utility Kit.lnk
[2012/11/25 22:36:19 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\PC Utility Kit Update3.job
[2012/11/25 22:36:17 | 000,000,420 | ---- | M] () -- C:\WINDOWS\tasks\PC Utility Kit.job
[2012/11/25 18:27:51 | 000,001,695 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2012/11/25 18:27:43 | 000,002,638 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2012/11/24 19:00:38 | 000,002,412 | ---- | M] () -- C:\WINDOWS\System32\lgAxconfig.ini
[2012/11/24 17:26:52 | 000,001,945 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2012/11/24 17:07:33 | 000,000,034 | ---- | M] () -- C:\Program Files\Mozilla Firefoxoverride.ini
[2012/11/24 17:07:28 | 000,023,145 | ---- | M] () -- C:\Documents and Settings\annas\config.cfg
[2012/11/24 11:15:14 | 000,181,040 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/11/24 10:42:41 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/11/24 00:13:11 | 000,545,318 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/11/24 00:13:11 | 000,107,032 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/11/23 23:35:34 | 000,000,434 | ---- | M] () -- C:\Documents and Settings\annas\Desktop\Shortcut to Problems Nov 2012.lnk
[2012/11/22 12:52:01 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-459166176-3624373595-3541044804-1006.job
[2012/11/20 16:24:00 | 000,000,270 | ---- | M] () -- C:\WINDOWS\tasks\Uniblue SpeedUpMyPC Nag.job
[2012/10/31 21:27:54 | 000,236,218 | ---- | M] () -- C:\28086-utorrent.0000.dmp
[2012/10/30 23:51:58 | 000,738,504 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2012/10/30 23:51:58 | 000,361,032 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2012/10/30 23:51:58 | 000,054,232 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2012/10/30 23:51:58 | 000,035,928 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2012/10/30 23:51:57 | 000,097,608 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2012/10/30 23:51:57 | 000,089,752 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2012/10/30 23:51:56 | 000,025,256 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2012/10/30 23:51:56 | 000,021,256 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2012/10/30 23:51:07 | 000,041,224 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2012/10/30 23:50:59 | 000,227,648 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2012/11/26 18:24:11 | 000,001,623 | ---- | C] () -- C:\scu.dat
[2012/11/26 17:57:45 | 000,856,731 | ---- | C] () -- C:\Documents and Settings\annas\Desktop\SecurityCheck.exe
[2012/11/26 14:25:07 | 000,000,802 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/25 23:14:40 | 000,000,580 | -H-- | C] () -- C:\WINDOWS\tasks\DataUpload.job
[2012/11/25 23:14:39 | 000,000,616 | -H-- | C] () -- C:\WINDOWS\tasks\ConfigExec.job
[2012/11/25 23:11:00 | 000,000,742 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Fix it Center.lnk
[2012/11/25 23:11:00 | 000,000,736 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Fix it Center.lnk
[2012/11/25 22:36:36 | 000,000,456 | ---- | C] () -- C:\WINDOWS\tasks\PC Utility Kit Registration3.job
[2012/11/25 22:36:19 | 000,000,911 | ---- | C] () -- C:\Documents and Settings\annas\Desktop\PC Utility Kit.lnk
[2012/11/25 22:36:18 | 000,000,422 | ---- | C] () -- C:\WINDOWS\tasks\PC Utility Kit Update3.job
[2012/11/25 22:36:16 | 000,000,420 | ---- | C] () -- C:\WINDOWS\tasks\PC Utility Kit.job
[2012/11/25 18:27:51 | 000,001,695 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2012/11/25 18:27:42 | 000,000,314 | -H-- | C] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2012/11/24 17:36:30 | 000,000,384 | -H-- | C] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012/11/24 17:26:31 | 000,001,714 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/11/24 17:05:29 | 000,001,945 | ---- | C] () -- C:\WINDOWS\epplauncher.mif
[2012/11/23 23:35:38 | 000,000,434 | ---- | C] () -- C:\Documents and Settings\annas\Desktop\Shortcut to Problems Nov 2012.lnk
[2012/10/31 21:27:52 | 000,236,218 | ---- | C] () -- C:\28086-utorrent.0000.dmp
[2012/10/26 16:38:26 | 094,065,368 | R--- | C] () -- C:\Documents and Settings\annas\firmware_archos_android_gen8.aos
[2012/10/16 08:19:46 | 000,023,145 | ---- | C] () -- C:\Documents and Settings\annas\config.cfg
[2012/10/13 17:10:25 | 000,000,034 | ---- | C] () -- C:\Program Files\Mozilla Firefoxoverride.ini
[2012/09/27 17:40:26 | 000,046,060 | ---- | C] () -- C:\Documents and Settings\annas\A Youtube Downloader Free.xpi
[2012/07/09 09:08:19 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\DriverCoInstaller.dll
[2012/07/09 09:08:05 | 000,011,264 | ---- | C] () -- C:\WINDOWS\System32\rockusbCoInstaller.dll
[2012/02/14 22:15:34 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2010/12/30 16:36:29 | 000,001,580 | ---- | C] () -- C:\Documents and Settings\annas\.recently-used.xbel
[2010/12/27 17:45:33 | 000,000,759 | ---- | C] () -- C:\Documents and Settings\annas\.ufrawrc
[2010/02/17 15:24:53 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\annas\Local Settings\Application Data\PUTTY.RND
[2008/11/19 15:29:47 | 000,061,224 | ---- | C] () -- C:\Documents and Settings\annas\GoToAssistDownloadHelper.exe
[2008/11/18 17:34:06 | 000,000,378 | ---- | C] () -- C:\Documents and Settings\annas\Application Data\burnaware.ini
[2007/03/24 21:17:54 | 000,001,755 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/04/11 23:16:15 | 000,108,032 | ---- | C] () -- C:\Documents and Settings\annas\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/04/11 08:55:40 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\annas\Local Settings\Application Data\fusioncache.dat

[color=#E56717]========== ZeroAccess Check ==========[/color]

[2005/08/16 04:39:16 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2011/12/19 09:53:33 | 001,510,400 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 13:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/14 01:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[color=#E56717]========== Files - Unicode (All) ==========[/color]
[2008/08/19 02:11:54 | 000,000,000 | ---D | M](C:\WINDOWS\System32\?ý??????????) -- C:\WINDOWS\System32\ý
[2008/08/19 02:11:54 | 000,000,000 | ---D | C](C:\WINDOWS\System32\?ý??????????) -- C:\WINDOWS\System32\ý

[color=#E56717]========== Alternate Data Streams ==========[/color]

@Alternate Data Stream - 235 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8E5EA40F
@Alternate Data Stream - 176 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EEFF768F
@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B174FAE
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AC6124CA