Here is the combofix logs
ComboFix 11-12-05.04 -Cheung 12/05/2011 23:40:31.1.2 - x64
Running from: c:\users\Cheung\Desktop\ComboFix.exe
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\users\Ken\AppData\Local\Microsoft\Windows\Temporary Internet Files\{C95B3F8A-55D3-4603-A186-F97E9045A2BD}.xps
c:\users\Ken\AppData\Local\Temp\_ir_sf_temp_0\npCouponPrinter.dll
c:\users\Ken\AppData\Local\Temp\_ir_sf_temp_0\npMozCouponPrinter.dll
c:\users\Ken\AppData\Local\Temp\{AC76BA86-1033-0000-7760-000000000002}\asneu.dll
c:\users\Ken\AppData\Local\Temp\{BD8D1903-49E4-46FE-8AF8-CF622F3522A1}\{C2A6CFA5-08A1-4072-B520-7C67DD7D85EC}\difxapi.dll
c:\users\Ken\AppData\Local\Temp\EPM\lib\gtk-2.0\2.10.0\engines\libpixmap.dll
c:\users\Ken\AppData\Local\Temp\EPM\lib\gtk-2.0\2.10.0\engines\libsvg.dll
c:\users\Ken\AppData\Local\Temp\EPM\lib\gtk-2.0\2.10.0\engines\libwimp.dll
c:\users\Ken\AppData\Local\Temp\EPM\lib\gtk-2.0\2.4.0\engines\libmetal.dll
c:\users\Ken\AppData\Local\Temp\EPM\lib\gtk-2.0\modules\modules\libgail.dll
c:\users\Ken\AppData\Local\Temp\EPM\lib\pango\1.6.0\modules\pango-arabic-fc.dll
c:\users\Ken\AppData\Local\Temp\EPM\lib\pango\1.6.0\modules\pango-arabic-lang.dll
c:\users\Ken\AppData\Local\Temp\EPM\lib\pango\1.6.0\modules\pango-basic-fc.dll
c:\users\Ken\AppData\Local\Temp\EPM\lib\pango\1.6.0\modules\pango-basic-win32.dll
c:\users\Ken\AppData\Local\Temp\EPM\lib\pango\1.6.0\modules\pango-hangul-fc.dll
c:\users\Ken\AppData\Local\Temp\EPM\lib\pango\1.6.0\modules\pango-hebrew-fc.dll
c:\users\Ken\AppData\Local\Temp\EPM\lib\pango\1.6.0\modules\pango-indic-fc.dll
c:\users\Ken\AppData\Local\Temp\EPM\lib\pango\1.6.0\modules\pango-indic-lang.dll
c:\users\Ken\AppData\Local\Temp\EPM\lib\pango\1.6.0\modules\pango-khmer-fc.dll
c:\users\Ken\AppData\Local\Temp\EPM\lib\pango\1.6.0\modules\pango-syriac-fc.dll
c:\users\Ken\AppData\Local\Temp\EPM\lib\pango\1.6.0\modules\pango-thai-fc.dll
c:\users\Ken\AppData\Local\Temp\EPM\lib\pango\1.6.0\modules\pango-tibetan-fc.dll
c:\users\Ken\AppData\Local\Temp\EPM\system32\BootMan.exe
c:\users\Ken\AppData\Local\Temp\EPM\system32\epmntdrv.sys
c:\users\Ken\AppData\Local\Temp\EPM\system32\EuEpmGdi.dll
c:\users\Ken\AppData\Local\Temp\EPM\system32\EuGdiDrv.sys
c:\users\Ken\AppData\Local\Temp\EPM\system32\setupempdrv03.exe
c:\users\Ken\AppData\Local\Temp\Low\udDownload.tmp
c:\users\Ken\AppData\Local\Temp\Low\udDownload[1].tmp
c:\users\Ken\AppData\Local\Temp\Low\udDownload[2].tmp
c:\users\Ken\AppData\Local\Temp\Low\udDownload[3].tmp
c:\users\Ken\AppData\Local\Temp\Low\udDownload[4].tmp
c:\users\Ken\AppData\Local\Temp\Low\udDownload[5].tmp
c:\users\Ken\AppData\Local\Temp\Low\udDownload[6].tmp
c:\users\Ken\AppData\Local\Temp\Low\udDownload[7].tmp
c:\users\Ken\AppData\Local\Temp\Low\udDownload[8].tmp
c:\users\Ken\AppData\Local\Temp\Low\udDownload[9].tmp
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Client Profile Setup_4.0.30319\1025\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Client Profile Setup_4.0.30319\1028\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Client Profile Setup_4.0.30319\1029\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Client Profile Setup_4.0.30319\1030\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Client Profile Setup_4.0.30319\1031\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Client Profile Setup_4.0.30319\1032\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Client Profile Setup_4.0.30319\1033\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Client Profile Setup_4.0.30319\1035\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Client Profile Setup_4.0.30319\1036\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Client Profile Setup_4.0.30319\1037\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Client Profile Setup_4.0.30319\1038\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Client Profile Setup_4.0.30319\1040\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Client Profile Setup_4.0.30319\1041\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Client Profile Setup_4.0.30319\1042\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Client Profile Setup_4.0.30319\1043\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Client Profile Setup_4.0.30319\1044\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Client Profile Setup_4.0.30319\1045\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Client Profile Setup_4.0.30319\1046\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Client Profile Setup_4.0.30319\1049\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Client Profile Setup_4.0.30319\1053\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Client Profile Setup_4.0.30319\1055\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Client Profile Setup_4.0.30319\2052\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Client Profile Setup_4.0.30319\2070\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Client Profile Setup_4.0.30319\3076\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Client Profile Setup_4.0.30319\3082\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Client Profile Setup_4.0.30319\Setup.exe
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Client Profile Setup_4.0.30319\SetupEngine.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Client Profile Setup_4.0.30319\SetupUi.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Client Profile Setup_4.0.30319\SetupUtility.exe
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Client Profile Setup_4.0.30319\sqmapi.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1025\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1028\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1029\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1030\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1031\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1032\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1033\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1035\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1036\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1037\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1038\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1040\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1041\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1042\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1043\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1044\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1045\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1046\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1049\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1053\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1055\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\2052\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\2070\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\3076\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\3082\SetupResources.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\Setup.exe
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\SetupEngine.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\SetupUi.dll
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\SetupUtility.exe
c:\users\Ken\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\sqmapi.dll
.
.
((((((((((((((((((((((((( Files Created from 2011-11-06 to 2011-12-06 )))))))))))))))))))))))))))))))
.
.
2011-12-06 04:48 . 2011-12-06 04:48 -------- d-----w- c:\users\Ken\AppData\Local\temp
2011-12-06 04:48 . 2011-12-06 04:48 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-12-05 19:21 . 2011-12-05 19:22 -------- d-----w- c:\users\Ken-Cheun Cheung
2011-12-05 18:28 . 2011-12-05 18:28 -------- d-----w- C:\found.000
2011-11-19 04:06 . 2011-11-19 04:06 -------- d-----w- c:\program files (x86)\Common Files\Java
2011-11-17 03:32 . 2010-04-06 19:21 2018596 ----a-w- c:\windows\system32\drivers\macxvi200.bin
2011-11-17 03:32 . 2010-04-06 19:21 2018596 ------w- c:\windows\SysWow64\drivers\macxvi200.bin
2011-11-17 03:32 . 2010-04-06 19:21 10752 ----a-w- c:\windows\system32\drivers\usbws320.sys
2011-11-17 03:32 . 2011-11-17 03:32 -------- d-----w- c:\windows\SysWow64\SupportWimax
2011-11-17 03:32 . 2010-04-06 19:21 34816 ----a-w- c:\windows\system32\drivers\BcmBusCtr.sys
2011-11-17 03:32 . 2010-04-06 19:21 216576 ----a-w- c:\windows\system32\drivers\drxvi314.sys
2011-11-17 03:32 . 2011-11-17 03:32 -------- d-----w- c:\program files (x86)\Digicel Broadband CM
2011-11-08 10:19 . 2011-09-06 21:36 24408 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-11-08 10:19 . 2011-09-06 21:38 301912 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-11-08 10:19 . 2011-09-06 21:36 42328 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-11-08 10:19 . 2011-09-06 21:36 58200 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-11-08 10:19 . 2011-09-06 21:38 601944 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-11-08 10:19 . 2011-09-06 21:36 65368 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-11-08 10:19 . 2011-09-06 21:45 254400 ----a-w- c:\windows\system32\aswBoot.exe
2011-11-08 10:17 . 2011-09-06 21:45 41184 ----a-w- c:\windows\avastSS.scr
2011-11-08 10:17 . 2011-09-06 21:45 199304 ----a-w- c:\windows\SysWow64\aswBoot.exe
2011-11-08 10:16 . 2011-11-08 10:16 -------- d-----w- c:\programdata\AVAST Software
2011-11-08 10:16 . 2011-11-08 10:16 -------- d-----w- c:\program files\AVAST Software
2011-11-08 08:29 . 2011-11-08 08:29 -------- d-----w- c:\windows\SysWow64\Wat
2011-11-08 08:29 . 2011-11-08 08:29 -------- d-----w- c:\windows\system32\Wat
2011-11-08 08:06 . 2011-11-08 08:06 -------- d-----w- c:\program files (x86)\MSXML 4.0
2011-11-08 08:04 . 2011-11-08 08:04 -------- d-----w- c:\windows\SysWow64\x64
2011-11-08 08:04 . 2009-09-24 00:30 1002008 ----a-w- c:\windows\SysWow64\igxpun.exe
2011-11-08 04:22 . 2011-11-08 10:00 -------- d-----w- c:\windows\AutoKMS
2011-11-08 03:34 . 2011-10-18 07:27 8570192 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{DC99A552-14B0-48D8-9FBF-86944452485F}\mpengine.dll
2011-11-08 03:15 . 2010-12-23 10:42 1118720 ----a-w- c:\windows\system32\sbe.dll
2011-11-08 03:14 . 2011-07-09 02:46 288768 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-11-08 03:13 . 2011-03-11 06:34 1359872 ----a-w- c:\windows\system32\mfc42u.dll
2011-11-08 03:12 . 2011-06-21 06:34 1923968 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-11-08 03:10 . 2011-02-23 04:55 90624 ----a-w- c:\windows\system32\drivers\bowser.sys
2011-11-08 02:56 . 2011-08-27 05:37 861696 ----a-w- c:\windows\system32\oleaut32.dll
2011-11-08 02:56 . 2011-08-27 05:37 331776 ----a-w- c:\windows\system32\oleacc.dll
2011-11-08 02:56 . 2011-08-27 04:26 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll
2011-11-08 02:56 . 2011-08-27 04:26 233472 ----a-w- c:\windows\SysWow64\oleacc.dll
2011-11-08 02:55 . 2011-06-23 04:33 3912576 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2011-11-08 02:55 . 2011-06-23 05:43 5561216 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-11-08 02:55 . 2011-06-23 04:33 3967872 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2011-11-08 02:12 . 2011-11-08 02:12 -------- d-----w- c:\windows\system32\SPReview
2011-11-08 01:36 . 2010-11-20 10:13 6144 ----a-w- c:\windows\system32\drivers\en-US\rdvgkmd.sys.mui
2011-11-08 01:36 . 2010-11-20 10:01 2560 ----a-w- c:\windows\system32\drivers\en-US\rdpwd.sys.mui
2011-11-08 01:36 . 2010-11-20 09:57 3072 ----a-w- c:\windows\system32\drivers\en-US\tsusbflt.sys.mui
2011-11-08 01:36 . 2010-11-20 10:11 4096 ----a-w- c:\windows\system32\drivers\en-US\tsusbhub.sys.mui
2011-11-08 01:36 . 2010-11-20 10:11 6144 ----a-w- c:\windows\system32\drivers\en-US\IPMIDrv.sys.mui
2011-11-08 01:36 . 2010-11-20 10:10 4608 ----a-w- c:\windows\system32\drivers\en-US\kbdclass.sys.mui
2011-11-08 01:14 . 2010-11-20 10:27 185856 ----a-w- c:\windows\system32\wbem\viewprov.dll
2011-11-08 01:13 . 2010-11-20 10:27 65536 ----a-w- c:\windows\system32\RpcRtRemote.dll
2011-11-08 01:09 . 2011-11-08 01:09 -------- d-----w- c:\windows\system32\EventProviders
2011-11-06 10:27 . 2011-11-06 10:27 -------- d-----w- c:\windows\SysWow64\BestPractices
2011-11-06 10:27 . 2011-11-06 10:27 -------- d-----w- c:\windows\system32\BestPractices
2011-11-06 10:27 . 2011-11-06 10:27 -------- d-----w- C:\inetpub
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-08 02:01 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-11-08 02:01 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-10-03 10:06 . 2010-06-14 04:21 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
2010-12-09 17:51 3911776 ----a-w- c:\program files (x86)\uTorrentBar\tbuTor.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\tbuTor.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-09-06 3722416]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"DisableCAD"= 1 (0x1)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-1
C:\Windows\system32\Winbhdupdt\
C:\Windows\windl32\
C:\Windows\SysWow64\Keylogger\
C:\Windows\system32\Keylogger\
C:\Windows\SysWow64\multi\
C:\Windows\system32\multi\
C:\Windows\installlytt\
C:\Windows\winrock32\
C:\Windows\SysWow64\Arquivo Comum\
C:\Windows\system32\Arquivo Comum\
C:\Windows\SysWow64\Date250\
C:\Windows\system32\Date250\
C:\Windows\SysWow64\tmpupdate\
C:\Windows\system32\tmpupdate\
C:\'\
C:\Windows\yahoo\Server.exe\
C:\Program Files (x86)\DealScout\
C:\Program Files\DealScout\
C:\Program Files (x86)\micro_sponsor12\
C:\Program Files\micro_sponsor12\
C:\Windows\SysWow64\nwebjeet\
C:\Windows\system32\nwebjeet\
C:\backup.bin\
C:\Windows\SysWow64\msn.exe\
C:\Windows\system32\msn.exe\
C:\Users\ac4tuje\
C:\Program Files (x86)\ATIdomji\
C:\Program Files\ATIdomji\
C:\Program Files (x86)\bomulmultisearchbar\
C:\Program Files\bomulmultisearchbar\
C:\Program Files (x86)\Microsoft Office\Officell\
C:\Program Files\Microsoft Office\Officell\
C:\Program Files (x86)\untswinsearch\
C:\Program Files\untswinsearch\
C:\Program Files (x86)\ysy\
C:\Program Files\ysy\
C:\Windows\SysWow64\burl\
C:\Windows\system32\burl\
C:\y2urhatg\
C:\Windows\assembly\tmp\U\
C:\Windows\XiaoNiu\
C:\Program Files (x86)\Common Files\Microsoft Services\S-1-5-21-0911896123-3820865822-3393560520-9587\
C:\Program Files\Common Files\Microsoft Services\S-1-5-21-0911896123-3820865822-3393560520-9587\
C:\su71u73.bin\
C:\Program Files (x86)\Ph4jk\
C:\Program Files\Ph4jk\
C:\Windows\SysWow64\window34\
C:\Windows\system32\window34\
C:\Program Files (x86)\hiyblpjxxw\
C:\Program Files\hiyblpjxxw\
C:\Program Files (x86)\ineeyylpwk\
C:\Program Files\ineeyylpwk\
C:\Program Files (x86)\wqjwiovm\
C:\Program Files\wqjwiovm\
C:\Windows\SysWow64\gamecdkeylist\
C:\Windows\system32\gamecdkeylist\
C:\Windows\winnnn\
C:\gaisyhudjia\
C:\servi3e.bin\
C:\Windows\SysWow64\del\
C:\Windows\system32\del\
C:\Windows\SysWow64\FileSys\
C:\Windows\system32\FileSys\
C:\Windows\SysWow64\FolderFiles\
C:\Windows\system32\FolderFiles\
C:\Windows\SysWow64\runfold\
C:\Windows\system32\runfold\
C:\Windows\SysWow64\wlpuses\
C:\Windows\system32\wlpuses\
C:\Windows\onlyyou\
C:\Windows\systam32\
C:\Windows\systemobjecthelper\
C:\Windows\thg\
C:\Program Files (x86)\SmartFind\
C:\Program Files\SmartFind\
C:\Program Files (x86)\WallTab\
C:\Program Files\WallTab\
C:\Program Files (x86)\annahussie\
C:\Program Files\annahussie\
C:\Windows\Dir\
C:\Intelmedia\
C:\Program Files (x86)\VirusScan\
C:\Program Files\VirusScan\
C:\Windows\SysWow64\frhj\
C:\Windows\system32\frhj\
C:\Windows\dosa\
C:\Windows\files\
C:\Windows\jlq\
C:\Program Files (x86)\adh6ad\
C:\Program Files\adh6ad\
C:\Program Files (x86)\cbcopop\
C:\Program Files\cbcopop\
C:\Program Files (x86)\Inter Virus Avira Laptops\
C:\Program Files\Inter Virus Avira Laptops\
C:\Program Files (x86)\mwinsearchopen\
C:\Program Files\mwinsearchopen\
C:\Windows\SysWow64\BrcServer\
C:\Windows\system32\BrcServer\
C:\helpbin.Bin\
C:\InstDrvs\
C:\Windows\inf\$P29XK4IGJ615H$\
C:\Program Files (x86)\AdobeFlashPlayer\Ìóñîð\
C:\Program Files\AdobeFlashPlayer\Ìóñîð\
C:\Program Files (x86)\greend\
C:\Program Files\greend\
C:\Program Files (x86)\isrchro\
C:\Program Files\isrchro\
C:\Program Files (x86)\LineAd\
C:\Program Files\LineAd\
C:\Program Files (x86)\WhenU\
C:\Program Files\WhenU\
C:\Program Files (x86)\win mysidebar\
C:\Program Files\win mysidebar\
C:\Program Files (x86)\Windows Live Show\
C:\Program Files\Windows Live Show\
C:\Windows\Wind32\
C:\Windows\SysWow64\sector\
C:\Windows\system32\sector\
C:\Windows\SysWow64\shell23\
C:\Windows\system32\shell23\
C:\Windows\SysWow64\Winwos\
C:\Windows\system32\Winwos\
C:\Windows\SysWow64\joinernormal\
C:\Windows\system32\joinernormal\
C:\Program Files (x86)\dialers\hot_netherlands\
C:\Program Files\dialers\hot_netherlands\
C:\Program Files (x86)\PopinMV\
C:\Program Files\PopinMV\
C:\Program Files (x86)\Winsoftwaer\
C:\Program Files\Winsoftwaer\
C:\Windows\SysWow64\25321\
C:\Windows\system32\25321\
C:\Windows\InstallDir\
C:\Program Files (x86)\ATIyjcyd\
C:\Program Files\ATIyjcyd\
C:\Program Files (x86)\Company\asfgrtrefd\
C:\Program Files\Company\asfgrtrefd\
C:\Program Files (x86)\svchoot\
C:\Program Files\svchoot\
C:\directory\micr\
C:\Windows\win32dc\
C:\Windows\winfiles\
C:\Windows\Winohgfgoisd\
C:\Windows\WORLD2\
C:\Windows\SysWow64\Important\
C:\Windows\system32\Important\
C:\Windows\SysWow64\VistaWin32update\
C:\Windows\system32\VistaWin32update\
C:\Windows\NUL\
C:\Windows\messenger\
C:\Windows\system\jssetup\
C:\Windows\SysWow64\JSsetup\
C:\Windows\system32\JSsetup\
C:\Windows\SysWow64\comdlg32\
C:\Windows\system32\comdlg32\
C:\SYSTEM\G-923-321232-3232-32211-23\
C:\Windows\SysWow64\Updata\
C:\Windows\system32\Updata\
C:\Windows\SysWow64\copy\
C:\Windows\system32\copy\
C:\Windows\xxxxxxx\
C:\Windows\windows33\
C:\Windows\SysWow64\mswr\
C:\Windows\system32\mswr\
C:\Windows\SysWow64\oobe\rule7\
C:\Windows\system32\oobe\rule7\
C:\Program Files (x86)\srchtist\
C:\Program Files\srchtist\
C:\Windows\SysWow64\%SYSTE~1\
C:\Windows\system32\%SYSTE~1\
C:\Windows\SysWow64\rundl\
C:\Windows\system32\rundl\
C:\Windows\SysWow64\win33\
C:\Windows\system32\win33\
C:\Windows\Messeng\
C:\Windows\NR\
C:\Program Files (x86)\Company Nival\pwmap\
C:\Program Files\Company Nival\pwmap\
C:\Program Files (x86)\Program Files\
C:\Program Files\Program Files\
C:\Program Files (x86)\ReAlplay\Dsetup2\
C:\Program Files\ReAlplay\Dsetup2\
C:\Program Files (x86)\ReAlplay\during\
C:\Program Files\ReAlplay\during\
C:\Program Files (x86)\RealPlay\Russian\
C:\Program Files\RealPlay\Russian\
C:\Program Files (x86)\ResultBrowse\
C:\Program Files\ResultBrowse\
C:\Program Files (x86)\SearchInOneStep\
C:\Program Files\SearchInOneStep\
C:\Program Files (x86)\WinRAR\Formats\Date\H%SESS~1\
C:\Program Files\WinRAR\Formats\Date\H%SESS~1\
C:\Windows\SysWow64\CPAPP\
C:\Windows\system32\CPAPP\
C:\Windows\SysWow64\dlhostest\
C:\Windows\system32\dlhostest\
C:\dialerfun\
C:\Program Files (x86)\augnum\
C:\Program Files\augnum\
C:\Program Files (x86)\windowsliveprotect\
C:\Program Files\windowsliveprotect\
C:\Windows Graphics Manager\
C:\Windows\SysWow64\msgs\
C:\Windows\system32\msgs\
C:\Windows\SysWow64\win321\
C:\Windows\system32\win321\
C:\Windows\SysWow64\wlpMX\
C:\Windows\system32\wlpMX\
C:\Windows\Winohgfgois\
C:\Program Files (x86)\ReAlplay\accordingly\
C:\Program Files\ReAlplay\accordingly\
C:\Program Files (x86)\ReAlplay\integrate\
C:\Program Files\ReAlplay\integrate\
C:\Program Files (x86)\ReAlplay\Platfor\
C:\Program Files\ReAlplay\Platfor\
C:\Program Files (x86)\ReAlplay\privileges\
C:\Program Files\ReAlplay\privileges\
C:\Program Files (x86)\ReAlplay\provided\
C:\Program Files\ReAlplay\provided\
C:\Program Files (x86)\ReAlplay\skipto\
C:\Program Files\ReAlplay\skipto\
C:\Program Files (x86)\ReAlplay\thatcomes\
C:\Program Files\ReAlplay\thatcomes\
C:\Program Files (x86)\ke\
C:\Program Files\ke\
C:\Windows\SysWow64\sora\
C:\Windows\system32\sora\
C:\Program Files (x86)\DictionaryBoss\bar\
C:\Program Files\DictionaryBoss\bar\
C:\Program Files (x86)\Clean-Top\
C:\Program Files\Clean-Top\
C:\Windows\System72\
C:\Program Files (x86)\Green\
C:\Program Files\Green\
C:\Program Files (x86)\greenbb\
C:\Program Files\greenbb\
C:\Program Files (x86)\vaccinecom\
C:\Program Files\vaccinecom\
C:\Windows\SysWow64\sedf\
C:\Windows\system32\sedf\
C:\Windows\Free\
C:\Windows\kingsoftv\
C:\Windows\vista321\
C:\Windows\winsxsss\
C:\Windows\WinXPs.com\
C:\Program Files (x86)\perfectcure\
C:\Program Files\perfectcure\
C:\Program Files (x86)\reall\
C:\Program Files\reall\
C:\Program Files (x86)\searchro\
C:\Program Files\searchro\
C:\Program Files (x86)\sodk\
C:\Program Files\sodk\
C:\Program Files (x86)\toowo\
C:\Program Files\toowo\
C:\Windows\SysWow64\BD\
C:\Windows\system32\BD\
C:\Windows\SysWow64\Micro\Black Ops.com\
C:\Windows\system32\Micro\Black Ops.com\
C:\syst63e.bin\
C:\Windows\spy-net\
C:\Windows\SysWow64\sora\
C:\Windows\system32\sora\
C:\Program Files (x86)\search_link\
C:\Program Files\search_link\
C:\Windows\SysWow64\bL\
C:\Windows\system32\bL\
C:\Windows\SysWow64\clrprv.oo\
C:\Windows\system32\clrprv.oo\
C:\Windows\SysWow64\embedded\
C:\Windows\system32\embedded\
C:\Windows\SysWow64\lothed\
C:\Windows\system32\lothed\
C:\Windows\SysWow64\winp\
C:\Windows\system32\winp\
C:\$recycle.bin\{5f229c11-5039-40e4-8537-6950bb1c9ecc}\
C:\dnf.lianfa\
C:\EshraQ PM Spammer V1.0[
www.topfarsi.com]\
C:\zv\exp\
C:\Windows\lz\
C:\Program Files (x86)\mrgibbage\
C:\Program Files\mrgibbage\
C:\Program Files (x86)\TpScrex\
C:\Program Files\TpScrex\
C:\Userow\
C:\Windows\mspack32\
C:\Windows\sumwin\
C:\Program Files (x86)\2\2\
C:\Program Files\2\2\
C:\Program Files (x86)\dyn_v27\
C:\Program Files\dyn_v27\
C:\Program Files (x86)\Give2SMS\
C:\Program Files\Give2SMS\
C:\Program Files (x86)\greenopen\
C:\Program Files\greenopen\
C:\Program Files (x86)\MClearPC\
C:\Program Files\MClearPC\
C:\Program Files (x86)\nacar\
C:\Program Files\nacar\
C:\Program Files (x86)\popupo\
C:\Program Files\popupo\
C:\Program Files (x86)\qq388\
C:\Program Files\qq388\
C:\Program Files (x86)\tabbrowser\
C:\Program Files\tabbrowser\
C:\Windows\SysWow64\coffin\
C:\Windows\system32\coffin\
C:\Windows\SysWow64\serv\
C:\Windows\system32\serv\
C:\System\kernels\phatk\
C:\Windows\SysWow64\x7\
C:\Windows\system32\