Hello Rrredblack009,
In addition to what Richard has said, I would request you to help me with the following details:
- Since when are you facing the issue?
- Is it happening as soon as you turn on the computer?
- Were there any recent hardware or software changes made on the computer?
- Did you check in safe mode if the issue persists? In order to boot the computer into Safe Mode, restart the computer and keep tapping F8 key. From the Advanced Boot Option, select Safe Mode and check the functionality.
Please write back with the details.
Hello allan, the issue since 1 years ago..!!yes, it is happening from booting process....!!more precisely at a time when the logo "Intel"!!on firstly screen appear..!!
no hardware or software recently change...!!
a few hour ago...!!im just do the same things with malwarebytes, combofix and sfc /scannow on safe mode to solve this issue..!!
Here I include the log file and my computer sytem imformation together...!!
this is log for "ComboFix" :
ComboFix 13-08-20.01 - User 22/08/2013 0:38.1.2 - x86 MINIMAL
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.60.1033.18.2044.1468 [GMT 8:00]
Running from: c:\users\User\Downloads\Programs\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: IObit Malware Fighter *Disabled/Outdated* {A751AC20-3B48-5237-898A-78C4436BB78D}
SP: Microsoft Security Essentials *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\desktop.ini
c:\users\User\AppData\Local\Microsoft\Windows\Temporary Internet Files\ApnStub.exe
c:\users\User\AppData\Roaming\.#
c:\users\User\AppData\Roaming\DefaultTab\DefaultTab
c:\users\User\AppData\Roaming\DefaultTab\DefaultTab\addon.ico
c:\users\User\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.cfg
c:\users\User\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabUninstaller.exe
c:\users\User\AppData\Roaming\DefaultTab\DefaultTab\DT.ico
c:\users\User\AppData\Roaming\DefaultTab\DefaultTab\facebook_ie.ico
c:\users\User\AppData\Roaming\DefaultTab\DefaultTab\search_here_ie.ico
c:\users\User\AppData\Roaming\DefaultTab\DefaultTab\searchhere.ico
c:\users\User\AppData\Roaming\DefaultTab\DefaultTab\uninstalldt.exe
c:\users\User\AppData\Roaming\DefaultTab\DefaultTab\update.exe
c:\windows\system32\roboot.exe
c:\windows\system32\uxt34E5.tmp
.
.
((((((((((((((((((((((((( Files Created from 2013-07-21 to 2013-08-21 )))))))))))))))))))))))))))))))
.
.
2013-08-21 16:42 . 2013-08-21 16:43 -------- d-----w- c:\users\User\AppData\Local\temp
2013-08-21 16:42 . 2013-08-21 16:42 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-08-21 16:42 . 2013-08-21 16:42 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-08-21 13:14 . 2013-08-06 07:28 7166848 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{92EC2160-437E-4D7E-88A4-E52ED4BEB069}\mpengine.dll
2013-08-21 12:50 . 2013-08-21 12:50 -------- d-----w- C:\NvidiaLogging
2013-08-21 12:11 . 2013-08-21 12:59 -------- d-----w- c:\programdata\Systweak
2013-08-21 12:11 . 2012-07-25 04:03 17136 ----a-w- c:\windows\system32\sasnative32.exe
2013-08-21 12:10 . 2013-08-21 12:59 -------- d-----w- c:\users\User\AppData\Roaming\Systweak
2013-08-21 11:55 . 2013-08-21 11:56 -------- d-----w- c:\users\User\AppData\Local\eSupport.com
2013-08-21 11:55 . 2013-08-21 11:55 23456 ----a-w- c:\windows\system32\drivers\DrvAgent32.sys
2013-08-21 11:48 . 2013-08-21 11:49 -------- d-----w- c:\users\User\AppData\Local\Deployment
2013-08-21 11:45 . 2013-08-21 11:45 -------- d-----w- c:\programdata\UAB
2013-08-21 11:45 . 2013-08-21 11:45 -------- d-----w- c:\users\User\AppData\Local\PC_Drivers_Headquarters
2013-08-21 11:45 . 2013-08-21 11:45 -------- d-----w- c:\programdata\PC Drivers HeadQuarters
2013-08-21 11:43 . 2013-08-21 11:43 -------- d-----w- c:\program files\PC Drivers HeadQuarters
2013-08-21 11:41 . 2013-08-21 11:41 -------- d-----w- c:\programdata\APN
2013-08-21 10:49 . 2013-08-21 10:49 -------- d-----w- c:\program files\Smart Driver Updater
2013-08-21 10:48 . 2013-08-21 11:14 -------- d-----w- c:\users\User\AppData\Roaming\Smart Driver Updater
2013-08-21 09:18 . 2013-08-21 09:19 -------- d-----w- c:\programdata\BSD
2013-08-21 09:16 . 2013-08-21 09:18 -------- d-----w- c:\users\User\AppData\Roaming\Fighters
2013-08-21 09:16 . 2013-08-21 09:17 -------- d-----w- c:\program files\Fighters
2013-08-21 09:15 . 2013-08-21 09:17 -------- d-----w- c:\programdata\Fighters
2013-08-21 07:09 . 2013-08-21 07:09 -------- d-----w- c:\users\User\AppData\Roaming\QuickScan
2013-08-20 12:45 . 2013-07-01 15:54 7143960 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-08-20 11:56 . 2013-08-20 11:56 -------- d-----w- c:\users\User\AppData\Roaming\dll-files.com
2013-08-20 11:55 . 2013-08-20 11:58 -------- d-----w- c:\program files\Dll-Files.com Fixer
2013-08-20 10:01 . 2013-08-20 10:01 -------- d-----w- c:\windows\system32\RTCOM
2013-08-20 08:50 . 2013-08-20 08:50 -------- d-----w- c:\users\User\AppData\Local\NeoSmart_Technologies
2013-08-20 08:46 . 2013-08-20 08:46 -------- d-----w- c:\program files\NeoSmart Technologies
2013-08-19 20:31 . 2013-08-19 20:32 -------- d-----w- c:\programdata\SecTaskMan
2013-08-19 20:31 . 2013-08-19 20:31 -------- d-----w- c:\program files\Security Task Manager
2013-08-19 17:54 . 2013-05-22 10:49 29528 ----a-w- c:\windows\system32\SmartDefragBootTime.exe
2013-08-19 17:54 . 2013-05-22 10:49 15672 ----a-w- c:\windows\system32\drivers\SmartDefragDriver.sys
2013-08-16 17:49 . 2013-08-16 17:49 -------- d-----w- c:\users\User\AppData\Local\DDMSettings
2013-08-16 17:49 . 2013-08-16 17:49 -------- d-----w- c:\users\User\AppData\Local\Conduit
2013-08-16 17:47 . 2013-08-16 17:48 -------- d-----w- c:\users\User\AppData\Local\CRE
2013-08-16 17:47 . 2013-08-16 17:49 -------- d-----w- c:\program files\Conduit
2013-08-16 17:46 . 2013-08-19 23:41 -------- d-----w- c:\program files\SearchProtect
2013-08-16 17:44 . 2013-08-21 12:59 -------- d-----w- c:\users\User\AppData\Roaming\SearchProtect
2013-08-16 17:44 . 2013-08-16 17:45 -------- d-----w- c:\program files\Common Files\DivX Shared
2013-08-16 17:31 . 2013-08-16 17:31 81768 ----a-w- C:\ministub.exe
2013-08-16 17:31 . 2013-08-16 17:31 -------- d-----w- c:\programdata\Conduit
2013-08-16 17:31 . 2013-08-16 17:45 -------- d-----w- c:\program files\DivX
2013-08-16 17:27 . 2013-08-16 17:45 -------- d-----w- c:\programdata\DivX
2013-08-16 10:35 . 2013-08-16 10:35 -------- d-----w- c:\windows\MATS
2013-08-16 10:35 . 2013-08-16 10:35 -------- d-----w- c:\program files\Microsoft Fix it Center
2013-08-16 10:19 . 2013-08-16 10:31 -------- d-----w- c:\users\User\AppData\Local\ElevatedDiagnostics
2013-08-16 08:24 . 2013-08-16 08:27 -------- d-----w- c:\windows\system32\MRT
2013-08-16 08:15 . 2010-02-12 10:32 293376 ----a-w- c:\windows\system32\browserchoice.exe
2013-08-16 07:42 . 2013-08-16 07:42 -------- d-----w- c:\users\User\AppData\Roaming\Intel
2013-08-16 07:42 . 2013-08-16 07:42 -------- d-----w- c:\programdata\Intel
2013-08-16 07:36 . 2013-06-04 01:50 2049024 ----a-w- c:\windows\system32\win32k.sys
2013-08-16 07:36 . 2013-06-15 13:22 15872 ----a-w- c:\windows\system32\icaapi.dll
2013-08-16 07:36 . 2013-06-15 11:23 24064 ----a-w- c:\windows\system32\drivers\tssecsrv.sys
2013-08-16 07:36 . 2013-05-08 04:04 1548288 ----a-w- c:\windows\system32\WMVDECOD.DLL
2013-08-16 07:36 . 2013-07-08 04:20 172544 ----a-w- c:\windows\system32\wintrust.dll
2013-08-16 07:36 . 2013-07-08 04:16 98304 ----a-w- c:\windows\system32\cryptnet.dll
2013-08-16 07:36 . 2013-07-08 04:16 133120 ----a-w- c:\windows\system32\cryptsvc.dll
2013-08-16 07:36 . 2013-07-08 04:16 992768 ----a-w- c:\windows\system32\crypt32.dll
2013-08-16 07:36 . 2013-07-05 03:20 914880 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-08-16 07:36 . 2013-06-01 04:06 505344 ----a-w- c:\windows\system32\qedit.dll
2013-08-16 07:36 . 2013-07-05 01:43 31232 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2013-08-16 07:25 . 2000-01-01 00:00 970752 ----a-w- c:\windows\system32\ismbun.exe
2013-08-16 07:24 . 2013-08-16 07:24 -------- d-----w- c:\users\User\AppData\Local\Downloaded Installations
2013-08-16 07:24 . 2000-01-01 00:00 22272 ----a-w- c:\windows\system32\drivers\intelsmb.sys
2013-08-16 06:57 . 2013-08-16 06:57 -------- d--h--w- c:\programdata\Common Files
2013-08-16 06:57 . 2013-08-16 06:57 -------- d-----w- c:\program files\SlimDrivers
2013-08-16 06:44 . 2013-08-16 06:44 -------- d-----w- c:\users\User\AppData\Local\NVIDIA
2013-08-16 06:10 . 2013-08-16 06:10 -------- d-----w- c:\program files\AGEIA Technologies
2013-08-16 06:03 . 2013-06-21 12:02 9069344 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2013-08-16 06:03 . 2013-06-21 12:02 893728 ----a-w- c:\windows\system32\nvdispgenco3232049.dll
2013-08-16 06:03 . 2013-06-21 12:02 7687592 ----a-w- c:\windows\system32\nvcuda.dll
2013-08-16 06:03 . 2013-06-21 12:02 6324360 ----a-w- c:\windows\system32\nvopencl.dll
2013-08-16 06:03 . 2013-06-21 12:02 2777888 ----a-w- c:\windows\system32\nvcuvid.dll
2013-08-16 06:03 . 2013-06-21 12:02 21102368 ----a-w- c:\windows\system32\nvoglv32.dll
2013-08-16 06:03 . 2013-06-21 12:02 2002720 ----a-w- c:\windows\system32\nvcuvenc.dll
2013-08-16 06:03 . 2013-06-21 12:02 17560352 ----a-w- c:\windows\system32\nvcompiler.dll
2013-08-16 06:03 . 2013-06-21 12:02 13411896 ----a-w- c:\windows\system32\nvwgf2um.dll
2013-08-16 06:03 . 2013-06-21 12:02 12427240 ----a-w- c:\windows\system32\nvd3dum.dll
2013-08-16 06:03 . 2013-06-21 12:02 1024288 ----a-w- c:\windows\system32\nvdispco3232049.dll
2013-08-16 06:02 . 2013-08-16 06:02 -------- d-----w- C:\NVIDIA
2013-08-13 09:31 . 2013-08-13 09:31 -------- d-----w- c:\program files\Microsoft Silverlight
2013-08-10 22:05 . 2013-07-24 02:10 41160 ----a-w- c:\windows\system32\drivers\hssdrv6.sys
2013-08-10 22:05 . 2013-08-19 19:10 -------- d-----w- c:\users\fbwuser
2013-08-06 21:36 . 2013-08-06 21:36 -------- d-----w- c:\programdata\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}
2013-08-06 21:36 . 2013-08-06 21:36 -------- d-----w- c:\users\User\AppData\Roaming\Apple Computer
2013-08-06 11:13 . 2013-08-06 11:11 698504 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{20F61854-9E78-400C-9FAC-6781B5E8418B}\gapaengine.dll
2013-08-06 11:04 . 2013-08-06 11:04 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-08-06 11:04 . 2013-08-06 11:04 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-08-06 10:46 . 2013-08-06 10:46 -------- d-----w- c:\windows\system32\Adobe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-08-21 16:05 . 2011-10-30 20:10 13464 ----a-w- c:\windows\system32\drivers\SWDUMon.sys
2013-08-20 09:59 . 2009-06-14 12:24 319456 ----a-w- c:\windows\DIFxAPI.dll
2013-06-21 12:02 . 2011-10-30 21:17 2597856 ----a-w- c:\windows\system32\nvapi.dll
2013-06-21 09:52 . 2011-10-30 21:18 4192544 ----a-w- c:\windows\system32\nvcpl.dll
2013-06-21 09:52 . 2011-10-30 21:18 3045664 ----a-w- c:\windows\system32\nvsvc.dll
2013-06-21 09:52 . 2011-10-30 21:18 640288 ----a-w- c:\windows\system32\nvvsvc.exe
2013-06-21 09:52 . 2011-10-30 21:18 62752 ----a-w- c:\windows\system32\nvshext.dll
2013-06-21 09:52 . 2011-10-30 21:18 223008 ----a-w- c:\windows\system32\nvmctray.dll
2013-06-18 13:50 . 2013-06-18 13:50 211560 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2013-06-18 13:50 . 2011-04-27 07:25 107392 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2013-05-24 20:01 . 2012-02-16 11:35 724464 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2011-07-08 07:16 . 2011-07-16 10:49 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2012-02-08 00:49 22376 ----a-w- d:\program\Internet Download Manager\IDMShellExt.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 6"="c:\program files\IObit\Advanced SystemCare 6\ASCTray.exe" [2013-04-18 491840]
"IDMan"="d:\program\internet download manager\idman.exe" [2012-08-22 3478936]
"ConduitFloatingPlugin_pkmpcdbgnfjfeelcpebpkflcmbkclfho"="c:\program files\Conduit\CT3288691\plugins\TBVerifier.dll" [1617-11-28 287008]
"Smart Driver Updater"="c:\program files\Smart Driver Updater\SDULauncher.exe" [2013-02-22 391992]
"Driver Detective"="c:\program files\PC Drivers HeadQuarters\Driver Detective\DriversHQ.DriverDetective.Client.exe" [2013-07-22 3980696]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-06-20 995176]
"Malwarebytes' Anti-Malware"="d:\program\sofware\malwarebytes' anti-malware\mbamgui.exe" [2011-08-31 449608]
"QvodTerminal"="c:\program files\qvodplayer\qvodterminal.exe" [2013-06-13 1265280]
"UnlockerAssistant"="c:\program files\unlocker\unlockerassistant.exe" [2010-07-04 17408]
"AdobeAAMUpdater-1.0"="c:\program files\common files\adobe\oobe\pdapp\uwa\updaterstartuputility.exe" [2012-04-03 446392]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2000-01-01 10996368]
"Nvtmru"="c:\program files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-07-27 1028896]
"CommonToolkitTray"="c:\program files\Fighters\Tray\FightersTray.exe" [2013-07-01 1497120]
"Malwarebytes' Anti-Malware (reboot)"="d:\program\sofware\Malwarebytes' Anti-Malware\mbam.exe" [2011-08-31 1047208]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0SmartDefragBootTime.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASKL Startup
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ehTray.exe"=c:\windows\ehome\ehTray.exe
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe"
"Sidebar"=c:\program files\Windows Sidebar\sidebar.exe /autoRun
"Search Protection"=c:\program files\Yahoo!\Search Protection\SearchProtection.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe"
"HP Software Update"=c:\program files\HP\HP Software Update\HPWuSchd2.exe
"hpqSRMon"=c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe
"NeroFilterCheck"=c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
"WatcherHelper"="c:\program files\Sierra Wireless Inc\3G Watcher\WaHelper.exe"
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe"
.
R2 AdvancedSystemCareService6;Advanced SystemCare Service 6;c:\program files\IObit\Advanced SystemCare 6\ASCService.exe [2013-04-18 574272]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
cthebkjk
.
Contents of the 'Scheduled Tasks' folder
.
2013-08-21 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-06 11:04]
.
2013-08-21 c:\windows\Tasks\DLL-files.com Fixer_UPDATES.job
- c:\program files\Dll-Files.com Fixer\DLLFixer.exe [2013-08-20 14:45]
.
2013-08-21 c:\windows\Tasks\Driver Detective-RTMRules.job
- c:\program files\PC Drivers HeadQuarters\Driver Detective\DriversHQ.DriverDetective.Client.exe [2013-07-22 00:15]
.
2013-08-21 c:\windows\Tasks\Driver Detective-RTMScan.job
- c:\program files\PC Drivers HeadQuarters\Driver Detective\DriversHQ.DriverDetective.Client.exe [2013-07-22 00:15]
.
2013-08-21 c:\windows\Tasks\Driver Detective-RTMUpdater.job
- c:\program files\PC Drivers HeadQuarters\Driver Detective\DriversHQ.DriverDetective.Client.exe [2013-07-22 00:15]
.
2013-08-21 c:\windows\Tasks\DRIVERfighter Auto Start.job
- c:\program files\Fighters\DRIVERfighter\DRIVERfighter.exe [2013-08-08 08:34]
.
2013-08-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-880357501-2417163729-3689644502-1000Core.job
- c:\users\User\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-18 13:00]
.
2013-08-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-880357501-2417163729-3689644502-1000UA.job
- c:\users\User\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-18 13:00]
.
2013-08-21 c:\windows\Tasks\RDReminder.job
- c:\program files\Dll-Files.com Fixer\DLLFixer.exe [2013-08-20 14:45]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.conduit.com/?ctid=CT3288691&octid=CT3288691&SearchSource=61&CUI=UN18504787128467293&UM=2&UP=SPCE0F2C6C-2B31-474D-B554-88496C6A3491
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://woofi.info
uInternet Settings,ProxyOverride = local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: ????????
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Download all links with IDM - d:\program\Internet Download Manager\IEGetAll.htm
IE: Download with IDM - d:\program\Internet Download Manager\IEExt.htm
IE: Download with Xilisoft YouTube Video Converter
IE: ???????? - c:\program files\QvodPlayer\AddIn\ImgSeed.htm
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{74E9849D-9380-46DE-AD5C-E9D34E56A081}: NameServer = 8.8.8.8,8.8.4.4
FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\9denrbzu.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3288691&CUI=UN10910293642918196&UM=2&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - DivX Browser Bar Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT3288691&octid=CT3288691&SearchSource=61&CUI=UN10910293642918196&UM=2&UP=SPCE0F2C6C-2B31-474D-B554-88496C6A3491
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3288691&SearchSource=2&CUI=UN10910293642918196&UM=2&q=
FF - prefs.js: network.proxy.type - 2
FF - ExtSQL: 2013-08-07 13:36;
[email protected]; c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\9denrbzu.default\extensions\
[email protected]
FF - ExtSQL: !HIDDEN! 2009-08-01 18:38; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - user.js: extensions.delta.tlbrSrchUrl -
FF - user.js: extensions.delta.id - 72a379f200000000000000ff5a7896e5
FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
FF - user.js: extensions.delta.instlDay - 15872
FF - user.js: extensions.delta.vrsn - 1.8.21.5
FF - user.js: extensions.delta.vrsni - 1.8.21.5
FF - user.js: extensions.delta.vrsnTs - 1.8.21.518:16
FF - user.js: extensions.delta.prtnrId - delta
FF - user.js: extensions.delta.prdct - delta
FF - user.js: extensions.delta.aflt - babsst
FF - user.js: extensions.delta.smplGrp - none
FF - user.js: extensions.delta.tlbrId - base
FF - user.js: extensions.delta.instlRef - sst
FF - user.js: extensions.delta.dfltLng - en
FF - user.js: extensions.delta.excTlbr - false
FF - user.js: extensions.delta.ffxUnstlRst - true
FF - user.js: extensions.delta.admin - false
FF - user.js: extensions.delta_i.babTrack - affID=122471
FF - user.js: extensions.delta_i.babExt -
FF - user.js: extensions.delta_i.srcExt - ss
FF - user.js: extensions.delta.autoRvrt - false
FF - user.js: extensions.delta.rvrt - false
FF - user.js: extensions.delta.newTab - false
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: content.notify.ontimer - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.switch.threshold - 750000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{038cb5c7-48ea-4af9-94e0-a1646542e62b} - (no file)
URLSearchHooks-{a4d09ede-8a9c-4090-a54d-5ada4f7fff35} - (no file)
URLSearchHooks-{55e19115-8ef8-465c-90ac-deacc491b0cc} - (no file)
URLSearchHooks-{77e8143b-6759-416e-b521-82cfed75150b} - (no file)
BHO-{038cb5c7-48ea-4af9-94e0-a1646542e62b} - (no file)
BHO-{0974BA1E-64EC-11DE-B2A5-E43756D89593} - (no file)
BHO-{55e19115-8ef8-465c-90ac-deacc491b0cc} - (no file)
BHO-{77e8143b-6759-416e-b521-82cfed75150b} - (no file)
BHO-{8E384D31-CD5E-6109-734C-F91D658549DC} - (no file)
Toolbar-{0974BA1E-64EC-11DE-B2A5-E43756D89593} - (no file)
Toolbar-{77e8143b-6759-416e-b521-82cfed75150b} - (no file)
WebBrowser-{77E8143B-6759-416E-B521-82CFED75150B} - (no file)
ShellIconOverlayIdentifiers-{A8502600-B272-4F68-A67B-A0305D46D297} - (no file)
SafeBoot-WudfPf
SafeBoot-WudfRd
SafeBoot-IMFservice
AddRemove-Ashampoo Burning Studio Elements_is1 - d:\iwe\program\Ashampoo Burning Studio Elements\unins000.exe
AddRemove-DefaultTab - c:\users\User\AppData\Roaming\DefaultTab\DefaultTab\uninstalldt.exe
AddRemove-{3FDC48B2-98EC-4099-99C2-20F4FB9C9093} - c:\program files (x86)\InstallShield Installation Information\{3FDC48B2-98EC-4099-99C2-20F4FB9C9093}\setup.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
GMER - Rootkit Detector and Remover
Rootkit scan 2013-08-22 00:43
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Yonline]
"ImagePath"="\??\c:\windows\system32\drivers\Yonline.ahc"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cthebkjk]
"ServiceDll"="c:\windows\system32\hmcencx.dll"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-880357501-2417163729-3689644502-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{ABBCF934-B8D5-E9D9-42B3-9872DB2C5D4D}*]
"jaaaoldpplhidodefahi"=hex:66,61,68,61,68,6d,66,6e,62,65,6e,6d,00,00
"paiomfhmccjchknmeaagfdoaafnencpk"=hex:65,61,68,61,69,6d,6a,6e,6c,66,00,6d
"haaaoldpplhidode"=hex:6e,62,68,61,66,6d,63,6c,69,66,6e,68,65,64,63,65,68,6a,
69,66,68,63,66,63,67,65,6b,70,63,69,66,63,64,69,62,6e,65,61,66,6d,64,6f,63,\
.
[HKEY_USERS\S-1-5-21-880357501-2417163729-3689644502-1000_Classes\CLSID\{6a81c1e4-e668-4afe-8e88-476b677631f2}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:00000169
"Therad"=dword:00000019
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\
.
[HKEY_USERS\S-1-5-21-880357501-2417163729-3689644502-1000_Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):1b,b7,59,a5,cc,63,e6,42,95,cd,1d,d6,d6,7a,37,b2,17,de,2f,4a,28,
36,bd,7e,ca,53,4c,4d,db,fe,c6,1b,67,a0,ab,0b,36,7e,66,ee,00,00,00,00,00,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2013-08-22 00:44:28
ComboFix-quarantined-files.txt 2013-08-21 16:44
.
Pre-Run: 7,597,760,512 bytes free
Post-Run: 8,047,521,792 bytes free
.
- - End Of File - - 316D6107CCBF2DFEFB61F45C76D452C6
A36C5E4F47E84449FF07ED3517B43A31
and this is log for Malwarebytes, im scan before that...!!and im just deleted about 162 infected files already...
Malwarebytes' Anti-Malware 1.51.2.1300
Malwarebytes : Free anti-malware download
Database version: 913081804
Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421
20/08/2013 7:41:42
mbam-log-2013-08-20 (07-41-42).txt
Scan type: Full scan (C:\|D:\|)
Objects scanned: 466254
Time elapsed: 1 hour(s), 5 minute(s), 14 second(s)
Memory Processes Infected: 4
Memory Modules Infected: 7
Registry Keys Infected: 20
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 29
Files Infected: 100
Memory Processes Infected:
c:\Users\User\AppData\Roaming\searchprotect\bin\cltmng.exe (PUP.Optional.SearchProtect.A) -> 4016 -> Unloaded process successfully.
c:\program files\searchprotect\bin\cltmngsvc.exe (PUP.Optional.SearchProtect.A) -> 1772 -> Unloaded process successfully.
c:\Users\User\AppData\Roaming\defaulttab\defaulttab\DTUpdate.exe (PUP.Optional.DefaultTab) -> 1624 -> Unloaded process successfully.
c:\program files\defaulttab\defaulttabsearch.exe (PUP.Optional.DefaultTab) -> 1808 -> Unloaded process successfully.
Memory Modules Infected:
c:\program files\searchprotect\bin\msvcr100.dll (PUP.Optional.SearchProtect.A) -> Delete on reboot.
c:\Users\User\AppData\Roaming\searchprotect\bin\msvcp100.dll (PUP.Optional.SearchProtect.A) -> Delete on reboot.
c:\Users\User\AppData\Roaming\searchprotect\bin\msvcr100.dll (PUP.Optional.SearchProtect.A) -> Delete on reboot.
c:\Users\User\AppData\Roaming\searchprotect\bin\internetexplorermodule.dll (PUP.Optional.SearchProtect.A) -> Delete on reboot.
c:\program files\searchprotect\bin\msvcp100.dll (PUP.Optional.SearchProtect.A) -> Delete on reboot.
c:\Users\User\AppData\Roaming\searchprotect\bin\chromemodule.dll (PUP.Optional.SearchProtect.A) -> Delete on reboot.
c:\Users\User\AppData\Roaming\searchprotect\bin\firefoxmodule.dll (PUP.Optional.SearchProtect.A) -> Delete on reboot.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7F6AFBF1-E065-4627-A2FD-810366367D01} (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{FBEDBA6C-44A2-43b9-BD49-20EB6E0C4E86} (PUP.Funshion) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11CC93E4-0BE6-4F8F-82AA-D577FB955B05} (PUP.Funshion) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ASBarBroker.BDBroker.1 (PUP.Funshion) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{11CC93E4-0BE6-4f8f-82AA-D577FB955B05} (PUP.Funshion) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{FCB380C4-D350-44BE-8791-50216F4747AC} (PUP.Funshion) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{91878E42-FC03-4785-B513-1F9E613D1027} (PUP.Funshion) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\DataMngr_Toolbar (PUP.Optional.DataMngr) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{D02E3AB9-7796-40CB-BDFC-20D834FE1F75} (PUP.Funshion) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{1DD31B76-C57E-49ba-94BC-BF53F0C82CD4} (PUP.Funshion) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01} (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CltMngSvc (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\DataMngr (PUP.Optional.DataMngr) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1DD31B76-C57E-49ba-94BC-BF53F0C82CD4} (PUP.Funshion) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DefaultTabUpdate (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35C-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ASBarBroker.BDBroker (PUP.Funshion) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01} (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DefaultTabSearch (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SearchProtect (PUP.Optional.SearchProtect.A) -> Value: SearchProtect -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SearchProtectAll (PUP.Optional.SearchProtect.A) -> Value: SearchProtectAll -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
c:\Users\User\AppData\Roaming\searchprotect\ffprotect (PUP.Optional.SearchProtect.A) -> Not selected for removal.
c:\Users\User\AppData\Roaming\searchprotect\ffprotect\Dialogs (PUP.Optional.SearchProtect.A) -> Not selected for removal.
c:\Users\User\AppData\Roaming\Babylon (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
c:\program files\searchprotect\Dialogs\lib (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\opencandy (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\Dialogs\spbd\images (PUP.Optional.SearchProtect.A) -> Not selected for removal.
c:\program files\searchprotect\Dialogs\spsd\images (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\ffprotect\Dialogs\spbd (PUP.Optional.SearchProtect.A) -> Not selected for removal.
c:\programdata\tarma installer (PUP.Optional.Tarma.A) -> Not selected for removal.
c:\Users\User\AppData\Roaming\searchprotect\Dialogs\spsd\images (PUP.Optional.SearchProtect.A) -> Not selected for removal.
c:\program files\searchprotect\Dialogs\spsd (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\Dialogs (PUP.Optional.SearchProtect.A) -> Not selected for removal.
c:\Users\User\AppData\Roaming\searchprotect\bin (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\Dialogs\spsd (PUP.Optional.SearchProtect.A) -> Not selected for removal.
c:\Users\User\AppData\Roaming\searchprotect\ffprotect\Dialogs\lib (PUP.Optional.SearchProtect.A) -> Not selected for removal.
c:\Users\User\AppData\Roaming\searchprotect\Dialogs\spbd (PUP.Optional.SearchProtect.A) -> Not selected for removal.
c:\program files\searchprotect\Dialogs\spbd\images (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\program files\defaulttab (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
c:\program files\searchprotect\Dialogs\spbd (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\programdata\tarma installer\{361e80be-388b-4270-bf54-a10c2b756504} (PUP.Optional.Tarma.A) -> Not selected for removal.
c:\program files\searchprotect\ffprotect (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\programdata\tarma installer\{361e80be-388b-4270-bf54-a10c2b756504}\Cache (PUP.Optional.Tarma.A) -> Not selected for removal.
c:\Users\User\AppData\Roaming\searchprotect\ffprotect\Dialogs\spbd\images (PUP.Optional.SearchProtect.A) -> Not selected for removal.
c:\Users\User\AppData\Roaming\searchprotect\ffprotect\Dialogs\spsd\images (PUP.Optional.SearchProtect.A) -> Not selected for removal.
c:\Users\User\AppData\Roaming\searchprotect\ffprotect\Dialogs\spsd (PUP.Optional.SearchProtect.A) -> Not selected for removal.
c:\Users\User\AppData\Roaming\searchprotect\Dialogs\lib (PUP.Optional.SearchProtect.A) -> Not selected for removal.
c:\program files\searchprotect\bin (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\ffprotect\sprotectorrepository (PUP.Optional.SearchProtect.A) -> Not selected for removal.
c:\program files\searchprotect\Dialogs (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
Files Infected:
c:\program files\searchprotect\Dialogs\spsd\searchprotector.css (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\ffprotect\Dialogs\spbd\bubble.css (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\program files\defaulttab\uid (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\ffprotect\Dialogs\spbd\bubble.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\program files\qvodplayer\AddIn\{8e384d31-cd5e-6109-734c-f91d658549dc}\asbarbroker.exe (PUP.Funshion) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\ffprotect\Dialogs\spbd\images\x-default-ltr.png (PUP.Optional.SearchProtect.A) -> Not selected for removal.
c:\program files\searchprotect\Dialogs\spbd\images\x-default-rtl.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\bin\rep.dat (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\program files\searchprotect\ffprotect\nsprotector.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\Dialogs\spbd\bubble.css (PUP.Optional.SearchProtect.A) -> Not selected for removal.
c:\Users\User\AppData\Roaming\opencandy\xobni_oc18.exe (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\bin\chromemodule.dll (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\defaulttab\defaulttab\defaulttabstart.exe (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\ffprotect\nsprotector.js (PUP.Optional.SearchProtect.A) -> Not selected for removal.
c:\Users\User\AppData\Roaming\searchprotect\ffprotect\Dialogs\spbd\images\x-mouseover-rtl.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\ffprotect\Dialogs\spsd\main.html (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\ffprotect\Dialogs\spsd\searchprotector.css (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\program files\defaulttab\defaulttab.crx (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
c:\program files\searchprotect\Dialogs\spbd\images\information.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\program files\searchprotect\bin\uninstall.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\ffprotect\Dialogs\spbd\main.html (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\ffprotect\Dialogs\spsd\settings.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\defaulttab\defaulttab\DTUpdate.exe (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\Dialogs\spbd\images\information.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\program files\searchprotect\Dialogs\lib\jquery.min.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\bin\firefoxmodule.dll (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\ffprotect\Dialogs\spbd\images\x-mouseover-ltr.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\program files\searchprotect\Dialogs\spbd\bubble.css (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\program files\searchprotect\Dialogs\spbd\bubble.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\program files\searchprotect\Dialogs\spbd\main.html (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\program files\searchprotect\bin\SPHook32.dll (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\program files\searchprotect\bin\SPRunner.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\ffprotect\Dialogs\spbd\images\information.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\program files\searchprotect\ffprotect\abstraction.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\program files\searchprotect\Dialogs\spbd\images\x-mouseover-ltr.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\program files\searchprotect\Dialogs\spbd\images\x-default-ltr.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\Dialogs\spsd\main.html (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\program files\searchprotect\Dialogs\spsd\main.html (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\program files\searchprotect\Dialogs\lib\json2.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\Dialogs\dialogsapi.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\Dialogs\spbd\images\x-mouseover-rtl.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\program files\defaulttab\defaulttabsearch.exe (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
c:\program files\searchprotect\Dialogs\spsd\images\separation-line.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\Dialogs\lib\json2.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\bin\internetexplorermodule.dll (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\Dialogs\spsd\settings.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\bin\msvcp100.dll (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\program files\searchprotect\ffprotect\application.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\Dialogs\spsd\images\warning.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\ffprotect\Dialogs\spsd\images\separation-line.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\ffprotect\Dialogs\spsd\images\warning.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\bin\SPHook32.dll (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\defaulttab\defaulttab\defaulttabwrap.dll (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\bin\cltmng.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\ffprotect\popuptransparent.xul (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\ffprotect\Dialogs\dialogsapi.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\program files\searchprotect\bin\msvcr100.dll (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\Dialogs\spsd\searchprotector.css (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\ffprotect\Dialogs\lib\jquery.min.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
d:\games\ignite pc game{gndh}\d3drm.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\Dialogs\spsd\images\ok-button.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\Dialogs\spbd\main.html (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\program files\searchprotect\Dialogs\spbd\images\x-mouseover-rtl.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\ffprotect\Dialogs\spsd\images\ok-button.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\program files\searchprotect\bin\cltmngsvc.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\ffprotect\Dialogs\spbd\images\x-default-rtl.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\Dialogs\spbd\images\x-mouseover-ltr.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\ffprotect\sprotectorrepository\EN (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\program files\searchprotect\Dialogs\spsd\images\ok-button.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\Dialogs\lib\jquery.min.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\Dialogs\spsd\images\separation-line.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\ffprotect\abstraction.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\Babylon\log_file.txt (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\ffprotect\Dialogs\lib\json2.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\Dialogs\spbd\images\x-default-rtl.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\Dialogs\spbd\images\x-default-ltr.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\defaulttab\defaulttab\defaulttabstart64.exe (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
c:\program files\searchprotect\bin\msvcp100.dll (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\bin\SPRunner.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\program files\searchprotect\Dialogs\spsd\settings.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\program files\searchprotect\bin\internetexplorermodule.dll (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\program files\searchprotect\bin\firefoxmodule.dll (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\program files\searchprotect\bin\chromemodule.dll (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\program files\searchprotect\Dialogs\spsd\images\warning.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\program files\searchprotect\Dialogs\dialogsapi.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\program files\searchprotect\bin\cltmng.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\bin\cltmngsvc.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\Dialogs\spbd\bubble.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\bin\msvcr100.dll (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\defaulttab\defaulttab\defaulttabwrap64.dll (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
c:\programdata\tarma installer\{361e80be-388b-4270-bf54-a10c2b756504}\Setup.dat (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
c:\programdata\tarma installer\{361e80be-388b-4270-bf54-a10c2b756504}\_Setup.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Roaming\searchprotect\ffprotect\application.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
c:\programdata\tarma installer\{361e80be-388b-4270-bf54-a10c2b756504}\_Setupx.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
c:\programdata\tarma installer\{361e80be-388b-4270-bf54-a10c2b756504}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
c:\programdata\tarma installer\{361e80be-388b-4270-bf54-a10c2b756504}\Setup.ico (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
d:\program\adobe photoshop cs6\amtlib.dll (PUP.RiskwareTool.CK) -> Not selected for removal.
d:\iwe\adobe photoshop cs6\crack\32bit\amtlib.dll (PUP.RiskwareTool.CK) -> Not selected for removal.
d:\iwe\adobe photoshop cs6\crack\64bit\amtlib.dll (PUP.RiskwareTool.CK) -> Not selected for removal.
d:\program\sofware\installerjdownloadersetup.exe (PUP.SmsPay.PGen) -> Quarantined and deleted successfully.
And this is my computer System Information :
System Information Report
General
Operating System Microsoft® Windows Vista™ Home Premium
Central Processor Intel(R) Core(TM)2 CPU E7400 @ 2.80GHz
User Name User
Graphics
Video Adapter NVIDIA GeForce 9500 GT
Video Memory 512.00 MB
Screen Resolution NULL x NULL
Storage
Total Memory 2.00 GB
Free Memory 748.79 MB
Total Hard disk 298.09 GB
Free Hard disk 27.56 GB
I/O
Mouse USB Human Interface Device
Keyboard USB Human Interface Device
Computer System
Computer Name USER-PC
User Name User
Organization N/A
Operating System
OS Name Microsoft® Windows Vista™ Home Premium
OS Version 6.0.6002
Service Pack 2.0
Product ID 89578-OEM-7841393-54917
System Up Time 21/08/2013 0:16:52
Internet Explorer Version 9.0.8112.16421
Microsoft DirectX Version 10.0
OpenGL Version 6.0.6000.16386 (vista_rtm.061101-2205)
Registry
Maximum Size 682 MB
Current Size 24 MB
Status OK
Central Processor
CPU Name Intel(R) Core(TM)2 CPU E7400 @ 2.80GHz
Code Name Model 7, Stepping 10
Manufacturer GenuineIntel
Current Clock Speed 2799 Mhz
Max Clock Speed 2799 Mhz
Voltage Unknown
External Clock 1066 Mhz
Serial Number BFEBFBFF0001067A
CPU ID x64 Family 6 Model 23 Stepping 10
Socket Designation J3E1
Unknown 32 KB
Unknown 3072 KB
Motherboard
Model DG31PR
Manufacturer Intel Corporation
Serial Number BTPR91800QK5
BIOS Name BIOS Date: 03/13/08 17:38:29 Ver: 08.00.10
BIOS Vendor Intel Corp.
SMBIOS Version PRG3110H.86A.0052.2008.0612.1910
BIOS Date 12/06/2008
BIOS Features
PCI is supported Yes
BIOS is Upgradable (Flash) Yes
BIOS shadowing is allowed Yes
ESCD support is available Yes
Boot from CD is supported Yes
Selectable Boot is supported Yes
BIOS ROM is socketed Yes
EDD (Enhanced Disk Drive) Specification is supported Yes
Int 13h - 5.25 /1.2MB Floppy Services are supported Yes
Int 13h - 3.5 / 720 KB Floppy Services are supported Yes
Int 13h - 3.5 / 2.88 MB Floppy Services are supported Yes
Int 5h, Print Screen Service is supported Yes
Int 9h, 8042 Keyboard services are supported Yes
Int 14h, Serial Services are supported Yes
Int 17h, printer services are supported Yes
Int 10h, CGA/Mono Video Services are supported Yes
ACPI supported Yes
USB Legacy is supported Yes
LS-120 boot is supported Yes
ATAPI ZIP Drive boot is supported Yes
Memory Resource
Total Memory 2.00 GB
Used Memory 1.26 GB
Free Memory 756.52 MB
Memory Usage 62%
Physical Memory
Memory Bank CHAN A DIMM 0
Description Physical Memory 0
Device Locator J6H1
Capacity 2.00 GB
Speed 800 Mhz
Manufacturer Unknown
Data Width 64 bit
Memory Type DDR
Form Factor DIMM
Disk Drives
Name WDC WD3200AAKS-00L9A0 ATA Device
Media Type Fixed hard disk media
Capability 298.09 GB
Interface Type IDE
Partitions 2
Total Cylinders 38913
Total Heads 255
Total Sectors 625137345
Total Tracks 9922815
Tracks Per Cylinder 255
Bytes Per Sector 512
Sectors Per Track 63
S.M.A.R.T Support Yes
Current Temperature 0C (32F)
CD-ROM Drive
Name HL-DT-ST DVD-RAM GH22NS30 ATA Device
Drive E:
Transfer Rate -1
Status OK
IDE Controller
Name Intel(R) ICH7 Family Ultra ATA Storage Controllers - 27DF
Manufacturer Intel
Status OK
IDE Controller
Name IDE Channel
Manufacturer (Standard IDE ATA/ATAPI controllers)
Status OK
IDE Controller
Name Intel(R) N10/ICH7 Family Serial ATA Storage Controller - 27C0
Manufacturer Intel
Status OK
IDE Controller
Name IDE Channel
Manufacturer (Standard IDE ATA/ATAPI controllers)
Status OK
IDE Controller
Name IDE Channel
Manufacturer (Standard IDE ATA/ATAPI controllers)
Status OK
Video Adapter
Name NVIDIA GeForce 9500 GT
Video Processor GeForce 9500 GT
Manufacturer NVIDIA
Video Architecture VGA
DAC Type Integrated RAMDAC
Memory Size 512.00 MB
Memory Type Unknown
Video Mode NULL
Current Refresh Rate NULL Hz
Driver Version 9.18.13.2049
Driver Date 21/06/2013 12:02:43
Monitor
Name Default Monitor
Screen Height NULL
Screen Width NULL
Status OK
Local Area Connection
Product Name Realtek RTL8168/8111 Family PCI-E Gigabit Ethernet NIC (NDIS 6.0)
Service Name RTL8169
Manufacturer Realtek
MAC Address 00:1C:C0:D5:1C:A0
NULL
Product Name Anchorfree HSS VPN Adapter
Service Name taphss6
Manufacturer Anchorfree HSS VPN Adapter
MAC Address 00:FF:5A:78:96:E5
Sound Device
Name Realtek High Definition Audio
Manufacturer Realtek
Status OK
Mouse
Name USB Human Interface Device
Manufacturer (Standard system devices)
Buttons 0
Status OK
Keyboard
Name USB Human Interface Device
Description Enhanced (101- or 102-key)
Function Keys 12
Status OK
USB Controller
Product Name Intel(R) N10/ICH7 Family USB Universal Host Controller - 27C8
Manufacturer Intel
Protocol Supported Universal Serial Bus
Status OK
USB Controller
Product Name Intel(R) N10/ICH7 Family USB Universal Host Controller - 27C9
Manufacturer Intel
Protocol Supported Universal Serial Bus
Status OK
USB Controller
Product Name Intel(R) N10/ICH7 Family USB Universal Host Controller - 27CA
Manufacturer Intel
Protocol Supported Universal Serial Bus
Status OK
USB Controller
Product Name Intel(R) N10/ICH7 Family USB Universal Host Controller - 27CB
Manufacturer Intel
Protocol Supported Universal Serial Bus
Status OK
USB Controller
Product Name Intel(R) N10/ICH7 Family USB2 Enhanced Host Controller - 27CC
Manufacturer Intel
Protocol Supported Universal Serial Bus
Status OK