Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-01-2014 03 Ran by Leo Carpenter (administrator) on LEOCARPENTER-PC on 16-01-2014 16:33:24 Running from C:\Users\Leo Carpenter\Desktop Windows 7 Professional Service Pack 1 (X64) OS Language: English(US) Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (Trusteer Ltd.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe (AMD) C:\Windows\System32\atiesrxx.exe (SANDBOXIE L.T.D) C:\Program Files\Sandboxie\SbieSvc.exe (AMD) C:\Windows\System32\atieclxx.exe (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgfws.exe (Trusteer Ltd.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe (Akamai Technologies, Inc.) C:\Users\Leo Carpenter\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) C:\Users\Leo Carpenter\AppData\Local\Akamai\netsession_win.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\Software Update 3\SoftAuto.exe (Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.) C:\Users\Leo Carpenter\AppData\Local\Google\Update\GoogleUpdate.exe (Overwolf) C:\Program Files (x86)\Overwolf\Overwolf.exe () C:\Users\Leo Carpenter\AppData\Local\Temp\Rar$EX00.754\Chat Logger++.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTDevSrv.exe (Ellora Assets Corp.) C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe (Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe (SteelSeries ApS) C:\Program Files\SteelSeries\SteelSeries Engine\SteelSeriesEngine.exe (AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe () C:\Program Files (x86)\nuragoLSPService\nurago-WatchDog.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe (AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe (Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe (Acer Incorporated) C:\Program Files (x86)\Packard Bell\Registration\GregHSRW.exe (Google Inc.) C:\Users\Leo Carpenter\AppData\Local\Google\Chrome\Application\chrome.exe (Hi-Rez Studios) D:\games\Game\HiPatchService.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe (LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe (Google Inc.) C:\Users\Leo Carpenter\AppData\Local\Google\Chrome\Application\chrome.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe (nurago) C:\Program Files (x86)\nuragoLSPService\nuragoLspService.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (TorchMedia Inc.) C:\Users\Leo Carpenter\AppData\Local\Torch\Update\TorchCrashHandler.exe (Acer Group) C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe () C:\OEM\USBDECTION\USBS3S4Detection.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (Google Inc.) C:\Users\Leo Carpenter\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Leo Carpenter\AppData\Local\Google\Chrome\Application\chrome.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Google Inc.) C:\Users\Leo Carpenter\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Leo Carpenter\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Leo Carpenter\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Leo Carpenter\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Leo Carpenter\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Leo Carpenter\AppData\Local\Google\Chrome\Application\chrome.exe (Overwolf) C:\Program Files (x86)\Common Files\Overwolf\OverwolfHelper64.exe (Google Inc.) C:\Users\Leo Carpenter\AppData\Local\Google\Chrome\Application\chrome.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe (Google Inc.) C:\Users\Leo Carpenter\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Leo Carpenter\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Kernel and Hardware Abstraction Layer] - C:\Windows\KHALMNPR.EXE [130576 2009-06-17] (Logitech, Inc.) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [nurago-WatchDog] - C:\Program Files (x86)\nuragoLSPService\nurago-WatchDog.exe [60536 2013-07-17] () HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3806544 2013-11-29] (LogMeIn Inc.) HKLM-x32\...\Run: [AVG_UI] - C:\Program Files (x86)\AVG\AVG2014\avgui.exe [4956176 2013-11-07] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Runonce: [AvgUninstallURL] - cmd.exe /c start http://www.avg.com/ww.special-uninstallation-feedback-app?lic=OE1FSC1SUzQ3WS04MkhUOC1HT05WQS1CQ0NDWi1ERU1CUg"&"inst=NzYtNzA4NzU1NTIyLUQzODFMKzYtU1AxKzEtU1AxVEIrMS1TVVArNC1TUDFTMisxLUREVCswLUxTRCsyLUkxMCsxLVNUMTBBUFArMQ"&"prod=94"&"ver=10.0.1424 [x] Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.) HKLM\...\Policies\Explorer: [NoSetActiveDesktop] 0 HKLM\...\Policies\Explorer: [NoFolderOptions] 0 HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.) HKCU\...\Run: [Clownfish] - [x] HKCU\...\Run: [Akamai NetSession Interface] - C:\Users\Leo Carpenter\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.) HKCU\...\Run: [Media Finder] - "C:\Program Files (x86)\Media Finder\Media Finder.exe" /opentotray HKCU\...\Run: [SoftAuto.exe] - C:\Program Files (x86)\Creative\Software Update 3\SoftAuto.exe [405504 2008-08-13] (Creative Technology Ltd) HKCU\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2010-05-11] (Google Inc.) HKCU\...\Run: [Google Update] - C:\Users\Leo Carpenter\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2011-09-24] (Google Inc.) HKCU\...\Run: [Overwolf] - C:\Program Files (x86)\Overwolf\Overwolf.exe [35768 2013-12-09] (Overwolf) HKCU\...\Run: [Chat Logger++] - C:\Users\Leo Carpenter\AppData\Local\Temp\Rar$EX00.754\Chat Logger++.exe [1516544 2012-10-14] () <===== ATTENTION HKCU\...\Run: [GarminExpressTrayApp] - C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1095000 2013-11-08] (Garmin Ltd or its subsidiaries) HKCU\...\Run: [SteelSeries Engine] - C:\Program Files\SteelSeries\SteelSeries Engine\SteelSeriesEngine.exe [242688 2013-11-05] (SteelSeries ApS) HKCU\...\Run: [HydraVisionDesktopManager] - C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [393216 2011-09-23] (AMD) HKCU\...\Policies\system: [DisableCMD] 0 HKCU\...\Policies\Explorer: [NoSetActiveDesktop] 0 HKCU\...\Policies\Explorer: [NoFolderOptions] 0 MountPoints2: G - G:\setup.exe MountPoints2: {2e8e54bb-fe15-11df-931d-4487fcc51651} - N:\Autorun.exe MountPoints2: {55305ef1-92b3-11e1-9da2-4487fcc51651} - P:\iStudio.exe HKU\Default\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Packard Bell\Screensaver\run_Packard Bell.exe [162336 2009-07-22] () HKU\Default User\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Packard Bell\Screensaver\run_Packard Bell.exe [162336 2009-07-22] () HKU\Guest\...\Run: [Software Informer] - "C:\Program Files (x86)\Software Informer\softinfo.exe" -autorun HKU\Guest\...\Run: [fsm] - [x] HKU\Guest\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2010-05-11] (Google Inc.) HKU\Guest\...\Run: [Software Suite SE] - C:\Program Files (x86)\Packard Bell\Software Suite SE\SoftSuiteSE.exe [2275360 2009-09-29] (Acer Incorporated) HKU\Guest\...\Run: [SteamCracker.exe] - C:\Users\Guest\AppData\Local\Temp\ [0 ] () <===== ATTENTION HKU\Guest\...\Run: [Steam] - C:\Program Files (x86)\Steam\steam.exe [1815976 2014-01-14] (Valve Corporation) HKU\Guest\...\Run: [TRDIse] - C:\Users\Guest\Desktop\do not remove !!!\Red Dragon 6.exe HKU\Guest\...\Run: [DAEMON Tools Pro Agent] - "C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun HKU\Guest\...\Run: [FormAutoFiller] - C:\Program Files (x86)\FormAutoFiller\faf.exe HKU\Guest\...\Run: [Facebook Update] - C:\Users\Leo Carpenter\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-07-12] (Facebook Inc.) HKU\Guest\...\Run: [Google Update] - C:\Users\Leo Carpenter\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2011-09-24] (Google Inc.) HKU\Guest\...\Run: [Exetender] - "C:\Program Files (x86)\Free Ride Games\GPlayer.exe" /schedule 300000 HKU\Guest\...\Run: [Akamai NetSession Interface] - C:\Users\Guest\AppData\Local\Akamai\netsession_win.exe HKU\Guest\...\Run: [ISUSPM Startup] - C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup HKU\Guest\...\RunOnce: [spchecker] - "C:\Program Files (x86)\AVG\AVG10\Notification\SPCheckerTE.exe" HKU\School Work-Bradley\...\Run: [HydraVisionDesktopManager] - C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [393216 2011-09-23] (AMD) HKU\School Work-Bradley\...\Run: [Akamai NetSession Interface] - C:\Users\School Work-Bradley\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.) AppInit_DLLs: [ ] () Startup: C:\Users\Leo Carpenter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DCOM Utilities.url () ==================== Internet (Whitelisted) ==================== ProxyServer: 69.105.24.201:54778 HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.co.uk/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?babsrc=HP_def_sps HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Before = http://search.hotspotshield.com/g/?c=h HKCU\Software\Microsoft\Internet Explorer\Main,Search Page Before = http://downloads.phpnuke.org/en/index.php?rvs=google HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://downloads.phpnuke.org/en/index.php?rvs=google URLSearchHook: HKLM-x32 - (No Name) - {dd02a4eb-4afd-4d60-99d8-e67f964ca813} - No File URLSearchHook: HKLM-x32 - (No Name) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - No File URLSearchHook: HKLM-x32 - (No Name) - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - No File SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snapdo.com/?publisher=VertiTechnologyYB&dpid=VertiTechnologyYB&co=GB&userid=3f81bba1-31e7-4dcb-bbe6-734d280d6bf9&searchtype=ds&q={searchTerms}&installDate=27/07/2013 SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snapdo.com/?publisher=VertiTechnologyYB&dpid=VertiTechnologyYB&co=GB&userid=3f81bba1-31e7-4dcb-bbe6-734d280d6bf9&searchtype=ds&q={searchTerms}&installDate=27/07/2013 SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www2.delta-search.com/?q={searchTerms}&affID=119816&babsrc=SP_ss&mntrId=E4CB00FF89FCEE49 SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\jp2ssv.dll (Oracle Corporation) BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE_64.dll No File BHO-x32: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll No File BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: PC Tools Browser Guard BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.) BHO-x32: DivX Plus Web Player HTML5