Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Outlook and Firefox Internet Access Blocked; IE9 is Ok


  • Please log in to reply

#1
Braind

Braind

    Member

  • Member
  • PipPipPip
  • 246 posts
OS = MS 7 Home Premium, 64 bit

On 10/20/13, I used the free version of VIPRE Rescue Tool. It cleaned a malware that required a reboot to complete. After rebooting, I used Bitfinder Internet Security 2012 complete system scan. It also find another malware and deleted it.

Soon after that, I lost Firefox and Chrome access to the internet. The browsers would load but could not get acces to the internet. Outlook 2010 and the IE9 browser worked fine on 10/20/13.
I uninstalled Chrome and tried to reinstall using IE9 to download Chrome, but it would not install, giving me Error 0x80040707.

Now on 10/21/13, Outlook 2010 stopped getting emails from the internet. IE9 still works, for now.

I tried to run the OTL software, but it gets stuck at "Scanning Firefox Settings...."
and just keeps on running.
This where I am at now.

  • 0

Advertisements


#2
Braind

Braind

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 246 posts
I ran a MBAM full scan. It found no malware. Please see attached.Attached File  mbam-log-2013-10-21 (19-25-50).txt   1.88KB   29 downloadsAttached File  mbam-log-2013-10-21 (19-25-50).txt   1.88KB   29 downloads
  • 0

#3
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,012 posts
  • MVP
In FireFox, (Tools or the Firefox button), Options, Advanced, Settings, check No Proxy then OK. Close Firefox and restart Firefox.

In Chrome, Wrench, Options, Under the Hood, Change Proxy Settings, uncheck all boxes, OK.

Restart and test. If still no good:

Please download MiniToolBox, save it to your desktop and run it.

Checkmark the following checkboxes:
  • Flush DNS
  • Report IE Proxy Settings
  • Reset IE Proxy Settings
  • Report FF Proxy Settings
  • Reset FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer Errors
  • List Installed Programs
  • List Devices
  • List Users, Partitions and Memory size.
  • List Minidump Files
Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run.

Note: When using "Reset FF Proxy Settings" option Firefox should be closed.


Also see if you can get one of these to scan:


Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.

Please download DDS from http://download.blee...om/sUBs/dds.com or http://download.blee...om/sUBs/dds.scr
and save it to your desktop.

* Disable any script blocking protection
* Double click dds.pif to run the tool. (Vista and Win 7 please right click and Run As Admin)
* When done, two DDS.txt's will open.
* Save both reports to your desktop.

---------------------------------------------------
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.
  • 0

#4
Braind

Braind

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 246 posts
The firefox fix did not work. I still can't download Chrome.

Here are the results you requested:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-10-2013 01
Ran by Brain (administrator) on BRAIN-HP on 21-10-2013 22:28:36
Running from C:\Users\Brain\AppData\Local\Temp\Temporary Internet Files\Content.IE5\9JRA0BTT
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Normal


==================== Processes (Whitelisted) =================

(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe
(Microsoft Corporation) c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
() C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(FileHippo.com) C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe
(Webshots) C:\Program Files (x86)\Webshots\Smile Desktop\Smile.exe
(Repkasoft) C:\Program Files (x86)\YoWindow\yowindow.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Abine Inc.) C:\Program Files\DoNotTrackPlus\IE\DNTPService.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\BingApp.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\BingBar.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\BingSurrogate.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\BingSurrogate.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\BingSurrogate.exe
(Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil64_11_9_900_117_ActiveX.exe
(Condusiv Technologies) C:\Program Files\Condusiv Technologies\Diskeeper\DkService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Bdagent] - C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe [1575192 2013-10-03] (Bitdefender)
HKLM\...\Run: [SBRegRebootCleaner] - C:\VIPRERESCUE\SBRC.exe [202128 2013-09-30] (ThreatTrack Security, Inc.)
HKLM-x32\...\RunOnce: [B Register C:\Program Files (x86)\DivX\DivX Plus DirectShow Filters\DirectShowDemuxFilter.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus DirectShow Filters\DirectShowDemuxFilter.dll",DllRegisterServer [1638400 2012-11-05] (DivX, Inc.)
HKCU\...\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6588144 2013-10-03] (SUPERAntiSpyware)
HKCU\...\Run: [GoogleDriveSync] - C:\Program Files (x86)\Google\Drive\googledrivesync.exe [20133824 2013-09-25] (Google)
HKCU\...\Run: [Google Update] - C:\Users\Brain\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2012-01-05] (Google Inc.)
HKCU\...\Run: [FileHippo.com] - C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe [307712 2012-11-23] (FileHippo.com)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
Startup: C:\Users\Brain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smile Desktop.lnk
ShortcutTarget: Smile Desktop.lnk -> C:\Program Files (x86)\Webshots\Smile Desktop\Smile.exe (Webshots)
Startup: C:\Users\Brain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\YoWindow.lnk
ShortcutTarget: YoWindow.lnk -> C:\Program Files (x86)\YoWindow\yowindow.exe (Repkasoft)


==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.bing.com/?PC=BNHP
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
URLSearchHook: (No Name) - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - No File
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...rc=IE-SearchBox
SearchScopes: HKLM - {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://search.ask.co...&l=dis&o=HPDTDF
SearchScopes: HKLM - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = http://search.yahoo....psg&type=HPDTDF
SearchScopes: HKLM - {C46296C9-9FB6-4509-8294-68FA8F44E6DB} URL = http://www.amazon.co...ds={searchTerms}
SearchScopes: HKLM - {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = http://en.wikipedia....ch={searchTerms}
SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.co...kw={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {22DE9C45-49D6-4693-9023-90CCAA229927} URL =
SearchScopes: HKLM-x32 - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} URL = http://search.imgag....&q={searchTerms}
SearchScopes: HKLM-x32 - {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://search.ask.co...&l=dis&o=HPDTDF
SearchScopes: HKLM-x32 - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = http://search.yahoo....psg&type=HPDTDF
SearchScopes: HKLM-x32 - {C46296C9-9FB6-4509-8294-68FA8F44E6DB} URL = http://www.amazon.co...ds={searchTerms}
SearchScopes: HKLM-x32 - {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = http://en.wikipedia....ch={searchTerms}
SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.co...kw={searchTerms}
SearchScopes: HKCU - DefaultScope {22DE9C45-49D6-4693-9023-90CCAA229927} URL = http://search.condui...3601889568&UM=2
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} URL = http://search.imgag....&q={searchTerms}
SearchScopes: HKCU - {22DE9C45-49D6-4693-9023-90CCAA229927} URL = http://search.condui...3601889568&UM=2
SearchScopes: HKCU - {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://search.ask.co...&l=dis&o=HPDTDF
SearchScopes: HKCU - {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = http://safesearchr.l...&q={searchTerms}
SearchScopes: HKCU - {70D46D94-BF1E-45ED-B567-48701376298E} URL = http://127.0.0.1:466...?q={searchTerms}
SearchScopes: HKCU - {A26C36F3-9D6C-4551-86A4-B3E9C4B7B3CD} URL = http://www.crawler.c...id=10005&lng=en
SearchScopes: HKCU - {B2E038B0-81C7-454F-B105-49E183CED4DF} URL = http://www.dogpile.c...kw={searchTerms}
SearchScopes: HKCU - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = http://search.yahoo....psg&type=HPDTDF
SearchScopes: HKCU - {C46296C9-9FB6-4509-8294-68FA8F44E6DB} URL = http://www.amazon.co...ds={searchTerms}
SearchScopes: HKCU - {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = http://en.wikipedia....ch={searchTerms}
SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.co...kw={searchTerms}
BHO: Bing Bar Helper - {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\amd64\BingExt.dll (Microsoft Corporation.)
BHO: Do Not Track Plus - {6E45F3E8-2683-4824-A6BE-08108022FB36} - C:\Program Files\DoNotTrackPlus\IE\DNTPAddon.dll (Abine)
BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Bing Bar Helper - {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\BingExt.dll (Microsoft Corporation.)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO-x32: Dogpile Toolbar BHO - {61AFBC1F-52F3-43F5-A5ED-AFA778C579E1} - C:\Program Files (x86)\Dogpile Toolbar\Toolbar.dll ()
BHO-x32: Do Not Track Plus - {6E45F3E8-2683-4824-A6BE-08108022FB36} - C:\Program Files (x86)\DoNotTrackPlus\ScriptHost.dll (Abine)
BHO-x32: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
BHO-x32: Norton Safe Web Lite BHO - {F0DA78E9-6B60-42fb-BC26-EF2CFB8C8FF3} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\coIEPlg.dll (Symantec Corporation)
Toolbar: HKLM - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\amd64\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - Dogpile Toolbar - {8A936F47-6B90-4537-A1BC-6F369A203D47} - C:\Program Files (x86)\Dogpile Toolbar\Toolbar.dll ()
Toolbar: HKLM-x32 - Norton Safe Web Lite - {30CEEEA2-3742-40e4-85DD-812BF1CBB83D} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\coIEPlg.dll (Symantec Corporation)
Toolbar: HKLM-x32 - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\BingExt.dll (Microsoft Corporation.)
DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab
Handler: crawler - {4545C96B-15D0-4E22-8DDE-6F2CAF531281} - No File
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: crawler - {4545C96B-15D0-4E22-8DDE-6F2CAF531281} - C:\Program Files (x86)\Crawler Toolbar\Crawler.dll (Crawler.com, LLC)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog9 01 C:\Windows\system32\Sendori.dll File Not found ()
Winsock: Catalog9 02 C:\Windows\system32\Sendori.dll File Not found ()
Winsock: Catalog9 03 C:\Windows\system32\Sendori.dll File Not found ()
Winsock: Catalog9 04 C:\Windows\system32\Sendori.dll File Not found ()
Winsock: Catalog9 15 C:\Windows\system32\Sendori.dll File Not found ()
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254


FireFox:
========
FF ProfilePath: C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\x1ft5x1x.default-1340583930802
FF user.js: detected! => C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\x1ft5x1x.default-1340583930802\user.js
FF NewTab: about:blank
FF DefaultSearchEngine: appbario12 Customized Web Search
FF SelectedSearchEngine: appbario12 Customized Web Search
FF Homepage: hxxp://www.dogpile.com/
FF Keyword.URL: hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3279411&SearchSource=2&CUI=UN14915692952109325&UM=2&q=
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=16.0.3.51 - c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpchromebrowserrecordext;version=15.0.6.14 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll No File
FF Plugin-x32: @real.com/nprphtml5videoshim;version=15.0.6.14 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll No File
FF Plugin-x32: @real.com/nprpplugin;version=16.0.3.51 - c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @hulu.com/Hulu Desktop - C:\Windows\..\Users\Default\AppData\Local\HuluDesktop\instances\0.9.13.1\npHDPlg.dll (Hulu LLC)
FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Brain\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Brain\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKCU: @talk.google.com/O3DPlugin - C:\Users\Brain\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Brain\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Brain\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: facebook.com/fbDesktopPlugin - C:\Users\Brain\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll (Facebook, Inc.)
FF SearchPlugin: C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\x1ft5x1x.default-1340583930802\searchplugins\my-web-search.xml
FF SearchPlugin: C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\x1ft5x1x.default-1340583930802\searchplugins\safesearch.xml
FF SearchPlugin: C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\x1ft5x1x.default-1340583930802\searchplugins\web-search.xml
FF Extension: No Name - C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\x1ft5x1x.default-1340583930802\Extensions\[email protected]
FF Extension: Виявлення пристроїв Logitech - C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\x1ft5x1x.default-1340583930802\Extensions\[email protected]
FF Extension: DoNotTrackMe - C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\x1ft5x1x.default-1340583930802\Extensions\[email protected]
FF Extension: No Name - C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\x1ft5x1x.default-1340583930802\Extensions\[email protected]
FF Extension: MaskMe - C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\x1ft5x1x.default-1340583930802\Extensions\[email protected]
FF Extension: Lavasoft Search Plugin - C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\x1ft5x1x.default-1340583930802\Extensions\[email protected]
FF Extension: appbario12 - C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\x1ft5x1x.default-1340583930802\Extensions\{465fcfbb-47a4-4866-a5d5-d12f9a77da00}
FF Extension: firefox - C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\x1ft5x1x.default-1340583930802\Extensions\[email protected]
FF Extension: personas - C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\x1ft5x1x.default-1340583930802\Extensions\[email protected]
FF Extension: testpilot - C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\x1ft5x1x.default-1340583930802\Extensions\[email protected]
FF Extension: No Name - C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\x1ft5x1x.default-1340583930802\Extensions\{9a94d785-2979-44e9-b331-9e09d0cc7cff}.xpi
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF HKLM\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext
FF Extension: No Name - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext
FF HKLM-x32\...\Firefox\Extensions: [{203FB6B2-2E1E-4474-863B-4C483ECCE78E}] - C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_1.2.0.6\coFFNST\
FF Extension: Norton Safe Web Lite Toolbar - C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_1.2.0.6\coFFNST\
FF HKLM-x32\...\Firefox\Extensions: [{0153E448-190B-4987-BDE1-F256CADA672F}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKLM-x32\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF HKLM-x32\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext
FF Extension: No Name - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext


==================== Services (Whitelisted) =================

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [143120 2013-05-23] (SUPERAntiSpyware.com)
S4 BdDesktopParental; C:\Program Files\Bitdefender\Bitdefender 2013\bdparentalservice.exe [69392 2013-08-27] (Bitdefender)
R2 BingDesktopUpdate; C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [173192 2013-06-27] (Microsoft Corp.)
S3 COMSysApp; C:\Windows\SysWow64\dllhost.exe [7168 2009-07-13] (Microsoft Corporation)
R2 Diskeeper; C:\Program Files\Condusiv Technologies\Diskeeper\DkService.exe [2721656 2012-07-27] (Condusiv Technologies)
S3 GoogleDesktopManager-051210-111108; C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe [30192 2011-07-25] (Google)
R2 HP Power Assistant Service; C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [107576 2010-11-17] ()
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 msiserver; C:\Windows\SysWow64\msiexec.exe [73216 2010-11-20] (Microsoft Corporation)
S4 NSL; C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe [130000 2010-11-23] (Symantec Corporation)
S4 pcCMService64; C:\Program Files\Common Files\Motive\pcCMService.exe [460288 2013-07-19] (Alcatel-Lucent)
S4 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1127448 2011-02-01] (PDF Complete Inc)
S4 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
R2 SafeBox; C:\Program Files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe [95184 2012-06-25] (Bitdefender)
R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe [67320 2013-08-27] (Bitdefender)
R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe [1645256 2013-10-03] (Bitdefender)
R2 WSearch; C:\Windows\SysWow64\SearchIndexer.exe [427520 2011-05-03] (Microsoft Corporation)
S4 Application Sendori; C:\Program Files (x86)\Sendori\SendoriSvc.exe [x]
S4 Service Sendori; C:\Program Files (x86)\Sendori\Sendori.Service.exe [x]
S4 sndappv2; C:\Program Files (x86)\Sendori\sndappv2.exe [x]


==================== Drivers (Whitelisted) ====================

R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [727592 2013-08-01] (BitDefender)
R3 avchv; C:\Windows\System32\DRIVERS\avchv.sys [261056 2012-11-02] (BitDefender)
R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [601360 2013-08-01] (BitDefender)
R1 BdfNdisf; c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [93600 2013-04-26] (BitDefender LLC)
R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [103504 2011-11-14] (BitDefender LLC)
S3 BDSandBox; C:\Windows\system32\drivers\bdsandbox.sys [82824 2013-08-01] (BitDefender SRL)
R1 BDVEDISK; C:\Windows\System32\DRIVERS\bdvedisk.sys [76944 2012-04-17] (BitDefender)
S3 CpqDfw; C:\Windows\System32\drivers\CpqDfw.sys [27456 2012-05-29] (Windows ® Codename Longhorn DDK provider)
R3 DKRtWrt; C:\Windows\System32\DRIVERS\DKRtWrt.sys [52048 2012-06-18] (Condusiv Technologies)
R0 DKTLFSMF; C:\Windows\System32\drivers\DKTLFSMF.sys [106832 2012-07-09] (Condusiv Technologies)
S3 gfiark; C:\Windows\System32\drivers\gfiark.sys [41032 2013-05-23] (ThreatTrack Security)
R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [14456 2013-01-06] (GFI Software)
S3 gfiutil; C:\Windows\System32\drivers\gfiutil.sys [31264 2013-09-04] (ThreatTrack Security)
R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [150256 2013-10-03] (BitDefender LLC)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-13] (Brother Industries Ltd.)
R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [389240 2013-10-03] (BitDefender S.R.L.)
S3 usbrndis6; C:\Windows\system32\drivers\usb80236.sys [19968 2013-02-11] (Microsoft Corporation)
S3 veebeampol; C:\Windows\System32\DRIVERS\veebeampol.sys [14952 2010-11-29] (Veebeam Corporation)
S3 MREMP50; \??\C:\PROGRA~2\COMMON~1\Motive\MREMP50.SYS [x]
S3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [x]
S3 MRESP50; \??\C:\PROGRA~2\COMMON~1\Motive\MRESP50.SYS [x]
S3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [x]


==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-10-21 22:27 - 2013-10-21 22:27 - 01954698 _____ (Farbar) C:\Users\Brain\Downloads\FRST64 (1).exe
2013-10-21 22:22 - 2013-10-21 22:22 - 00000000 ____D C:\FRST
2013-10-21 22:21 - 2013-10-21 22:25 - 01954698 _____ (Farbar) C:\Users\Brain\Downloads\FRST64.exe
2013-10-21 22:21 - 2013-10-21 22:21 - 00062920 _____ C:\Users\Brain\Desktop\Result.txt
2013-10-21 22:20 - 2013-10-21 22:20 - 00062920 _____ C:\Users\Brain\Downloads\Result.txt
2013-10-21 22:18 - 2013-10-21 22:18 - 00760937 _____ (Farbar) C:\Users\Brain\Downloads\MiniToolBox.exe
2013-10-21 22:18 - 2013-10-21 22:18 - 00001173 _____ C:\Users\Brain\Desktop\MiniToolBox.exe - Shortcut.lnk
2013-10-21 19:19 - 2013-10-21 19:19 - 00602112 _____ (OldTimer Tools) C:\Users\Brain\Downloads\OTL.com
2013-10-21 19:10 - 2013-10-21 19:10 - 00602112 _____ (OldTimer Tools) C:\Users\Brain\Downloads\OTL (1).exe
2013-10-21 19:10 - 2013-10-21 19:10 - 00001137 _____ C:\Users\Brain\Desktop\OTL (1).exe - Shortcut.lnk
2013-10-21 19:04 - 2013-10-21 19:04 - 00602112 _____ (OldTimer Tools) C:\Users\Brain\Downloads\OTL.exe
2013-10-20 16:59 - 2013-10-20 20:41 - 00000104 _____ C:\Windows\SysWOW64\SBRC.dat
2013-10-20 16:50 - 2013-10-20 16:52 - 145604608 _____ C:\Users\Brain\Downloads\VIPRERescue22558.exe
2013-10-18 20:37 - 2013-10-21 07:24 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-10-16 17:22 - 2013-10-08 07:50 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-10-16 17:22 - 2013-10-08 07:46 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-10-16 17:22 - 2013-10-08 07:46 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-10-16 17:22 - 2013-10-08 07:46 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-10-16 17:21 - 2013-10-16 17:22 - 00004746 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log
2013-10-16 17:20 - 2013-10-16 17:20 - 00915368 _____ (Oracle Corporation) C:\Users\Brain\Downloads\jxpiinstall(1).exe
2013-10-16 17:19 - 2013-10-16 17:22 - 00000000 ____D C:\ProgramData\Oracle
2013-10-16 17:19 - 2013-10-16 17:18 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-16 17:19 - 2013-10-16 17:18 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-16 17:19 - 2013-10-16 17:18 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-16 17:19 - 2013-10-16 17:18 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2013-10-16 17:18 - 2013-10-16 17:18 - 00000000 ____D C:\Program Files\Java
2013-10-16 17:16 - 2013-10-16 17:16 - 30694824 _____ (Oracle Corporation) C:\Users\Brain\Downloads\jre-7u45-windows-x64.exe
2013-10-15 22:27 - 2013-10-15 22:27 - 00003288 ____N C:\bootsqm.dat
2013-10-13 19:33 - 2013-09-04 14:57 - 00031264 _____ (ThreatTrack Security) C:\Windows\system32\Drivers\gfiutil.sys
2013-10-13 19:33 - 2013-05-23 08:39 - 00041032 _____ (ThreatTrack Security) C:\Windows\system32\Drivers\gfiark.sys
2013-10-13 19:29 - 2013-10-13 19:32 - 145285120 _____ C:\Users\Brain\Downloads\VIPRERescue22342.exe
2013-10-11 18:29 - 2013-10-11 18:29 - 00003134 _____ C:\Windows\System32\Tasks\{7A427579-FDC6-4DB9-900D-77A0759A83F3}
2013-10-11 18:27 - 2013-10-11 18:28 - 18093984 _____ (Adobe Systems Inc.) C:\Users\Brain\Downloads\air3-9_win(4).exe
2013-10-11 18:14 - 2013-09-04 07:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2013-10-11 18:14 - 2013-09-04 07:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2013-10-11 18:14 - 2013-09-04 07:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2013-10-11 18:14 - 2013-09-04 07:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2013-10-11 18:14 - 2013-09-04 07:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2013-10-11 18:14 - 2013-09-04 07:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2013-10-11 18:14 - 2013-09-04 07:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2013-10-09 19:51 - 2013-09-22 10:43 - 17833984 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-10-09 19:51 - 2013-09-22 10:01 - 10926080 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-10-09 19:51 - 2013-09-22 09:42 - 02312704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-10-09 19:51 - 2013-09-22 09:36 - 01346560 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-10-09 19:51 - 2013-09-22 09:33 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-10-09 19:51 - 2013-09-22 09:33 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-10-09 19:51 - 2013-09-22 09:30 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-10-09 19:51 - 2013-09-22 09:27 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-10-09 19:51 - 2013-09-22 09:23 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-10-09 19:51 - 2013-09-22 09:22 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-10-09 19:51 - 2013-09-22 09:21 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-10-09 19:51 - 2013-09-22 09:19 - 02147840 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-10-09 19:51 - 2013-09-22 09:19 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-10-09 19:51 - 2013-09-22 09:16 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-10-09 19:51 - 2013-09-22 09:15 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-10-09 19:51 - 2013-09-22 09:07 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-10-09 19:51 - 2013-09-22 05:29 - 12336128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-10-09 19:51 - 2013-09-22 05:22 - 09739264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-10-09 19:51 - 2013-09-22 05:22 - 01800704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-10-09 19:51 - 2013-09-22 05:14 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-10-09 19:51 - 2013-09-22 05:13 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-10-09 19:51 - 2013-09-22 05:13 - 01104896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-10-09 19:51 - 2013-09-22 05:12 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-10-09 19:51 - 2013-09-22 05:09 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-10-09 19:51 - 2013-09-22 05:08 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-10-09 19:51 - 2013-09-22 05:07 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-10-09 19:51 - 2013-09-22 05:06 - 00420864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-10-09 19:51 - 2013-09-22 05:05 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-10-09 19:51 - 2013-09-22 05:03 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-10-09 19:51 - 2013-09-22 05:03 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-10-09 19:51 - 2013-09-22 05:03 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-10-09 19:51 - 2013-09-22 04:59 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-10-09 19:36 - 2013-09-13 20:10 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-10-09 19:36 - 2013-09-07 21:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-10-09 19:36 - 2013-09-07 21:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2013-10-09 19:36 - 2013-09-07 21:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2013-10-09 19:36 - 2013-08-28 21:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-10-09 19:36 - 2013-08-28 21:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-10-09 19:36 - 2013-08-28 21:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2013-10-09 19:36 - 2013-08-28 21:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-10-09 19:36 - 2013-08-28 21:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2013-10-09 19:36 - 2013-08-28 20:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-10-09 19:36 - 2013-08-28 20:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-10-09 19:36 - 2013-08-28 20:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-10-09 19:36 - 2013-08-28 20:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2013-10-09 19:36 - 2013-08-28 20:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-10-09 19:36 - 2013-08-28 20:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2013-10-09 19:36 - 2013-08-28 19:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-10-09 19:36 - 2013-08-28 19:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-10-09 19:36 - 2013-08-28 19:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-10-09 19:36 - 2013-08-28 19:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-10-09 19:36 - 2013-08-27 20:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-10-09 19:36 - 2013-08-27 20:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2013-10-09 19:36 - 2013-07-20 05:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-09 19:36 - 2013-07-20 05:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2013-10-09 19:36 - 2013-07-12 05:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2013-10-09 19:36 - 2013-07-04 07:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2013-10-09 19:36 - 2013-07-04 07:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2013-10-09 19:36 - 2013-07-04 07:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2013-10-09 19:36 - 2013-07-04 06:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2013-10-09 19:36 - 2013-07-04 06:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2013-10-09 19:36 - 2013-07-04 06:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2013-10-09 19:36 - 2013-07-04 05:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2013-10-09 19:36 - 2013-07-02 23:40 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys
2013-10-09 19:36 - 2013-07-02 23:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2013-10-09 19:36 - 2013-07-02 23:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2013-10-09 19:36 - 2013-06-25 17:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2013-10-09 19:36 - 2013-06-06 00:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2013-10-09 19:36 - 2013-06-06 00:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2013-10-09 19:36 - 2013-06-06 00:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2013-10-09 19:36 - 2013-06-06 00:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2013-10-09 19:36 - 2013-06-05 23:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2013-10-09 19:36 - 2013-06-05 23:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2013-10-09 19:36 - 2013-06-05 23:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2013-10-09 19:36 - 2013-06-05 22:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2013-10-09 19:36 - 2013-06-05 22:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2013-10-09 19:36 - 2013-06-05 22:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2013-10-09 19:33 - 2013-08-01 07:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2013-10-09 17:24 - 2013-10-09 17:24 - 00003148 _____ C:\Windows\System32\Tasks\{DB257009-8FF4-4B0B-AD52-239FC0A9D55D}
2013-10-09 17:24 - 2013-10-09 17:24 - 00003148 _____ C:\Windows\System32\Tasks\{2A4C8CE8-8FAD-4614-82C6-BBB070B7AAC2}
2013-10-09 17:23 - 2013-10-09 17:23 - 01070800 _____ (Solid State Networks) C:\Users\Brain\Downloads\install_flashplayer11x32_mssd_aaa_aih(1).exe
2013-10-09 17:21 - 2013-10-09 17:21 - 06951048 _____ (Microsoft Corporation) C:\Users\Brain\Downloads\Silverlight(2).exe
2013-10-09 17:20 - 2013-10-09 17:20 - 18080872 _____ (Adobe Systems Inc.) C:\Users\Brain\Downloads\AdobeAIRInstaller(1).exe
2013-10-07 23:23 - 2013-10-20 13:21 - 00003362 _____ C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-649025149-514020257-970770016-1000
2013-10-07 23:23 - 2013-10-20 13:21 - 00003228 _____ C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-649025149-514020257-970770016-1000
2013-10-06 21:07 - 2013-10-06 21:09 - 143331328 _____ C:\Users\Brain\Downloads\VIPRERescue22130.exe
2013-10-06 18:34 - 2013-10-21 22:08 - 00013048 _____ C:\Windows\setupact.log
2013-10-06 18:34 - 2013-10-06 18:34 - 00000000 _____ C:\Windows\setuperr.log
2013-10-05 21:48 - 2013-10-05 21:48 - 01859296 _____ (Coupons.com Incorporated) C:\Users\Brain\Downloads\couponprinter(2).exe
2013-10-05 19:38 - 2013-10-05 19:38 - 01551008 _____ (Skype Technologies S.A.) C:\Users\Brain\Downloads\SkypeSetup(4).exe
2013-10-04 17:37 - 2013-10-04 17:37 - 00001745 _____ C:\Users\Public\Desktop\iTunes.lnk
2013-10-04 17:37 - 2013-10-04 17:37 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-10-04 17:37 - 2013-10-04 17:37 - 00000000 ____D C:\Program Files\iTunes
2013-10-04 17:31 - 2013-10-04 17:32 - 97206096 _____ (Apple Inc.) C:\Users\Brain\Downloads\iTunes64Setup(4).exe
2013-10-03 22:41 - 2013-10-03 22:41 - 31623168 _____ C:\Users\Brain\Downloads\gsync.msi
2013-10-03 20:15 - 2013-10-03 20:15 - 00150256 _____ (BitDefender LLC) C:\Windows\system32\Drivers\gzflt.sys
2013-09-29 20:45 - 2013-09-29 20:48 - 143028224 _____ C:\Users\Brain\Downloads\VIPRERescue21936.exe
2013-09-27 17:27 - 2013-09-27 17:27 - 36144992 _____ (Google Inc.) C:\Users\Brain\Downloads\31.0.1650.4_chrome_installer.exe
2013-09-25 17:54 - 2013-09-25 17:54 - 18091000 _____ (Adobe Systems Inc.) C:\Users\Brain\Downloads\air3-9_win(3).exe
2013-09-25 17:54 - 2013-09-25 17:54 - 04369632 _____ (Piriform Ltd) C:\Users\Brain\Downloads\ccsetup406.exe
2013-09-22 20:22 - 2013-09-22 20:26 - 142057472 _____ C:\Users\Brain\Downloads\VIPRERescue21712.exe
2013-09-22 15:50 - 2013-09-22 15:50 - 00003134 _____ C:\Windows\System32\Tasks\{68DCF659-E8B4-4B0B-B33D-F7B1C5A30AC5}
2013-09-22 15:50 - 2013-09-22 15:49 - 18090032 _____ (Adobe Systems Inc.) C:\Users\Brain\Downloads\air3-9_win(2).exe

==================== One Month Modified Files and Folders =======

2013-10-21 22:27 - 2013-10-21 22:27 - 01954698 _____ (Farbar) C:\Users\Brain\Downloads\FRST64 (1).exe
2013-10-21 22:25 - 2013-10-21 22:21 - 01954698 _____ (Farbar) C:\Users\Brain\Downloads\FRST64.exe
2013-10-21 22:22 - 2013-10-21 22:22 - 00000000 ____D C:\FRST
2013-10-21 22:21 - 2013-10-21 22:21 - 00062920 _____ C:\Users\Brain\Desktop\Result.txt
2013-10-21 22:20 - 2013-10-21 22:20 - 00062920 _____ C:\Users\Brain\Downloads\Result.txt
2013-10-21 22:18 - 2013-10-21 22:18 - 00760937 _____ (Farbar) C:\Users\Brain\Downloads\MiniToolBox.exe
2013-10-21 22:18 - 2013-10-21 22:18 - 00001173 _____ C:\Users\Brain\Desktop\MiniToolBox.exe - Shortcut.lnk
2013-10-21 22:14 - 2012-01-05 19:15 - 00000908 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-649025149-514020257-970770016-1000UA.job
2013-10-21 22:10 - 2011-07-15 01:01 - 01260619 _____ C:\Windows\WindowsUpdate.log
2013-10-21 22:09 - 2013-08-14 19:46 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-21 22:09 - 2012-03-08 19:41 - 00000928 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-649025149-514020257-970770016-1000UA.job
2013-10-21 22:08 - 2013-10-06 18:34 - 00013048 _____ C:\Windows\setupact.log
2013-10-21 20:13 - 2012-01-05 19:15 - 00000856 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-649025149-514020257-970770016-1000Core.job
2013-10-21 19:19 - 2013-10-21 19:19 - 00602112 _____ (OldTimer Tools) C:\Users\Brain\Downloads\OTL.com
2013-10-21 19:10 - 2013-10-21 19:10 - 00602112 _____ (OldTimer Tools) C:\Users\Brain\Downloads\OTL (1).exe
2013-10-21 19:10 - 2013-10-21 19:10 - 00001137 _____ C:\Users\Brain\Desktop\OTL (1).exe - Shortcut.lnk
2013-10-21 19:09 - 2011-07-24 01:01 - 00000000 ____D C:\Users\Brain\Documents\Outlook Files
2013-10-21 19:04 - 2013-10-21 19:04 - 00602112 _____ (OldTimer Tools) C:\Users\Brain\Downloads\OTL.exe
2013-10-21 18:55 - 2009-07-13 23:45 - 00024608 _____ C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-21 18:55 - 2009-07-13 23:45 - 00024608 _____ C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-21 18:49 - 2011-08-27 22:28 - 00000000 ____D C:\Users\Brain\AppData\Local\CrashDumps
2013-10-21 18:48 - 2012-10-09 23:05 - 00000000 ____D C:\Users\Brain\Documents\Smile
2013-10-21 18:47 - 2009-07-14 00:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-21 07:29 - 2011-07-24 22:11 - 00000000 ____D C:\Users\Brain\AppData\Local\Google
2013-10-21 07:29 - 2011-07-24 22:11 - 00000000 ____D C:\Program Files (x86)\Google
2013-10-21 07:24 - 2013-10-18 20:37 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-10-20 23:57 - 2012-12-09 02:47 - 00000000 ____D C:\Users\Brain\AppData\Local\DoNotTrackPlus
2013-10-20 20:41 - 2013-10-20 16:59 - 00000104 _____ C:\Windows\SysWOW64\SBRC.dat
2013-10-20 20:41 - 2012-12-15 22:15 - 00000000 ____D C:\ProgramData\Sendori
2013-10-20 20:41 - 2012-12-15 22:15 - 00000000 ____D C:\Program Files (x86)\Sendori
2013-10-20 20:40 - 2011-07-23 21:18 - 00000000 ____D C:\VIPRERESCUE
2013-10-20 19:45 - 2012-03-08 19:41 - 00000906 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-649025149-514020257-970770016-1000Core.job
2013-10-20 16:52 - 2013-10-20 16:50 - 145604608 _____ C:\Users\Brain\Downloads\VIPRERescue22558.exe
2013-10-20 13:21 - 2013-10-07 23:23 - 00003362 _____ C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-649025149-514020257-970770016-1000
2013-10-20 13:21 - 2013-10-07 23:23 - 00003228 _____ C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-649025149-514020257-970770016-1000
2013-10-20 13:21 - 2012-11-29 21:40 - 00000000 ___RD C:\Users\Brain\Google Drive
2013-10-20 13:21 - 2009-07-14 00:32 - 00000000 ____D C:\Windows\system32\FxsTmp
2013-10-19 23:03 - 2013-09-15 19:56 - 00003340 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-649025149-514020257-970770016-1000
2013-10-19 23:03 - 2013-09-15 19:56 - 00003206 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-649025149-514020257-970770016-1000
2013-10-19 23:03 - 2012-04-27 23:35 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-10-19 20:29 - 2013-08-02 20:19 - 00000332 _____ C:\Windows\Tasks\HPCeeScheduleForBrain.job
2013-10-18 20:25 - 2013-08-02 20:19 - 00003186 _____ C:\Windows\System32\Tasks\HPCeeScheduleForBrain
2013-10-18 20:25 - 2011-10-28 19:22 - 00000000 _____ C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2013-10-18 20:25 - 2011-07-22 19:07 - 00000052 _____ C:\Windows\SysWOW64\DOErrors.log
2013-10-18 20:24 - 2011-07-22 19:04 - 00000000 ____D C:\Users\Brain\AppData\Roaming\HpUpdate
2013-10-18 20:24 - 2011-07-22 19:04 - 00000000 ____D C:\Users\Brain\AppData\Roaming\HP Support Assistant
2013-10-16 17:22 - 2013-10-16 17:21 - 00004746 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log
2013-10-16 17:22 - 2013-10-16 17:19 - 00000000 ____D C:\ProgramData\Oracle
2013-10-16 17:22 - 2011-08-29 18:42 - 00000000 ____D C:\Program Files (x86)\Java
2013-10-16 17:20 - 2013-10-16 17:20 - 00915368 _____ (Oracle Corporation) C:\Users\Brain\Downloads\jxpiinstall(1).exe
2013-10-16 17:18 - 2013-10-16 17:19 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-16 17:18 - 2013-10-16 17:19 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-16 17:18 - 2013-10-16 17:19 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-16 17:18 - 2013-10-16 17:19 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2013-10-16 17:18 - 2013-10-16 17:18 - 00000000 ____D C:\Program Files\Java
2013-10-16 17:16 - 2013-10-16 17:16 - 30694824 _____ (Oracle Corporation) C:\Users\Brain\Downloads\jre-7u45-windows-x64.exe
2013-10-15 22:27 - 2013-10-15 22:27 - 00003288 ____N C:\bootsqm.dat
2013-10-15 17:06 - 2011-07-25 17:51 - 00000000 ____D C:\Users\Brain\AppData\Roaming\Skype
2013-10-13 19:32 - 2013-10-13 19:29 - 145285120 _____ C:\Users\Brain\Downloads\VIPRERescue22342.exe
2013-10-11 18:32 - 2013-01-02 19:22 - 00031318 _____ C:\Windows\DPINST.LOG
2013-10-11 18:32 - 2012-06-15 18:39 - 00000000 ____D C:\Escort
2013-10-11 18:29 - 2013-10-11 18:29 - 00003134 _____ C:\Windows\System32\Tasks\{7A427579-FDC6-4DB9-900D-77A0759A83F3}
2013-10-11 18:28 - 2013-10-11 18:27 - 18093984 _____ (Adobe Systems Inc.) C:\Users\Brain\Downloads\air3-9_win(4).exe
2013-10-11 18:24 - 2009-07-14 00:08 - 00032622 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-10-11 08:09 - 2009-07-14 00:13 - 00782902 _____ C:\Windows\system32\PerfStringBackup.INI
2013-10-11 08:04 - 2012-11-29 21:15 - 00000896 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-11 08:04 - 2012-11-29 21:15 - 00000892 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-10-09 22:11 - 2012-11-29 21:15 - 00003894 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-10-09 22:11 - 2012-11-29 21:15 - 00003642 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-10-09 22:08 - 2013-01-04 18:45 - 00357696 _____ C:\Windows\system32\FNTCACHE.DAT
2013-10-09 22:07 - 2013-03-13 00:55 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-10-09 22:07 - 2013-03-13 00:55 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-10-09 20:43 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\rescache
2013-10-09 19:54 - 2011-07-21 22:53 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-10-09 19:50 - 2011-02-11 12:15 - 00776626 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-10-09 19:46 - 2013-07-28 21:16 - 00000000 ____D C:\Windows\system32\MRT
2013-10-09 19:44 - 2011-07-21 23:40 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-10-09 18:09 - 2013-09-18 18:09 - 17226632 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2013-10-09 18:09 - 2013-08-14 19:46 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-10-09 18:09 - 2013-01-05 03:52 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-10-09 18:09 - 2013-01-05 03:52 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-10-09 17:24 - 2013-10-09 17:24 - 00003148 _____ C:\Windows\System32\Tasks\{DB257009-8FF4-4B0B-AD52-239FC0A9D55D}
2013-10-09 17:24 - 2013-10-09 17:24 - 00003148 _____ C:\Windows\System32\Tasks\{2A4C8CE8-8FAD-4614-82C6-BBB070B7AAC2}
2013-10-09 17:24 - 2013-02-15 15:04 - 00000000 ____D C:\Users\Brain\AppData\Local\Adobe
2013-10-09 17:23 - 2013-10-09 17:23 - 01070800 _____ (Solid State Networks) C:\Users\Brain\Downloads\install_flashplayer11x32_mssd_aaa_aih(1).exe
2013-10-09 17:21 - 2013-10-09 17:21 - 06951048 _____ (Microsoft Corporation) C:\Users\Brain\Downloads\Silverlight(2).exe
2013-10-09 17:20 - 2013-10-09 17:20 - 18080872 _____ (Adobe Systems Inc.) C:\Users\Brain\Downloads\AdobeAIRInstaller(1).exe
2013-10-09 17:11 - 2013-01-05 04:18 - 00094072 _____ C:\Windows\PFRO.log
2013-10-08 20:08 - 2012-01-05 19:15 - 00003878 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-649025149-514020257-970770016-1000UA
2013-10-08 20:08 - 2012-01-05 19:15 - 00003482 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-649025149-514020257-970770016-1000Core
2013-10-08 07:50 - 2013-10-16 17:22 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-10-08 07:46 - 2013-10-16 17:22 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-10-08 07:46 - 2013-10-16 17:22 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-10-08 07:46 - 2013-10-16 17:22 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-10-06 22:24 - 2012-12-02 16:41 - 00003218 _____ C:\Windows\System32\Tasks\HPCeeScheduleForBRAIN-HP$
2013-10-06 22:24 - 2012-12-02 16:41 - 00000342 _____ C:\Windows\Tasks\HPCeeScheduleForBRAIN-HP$.job
2013-10-06 21:09 - 2013-10-06 21:07 - 143331328 _____ C:\Users\Brain\Downloads\VIPRERescue22130.exe
2013-10-06 19:52 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\registration
2013-10-06 18:34 - 2013-10-06 18:34 - 00000000 _____ C:\Windows\setuperr.log
2013-10-05 21:49 - 2011-10-07 17:42 - 00000000 ____D C:\Program Files (x86)\Coupons
2013-10-05 21:48 - 2013-10-05 21:48 - 01859296 _____ (Coupons.com Incorporated) C:\Users\Brain\Downloads\couponprinter(2).exe
2013-10-05 19:39 - 2011-07-25 17:51 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-10-05 19:39 - 2011-07-25 17:51 - 00000000 ____D C:\ProgramData\Skype
2013-10-05 19:38 - 2013-10-05 19:38 - 01551008 _____ (Skype Technologies S.A.) C:\Users\Brain\Downloads\SkypeSetup(4).exe
2013-10-05 19:05 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\system32\NDF
2013-10-04 17:37 - 2013-10-04 17:37 - 00001745 _____ C:\Users\Public\Desktop\iTunes.lnk
2013-10-04 17:37 - 2013-10-04 17:37 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-10-04 17:37 - 2013-10-04 17:37 - 00000000 ____D C:\Program Files\iTunes
2013-10-04 17:37 - 2011-07-25 17:27 - 00000000 ____D C:\Program Files\iPod
2013-10-04 17:37 - 2011-07-25 17:27 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-10-04 17:32 - 2013-10-04 17:31 - 97206096 _____ (Apple Inc.) C:\Users\Brain\Downloads\iTunes64Setup(4).exe
2013-10-03 22:41 - 2013-10-03 22:41 - 31623168 _____ C:\Users\Brain\Downloads\gsync.msi
2013-10-03 20:15 - 2013-10-03 20:15 - 00150256 _____ (BitDefender LLC) C:\Windows\system32\Drivers\gzflt.sys
2013-10-03 20:15 - 2013-05-29 10:49 - 00389240 _____ (BitDefender S.R.L.) C:\Windows\system32\Drivers\trufos.sys
2013-10-03 20:10 - 2013-08-13 20:51 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2013-09-29 20:48 - 2013-09-29 20:45 - 143028224 _____ C:\Users\Brain\Downloads\VIPRERescue21936.exe
2013-09-27 23:03 - 2011-07-21 21:17 - 00000000 ____D C:\Users\Brain\AppData\Roaming\Mozilla
2013-09-27 17:27 - 2013-09-27 17:27 - 36144992 _____ (Google Inc.) C:\Users\Brain\Downloads\31.0.1650.4_chrome_installer.exe
2013-09-25 18:01 - 2013-03-24 12:21 - 00000784 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-09-25 18:01 - 2011-07-24 22:12 - 00000000 ____D C:\Program Files\CCleaner
2013-09-25 17:54 - 2013-09-25 17:54 - 18091000 _____ (Adobe Systems Inc.) C:\Users\Brain\Downloads\air3-9_win(3).exe
2013-09-25 17:54 - 2013-09-25 17:54 - 04369632 _____ (Piriform Ltd) C:\Users\Brain\Downloads\ccsetup406.exe
2013-09-23 23:45 - 2013-07-02 18:07 - 00000000 ____D C:\Users\Brain\Documents\Latest Resumes
2013-09-22 20:26 - 2013-09-22 20:22 - 142057472 _____ C:\Users\Brain\Downloads\VIPRERescue21712.exe
2013-09-22 15:50 - 2013-09-22 15:50 - 00003134 _____ C:\Windows\System32\Tasks\{68DCF659-E8B4-4B0B-B33D-F7B1C5A30AC5}
2013-09-22 15:49 - 2013-09-22 15:50 - 18090032 _____ (Adobe Systems Inc.) C:\Users\Brain\Downloads\air3-9_win(2).exe
2013-09-22 10:43 - 2013-10-09 19:51 - 17833984 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-22 10:01 - 2013-10-09 19:51 - 10926080 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-22 09:42 - 2013-10-09 19:51 - 02312704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-22 09:36 - 2013-10-09 19:51 - 01346560 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-22 09:33 - 2013-10-09 19:51 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-09-22 09:33 - 2013-10-09 19:51 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-22 09:30 - 2013-10-09 19:51 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-09-22 09:27 - 2013-10-09 19:51 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-22 09:23 - 2013-10-09 19:51 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-09-22 09:22 - 2013-10-09 19:51 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-22 09:21 - 2013-10-09 19:51 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-09-22 09:19 - 2013-10-09 19:51 - 02147840 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-22 09:19 - 2013-10-09 19:51 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-22 09:16 - 2013-10-09 19:51 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-09-22 09:15 - 2013-10-09 19:51 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-22 09:07 - 2013-10-09 19:51 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-09-22 05:29 - 2013-10-09 19:51 - 12336128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-09-22 05:22 - 2013-10-09 19:51 - 09739264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-09-22 05:22 - 2013-10-09 19:51 - 01800704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-09-22 05:14 - 2013-10-09 19:51 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-09-22 05:13 - 2013-10-09 19:51 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-09-22 05:13 - 2013-10-09 19:51 - 01104896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-09-22 05:12 - 2013-10-09 19:51 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-09-22 05:09 - 2013-10-09 19:51 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-09-22 05:08 - 2013-10-09 19:51 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-09-22 05:07 - 2013-10-09 19:51 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-09-22 05:06 - 2013-10-09 19:51 - 00420864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-09-22 05:05 - 2013-10-09 19:51 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-09-22 05:03 - 2013-10-09 19:51 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-09-22 05:03 - 2013-10-09 19:51 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-09-22 05:03 - 2013-10-09 19:51 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-09-22 04:59 - 2013-10-09 19:51 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-10-16 19:23

==================== End Of Log ============================



Additional scan result of Farbar Recovery Scan Tool (x64) Version: 21-10-2013 01
Ran by Brain at 2013-10-21 22:29:02
Running from C:\Users\Brain\AppData\Local\Temp\Temporary Internet Files\Content.IE5\9JRA0BTT
Boot Mode: Normal
==========================================================



==================== Security Center ========================

AV: Bitdefender Antivirus (Enabled - Up to date) {9B5F5313-CAF9-DD97-C460-E778420237B4}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Bitdefender Antispyware (Enabled - Up to date) {203EB2F7-ECC3-D219-FED0-DC0A39857D09}
FW: Bitdefender Firewall (Enabled) {A364D236-8096-DCCF-EF3F-4E4DBCD170CF}

==================== Installed Programs ======================

Acronis True Image Personal (x32 Version: 13.0.1264)
Adobe AIR (x32 Version: 3.9.0.1050)
Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117)
Adobe Reader XI (11.0.05) (x32 Version: 11.0.05)
Apple Application Support (x32 Version: 2.3.6)
Apple Mobile Device Support (Version: 7.0.0.117)
Apple Software Update (x32 Version: 2.1.3.127)
ATI Stream SDK v2 Developer (Version: 2.2.0.0)
Bing Bar (x32 Version: 7.3.107.0)
Bing Desktop (x32 Version: 1.3.174.0)
Bitdefender Total Security 2013 (Version: 16.20.0.1483)
Blio (x32 Version: 2.2.6699)
Bonjour (Version: 3.0.0.10)
ccc-utility64 (Version: 2010.1123.1002.17926)
CCleaner (Version: 4.06)
CheckIt Diagnostics 8 (Version: 8.0.2.677)
Coupon Printer for Windows (x32 Version: 5.0.0.4)
Crawler Toolbar (x32 Version: 6.0.0.22)
Cubby (HKCU Version: 1.0.0.12237)
D3DX10 (x32 Version: 15.4.2368.0902)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32)
DetectorTools (x32 Version: 1.11.5)
Diskeeper 12 Professional (Version: 16.0.1017.64)
DivX Setup (x32 Version: 2.6.1.84)
Do Not Track Plus Add-on (64bit) 2.2.2.1022 (Version: 2.2.2.1022)
Do Not Track Plus Add-on 1.0.5289.0208 (x32 Version: 1.0.5289.0208)
Dogpile Toolbar (x32 Version: 1.504)
eReg (x32 Version: 1.20.138.34)
erLT (x32 Version: 1.20.0137)
Facebook Messenger 2.1.4814.0 (x32 Version: 2.1.4814.0)
FileHippo.com Update Checker (x32)
Google Desktop (x32 Version: 5.9.1005.12335)
Google Drive (x32 Version: 1.12.5329.1887)
Google Talk Plugin (x32 Version: 4.7.0.15362)
Google Update Helper (x32 Version: 1.3.21.165)
Hewlett-Packard ACLM.NET v1.2.1.1 (x32 Version: 1.00.0000)
HP Auto (Version: 1.0.12935.3667)
HP Client Services (Version: 1.1.12938.3539)
HP Customer Experience Enhancements (x32 Version: 6.0.1.7)
HP LinkUp (x32 Version: 2.01.026)
HP MediaSmart/TouchSmart Netflix (x32 Version: 1.0.6.0)
HP MovieStore (x32 Version: 1.0.045)
HP Odometer (x32 Version: 2.10.0000)
HP Officejet 6500 E710a-f Basic Device Software (Version: 22.50.231.0)
HP Officejet 6500 E710a-f Help (x32 Version: 140.0.2.2)
HP Officejet 6500 E710a-f Product Improvement Study (Version: 22.50.231.0)
HP Photo Creations (x32 Version: 1.0.0.9572)
HP Power Assistant (Version: 1.1.1.6)
HP Product Detection (x32 Version: 11.14.0001)
HP Setup (x32 Version: 8.6.4530.3651)
HP Setup Manager (x32 Version: 1.1.13253.3682)
HP Support Information (x32 Version: 10.1.1000)
HP Update (x32 Version: 5.002.006.003)
HP Vision Hardware Diagnostics (Version: 2.5.0.0)
HPDiagnosticAlert (x32 Version: 1.00.0000)
Hulu Desktop (HKCU Version: 0.9.13)
I.R.I.S. OCR (x32 Version: 12.3.4.0)
iCloud (Version: 3.0.2.163)
Intel® Management Engine Components (x32 Version: 7.0.0.1144)
iTunes (Version: 11.1.1.11)
Java 7 Update 45 (64-bit) (Version: 7.0.450)
Java 7 Update 45 (x32 Version: 7.0.450)
Java Auto Updater (x32 Version: 2.1.9.8)
Junk Mail filter update (x32 Version: 16.4.3508.0205)
Logitech Harmony Remote Software 7 (x32 Version: 7.7.0.0)
Malwarebytes Anti-Malware version 1.75.0.1300 (x32 Version: 1.75.0.1300)
Marketsplash Print Software (x32 Version: 1.0.1.31)
Marketsplash Shortcuts (x32 Version: 1.0.1.7)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Mouse and Keyboard Center (Version: 2.2.173.0)
Microsoft Office 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Access MUI (English) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Access Setup Metadata MUI (English) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Excel MUI (English) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Home and Business 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000)
Microsoft Office OneNote MUI (English) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Outlook Connector (x32 Version: 14.0.6123.5001)
Microsoft Office Outlook MUI (English) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office PowerPoint MUI (English) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Proof (Spanish) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Proofing (English) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Publisher MUI (English) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Shared 64-bit MUI (English) 2010 (Version: 14.0.7015.1000)
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010 (Version: 14.0.7015.1000)
Microsoft Office Shared MUI (English) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Shared Setup Metadata MUI (English) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Single Image 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Word MUI (English) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bit (x32 Version: 14.0.5120.5000)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft SkyDrive (HKCU Version: 17.0.2015.0811)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (x32 Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0)
Movie Maker (x32 Version: 16.4.3508.0205)
Mozilla Firefox 25.0 (x86 en-US) (x32 Version: 25.0)
Mozilla Maintenance Service (x32 Version: 25.0)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT_amd64 (x32 Version: 15.4.2862.0708)
MSVCRT110 (x32 Version: 16.4.1108.0727)
MSVCRT110_amd64 (Version: 16.4.1109.0912)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
PDF Complete Special Edition (x32 Version: 4.0.35)
Photo Gallery (x32 Version: 16.4.3508.0205)
PlayReady PC Runtime amd64 (Version: 1.3.0)
PlayReady PC Runtime x86 (x32 Version: 1.3.0)
QuickTime (x32 Version: 7.74.80.86)
RealDownloader (x32 Version: 1.3.3)
RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0)
RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0)
RealPlayer (x32 Version: 16.0.3)
RealUpgrade 1.1 (x32 Version: 1.1.0)
Revo Uninstaller Pro 3.0.7 (Version: 3.0.7)
RoxioNow Player (x32 Version: 1.9.5.103)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32)
Skype Click to Call (x32 Version: 6.12.13601)
Skype™ 6.9 (x32 Version: 6.9.106)
Smile Desktop version 1.0.4.259 (x32 Version: 1.0.4.259)
SpywareBlaster 5.0 (x32 Version: 5.0.0)
SUPERAntiSpyware (Version: 5.6.1030)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (x32 Version: 3)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (x32)
Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2494150) (x32)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2826026) 32-Bit Edition (x32)
Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition (x32)
Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (x32)
Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (x32)
Update for Microsoft Word 2010 (KB2827323) 32-Bit Edition (x32)
uRex DVD Ripper Platinum (x32)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0)
Windows Driver Package - ESCORT Inc. (WinUSB) MyDeviceClass (05/21/2013 ) (Version: 05/21/2013 )
Windows Driver Package - ESCORT, Inc. (usbser) Ports (01/15/2013 1.0.0.0) (Version: 01/15/2013 1.0.0.0)
Windows Driver Package - ESCORT, Inc. (usbser) Ports (04/24/2013 1.0.0.0) (Version: 04/24/2013 1.0.0.0)
Windows Driver Package - Escort, Inc. (usbser) Ports (07/28/2010 1.0.0.0) (Version: 07/28/2010 1.0.0.0)
Windows Driver Package - Escort, Inc. (usbser) Ports (11/09/2012 1.0.0.0) (Version: 11/09/2012 1.0.0.0)
Windows Live Communications Platform (x32 Version: 16.4.3508.0205)
Windows Live Essentials (x32 Version: 16.4.3508.0205)
Windows Live Family Safety (Version: 16.4.3508.0205)
Windows Live Family Safety (x32 Version: 16.4.3508.0205)
Windows Live ID Sign-in Assistant (Version: 7.250.4311.0)
Windows Live Installer (x32 Version: 16.4.3508.0205)
Windows Live Mail (x32 Version: 16.4.3508.0205)
Windows Live Messenger (x32 Version: 16.4.3508.0205)
Windows Live MIME IFilter (Version: 16.4.3508.0205)
Windows Live Photo Common (x32 Version: 16.4.3508.0205)
Windows Live PIMT Platform (x32 Version: 16.4.3508.0205)
Windows Live SOXE (x32 Version: 16.4.3508.0205)
Windows Live SOXE Definitions (x32 Version: 16.4.3508.0205)
Windows Live UX Platform (x32 Version: 16.4.3508.0205)
Windows Live UX Platform Language Pack (x32 Version: 16.4.3508.0205)
Windows Live Writer (x32 Version: 16.4.3508.0205)
Windows Live Writer Resources (x32 Version: 16.4.3508.0205)
Windows Media Player 64-bit Plug-in Fix
Windows Media Player Firefox Plugin (x32 Version: 1.0.0.8)
Windows Media Player Plus! 2.1 (x32 Version: 2.1)
WinX Blu-ray Decrypter 3.0.0 (x32)
YoWindow (x32 Version: 3)
Zinio Reader 4 (x32 Version: 4.0.3184)

==================== Restore Points =========================

16-10-2013 22:17:26 Installed Java 7 Update 45 (64-bit)
16-10-2013 22:21:31 Installed Java 7 Update 45
21-10-2013 12:27:18 Revo Uninstaller Pro's restore point - Google Chrome

==================== Hosts content: ==========================

2009-07-13 21:34 - 2009-06-10 16:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {010BD8D6-EA03-4FBD-8CB4-2A973E3BFC77} - System32\Tasks\{93F8F24A-0471-46CB-80AD-745C89354000} => Firefox.exe
Task: {07F69F84-6CA5-4F84-A087-B783FC9128E1} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company)
Task: {0EBC823A-1261-4424-85E6-8BA652526749} - System32\Tasks\HPCustParticipation HP Officejet 6500 E710a-f => C:\Program Files\HP\HP Officejet 6500 E710a-f\Bin\HPCustPartic.exe [2010-11-16] (Hewlett-Packard Co.)
Task: {1D23E915-8720-49C9-9EC2-4D13F96746ED} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-649025149-514020257-970770016-1000UA => C:\Users\Brain\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-08-24] (Facebook Inc.)
Task: {23E3188B-DAFC-4EC7-853D-ABA870E2C2BB} - System32\Tasks\Ad-Aware Update (Weekly) => C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe
Task: {2AB4C585-7DC6-4B02-B9BA-5427CF2CFD08} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-11-29] (Google Inc.)
Task: {308AA041-4764-4EEE-B054-4A4460B1BACC} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2013-05-13] (Microsoft)
Task: {528C8DF8-67A9-4598-A2F2-3C30C25F9FDF} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-09] (Adobe Systems Incorporated)
Task: {54645097-926B-466E-A1EF-5050ECBC6CC0} - System32\Tasks\Microsoft_Hardware_Launch_rundll32_exe => C:\Windows\System32\url.dll [2013-09-22] (Microsoft Corporation)
Task: {5BD6C717-8E78-4DCD-8946-D5149C105C3A} - System32\Tasks\HPCeeScheduleForBRAIN-HP$ => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14] (Hewlett-Packard)
Task: {5E3ECC7A-A745-4A05-A381-542F744EE4F3} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation)
Task: {68E709E3-707D-4936-B562-FDD4EE3FEF86} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-649025149-514020257-970770016-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe [2013-08-14] (RealNetworks, Inc.)
Task: {693FF29A-5715-4CC4-8A20-4587EE376069} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-649025149-514020257-970770016-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {6C9AFF08-D16B-4561-8EB7-DCE45CDD71CA} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2013-08-09] (Hewlett-Packard)
Task: {7214B801-45F1-4AA9-8B27-30B14FB8BB1F} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-649025149-514020257-970770016-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {7E58B723-AB16-42F0-A30C-5CF7129EB390} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {84F8633D-0B60-4C13-991D-EDA3F9511982} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-649025149-514020257-970770016-1000UA => C:\Users\Brain\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-05] (Google Inc.)
Task: {88E5E8D7-ECEC-4310-A8DC-313CBE643549} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company)
Task: {94A19C18-53DB-4C99-89FB-0DCA4991EAA0} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation)
Task: {968B5D3E-558A-411D-83ED-2D1614C1DF1F} - System32\Tasks\Microsoft_Hardware_Launch_devicecenter_exe => c:\Program Files\Microsoft Device Center\devicecenter.exe
Task: {9B48EFC6-FB74-4CF1-9302-041136F0EF1B} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files (x86)\Ask.com\UpdateTask.exe
Task: {9CDA46E2-CA04-4495-A6B9-5239759293FF} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {9E12FA1A-DCCA-438D-A868-0E24B6C9AC56} - System32\Tasks\HPCeeScheduleForBrain => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14] (Hewlett-Packard)
Task: {A0AC67B9-4589-47C7-BD53-DEAEB8D956F0} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation)
Task: {A2629B3E-CBF1-4371-A085-AE289A4F487C} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation)
Task: {AC222730-DDB1-4C9E-B48A-B9FF783B8865} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-11-29] (Google Inc.)
Task: {AC6A767D-50D4-4668-BECA-7C4356ED5BF7} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-09-19] (Piriform Ltd)
Task: {BB650271-8BE9-4E24-AAE2-935BA41F00C0} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company)
Task: {CBC6A39D-5EAB-4EE3-913B-CDE229CE4E41} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-649025149-514020257-970770016-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {D09B76B4-1968-4683-BD75-DE5AB9FE9E41} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-649025149-514020257-970770016-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {D297DF1E-B04D-48C3-8838-9FE04B247610} - System32\Tasks\Disk Cleanup => C:\Windows\System32\cleanmgr.exe [2009-07-13] (Microsoft Corporation)
Task: {D4140AA9-A6FA-492B-8F44-0D59DE488DA4} - System32\Tasks\Ad-Aware Antivirus Scheduled Scan => C:\PROGRA~2\AD-AWA~1\AdAwareLauncher.exe
Task: {D9E1D393-0645-4A01-A16B-048CA5A3574E} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-649025149-514020257-970770016-1000Core => C:\Users\Brain\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-08-24] (Facebook Inc.)
Task: {DF38BD0D-66A2-408C-96F1-1AC77B2D79A3} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-649025149-514020257-970770016-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {EC331035-A08F-496B-9455-B48945C72EC6} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-649025149-514020257-970770016-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {ED2FFECE-4C45-4E2F-BB18-E5056649D67E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2013-04-01] (Hewlett-Packard Company)
Task: {F385956A-5084-4CF4-9C05-8FD95A5C7577} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-649025149-514020257-970770016-1000Core => C:\Users\Brain\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-05] (Google Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => ?
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-649025149-514020257-970770016-1000Core.job => ?
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-649025149-514020257-970770016-1000UA.job => ?
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => ?
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => ?
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-649025149-514020257-970770016-1000Core.job => ?
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-649025149-514020257-970770016-1000UA.job => ?
Task: C:\Windows\Tasks\HPCeeScheduleForBRAIN-HP$.job => ?
Task: C:\Windows\Tasks\HPCeeScheduleForBrain.job => ?

==================== Loaded Modules (whitelisted) =============

2013-08-27 22:15 - 2013-08-27 22:15 - 00265080 _____ () C:\Program Files\Bitdefender\Bitdefender 2013\txmlutil.dll
2012-12-09 02:46 - 2012-10-22 20:48 - 00287680 _____ () C:\Program Files\DoNotTrackPlus\IE\DNTPButton.dll
2012-12-09 02:46 - 2012-10-22 20:48 - 00817088 _____ () C:\Program Files\DoNotTrackPlus\IE\DNTPContentFilter.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\ProgramData\Temp:5C321E34
AlternateDataStreams: C:\ProgramData\Temp:D1B5B4F1
AlternateDataStreams: C:\Users\Brain\Downloads\29.0.1547.49_chrome_installer.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\30.0.1599.14_chrome_installer (1).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\30.0.1599.14_chrome_installer (2).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\30.0.1599.14_chrome_installer(1).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\30.0.1599.14_chrome_installer.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\30.0.1599.37_chrome_installer (1).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\30.0.1599.37_chrome_installer.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\31.0.1612.2_chrome_installer (1).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\31.0.1612.2_chrome_installer(1).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\31.0.1612.2_chrome_installer(2).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\31.0.1612.2_chrome_installer(3).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\31.0.1612.2_chrome_installer.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\31.0.1650.4_chrome_installer.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\Adaware_Installer(10).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\Adaware_Installer(2).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\Adaware_Installer(8).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\Adaware_Installer(9).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\AdbeRdr11004_en_US.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\AdobeAIRInstaller(1).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\air3-8_win(1).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\air3-8_win(2).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\air3-8_win(3).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\air3-8_win.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\air3-9_win(1).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\air3-9_win(2).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\air3-9_win(4).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\air3-9_win.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\ATT_SST(1).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\ATT_SST.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\ccsetup326.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\ccsetup328.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\ccsetup401.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\ccsetup404(1).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\ccsetup404.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\ccsetup405(1).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\ccsetup405(2).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\ccsetup405.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\ccsetup406.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\CheckItDiagnostics8.0.2.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\ChromeSetup(2).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\couponprinter(2).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\Diskeeper12_Professional.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\DivXInstaller(1).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\DivXInstaller(2).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\FHSetup(1).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\Firefox Setup 18.0.1.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\Firefox Setup 18.0.2.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\Firefox Setup 18.0.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\Firefox Setup 19.0.2 (1).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\Firefox Setup 19.0.2.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\Firefox Setup 19.0.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\Firefox Setup 20.0.1(1).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\Firefox Setup 20.0.1(2).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\Firefox Setup 20.0.1.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\Firefox Setup 21.0.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\Firefox Setup 22.0.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\Firefox Setup 23.0.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\Firefox Setup 24.0b1.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\Firefox Setup 24.0b4.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\Firefox Setup Stub 22.0(1).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\Firefox Setup Stub 22.0(2).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\Firefox Setup Stub 22.0(3).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\Firefox Setup Stub 22.0.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\Firefox Setup Stub 23.0(1).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\Firefox Setup Stub 23.0.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\flashplayer11-8_debug_win_ax.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\flashplayer11-8_debug_win_pi.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\flashplayer11-8_install_win_ax.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\flashplayer11-8_install_win_pi(1).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\flashplayer11-8_install_win_pi.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\FRST64 (1).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\FRST64.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\IE10-Windows6.1-en-us.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\IE10-Windows6.1-x64-en-us.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\IE9-Windows7-x86-enu.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\install_flashplayer11x32_mssd_aaa_aih(1).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\install_flash_player(1).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\install_flash_player(2).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\install_flash_player(3).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\install_flash_player(4).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\install_flash_player.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\ITPx64_1033_8.20.469.0.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\iTunes64Setup(3).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\iTunes64Setup(4).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\jre-7u10-windows-i586.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\jre-7u10-windows-x64.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\jre-7u11-windows-x64.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\jre-7u40-windows-x64.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\jre-7u45-windows-x64.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\jxpiinstall(1).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\jxpiinstall.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\mbam-setup-1.75.0.1300(1).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\mbam-setup-1.75.0.1300.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\MiniToolBox.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\MouseKeyboardCenter_64bit_ENG_1.1.500.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\Norman_Malware_Cleaner (5).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\Norman_Malware_Cleaner(56).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\Norman_Malware_Cleaner(57).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\OTL (1).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\OTL.com:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\OTL.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\QuickTimeInstaller.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\RealPlayer (1).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\RealPlayer(3).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\RealPlayer(4).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\RealPlayer(5).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\RealPlayer(6).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\RealPlayer(7).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\RevoUninProSetup(3).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\RevoUninProSetup(4).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\RevoUninProSetup(5).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\RevoUninProSetup(6).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\RevoUninProSetup(7).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\RevoUninProSetup302.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\Silverlight(1).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\Silverlight(2).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\SkypeSetup(1).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\SkypeSetup(2).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\SkypeSetup(3).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\SkypeSetup(4).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\sp58919.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\spywareblastersetup46.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\spywareblastersetup50.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\SUPERAntiSpyware(2).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\unetbootin-windows-585 (1).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\unetbootin-windows-585 (2).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\unetbootin-windows-585.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\uninstall_flash_player.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue12590.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue12684.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue12792.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue12864.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue12880.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue14856.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue14988.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue15006.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue15118.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue15220.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue15238.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue15358.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue15596.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue15716.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue15832.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue16102.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue16266.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue16434.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue16636.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue16842.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue17256.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue17454.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue17672.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue17900.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue18118.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue18352.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue18376.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue18558.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue18764.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue18964.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue19164.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue19368.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue19570.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue19748.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue20168.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue20382.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue20594.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue20826.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue21072.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue21280.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue21526.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue21712.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue21936.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue22130.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue22342.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\VIPRERescue22558.exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\weathersp3_StubInstaller(1).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\wlsetup-web(1).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\wlsetup-web(2).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\wlsetup-web(3).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\wlsetup-web(4).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\wlsetup-web(5).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\wlsetup-web(6).exe:BDU
AlternateDataStreams: C:\Users\Brain\Downloads\wlsetup-web(7).exe:BDU

==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sndappv2 => ""="service"

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (10/21/2013 10:26:27 PM) (Source: Application Hang) (User: )
Description: The program FRST64.exe version 3.3.8.1 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 10dc

Start Time: 01ceced65cc36998

Termination Time: 0

Application Path: C:\Users\Brain\Downloads\FRST64.exe

Report Id: b0dd6b8e-3ac9-11e3-91a1-e06995dae38e

Error: (10/21/2013 10:09:01 PM) (Source: Google Update) (User: Brain-HP)
Description: Network Request Error.
Error: 0x80072ee7. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=FireFox, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=auto, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=FireFox, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=auto, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned

Error: (10/21/2013 07:56:59 PM) (Source: Application Hang) (User: )
Description: The program OTL (1).exe version 3.2.69.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 12b0

Start Time: 01cecebb384c684e

Termination Time: 0

Application Path: C:\Users\Brain\Downloads\OTL (1).exe

Report Id: d3c89d57-3ab4-11e3-91a1-e06995dae38e

Error: (10/21/2013 07:56:35 PM) (Source: Application Hang) (User: )
Description: The program OTL.com version 3.2.69.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 1754

Start Time: 01cecebc9878a0d5

Termination Time: 15

Application Path: C:\Users\Brain\Downloads\OTL.com

Report Id: c5a671b7-3ab4-11e3-91a1-e06995dae38e

Error: (10/21/2013 07:09:43 PM) (Source: Application Hang) (User: )
Description: The program OTL.exe version 3.2.69.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: f30

Start Time: 01ceceba59a8f229

Termination Time: 0

Application Path: C:\Users\Brain\Downloads\OTL.exe

Report Id: 2d2d3c6a-3aae-11e3-91a1-e06995dae38e

Error: (10/21/2013 06:49:24 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/21/2013 06:49:09 PM) (Source: Application Error) (User: )
Description: Faulting application name: BingBar.exe, version: 7.3.107.0, time stamp: 0x52214f7a
Faulting module name: BingBar.exe, version: 7.3.107.0, time stamp: 0x52214f7a
Exception code: 0xc0000005
Fault offset: 0x0003ea14
Faulting process id: 0x1510
Faulting application start time: 0xBingBar.exe0
Faulting application path: BingBar.exe1
Faulting module path: BingBar.exe2
Report Id: BingBar.exe3

Error: (10/21/2013 06:46:29 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/21/2013 06:29:27 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/21/2013 06:29:06 PM) (Source: Application Error) (User: )
Description: Faulting application name: BingBar.exe, version: 7.3.107.0, time stamp: 0x52214f7a
Faulting module name: BingBar.exe, version: 7.3.107.0, time stamp: 0x52214f7a
Exception code: 0xc0000005
Fault offset: 0x0003ea14
Faulting process id: 0x1480
Faulting application start time: 0xBingBar.exe0
Faulting application path: BingBar.exe1
Faulting module path: BingBar.exe2
Report Id: BingBar.exe3


System errors:
=============
Error: (10/21/2013 06:48:00 PM) (Source: Microsoft-Windows-Time-Service) (User: NT AUTHORITY)
Description: The time provider 'VMICTimeProvider' failed to start due to the following error: The specified module could not be found. (0x8007007E)

Error: (10/21/2013 06:45:43 PM) (Source: Microsoft-Windows-Time-Service) (User: NT AUTHORITY)
Description: The time provider 'VMICTimeProvider' failed to start due to the following error: The specified module could not be found. (0x8007007E)

Error: (10/21/2013 06:45:03 PM) (Source: EventLog) (User: )
Description: The previous system shutdown at 6:42:33 PM on ‎10/‎21/‎2013 was unexpected.

Error: (10/21/2013 06:28:00 PM) (Source: Microsoft-Windows-Time-Service) (User: NT AUTHORITY)
Description: The time provider 'VMICTimeProvider' failed to start due to the following error: The specified module could not be found. (0x8007007E)

Error: (10/21/2013 06:19:09 PM) (Source: Microsoft-Windows-Time-Service) (User: NT AUTHORITY)
Description: The time provider 'VMICTimeProvider' failed to start due to the following error: The specified module could not be found. (0x8007007E)

Error: (10/21/2013 06:16:34 PM) (Source: Service Control Manager) (User: )
Description: The Diskeeper service failed to start due to the following error:
%%109

Error: (10/21/2013 06:14:27 PM) (Source: Microsoft-Windows-Time-Service) (User: NT AUTHORITY)
Description: The time provider 'VMICTimeProvider' failed to start due to the following error: The specified module could not be found. (0x8007007E)

Error: (10/21/2013 06:13:58 PM) (Source: EventLog) (User: )
Description: The previous system shutdown at 6:11:28 PM on ‎10/‎21/‎2013 was unexpected.

Error: (10/21/2013 06:08:57 PM) (Source: Microsoft-Windows-Time-Service) (User: NT AUTHORITY)
Description: The time provider 'VMICTimeProvider' failed to start due to the following error: The specified module could not be found. (0x8007007E)

Error: (10/21/2013 07:31:48 AM) (Source: Microsoft-Windows-Time-Service) (User: NT AUTHORITY)
Description: The time provider 'VMICTimeProvider' failed to start due to the following error: The specified module could not be found. (0x8007007E)


Microsoft Office Sessions:
=========================
Error: (10/21/2013 10:26:27 PM) (Source: Application Hang)(User: )
Description: FRST64.exe3.3.8.110dc01ceced65cc369980C:\Users\Brain\Downloads\FRST64.exeb0dd6b8e-3ac9-11e3-91a1-e06995dae38e

Error: (10/21/2013 10:09:01 PM) (Source: Google Update)(User: Brain-HP)
Description: Network Request Error.
Error: 0x80072ee7. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=FireFox, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=auto, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=FireFox, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=auto, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned

Error: (10/21/2013 07:56:59 PM) (Source: Application Hang)(User: )
Description: OTL (1).exe3.2.69.012b001cecebb384c684e0C:\Users\Brain\Downloads\OTL (1).exed3c89d57-3ab4-11e3-91a1-e06995dae38e

Error: (10/21/2013 07:56:35 PM) (Source: Application Hang)(User: )
Description: OTL.com3.2.69.0175401cecebc9878a0d515C:\Users\Brain\Downloads\OTL.comc5a671b7-3ab4-11e3-91a1-e06995dae38e

Error: (10/21/2013 07:09:43 PM) (Source: Application Hang)(User: )
Description: OTL.exe3.2.69.0f3001ceceba59a8f2290C:\Users\Brain\Downloads\OTL.exe2d2d3c6a-3aae-11e3-91a1-e06995dae38e

Error: (10/21/2013 06:49:24 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/21/2013 06:49:09 PM) (Source: Application Error)(User: )
Description: BingBar.exe7.3.107.052214f7aBingBar.exe7.3.107.052214f7ac00000050003ea14151001ceceb8207b01f6C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\BingBar.exeC:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\BingBar.exe604b0955-3aab-11e3-91a1-e06995dae38e

Error: (10/21/2013 06:46:29 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/21/2013 06:29:27 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/21/2013 06:29:06 PM) (Source: Application Error)(User: )
Description: BingBar.exe7.3.107.052214f7aBingBar.exe7.3.107.052214f7ac00000050003ea14148001ceceb552445d94C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\BingBar.exeC:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\BingBar.exe93b77e34-3aa8-11e3-8e87-e06995dae38e


CodeIntegrity Errors:
===================================
Date: 2013-01-29 21:07:06.202
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Bitdefender\Bitdefender 2013\active virus control\Avc3_00175_005\avcuf64.dll because the set of per-page image hashes could not be found on the system.

Date: 2013-01-29 20:59:33.700
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Bitdefender\Bitdefender 2013\active virus control\Avc3_00175_005\avcuf64.dll because the set of per-page image hashes could not be found on the system.

Date: 2013-01-29 20:50:25.738
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Bitdefender\Bitdefender 2013\active virus control\Avc3_00175_005\avcuf64.dll because the set of per-page image hashes could not be found on the system.

Date: 2013-01-29 20:35:00.004
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Bitdefender\Bitdefender 2013\active virus control\Avc3_00175_005\avcuf64.dll because the set of per-page image hashes could not be found on the system.

Date: 2013-01-29 20:20:27.325
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Bitdefender\Bitdefender 2013\active virus control\Avc3_00175_005\avcuf64.dll because the set of per-page image hashes could not be found on the system.

Date: 2013-01-29 19:27:28.922
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Bitdefender\Bitdefender 2013\active virus control\Avc3_00175_005\avcuf64.dll because the set of per-page image hashes could not be found on the system.

Date: 2013-01-29 19:15:43.086
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Bitdefender\Bitdefender 2013\active virus control\Avc3_00175_005\avcuf64.dll because the set of per-page image hashes could not be found on the system.

Date: 2013-01-29 19:03:58.431
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Bitdefender\Bitdefender 2013\active virus control\Avc3_00175_005\avcuf64.dll because the set of per-page image hashes could not be found on the system.

Date: 2013-01-29 18:48:50.744
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Bitdefender\Bitdefender 2013\active virus control\Avc3_00175_005\avcuf64.dll because the set of per-page image hashes could not be found on the system.

Date: 2013-01-29 18:27:05.731
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Bitdefender\Bitdefender 2013\active virus control\Avc3_00175_005\avcuf64.dll because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Percentage of memory in use: 32%
Total physical RAM: 6126.53 MB
Available physical RAM: 4139.14 MB
Total Pagefile: 12251.24 MB
Available Pagefile: 8969.21 MB
Total Virtual: 8192 MB
Available Virtual: 8191.8 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:848.86 GB) (Free:694.51 GB) NTFS
Drive d: (HP_RECOVERY) (Fixed) (Total:11.25 GB) (Free:1.34 GB) NTFS ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 932 GB) (Disk ID: 7021AD4E)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=849 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=11 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=71 GB) - (Type=05)

==================== End Of Log ============================

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16514 BrowserJavaVersion: 10.45.2
Run by Brain at 22:37:42 on 2013-10-21
#Option Extended Search is enabled.
#Option Whitelisting is disabled.
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6127.4111 [GMT -5:00]
.
AV: Bitdefender Antivirus *Enabled/Updated* {9B5F5313-CAF9-DD97-C460-E778420237B4}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Bitdefender Antispyware *Enabled/Updated* {203EB2F7-ECC3-D219-FED0-DC0A39857D09}
FW: Bitdefender Firewall *Enabled* {A364D236-8096-DCCF-EF3F-4E4DBCD170CF}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
C:\Windows\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\WUDFHost.exe
C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe
C:\Program Files (x86)\Webshots\Smile Desktop\Smile.exe
C:\Program Files (x86)\YoWindow\yowindow.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\DoNotTrackPlus\IE\DNTPService.exe
C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\BingApp.exe
C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\BingBar.exe
C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\BingSurrogate.exe
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\BingSurrogate.exe
C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\BingSurrogate.exe
C:\Windows\system32\Macromed\Flash\FlashUtil64_11_9_900_117_ActiveX.exe
C:\Program Files\Condusiv Technologies\Diskeeper\DkService.exe
C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Users\Brain\AppData\Local\Temp\Temporary Internet Files\Content.IE5\9JRA0BTT\FRST64.exe
C:\Windows\system32\notepad.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uLocal Page = C:\Windows\System32\blank.htm
uSearch Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
mStart Page = about:blank
mLocal Page = C:\Windows\SysWOW64\blank.htm
mSearch Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
uProxyOverride = *.local
uURLSearchHooks: {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - <orphaned>
uURLSearchHooks: Microsoft Url Search Hook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll
mWinlogon: Shell = explorer.exe
mWinlogon: Userinit = userinit.exe
BHO: Bing Bar Helper: {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\BingExt.dll
BHO: RealNetworks Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
BHO: Dogpile Toolbar BHO: {61AFBC1F-52F3-43F5-A5ED-AFA778C579E1} - C:\Program Files (x86)\Dogpile Toolbar\Toolbar.dll
BHO: Do Not Track Plus: {6E45F3E8-2683-4824-A6BE-08108022FB36} - C:\Program Files (x86)\DoNotTrackPlus\ScriptHost.dll
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: HP Network Check Helper: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
BHO: Norton Safe Web Lite BHO: {F0DA78E9-6B60-42fb-BC26-EF2CFB8C8FF3} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll
TB: Dogpile Toolbar: {8A936F47-6B90-4537-A1BC-6F369A203D47} - C:\Program Files (x86)\Dogpile Toolbar\Toolbar.dll
TB: Norton Safe Web Lite: {30CEEEA2-3742-40e4-85DD-812BF1CBB83D} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll
TB: Bing Bar: {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\BingExt.dll
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
uRun: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
uRun: [Google Update] "C:\Users\Brain\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [FileHippo.com] "C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe" /background
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRunOnce: [B Register C:\Program Files (x86)\DivX\DivX Plus DirectShow Filters\DirectShowDemuxFilter.dll] "C:\Windows\System32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus DirectShow Filters\DirectShowDemuxFilter.dll",DllRegisterServer
StartupFolder: C:\Users\Brain\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\SMILED~1.LNK - C:\Program Files (x86)\Webshots\Smile Desktop\Smile.exe
StartupFolder: C:\Users\Brain\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\YoWindow.lnk - C:\Program Files (x86)\YoWindow\yowindow.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-Explorer: ForceActiveDesktopOn = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableInstallerDetection = dword:1
mPolicies-System: EnableLUA = dword:1
mPolicies-System: EnableSecureUIAPaths = dword:1
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: EnableVirtualization = dword:1
mPolicies-System: PromptOnSecureDesktop = dword:1
mPolicies-System: ValidateAdminCodeSignatures = dword:0
mPolicies-System: dontdisplaylastusername = dword:0
mPolicies-System: scforceoption = dword:0
mPolicies-System: shutdownwithoutlogon = dword:1
mPolicies-System: undockwithoutlogon = dword:1
mPolicies-System: FilterAdministratorToken = dword:0
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
LSP: C:\Windows\System32\Sendori.dll
LSP: %SystemRoot%\system32\mswsock.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
TCP: NameServer = 192.168.1.254
TCP: Interfaces\{136F715D-1007-4CF1-8ADB-AA43DA411B61} : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{1ECC3F87-7F65-47CB-A24C-E6C8EE539668} : DHCPNameServer = 192.168.1.254
Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} -
Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} -
Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} -
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll
Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll
Handler: crawler - {4545C96B-15D0-4E22-8DDE-6F2CAF531281} - C:\Program Files (x86)\Crawler Toolbar\Crawler.dll
Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\MSVidCtl.dll
Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll
Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll
Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll
Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll
Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll
Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll
Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll
Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll
Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\System32\inetcomm.dll
Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll
Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll
Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll
Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\MSVidCtl.dll
Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll
Handler: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Name-Space Handler: mk\* - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll
SSODL: WebCheck - <orphaned>
SecurityProviders: SecurityProviders = credssp.dll
LSA: Authentication Packages = msv1_0
LSA: Notification Packages = scecli
LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg pku2u livessp
SubSystems: Windows = basesrv,1 winsrv:UserServerDllInitialization,3 winsrv:ConServerDllInitialization,2 sxssrv,4
mASetup: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\System32\unregmp2.exe /ShowWMP
mASetup: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
mASetup: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
mASetup: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - C:\Windows\System32\regsvr32.exe /s /n /i:/UserInstall C:\Windows\System32\themeui.dll
mASetup: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "C:\Program Files (x86)\Windows Mail\WinMail.exe" OCInstallUserConfigOE
mASetup: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - C:\Windows\System32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI
mASetup: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
mASetup: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
mASetup: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
CLSID: {603D3801-BD81-11d0-A3A5-00C04FD706EC} - C:\Windows\System32\shell32.dll
x64-mStart Page = about:blank
x64-mLocal Page = C:\Windows\System32\blank.htm
x64-mSearch Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
x64-mWinlogon: Shell = explorer.exe
x64-mWinlogon: Userinit = C:\Windows\System32\userinit.exe,
x64-BHO: Bing Bar Helper: {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\amd64\BingExt.dll
x64-BHO: Do Not Track Plus: {6E45F3E8-2683-4824-A6BE-08108022FB36} - C:\Program Files\DoNotTrackPlus\IE\DNTPAddon.dll
x64-BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Skype add-on for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-TB: Bing Bar: {eec0f710-38b5-4aba-99bf-ec87564a4e13} -
x64-Run: [Bdagent] C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe
x64-Run: [SBRegRebootCleaner] "C:\VIPRERESCUE\SBRC.exe"
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {6E45F3E8-2683-4824-A6BE-08108022FB36} - {23249465-AA46-4DED-BD4B-8EFB20F968FE} - C:\Program Files\DoNotTrackPlus\IE\DNTPAddon.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
x64-IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
x64-Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} -
x64-Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} -
x64-Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} -
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll
x64-Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\System32\urlmon.dll
x64-Handler: crawler - {4545C96B-15D0-4E22-8DDE-6F2CAF531281} - <orphaned>
x64-Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\System32\MSVidCtl.dll
x64-Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll
x64-Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll
x64-Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll
x64-Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll
x64-Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll
x64-Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll
x64-Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - <orphaned>
x64-Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll
x64-Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll
x64-Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\System32\inetcomm.dll
x64-Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll
x64-Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - <orphaned>
x64-Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll
x64-Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - <orphaned>
x64-Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll
x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\System32\MSVidCtl.dll
x64-Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll
x64-Handler: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Name-Space Handler: mk\* - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll
x64-SSODL: WebCheck - <orphaned>
x64-mASetup: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\System32\unregmp2.exe /ShowWMP
x64-mASetup: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
x64-mASetup: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
x64-mASetup: {12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\Windows\System32\ieudinit.exe
x64-mASetup: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - C:\Windows\System32\regsvr32.exe /s /n /i:/UserInstall C:\Windows\System32\themeui.dll
x64-mASetup: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\System32\cmd.exe /D /C start C:\Windows\System32\ie4uinit.exe -ClearIconCache
x64-mASetup: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "C:\Program Files (x86)\Windows Mail\WinMail.exe" OCInstallUserConfigOE
x64-mASetup: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - C:\Windows\System32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI
x64-mASetup: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
x64-mASetup: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
x64-mASetup: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install
x64-CLSID: {603D3801-BD81-11d0-A3A5-00C04FD706EC} - C:\Windows\System32\shell32.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\esuzx5jl.default\
FF - prefs.js: browser.search.selectedEngine - WebSearch+
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT3279411&octid=CT3279411&SearchSource=61&CUI=UN14915692952109325&UM=2&UP=SP477F5151-5953-44BA-8283-01CF3F4BFBB1
FF - prefs.js: keyword.URL - hxxp://safesearchr.lavasoft.com/?source=3336ca5f&tbp=url&toolbarid=adawaretb&u=82FDDE804350450F99A9E34F7BAFEFE8&q=
FF - prefs.js: browser.startup.homepage - hxxp://safesearchr.lavasoft.com/?source=3336ca5f&tbp=homepage&toolbarid=adawaretb&v=2_2&u=82FDDE804350450F99A9E350EA002600
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\nprjplug.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\nprpplugin.dll
FF - plugin: C:\Program Files (x86)\QuickTime\Plugins\npqtplugin.dll
FF - plugin: C:\Program Files (x86)\QuickTime\Plugins\npqtplugin2.dll
FF - plugin: C:\Program Files (x86)\QuickTime\Plugins\npqtplugin3.dll
FF - plugin: C:\Program Files (x86)\QuickTime\Plugins\npqtplugin4.dll
FF - plugin: C:\Program Files (x86)\QuickTime\Plugins\npqtplugin5.dll
FF - plugin: C:\Program Files (x86)\QuickTime\Plugins\npqtplugin6.dll
FF - plugin: C:\Program Files (x86)\QuickTime\Plugins\npqtplugin7.dll
FF - plugin: c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll
FF - plugin: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll
FF - plugin: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll
FF - plugin: c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll
FF - plugin: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll
FF - plugin: c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: C:\Users\Brain\AppData\Local\Facebook\Messenger\2.1.4520.0\npFbDesktopPlugin.dll
FF - plugin: C:\Users\Brain\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\esuzx5jl.default\extensions\[email protected]\plugins\npLogitechDeviceDetection.dll
FF - plugin: C:\Users\Default\AppData\Local\HuluDesktop\instances\0.9.13.1\nphdplg.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_257.dll
FF - ExtSQL: 2011-07-21 21:25; {ded0fc70-7215-4802-afeb-b2982d3e7225}; C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\esuzx5jl.default\extensions\{ded0fc70-7215-4802-afeb-b2982d3e7225}.xpi
FF - ExtSQL: 2011-07-21 21:26; [email protected]; C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\esuzx5jl.default\extensions\[email protected]
FF - ExtSQL: 2011-07-31 15:06; {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}; C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\esuzx5jl.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
FF - ExtSQL: 2011-07-31 23:52; [email protected]; C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\esuzx5jl.default\extensions\[email protected]
FF - ExtSQL: 2011-08-07 22:27; [email protected]; C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\esuzx5jl.default\extensions\[email protected]
FF - ExtSQL: 2011-08-12 13:55; [email protected]; C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\esuzx5jl.default\extensions\[email protected]
FF - ExtSQL: 2011-09-28 06:25; {BBDA0591-3099-440a-AA10-41764D9DB4DB}; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\IPSFFPlgn
FF - ExtSQL: 2011-10-07 18:00; [email protected]; C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\esuzx5jl.default\extensions\[email protected]
FF - ExtSQL: 2011-10-15 18:27; [email protected]; C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\esuzx5jl.default\extensions\[email protected]
FF - ExtSQL: 2011-10-21 18:35; [email protected]; C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\esuzx5jl.default\extensions\[email protected]
FF - ExtSQL: 2011-11-02 17:46; [email protected]; C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\esuzx5jl.default\extensions\[email protected]
FF - ExtSQL: 2011-11-04 18:05; [email protected]; C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\esuzx5jl.default\extensions\[email protected]
FF - ExtSQL: 2011-11-04 18:05; {9a94d785-2979-44e9-b331-9e09d0cc7cff}; C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\esuzx5jl.default\extensions\{9a94d785-2979-44e9-b331-9e09d0cc7cff}.xpi
FF - ExtSQL: 2011-11-11 06:41; {972ce4c6-7e08-4474-a285-3208198ce6fd}; C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - ExtSQL: 2011-11-11 17:45; {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn
FF - ExtSQL: 2011-11-19 14:45; {87934c42-161d-45bc-8cef-ef18abe2a30c}; C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\esuzx5jl.default\extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c}
FF - ExtSQL: 2012-02-14 18:13; [email protected]; C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\esuzx5jl.default\extensions\[email protected]
FF - ExtSQL: 2012-05-13 17:00; {23fcfd51-4958-4f00-80a3-ae97e717ed8b}; C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF - ExtSQL: 2012-05-27 13:59; {97E22097-9A2F-45b1-8DAF-36AD648C7EF4}; C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF - ExtSQL: 2012-06-24 16:11; [email protected]; C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\esuzx5jl.default\extensions\[email protected]
.
---- FIREFOX POLICIES ----
FF - user.js: general.useragent.extra.brc -
.
.
============= SERVICES / DRIVERS ===============
.
R0 ACPI;Microsoft ACPI Driver;C:\Windows\System32\drivers\acpi.sys [2010-11-20 334208]
R0 amdxata;amdxata;C:\Windows\System32\drivers\amdxata.sys [2011-7-22 27008]
R0 avc3;avc3;C:\Windows\System32\drivers\avc3.sys [2013-1-1 727592]
R0 CLFS;Common Log (CLFS);C:\Windows\System32\clfs.sys [2009-7-13 367696]
R0 CNG;CNG;C:\Windows\System32\drivers\cng.sys [2012-12-23 458712]
R0 Disk;Disk Driver;C:\Windows\System32\drivers\disk.sys [2009-7-13 73280]
R0 DKTLFSMF;Telemetry File System Mini Filter Driver;C:\Windows\System32\drivers\DKTLFSMF.sys [2012-8-4 106832]
R0 FileInfo;File Information FS MiniFilter;C:\Windows\System32\drivers\fileinfo.sys [2009-7-13 70224]
R0 FltMgr;FltMgr;C:\Windows\System32\drivers\fltMgr.sys [2010-11-20 289664]
R0 fvevol;Bitlocker Drive Encryption Filter Driver;C:\Windows\System32\drivers\fvevol.sys [2013-4-9 223752]
R0 gfibto;gfibto;C:\Windows\System32\drivers\gfibto.sys [2013-1-6 14456]
R0 gzflt;gzflt;C:\Windows\System32\drivers\gzflt.sys [2013-10-3 150256]
R0 hwpolicy;Hardware Policy Driver;C:\Windows\System32\drivers\hwpolicy.sys [2010-11-20 14720]
R0 iaStor;Intel RAID Controller;C:\Windows\System32\drivers\iaStor.sys [2011-7-15 438808]
R0 KSecDD;KSecDD;C:\Windows\System32\drivers\ksecdd.sys [2012-7-10 95600]
R0 KSecPkg;KSecPkg;C:\Windows\System32\drivers\ksecpkg.sys [2012-12-23 154480]
R0 mountmgr;Mount Point Manager;C:\Windows\System32\drivers\mountmgr.sys [2010-11-20 94592]
R0 msisadrv;msisadrv;C:\Windows\System32\drivers\msisadrv.sys [2009-7-13 15424]
R0 Mup;Mup;C:\Windows\System32\drivers\mup.sys [2009-7-13 60496]
R0 NDIS;NDIS System Driver;C:\Windows\System32\drivers\ndis.sys [2012-9-11 950128]
R0 partmgr;Partition Manager;C:\Windows\System32\drivers\partmgr.sys [2012-5-11 75120]
R0 pci;PCI Bus Driver;C:\Windows\System32\drivers\pci.sys [2010-11-20 184704]
R0 pcw;Performance Counters for Windows Driver;C:\Windows\System32\drivers\pcw.sys [2009-7-13 50768]
R0 rdyboost;ReadyBoost;C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 snapman;Acronis Snapshots Manager;C:\Windows\System32\drivers\snapman.sys [2012-1-20 277088]
R0 spldr;Security Processor Loader Driver;C:\Windows\System32\drivers\spldr.sys [2009-7-13 19008]
R0 Tcpip;TCP/IP Protocol Driver;C:\Windows\System32\drivers\tcpip.sys [2013-10-9 1903552]
R0 timounter;Acronis Backup Archive Explorer;C:\Windows\System32\drivers\timntr.sys [2012-1-20 970336]
R0 trufos;trufos;C:\Windows\System32\drivers\trufos.sys [2013-5-29 389240]
R0 vdrvroot;Microsoft Virtual Drive Enumerator Driver;C:\Windows\System32\drivers\vdrvroot.sys [2009-7-13 36432]
R0 volmgr;Volume Manager Driver;C:\Windows\System32\drivers\volmgr.sys [2010-11-20 71552]
R0 volmgrx;Dynamic Volume Manager;C:\Windows\System32\drivers\volmgrx.sys [2010-11-20 363392]
R0 volsnap;Storage volumes;C:\Windows\System32\drivers\volsnap.sys [2010-11-20 295808]
R0 Wdf01000;Kernel Mode Driver Frameworks service;C:\Windows\System32\drivers\Wdf01000.sys [2013-10-9 785624]
R1 AFD;Ancillary Function Driver for Winsock;C:\Windows\System32\drivers\afd.sys [2013-10-9 497152]
R1 BdfNdisf;BitDefender Firewall NDIS 6 Filter Driver;C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys [2013-4-26 93600]
R1 bdfwfpf;bdfwfpf;C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [2013-1-1 103504]
R1 BDVEDISK;BDVEDISK;C:\Windows\System32\drivers\bdvedisk.sys [2013-1-1 76944]
R1 Beep;Beep;C:\Windows\System32\drivers\beep.sys [2009-7-13 6656]
R1 blbdrive;blbdrive;C:\Windows\System32\drivers\blbdrive.sys [2009-7-13 45056]
R1 cdrom;CD-ROM Driver;C:\Windows\System32\drivers\cdrom.sys [2010-11-20 147456]
R1 DfsC;DFS Namespace Client Driver;C:\Windows\System32\drivers\dfsc.sys [2010-11-20 102400]
R1 discache;System Attribute Cache;C:\Windows\System32\drivers\discache.sys [2009-7-13 40448]
R1 Msfs;Msfs;C:\Windows\System32\drivers\msfs.sys [2009-7-13 26112]
R1 mssmbios;Microsoft System Management BIOS Driver;C:\Windows\System32\drivers\mssmbios.sys [2009-7-13 32320]
R1 NetBIOS;NetBIOS Interface;C:\Windows\System32\drivers\netbios.sys [2009-7-13 44544]
R1 NetBT;NetBT;C:\Windows\System32\drivers\netbt.sys [2010-11-20 261632]
R1 Npfs;Npfs;C:\Windows\System32\drivers\npfs.sys [2009-7-13 44032]
R1 nsiproxy;NSI proxy service driver.;C:\Windows\System32\drivers\nsiproxy.sys [2009-7-13 24576]
R1 Null;Null;C:\Windows\System32\drivers\null.sys [2009-7-13 6144]
R1 Psched;QoS Packet Scheduler;C:\Windows\System32\drivers\pacer.sys [2010-11-20 131584]
R1 rdbss;Redirected Buffering Sub Sysytem;C:\Windows\System32\drivers\rdbss.sys [2010-11-20 309248]
R1 RDPCDD;RDPCDD;C:\Windows\System32\drivers\RDPCDD.sys [2009-7-13 7680]
R1 RDPENCDD;RDP Encoder Mirror Driver;C:\Windows\System32\drivers\RDPENCDD.sys [2009-7-13 7680]
R1 RDPREFMP;Reflector Display Driver used to gain access to graphics data;C:\Windows\System32\drivers\RDPREFMP.sys [2009-7-13 8192]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R1 SBRE;SBRE;C:\Windows\System32\drivers\SBREDrv.sys [2013-1-13 57976]
R1 tdx;NetIO Legacy TDI Support Driver;C:\Windows\System32\drivers\tdx.sys [2010-11-20 119296]
R1 TermDD;Terminal Device Driver;C:\Windows\System32\drivers\termdd.sys [2010-11-20 63360]
R1 VgaSave;VgaSave;C:\Windows\System32\drivers\vga.sys [2009-7-13 29184]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-13 59904]
R1 Wanarpv6;Remote Access IPv6 ARP Driver;C:\Windows\System32\drivers\wanarp.sys [2010-11-20 88576]
R1 WfpLwf;WFP Lightweight Filter;C:\Windows\System32\drivers\wfplwf.sys [2009-7-13 12800]
R1 ws2ifsl;Windows Socket 2.0 Non-IFS Service Provider Support Environment;C:\Windows\System32\drivers\ws2ifsl.sys [2009-7-13 21504]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2013-5-23 143120]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-5-11 65640]
R2 AudioEndpointBuilder;Windows Audio Endpoint Builder;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
R2 AudioSrv;Windows Audio;C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [2009-7-13 27136]
R2 BFE;Base Filtering Engine;C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork [2009-7-13 27136]
R2 BingDesktopUpdate;Bing Desktop Update service;C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [2013-6-27 173192]
R2 BITS;Background Intelligent Transfer Service;C:\Windows\System32\svchost.exe -k netsvcs [2009-7-13 27136]
R2 CryptSvc;Cryptographic Services;C:\Windows\System32\svchost.exe -k NetworkService [2009-7-13 27136]
R2 DcomLaunch;DCOM Server Process Launcher;C:\Windows\System32\svchost.exe -k DcomLaunch [2009-7-13 27136]
R2 Dhcp;DHCP Client;C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [2009-7-13 27136]
R2 Diskeeper;Diskeeper;C:\Program Files\Condusiv Technologies\Diskeeper\DkService.exe [2012-7-27 2721656]
R2 Dnscache;DNS Client;C:\Windows\System32\svchost.exe -k NetworkService [2009-7-13 27136]
R2 DPS;Diagnostic Policy Service;C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork [2009-7-13 27136]
R2 EFS;Encrypting File System (EFS);C:\Windows\System32\lsass.exe [2012-1-26 31232]
R2 eventlog;Windows Event Log;C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [2009-7-13 27136]
R2 EventSystem;COM+ Event System;C:\Windows\System32\svchost.exe -k LocalService [2009-7-13 27136]
R2 FDResPub;Function Discovery Resource Publication;C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation [2009-7-13 27136]
R2 FontCache;Windows Font Cache Service;C:\Windows\System32\svchost.exe -k LocalService [2009-7-13 27136]
R2 gpsvc;Group Policy Client;C:\Windows\System32\svchost.exe -k GPSvcGroup [2009-7-13 27136]
R2 HP Power Assistant Service;HP Power Assistant Service;C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2010-11-17 107576]
R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2012-9-27 86528]
R2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168]
R2 IKEEXT;IKE and AuthIP IPsec Keying Modules;C:\Windows\System32\svchost.exe -k netsvcs [2009-7-13 27136]
R2 iphlpsvc;IP Helper;C:\Windows\System32\svchost.exe -k NetSvcs [2009-7-13 27136]
R2 LanmanServer;Server;C:\Windows\System32\svchost.exe -k netsvcs [2009-7-13 27136]
R2 LanmanWorkstation;Workstation;C:\Windows\System32\svchost.exe -k NetworkService [2009-7-13 27136]
R2 lltdio;Link-Layer Topology Discovery Mapper I/O Driver;C:\Windows\System32\drivers\lltdio.sys [2009-7-13 60928]
R2 lmhosts;TCP/IP NetBIOS Helper;C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [2009-7-13 27136]
R2 LMS;Intel® Management and Security Application Local Management Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe [2011-7-15 326168]
R2 luafv;UAC File Virtualization;C:\Windows\System32\drivers\luafv.sys [2009-7-13 113152]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-9-16 418376]
R2 MMCSS;Multimedia Class Scheduler;C:\Windows\System32\svchost.exe -k netsvcs [2009-7-13 27136]
R2 MpsSvc;Windows Firewall;C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork [2009-7-13 27136]
R2 NlaSvc;Network Location Awareness;C:\Windows\System32\svchost.exe -k NetworkService [2009-7-13 27136]
R2 nsi;Network Store Interface Service;C:\Windows\System32\svchost.exe -k LocalService [2009-7-13 27136]
R2 PcaSvc;Program Compatibility Assistant Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
R2 PEAUTH;PEAUTH;C:\Windows\System32\drivers\PEAuth.sys [2009-7-13 651264]
R2 PlugPlay;Plug and Play;C:\Windows\System32\svchost.exe -k DcomLaunch [2009-7-13 27136]
R2 Power;Power;C:\Windows\System32\svchost.exe -k DcomLaunch [2009-7-13 27136]
R2 ProfSvc;User Profile Service;C:\Windows\System32\svchost.exe -k netsvcs [2009-7-13 27136]
R2 RpcEptMapper;RPC Endpoint Mapper;C:\Windows\System32\svchost.exe -k RPCSS [2009-7-13 27136]
R2 RpcSs;Remote Procedure Call (RPC);C:\Windows\System32\svchost.exe -k rpcss [2009-7-13 27136]
R2 rspndr;Link-Layer Topology Discovery Responder;C:\Windows\System32\drivers\rspndr.sys [2009-7-13 76800]
R2 SafeBox;SafeBox;C:\Program Files\Bitdefender\Bitdefender Safebox\safeboxservice.exe [2013-1-1 95184]
R2 SamSs;Security Accounts Manager;C:\Windows\System32\lsass.exe [2012-1-26 31232]
R2 Schedule;Task Scheduler;C:\Windows\System32\svchost.exe -k netsvcs [2009-7-13 27136]
R2 secdrv;Security Driver;C:\Windows\System32\drivers\secdrv.sys [2009-7-13 23040]
R2 SENS;System Event Notification Service;C:\Windows\System32\svchost.exe -k netsvcs [2009-7-13 27136]
R2 ShellHWDetection;Shell Hardware Detection;C:\Windows\System32\svchost.exe -k netsvcs [2009-7-13 27136]
R2 Spooler;Print Spooler;C:\Windows\System32\spoolsv.exe [2012-8-14 559104]
R2 stisvc;Windows Image Acquisition (WIA);C:\Windows\System32\svchost.exe -k imgsvc [2009-7-13 27136]
R2 SysMain;Superfetch;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
R2 tcpipreg;TCP/IP Registry Compatibility;C:\Windows\System32\drivers\tcpipreg.sys [2012-11-13 45568]
R2 Themes;Themes;C:\Windows\System32\svchost.exe -k netsvcs [2009-7-13 27136]
R2 TrkWks;Distributed Link Tracking Client;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-7-15 2656280]
R2 UPDATESRV;Bitdefender Desktop Update Service;C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe [2013-8-27 67320]
R2 UxSms;Desktop Window Manager Session Manager;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
R2 VSSERV;Bitdefender Virus Shield;C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe [2013-10-3 1645256]
R2 WinDefend;Windows Defender;C:\Windows\System32\svchost.exe -k secsvcs [2009-7-13 27136]
R2 Winmgmt;Windows Management Instrumentation;C:\Windows\System32\svchost.exe -k netsvcs [2009-7-13 27136]
R2 Wlansvc;WLAN AutoConfig;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
R2 wlidsvc;Windows Live ID Sign-in Assistant;C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-7-17 2292480]
R2 WMPNetworkSvc;Windows Media Player Network Sharing Service;C:\Program Files\Windows Media Player\wmpnetwk.exe [2010-11-20 1525248]
R2 wscsvc;Security Center;C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [2009-7-13 27136]
R2 WSearch;Windows Search;C:\Windows\System32\SearchIndexer.exe [2011-7-21 591872]
R2 wuauserv;Windows Update;C:\Windows\System32\svchost.exe -k netsvcs [2009-7-13 27136]
R3 AeLookupSvc;Application Experience;C:\Windows\System32\svchost.exe -k netsvcs [2009-7-13 27136]
R3 amdkmdag;amdkmdag;C:\Windows\System32\drivers\atikmdag.sys [2012-4-26 11172864]
R3 amdkmdap;amdkmdap;C:\Windows\System32\drivers\atikmpag.sys [2012-4-26 339456]
R3 Appinfo;Application Information;C:\Windows\System32\svchost.exe -k netsvcs [2009-7-13 27136]
R3 AsyncMac;RAS Asynchronous Media Driver;C:\Windows\System32\drivers\asyncmac.sys [2009-7-13 23040]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2011-7-15 116752]
R3 avchv;avchv Function Driver;C:\Windows\System32\drivers\avchv.sys [2013-1-1 261056]
R3 avckf;avckf;C:\Windows\System32\drivers\avckf.sys [2013-7-15 601360]
R3 bowser;Browser Support Driver;C:\Windows\System32\drivers\bowser.sys [2011-7-21 90624]
R3 Browser;Computer Browser;C:\Windows\System32\svchost.exe -k netsvcs [2009-7-13 27136]
R3 CompositeBus;Composite Bus Enumerator Driver;C:\Windows\System32\drivers\CompositeBus.sys [2010-11-20 38912]
R3 dc3d;MS Hardware Device Detection Driver (USB);C:\Windows\System32\drivers\dc3d.sys [2013-3-25 76464]
R3 DKRtWrt;DKRtWrt;C:\Windows\System32\drivers\DKRtWrt.sys [2012-8-4 52048]
R3 DXGKrnl;LDDM Graphics Subsystem;C:\Windows\System32\drivers\dxgkrnl.sys [2013-10-9 983488]
R3 EapHost;Extensible Authentication Protocol;C:\Windows\System32\svchost.exe -k netsvcs [2009-7-13 27136]
R3 fastfat;FAT12/16/32 File System Driver;C:\Windows\System32\drivers\fastfat.sys [2009-7-13 204800]
R3 fdPHost;Function Discovery Provider Host;C:\Windows\System32\svchost.exe -k LocalService [2009-7-13 27136]
R3 GEARAspiWDM;GEAR ASPI Filter Driver;C:\Windows\System32\drivers\GEARAspiWDM.sys [2012-9-23 33240]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio;C:\Windows\System32\drivers\hdaudbus.sys [2010-11-20 122368]
R3 hidserv;Human Interface Device Access;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
R3 HidUsb;Microsoft HID Class Driver;C:\Windows\System32\drivers\hidusb.sys [2010-11-20 30208]
R3 HomeGroupListener;HomeGroup Listener;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
R3 HomeGroupProvider;HomeGroup Provider;C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [2009-7-13 27136]
R3 HTTP;HTTP;C:\Windows\System32\drivers\http.sys [2010-11-20 753664]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM);C:\Windows\System32\drivers\RTKVHD64.sys [2011-12-20 4720616]
R3 intelppm;Intel Processor Driver;C:\Windows\System32\drivers\intelppm.sys [2009-7-13 62464]
R3 kbdclass;Keyboard Class Driver;C:\Windows\System32\drivers\kbdclass.sys [2009-7-13 50768]
R3 kbdhid;Keyboard HID Driver;C:\Windows\System32\drivers\kbdhid.sys [2010-11-20 33280]
R3 KeyIso;CNG Key Isolation;C:\Windows\System32\lsass.exe [2012-1-26 31232]
R3 ksthunk;Kernel Streaming Thunks;C:\Windows\System32\drivers\ksthunk.sys [2009-7-13 20992]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2011-7-23 25928]
R3 MEIx64;Intel® Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2011-7-15 56344]
R3 monitor;Microsoft Monitor Class Function Driver Service;C:\Windows\System32\drivers\monitor.sys [2009-7-13 30208]
R3 mouclass;Mouse Class Driver;C:\Windows\System32\drivers\mouclass.sys [2009-7-13 49216]
R3 mouhid;Mouse HID Driver;C:\Windows\System32\drivers\mouhid.sys [2009-7-13 31232]
R3 mpsdrv;Windows Firewall Authorization Driver;C:\Windows\System32\drivers\mpsdrv.sys [2009-7-13 77312]
R3 mrxsmb;SMB MiniRedirector Wrapper and Engine;C:\Windows\System32\drivers\mrxsmb.sys [2011-7-21 158208]
R3 mrxsmb10;SMB 1.x MiniRedirector;C:\Windows\System32\drivers\mrxsmb10.sys [2011-8-10 288768]
R3 mrxsmb20;SMB 2.0 MiniRedirector;C:\Windows\System32\drivers\mrxsmb20.sys [2011-7-21 128000]
R3 NativeWifiP;NativeWiFi Filter;C:\Windows\System32\drivers\nwifi.sys [2009-7-13 318976]
R3 NdisTapi;Remote Access NDIS TAPI Driver;C:\Windows\System32\drivers\ndistapi.sys [2009-7-13 24064]
R3 Ndisuio;NDIS Usermode I/O Protocol;C:\Windows\System32\drivers\ndisuio.sys [2010-11-20 56832]
R3 NdisWan;Remote Access NDIS WAN Driver;C:\Windows\System32\drivers\ndiswan.sys [2010-11-20 164352]
R3 NDProxy;NDIS Proxy;C:\Windows\System32\drivers\ndproxy.sys [2010-11-20 57856]
R3 Netman;Network Connections;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
R3 netprofm;Network List Service;C:\Windows\System32\svchost.exe -k LocalService [2009-7-13 27136]
R3 Ntfs;Ntfs;C:\Windows\System32\drivers\ntfs.sys [2013-4-23 1656680]
R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
R3 p2pimsvc;Peer Networking Identity Manager;C:\Windows\System32\svchost.exe -k LocalServicePeerNet [2009-7-13 27136]
R3 p2psvc;Peer Networking Grouping;C:\Windows\System32\svchost.exe -k LocalServicePeerNet [2009-7-13 27136]
R3 PNRPsvc;Peer Name Resolution Protocol;C:\Windows\System32\svchost.exe -k LocalServicePeerNet [2009-7-13 27136]
R3 Point64;Microsoft Mouse and Keyboard Center Filter Driver;C:\Windows\System32\drivers\point64.sys [2013-5-13 50864]
R3 PolicyAgent;IPsec Policy Agent;C:\Windows\System32\svchost.exe -k NetworkServiceNetworkRestricted [2009-7-13 27136]
R3 PptpMiniport;WAN Miniport (PPTP);C:\Windows\System32\drivers\raspptp.sys [2010-11-20 111104]
R3 ProtectedStorage;Protected Storage;C:\Windows\System32\lsass.exe [2012-1-26 31232]
R3 RasAgileVpn;WAN Miniport (IKEv2);C:\Windows\System32\drivers\agilevpn.sys [2009-7-13 60416]
R3 Rasl2tp;WAN Miniport (L2TP);C:\Windows\System32\drivers\rasl2tp.sys [2010-11-20 129536]
R3 RasPppoe;Remote Access PPPOE Driver;C:\Windows\System32\drivers\raspppoe.sys [2009-7-13 92672]
R3 RasSstp;WAN Miniport (SSTP);C:\Windows\System32\drivers\rassstp.sys [2009-7-13 83968]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-5-16 533096]
R3 SDRSVC;Windows Backup;C:\Windows\System32\svchost.exe -k SDRSVC [2009-7-13 27136]
R3 srv;Server SMB 1.xxx Driver;C:\Windows\System32\drivers\srv.sys [2011-7-21 467456]
R3 srv2;Server SMB 2.xxx Driver;C:\Windows\System32\drivers\srv2.sys [2011-7-21 410112]
R3 srvnet;srvnet;C:\Windows\System32\drivers\srvnet.sys [2011-7-21 168448]
R3 SSDPSRV;SSDP Discovery;C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation [2009-7-13 27136]
R3 swenum;Software Bus Driver;C:\Windows\System32\drivers\swenum.sys [2009-7-13 12496]
R3 swprv;Microsoft Software Shadow Copy Provider;C:\Windows\System32\svchost.exe -k swprv [2009-7-13 27136]
R3 TermService;Remote Desktop Services;C:\Windows\System32\svchost.exe -k NetworkService [2009-7-13 27136]
R3 tunnel;Microsoft Tunnel Miniport Adapter Driver;C:\Windows\System32\drivers\tunnel.sys [2010-11-20 125440]
R3 umbus;UMBus Enumerator Driver;C:\Windows\System32\drivers\umbus.sys [2010-11-20 48640]
R3 upnphost;UPnP Device Host;C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation [2009-7-13 27136]
R3 usbccgp;Microsoft USB Generic Parent Driver;C:\Windows\System32\drivers\usbccgp.sys [2013-10-11 99840]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver;C:\Windows\System32\drivers\usbehci.sys [2013-10-11 52736]
R3 usbhub;Microsoft USB Standard Hub Driver;C:\Windows\System32\drivers\usbhub.sys [2013-10-11 343040]
R3 USBSTOR;USB Mass Storage Driver;C:\Windows\System32\drivers\USBSTOR.SYS [2011-7-22 91648]
R3 VSS;Volume Shadow Copy;C:\Windows\System32\VSSVC.exe [2010-11-20 1600512]
R3 wcncsvc;Windows Connect Now - Config Registrar;C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation [2009-7-13 27136]
R3 WdiServiceHost;Diagnostic Service Host;C:\Windows\System32\svchost.exe -k LocalService [2009-7-13 27136]
R3 WinHttpAutoProxySvc;WinHTTP Web Proxy Auto-Discovery Service;C:\Windows\System32\svchost.exe -k LocalService [2009-7-13 27136]
R3 WPDBusEnum;Portable Device Enumerator Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
R3 WudfPf;User Mode Driver Frameworks Platform Driver;C:\Windows\System32\drivers\WUDFPf.sys [2012-11-13 87040]
R3 WUDFRd;WUDFRd;C:\Windows\System32\drivers\WUDFRd.sys [2012-11-13 198656]
R3 wudfsvc;Windows Driver Foundation - User-mode Driver Framework;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-11-29 116648]
S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-9-16 701512]
S2 sppsvc;Software Protection;C:\Windows\System32\sppsvc.exe [2010-11-20 3524608]
S2 w32time;Windows Time;C:\Windows\System32\svchost.exe -k LocalService [2009-7-13 27136]
S3 1394ohci;1394 OHCI Compliant Host Controller;C:\Windows\System32\drivers\1394ohci.sys [2010-11-20 229888]
S3 AcpiPmi;ACPI Power Meter Driver;C:\Windows\System32\drivers\acpipmi.sys [2010-11-20 12800]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-8-14 257416]
S3 adp94xx;adp94xx;C:\Windows\System32\drivers\adp94xx.sys [2009-6-10 491088]
S3 adpahci;adpahci;C:\Windows\System32\drivers\adpahci.sys [2009-7-13 339536]
S3 adpu320;adpu320;C:\Windows\System32\drivers\adpu320.sys [2009-7-13 182864]
S3 agp440;Intel AGP Bus Filter;C:\Windows\System32\drivers\AGP440.sys [2009-7-13 61008]
S3 ALG;Application Layer Gateway Service;C:\Windows\System32\alg.exe [2009-7-13 79360]
S3 aliide;aliide;C:\Windows\System32\drivers\aliide.sys [2009-7-13 15440]
S3 amdide;amdide;C:\Windows\System32\drivers\amdide.sys [2009-7-13 15440]
S3 AmdK8;AMD K8 Processor Driver;C:\Windows\System32\drivers\amdk8.sys [2009-7-13 64512]
S3 AmdPPM;AMD Processor Driver;C:\Windows\System32\drivers\amdppm.sys [2009-7-13 60928]
S3 amdsata;amdsata;C:\Windows\System32\drivers\amdsata.sys [2011-7-22 107904]
S3 amdsbs;amdsbs;C:\Windows\System32\drivers\amdsbs.sys [2009-6-10 194128]
S3 AppID;AppID Driver;C:\Windows\System32\drivers\appid.sys [2010-11-20 61440]
S3 AppIDSvc;Application Identity;C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation [2009-7-13 27136]
S3 arc;arc;C:\Windows\System32\drivers\arc.sys [2009-7-13 87632]
S3 arcsas;arcsas;C:\Windows\System32\drivers\arcsas.sys [2009-7-13 97856]
S3 aspnet_state;ASP.NET State Service;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-3-18 44376]
S3 atapi;IDE Channel;C:\Windows\System32\drivers\atapi.sys [2009-7-13 24128]
S3 b06bdrv;Broadcom NetXtreme II VBD;C:\Windows\System32\drivers\bxvbda.sys [2009-6-10 468480]
S3 b57nd60a;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;C:\Windows\System32\drivers\b57nd60a.sys [2009-6-10 270848]
S3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;C:\Windows\System32\drivers\bcmwlhigh664.sys [2009-11-6 838136]
S3 BDESVC;BitLocker Drive Encryption Service;C:\Windows\System32\svchost.exe -k netsvcs [2009-7-13 27136]
S3 BDSandBox;BDSandBox;C:\Windows\System32\drivers\bdsandbox.sys [2013-1-1 82824]
S3 BrFiltLo;Brother USB Mass-Storage Lower Filter Driver;C:\Windows\System32\drivers\BrFiltLo.sys [2009-7-13 18432]
S3 BrFiltUp;Brother USB Mass-Storage Upper Filter Driver;C:\Windows\System32\drivers\BrFiltUp.sys [2009-7-13 8704]
S3 Brserid;Brother MFC Serial Port Interface Driver (WDM);C:\Windows\System32\drivers\BrSerId.sys [2009-7-13 286720]
S3 BrSerWdm;Brother WDM Serial driver;C:\Windows\System32\drivers\BrSerWdm.sys [2009-7-13 47104]
S3 BrUsbMdm;Brother MFC USB Fax Only Modem;C:\Windows\System32\drivers\BrUsbMdm.sys [2009-7-13 14976]
S3 BrUsbSer;Brother MFC USB Serial WDM Driver;C:\Windows\System32\drivers\BrUsbSer.sys [2009-7-13 14720]
S3 BTHMODEM;Bluetooth Serial Communications Driver;C:\Windows\System32\drivers\bthmodem.sys [2009-7-13 72192]
S3 CertPropSvc;Certificate Propagation;C:\Windows\System32\svchost.exe -k netsvcs [2009-7-13 27136]
S3 circlass;Consumer IR Devices;C:\Windows\System32\drivers\circlass.sys [2009-7-13 45568]
S3 CmBatt;Microsoft ACPI Control Method Battery Driver;C:\Windows\System32\drivers\CmBatt.sys [2009-7-13 17664]
S3 cmdide;cmdide;C:\Windows\System32\drivers\cmdide.sys [2009-7-13 17488]
S3 Compbatt;Compbatt;C:\Windows\System32\drivers\compbatt.sys [2009-7-13 21584]
S3 COMSysApp;COM+ System Application;C:\Windows\System32\dllhost.exe [2009-7-13 9728]
S3 CpqDfw;Compaq Dfw;C:\Windows\System32\drivers\cpqdfw.sys [2010-3-1 27456]
S3 defragsvc;Disk Defragmenter;C:\Windows\System32\svchost.exe -k defragsvc [2009-7-13 27136]
S3 dot3svc;Wired AutoConfig;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
S3 drmkaud;Microsoft Trusted Audio Drivers;C:\Windows\System32\drivers\drmkaud.sys [2009-7-13 5632]
S3 ebdrv;Broadcom NetXtreme II 10 GigE VBD;C:\Windows\System32\drivers\evbda.sys [2009-6-10 3286016]
S3 ehRecvr;Windows Media Center Receiver Service;C:\Windows\ehome\ehrecvr.exe [2010-11-20 696832]
S3 ehSched;Windows Media Center Scheduler Service;C:\Windows\ehome\ehsched.exe [2009-7-13 127488]
S3 elxstor;elxstor;C:\Windows\System32\drivers\elxstor.sys [2009-6-10 530496]
S3 ErrDev;Microsoft Hardware Error Device Driver;C:\Windows\System32\drivers\errdev.sys [2009-7-13 9728]
S3 exfat;exFAT File System Driver;C:\Windows\System32\drivers\exfat.sys [2009-7-13 195072]
S3 Fax;Fax;C:\Windows\System32\FXSSVC.exe [2010-11-20 689152]
S3 fdc;Floppy Disk Controller Driver;C:\Windows\System32\drivers\fdc.sys [2009-7-13 29696]
S3 Filetrace;Filetrace;C:\Windows\System32\drivers\filetrace.sys [2009-7-13 34304]
S3 flpydisk;Floppy Disk Driver;C:\Windows\System32\drivers\flpydisk.sys [2009-7-13 24576]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0;C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe [2010-11-20 42856]
S3 FsDepends;File System Dependency Minifilter;C:\Windows\System32\drivers\fsdepends.sys [2009-7-13 55376]
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2013-8-9 57840]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2013-2-5 1512448]
S3 gagp30kx;Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms;C:\Windows\System32\drivers\GAGP30KX.SYS [2009-7-13 65088]
S3 gfiark;gfiark;C:\Windows\System32\drivers\gfiark.sys [2013-10-13 41032]
S3 gfiutil;gfiutil;C:\Windows\System32\drivers\gfiutil.sys [2013-10-13 31264]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe [2011-7-25 30192]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-11-29 116648]
S3 hcw85cir;Hauppauge Consumer Infrared Receiver;C:\Windows\System32\drivers\hcw85cir.sys [2009-7-13 31232]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service;C:\Windows\System32\drivers\HdAudio.sys [2010-11-20 350208]
S3 HidBatt;HID UPS Battery Driver;C:\Windows\System32\drivers\hidbatt.sys [2009-7-13 26624]
S3 HidBth;Microsoft Bluetooth HID Miniport;C:\Windows\System32\drivers\hidbth.sys [2009-7-13 100864]
S3 HidIr;Microsoft Infrared HID Driver;C:\Windows\System32\drivers\hidir.sys [2009-7-13 46592]
S3 hkmsvc;Health Key and Certificate Management;C:\Windows\System32\svchost.exe -k netsvcs [2009-7-13 27136]
S3 hpqwmiex;HP Software Framework Service;C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2012-8-10 1001376]
S3 HpSAMD;HpSAMD;C:\Windows\System32\drivers\HpSAMD.sys [2010-11-20 78720]
S3 i8042prt;i8042 Keyboard and PS/2 Mouse Port Driver;C:\Windows\System32\drivers\i8042prt.sys [2009-7-13 105472]
S3 iaStorV;Intel RAID Controller Windows 7;C:\Windows\System32\drivers\iaStorV.sys [2011-7-22 410496]
S3 idsvc;Windows CardSpace;C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe [2010-11-20 856400]
S3 igfx;igfx;C:\Windows\System32\drivers\igdkmd64.sys [2009-6-10 6108416]
S3 iirsp;iirsp;C:\Windows\System32\drivers\iirsp.sys [2009-7-13 44112]
S3 intelide;intelide;C:\Windows\System32\drivers\intelide.sys [2009-7-13 16960]
S3 IPBusEnum;PnP-X IP Bus Enumerator;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
S3 IpFilterDriver;IP Traffic Filter Driver;C:\Windows\System32\drivers\ipfltdrv.sys [2010-11-20 82944]
S3 IPMIDRV;IPMIDRV;C:\Windows\System32\drivers\IPMIDrv.sys [2010-11-20 78848]
S3 IPNAT;IP Network Address Translator;C:\Windows\System32\drivers\ipnat.sys [2009-7-13 116224]
S3 iPod Service;iPod Service;C:\Program Files\iPod\bin\iPodService.exe [2013-10-1 641352]
S3 IRENUM;IR Bus Enumerator;C:\Windows\System32\drivers\irenum.sys [2009-7-13 17920]
S3 isapnp;isapnp;C:\Windows\System32\drivers\isapnp.sys [2009-7-13 20544]
S3 iScsiPrt;iScsiPort Driver;C:\Windows\System32\drivers\msiscsi.sys [2010-11-20 273792]
S3 KtmRm;KtmRm for Distributed Transaction Coordinator;C:\Windows\System32\svchost.exe -k NetworkServiceAndNoImpersonation [2009-7-13 27136]
S3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;C:\Windows\System32\drivers\LEqdUsb.sys [2011-4-30 76056]
S3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;C:\Windows\System32\drivers\LHidEqd.sys [2011-4-30 15128]
S3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver;C:\Windows\System32\drivers\LHidFilt.Sys [2011-4-30 66840]
S3 lltdsvc;Link-Layer Topology Discovery Mapper;C:\Windows\System32\svchost.exe -k LocalService [2009-7-13 27136]
S3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver;C:\Windows\System32\drivers\LMouFilt.Sys [2011-4-30 60184]
S3 LSI_FC;LSI_FC;C:\Windows\System32\drivers\lsi_fc.sys [2009-7-13 114752]
S3 LSI_SAS;LSI_SAS;C:\Windows\System32\drivers\lsi_sas.sys [2009-7-13 106560]
S3 LSI_SAS2;LSI_SAS2;C:\Windows\System32\drivers\lsi_sas2.sys [2009-7-13 65600]
S3 LSI_SCSI;LSI_SCSI;C:\Windows\System32\drivers\lsi_scsi.sys [2009-7-13 115776]
S3 megasas;megasas;C:\Windows\System32\drivers\megasas.sys [2009-6-10 35392]
S3 MegaSR;MegaSR;C:\Windows\System32\drivers\MegaSR.sys [2009-7-13 284736]
S3 Modem;Modem;C:\Windows\System32\drivers\modem.sys [2009-7-13 40448]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-4-27 119408]
S3 mpio;mpio;C:\Windows\System32\drivers\mpio.sys [2010-11-20 155008]
S3 MRxDAV;WebDav Client Redirector Driver;C:\Windows\System32\drivers\mrxdav.sys [2013-10-9 140800]
S3 msahci;msahci;C:\Windows\System32\drivers\msahci.sys [2010-11-20 31104]
S3 msdsm;msdsm;C:\Windows\System32\drivers\msdsm.sys [2010-11-20 140672]
S3 MSDTC;Distributed Transaction Coordinator;C:\Windows\System32\msdtc.exe [2009-7-13 141824]
S3 mshidkmdf;Pass-through HID to KMDF Filter Driver;C:\Windows\System32\drivers\mshidkmdf.sys [2009-7-13 8192]
S3 MSiSCSI;Microsoft iSCSI Initiator Service;C:\Windows\System32\svchost.exe -k netsvcs [2009-7-13 27136]
S3 msiserver;Windows Installer;C:\Windows\System32\msiexec.exe [2010-11-20 128000]
S3 MSKSSRV;Microsoft Streaming Service Proxy;C:\Windows\System32\drivers\mskssrv.sys [2009-7-13 11136]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy;C:\Windows\System32\drivers\mspclock.sys [2009-7-13 7168]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy;C:\Windows\System32\drivers\mspqm.sys [2009-7-13 6784]
S3 MsRPC;MsRPC;C:\Windows\System32\drivers\msrpc.sys [2010-11-20 366976]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter;C:\Windows\System32\drivers\mstee.sys [2009-7-13 8064]
S3 MTConfig;Microsoft Input Configuration Driver;C:\Windows\System32\drivers\MTConfig.sys [2009-7-13 15360]
S3 napagent;Network Access Protection Agent;C:\Windows\System32\svchost.exe -k NetworkService [2009-7-13 27136]
S3 NdisCap;NDIS Capture LightWeight Filter;C:\Windows\System32\drivers\ndiscap.sys [2009-7-13 35328]
S3 Netlogon;Netlogon;C:\Windows\System32\lsass.exe [2012-1-26 31232]
S3 nfrd960;nfrd960;C:\Windows\System32\drivers\nfrd960.sys [2009-7-13 51264]
S3 nv_agp;NVIDIA nForce AGP Bus Filter;C:\Windows\System32\drivers\NV_AGP.SYS [2009-7-13 122960]
S3 nvraid;nvraid;C:\Windows\System32\drivers\nvraid.sys [2011-7-22 148352]
S3 nvstor;nvstor;C:\Windows\System32\drivers\nvstor.sys [2011-7-22 166272]
S3 ohci1394;1394 OHCI Compliant Host Controller (Legacy);C:\Windows\System32\drivers\ohci1394.sys [2009-7-13 72832]
S3 ose;Office Source Engine;C:\Program Files (x86)\Common Files\microsoft shared\Source Engine\OSE.EXE [2010-1-9 149352]
S3 Parport;Parallel port driver;C:\Windows\System32\drivers\parport.sys [2009-7-13 97280]
S3 pciide;pciide;C:\Windows\System32\drivers\pciide.sys [2009-7-13 12352]
S3 pcmcia;pcmcia;C:\Windows\System32\drivers\pcmcia.sys [2009-7-13 220752]
S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2009-7-13 20992]
S3 pla;Performance Logs & Alerts;C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork [2009-7-13 27136]
S3 PNRPAutoReg;PNRP Machine Name Publication Service;C:\Windows\System32\svchost.exe -k LocalServicePeerNet [2009-7-13 27136]
S3 Processor;Processor Driver;C:\Windows\System32\drivers\processr.sys [2009-7-13 60416]
S3 ql2300;ql2300;C:\Windows\System32\drivers\ql2300.sys [2009-6-10 1524816]
S3 ql40xx;ql40xx;C:\Windows\System32\drivers\ql40xx.sys [2009-7-13 128592]
S3 QWAVE;Quality Windows Audio Video Experience;C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation [2009-7-13 27136]
S3 QWAVEdrv;QWAVE driver;C:\Windows\System32\drivers\qwavedrv.sys [2009-7-13 46592]
S3 RasAcd;Remote Access Auto Connection Driver;C:\Windows\System32\drivers\rasacd.sys [2009-7-13 14848]
S3 RasAuto;Remote Access Auto Connection Manager;C:\Windows\System32\svchost.exe -k netsvcs [2009-7-13 27136]
S3 RasMan;Remote Access Connection Manager;C:\Windows\System32\svchost.exe -k netsvcs [2009-7-13 27136]
S3 rcmirror;rcmirror;C:\Windows\System32\drivers\rcmirror.sys [2010-1-18 4608]
S3 rdpbus;Remote Desktop Device Redirector Bus Driver;C:\Windows\System32\drivers\rdpbus.sys [2009-7-13 24064]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2012-12-23 19456]
S3 RDPWD;RDP Winstation Driver;C:\Windows\System32\drivers\rdpwd.sys [2012-6-12 210944]
S3 RemoteRegistry;Remote Registry;C:\Windows\System32\svchost.exe -k regsvc [2009-7-13 27136]
S3 Revoflt;Revoflt;C:\Windows\System32\drivers\revoflt.sys [2013-8-7 31800]
S3 RpcLocator;Remote Procedure Call (RPC) Locator;C:\Windows\System32\Locator.exe [2009-7-13 10240]
S3 sbp2port;sbp2port;C:\Windows\System32\drivers\sbp2port.sys [2010-11-20 103808]
S3 SCardSvr;Smart Card;C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation [2009-7-13 27136]
S3 scfilter;Smart card PnP Class Filter Driver;C:\Windows\System32\drivers\scfilter.sys [2010-11-20 29696]
S3 SCPolicySvc;Smart Card Removal Policy;C:\Windows\System32\svchost.exe -k netsvcs [2009-7-13 27136]
S3 seclogon;Secondary Logon;C:\Windows\System32\svchost.exe -k netsvcs [2009-7-13 27136]
S3 SensrSvc;Adaptive Brightness;C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation [2009-7-13 27136]
S3 Serenum;Serenum Filter Driver;C:\Windows\System32\drivers\serenum.sys [2009-7-13 23552]
S3 Serial;Serial;C:\Windows\System32\drivers\serial.sys [2009-7-13 94208]
S3 sermouse;Serial Mouse Driver;C:\Windows\System32\drivers\sermouse.sys [2009-7-13 26624]
S3 SessionEnv;Remote Desktop Configuration;C:\Windows\System32\svchost.exe -k netsvcs [2009-7-13 27136]
S3 sffdisk;SFF Storage Class Driver;C:\Windows\System32\drivers\sffdisk.sys [2009-7-13 14336]
S3 sffp_mmc;SFF Storage Protocol Driver for MMC;C:\Windows\System32\drivers\sffp_mmc.sys [2009-7-13 13824]
S3 sffp_sd;SFF Storage Protocol Driver for SDBus;C:\Windows\System32\drivers\sffp_sd.sys [2010-11-20 14336]
S3 sfloppy;High-Capacity Floppy Disk Drive;C:\Windows\System32\drivers\sfloppy.sys [2009-7-13 16896]
S3 SiSRaid2;SiSRaid2;C:\Windows\System32\drivers\sisraid2.sys [2009-6-10 43584]
S3 SiSRaid4;SiSRaid4;C:\Windows\System32\drivers\sisraid4.sys [2009-7-13 80464]
S3 Smb;Message-oriented TCP/IP and TCP/IPv6 Protocol (SMB session);C:\Windows\System32\drivers\smb.sys [2009-7-13 93184]
S3 SNMPTRAP;SNMP Trap;C:\Windows\System32\snmptrap.exe [2009-7-13 14336]
S3 sppuinotify;SPP Notification Service;C:\Windows\System32\svchost.exe -k LocalService [2009-7-13 27136]
S3 SstpSvc;Secure Socket Tunneling Protocol Service;C:\Windows\System32\svchost.exe -k LocalService [2009-7-13 27136]
S3 stexstor;stexstor;C:\Windows\System32\drivers\stexstor.sys [2009-7-13 24656]
S3 TabletInputService;Tablet PC Input Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
S3 TapiSrv;Telephony;C:\Windows\System32\svchost.exe -k NetworkService [2009-7-13 27136]
S3 TBS;TPM Base Services;C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation [2009-7-13 27136]
S3 TCPIP6;Microsoft IPv6 Protocol Driver;C:\Windows\System32\drivers\tcpip.sys [2013-10-9 1903552]
S3 TDPIPE;TDPIPE;C:\Windows\System32\drivers\tdpipe.sys [2009-7-13 15872]
S3 TDTCP;TDTCP;C:\Windows\System32\drivers\tdtcp.sys [2012-3-13 23552]
S3 THREADORDER;Thread Ordering Server;C:\Windows\System32\svchost.exe -k LocalService [2009-7-13 27136]
S3 TrustedInstaller;Windows Modules Installer;C:\Windows\servicing\TrustedInstaller.exe [2010-11-20 194048]
S3 tssecsrv;Remote Desktop Services Security Filter Driver;C:\Windows\System32\drivers\tssecsrv.sys [2013-8-14 39936]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2012-12-23 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2012-12-23 30208]
S3 uagp35;Microsoft AGPv3.5 Filter;C:\Windows\System32\drivers\UAGP35.SYS [2009-7-13 64080]
S3 UI0Detect;Interactive Services Detection;C:\Windows\System32\UI0Detect.exe [2009-7-13 40960]
S3 uliagpkx;Uli AGP Bus Filter;C:\Windows\System32\drivers\ULIAGPKX.SYS [2009-7-13 64592]
S3 UmPass;Microsoft UMPass Driver;C:\Windows\System32\drivers\umpass.sys [2009-7-13 9728]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-12-13 54784]
S3 usbcir;eHome Infrared Receiver (USBCIR);C:\Windows\System32\drivers\usbcir.sys [2013-10-9 100864]
S3 usbohci;Microsoft USB Open Host Controller Miniport Driver;C:\Windows\System32\drivers\usbohci.sys [2013-10-11 25600]
S3 usbprint;Microsoft USB PRINTER Class;C:\Windows\System32\drivers\usbprint.sys [2009-7-13 25088]
S3 usbrndis6;USB RNDIS6 Adapter;C:\Windows\System32\drivers\usb80236.sys [2013-3-20 19968]
S3 usbscan;USB Scanner Driver;C:\Windows\System32\drivers\usbscan.sys [2013-10-9 42496]
S3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver;C:\Windows\System32\drivers\usbuhci.sys [2013-10-11 30720]
S3 VaultSvc;Credential Manager;C:\Windows\System32\lsass.exe [2012-1-26 31232]
S3 vds;Virtual Disk;C:\Windows\System32\vds.exe [2010-11-20 533504]
S3 veebeampol;Veebeam Loader Driver Service;C:\Windows\System32\drivers\veebeampol.sys [2010-11-29 14952]
S3 vga;vga;C:\Windows\System32\drivers\vgapnp.sys [2009-7-13 29184]
S3 vhdmp;vhdmp;C:\Windows\System32\drivers\vhdmp.sys [2010-11-20 215936]
S3 viaide;viaide;C:\Windows\System32\drivers\viaide.sys [2009-7-13 17488]
S3 vsmraid;vsmraid;C:\Windows\System32\drivers\vsmraid.sys [2009-6-10 161872]
S3 vwifibus;Virtual WiFi Bus Driver;C:\Windows\System32\drivers\vwifibus.sys [2009-7-13 24576]
S3 WacomPen;Wacom Serial Pen HID Driver;C:\Windows\System32\drivers\wacompen.sys [2009-7-13 27776]
S3 WANARP;Remote Access IP ARP Driver;C:\Windows\System32\drivers\wanarp.sys [2010-11-20 88576]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-7-21 1255736]
S3 wbengine;Block Level Backup Engine Service;C:\Windows\System32\wbengine.exe [2010-11-20 1504256]
S3 WbioSrvc;Windows Biometric Service;C:\Windows\System32\svchost.exe -k WbioSvcGroup [2009-7-13 27136]
S3 WcsPlugInService;Windows Color System;C:\Windows\System32\svchost.exe -k wcssvc [2009-7-13 27136]
S3 Wd;Wd;C:\Windows\System32\drivers\wd.sys [2009-7-13 21056]
S3 WdiSystemHost;Diagnostic System Host;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
S3 WebClient;WebClient;C:\Windows\System32\svchost.exe -k LocalService [2009-7-13 27136]
S3 Wecsvc;Windows Event Collector;C:\Windows\System32\svchost.exe -k NetworkService [2009-7-13 27136]
S3 wercplsupport;Problem Reports and Solutions Control Panel Support;C:\Windows\System32\svchost.exe -k netsvcs [2009-7-13 27136]
S3 WerSvc;Windows Error Reporting Service;C:\Windows\System32\svchost.exe -k WerSvcGroup [2009-7-13 27136]
S3 WIMMount;WIMMount;C:\Windows\System32\drivers\wimmount.sys [2009-7-13 22096]
S3 WinRM;Windows Remote Management (WS-Management);C:\Windows\System32\svchost.exe -k NetworkService [2009-7-13 27136]
S3 WinUSB;WinUSB Service;C:\Windows\System32\drivers\winusb.sys [2010-11-20 41984]
S3 WmiAcpi;Microsoft Windows Management Interface for ACPI;C:\Windows\System32\drivers\wmiacpi.sys [2009-7-13 14336]
S3 wmiApSrv;WMI Performance Adapter;C:\Windows\System32\wbem\WmiApSrv.exe [2009-7-13 203264]
S3 WPCSvc;Parental Controls;C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [2009-7-13 27136]
S3 WwanSvc;WWAN AutoConfig;C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork [2009-7-13 27136]
S4 AcrSch2Svc;Acronis Scheduler2 Service;C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe [2011-8-2 1164848]
S4 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2011-7-15 237056]
S4 Apple Mobile Device;Apple Mobile Device;C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2013-9-7 55624]
S4 Application Sendori;Application Sendori;C:\Program Files (x86)\Sendori\SendoriSvc.exe --> C:\Program Files (x86)\Sendori\SendoriSvc.exe [?]
S4 AxInstSV;ActiveX Installer (AxInstSV);C:\Windows\System32\svchost.exe -k AxInstSVGroup [2009-7-13 27136]
S4 BBSvc;BingBar Service;C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\BBSvc.EXE [2013-8-30 193696]
S4 BBUpdate;BBUpdate;C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\SeaPort.EXE [2013-8-30 240288]
S4 BdDesktopParental;Bitdefender Desktop Parental Control;C:\Program Files\Bitdefender\Bitdefender 2013\bdparentalservice.exe [2013-3-28 69392]
S4 Bonjour Service;Bonjour Service;C:\Program Files\Bonjour\mDNSResponder.exe [2011-8-30 462184]
S4 bthserv;Bluetooth Support Service;C:\Windows\System32\svchost.exe -k bthsvcs [2009-7-13 27136]
S4 cdfs;CD/DVD File System Reader;C:\Windows\System32\drivers\cdfs.sys [2009-7-13 92160]
S4 clr_optimization_v2.0.50727_32;Microsoft .NET Framework NGEN v2.0.50727_X86;C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2009-7-13 66384]
S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-7-13 89920]
S4 crcdisk;Crcdisk Filter Driver;C:\Windows\System32\drivers\crcdisk.sys [2009-7-13 24144]
S4 Mcx2Svc;Media Center Extender Service;C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation [2009-7-13 27136]
S4 NetMsmqActivator;Net.Msmq Listener Adapter;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-3-18 124240]
S4 NetPipeActivator;Net.Pipe Listener Adapter;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-3-18 124240]
S4 NetTcpActivator;Net.Tcp Listener Adapter;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-3-18 124240]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-3-18 124240]
S4 NSL;Norton Safe Web Lite;C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe [2011-9-18 130000]
S4 pcCMService;pcCMService;C:\Program Files (x86)\Common Files\Motive\pcCMService.exe [2013-7-27 369152]
S4 pcCMService64;pcCMService64;C:\Program Files\Common Files\Motive\pcCMService.exe [2013-7-27 460288]
S4 pdfcDispatcher;PDF Document Manager;C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2011-7-15 1127448]
S4 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [2013-8-14 39056]
S4 RemoteAccess;Routing and Remote Access;C:\Windows\System32\svchost.exe -k netsvcs [2009-7-13 27136]
S4 RoxioNow Service;RoxioNow Service;C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe [2010-11-26 399344]
S4 Service Sendori;Service Sendori;C:\Program Files (x86)\Sendori\Sendori.Service.exe --> C:\Program Files (x86)\Sendori\Sendori.Service.exe [?]
S4 SharedAccess;Internet Connection Sharing (ICS);C:\Windows\System32\svchost.exe -k netsvcs [2009-7-13 27136]
S4 Skype C2C Service;Skype C2C Service;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-8-14 3291008]
S4 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-9-5 171680]
S4 sndappv2;sndappv2;C:\Program Files (x86)\Sendori\sndappv2.exe --> C:\Program Files (x86)\Sendori\sndappv2.exe [?]
S4 udfs;udfs;C:\Windows\System32\drivers\udfs.sys [2010-11-20 328192]
.
=============== File Associations ===============
.
FileExt: .bat: batfile="%1" %*
FileExt: .cmd: cmdfile="%1" %*
FileExt: .com: comfile="%1" %*
FileExt: .exe: exefile="%1" %*
FileExt: .pif: piffile="%1" %*
FileExt: .scr: scrfile="%1" /S
FileExt: .reg: regfile=regedit.exe "%1"
FileExt: .txt: txtfile=C:\Windows\System32\NOTEPAD.EXE %1
FileExt: .chm: chm.file="C:\Windows\hh.exe" %1
FileExt: .ini: inifile=C:\Windows\System32\NOTEPAD.EXE %1
FileExt: .inf: inffile=C:\Windows\System32\NOTEPAD.EXE %1
ShellExec: AcroRD32.exe: Read="C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe" "%1"
ShellExec: ehshell.exe: open="C:\Windows\eHome\ehshell.exe" "%1"
ShellExec: iexplore.exe: open="C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1
ShellExec: iTunes.exe: open="C:\Program Files (x86)\iTunes\iTunes.exe" /open "%L"
ShellExec: iTunes.exe: play="C:\Program Files (x86)\iTunes\iTunes.exe" /play "%L"
ShellExec: MovieMaker.exe: Open="C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe" "%1"
ShellExec: mspaint.exe: edit="C:\Windows\System32\mspaint.exe" "%1"
ShellExec: notepad.exe: edit=C:\Windows\System32\NOTEPAD.EXE %1
ShellExec: notepad.exe: open=C:\Windows\System32\NOTEPAD.EXE %1
ShellExec: ois.exe: Edit=C:\PROGRA~2\MICROS~1\Office14\OIS.EXE /shellEdit "%1"
ShellExec: ois.exe: Open=C:\PROGRA~2\MICROS~1\Office14\OIS.EXE /shellOpen "%1"
ShellExec: ois.exe: Preview=C:\PROGRA~2\MICROS~1\Office14\OIS.EXE /shellPreview "%1"
ShellExec: photoviewer.dll: open=C:\Windows\System32\rundll32.exe "C:\Program Files (x86)\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen %1
ShellExec: photoviewer.dll: print=C:\Windows\System32\rundll32.exe "C:\Program Files (x86)\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen %1
ShellExec: RealPlay.exe: open="c:\program files (x86)\real\realplayer\realplay.exe" "%1"
ShellExec: Winword.exe: edit="C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /n "%1"
ShellExec: WLXPhotoViewer.dll: open="C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe" /LaunchPhotoViewer /v "%1"
ShellExec: wmplayer.exe: open="C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /Open "%L"
ShellExec: wmplayer.exe: play="C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /Play "%L"
ShellExec: wordpad.exe: open="C:\Program Files (x86)\Windows NT\Accessories\WORDPAD.EXE" "%1"
.
=============== Created Last 60 ================
.
2013-10-22 03:22:21 -------- d-----w- C:\FRST
2013-10-19 01:37:08 92272 ----a-w- C:\Program Files (x86)\Mozilla Firefox\nssdbm3.dll
2013-10-19 01:37:08 872352 ----a-w- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe
2013-10-19 01:37:08 770384 ----a-w- C:\Program Files (x86)\Mozilla Firefox\msvcr100.dll
2013-10-19 01:37:08 64112 ----a-w- C:\Program Files (x86)\Mozilla Firefox\libEGL.dll
2013-10-19 01:37:08 549488 ----a-w- C:\Program Files (x86)\Mozilla Firefox\libGLESv2.dll
2013-10-19 01:37:08 4806016 ----a-w- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
2013-10-19 01:37:08 421200 ----a-w- C:\Program Files (x86)\Mozilla Firefox\msvcp100.dll
2013-10-19 01:37:08 393328 ----a-w- C:\Program Files (x86)\Mozilla Firefox\nssckbi.dll
2013-10-19 01:37:08 3459696 ----a-w- C:\Program Files (x86)\Mozilla Firefox\gkmedias.dll
2013-10-19 01:37:08 3365488 ----a-w- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2013-10-19 01:37:08 302192 ----a-w- C:\Program Files (x86)\Mozilla Firefox\freebl3.dll
2013-10-19 01:37:08 28272 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugin-hang-ui.exe
2013-10-19 01:37:08 275568 ----a-w- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
2013-10-19 01:37:08 274032 ----a-w- C:\Program Files (x86)\Mozilla Firefox\updater.exe
2013-10-19 01:37:08 22028912 ----a-w- C:\Program Files (x86)\Mozilla Firefox\xul.dll
2013-10-19 01:37:08 2106216 ----a-w- C:\Program Files (x86)\Mozilla Firefox\D3DCompiler_43.dll
2013-10-19 01:37:08 208760 ----a-w- C:\Program Files (x86)\Mozilla Firefox\Plugins\nppdf32.dll
2013-10-19 01:37:08 194552 ----a-w- C:\Program Files (x86)\Mozilla Firefox\maintenanceservice_installer.exe
2013-10-19 01:37:08 18544 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
2013-10-19 01:37:08 1775728 ----a-w- C:\Program Files (x86)\Mozilla Firefox\nss3.dll
2013-10-19 01:37:08 170960 ----a-w- C:\Program Files (x86)\Mozilla Firefox\webapp-uninstaller.exe
2013-10-19 01:37:08 17008 ----a-w- C:\Program Files (x86)\Mozilla Firefox\mozalloc.dll
2013-10-19 01:37:08 163256 ----a-w- C:\Program Files (x86)\Mozilla Firefox\Plugins\np-mswmp.dll
2013-10-19 01:37:08 159744 ----a-w- C:\Program Files (x86)\Mozilla Firefox\Plugins\npqtplugin5.dll
2013-10-19 01:37:08 159744 ----a-w- C:\Program Files (x86)\Mozilla Firefox\Plugins\npqtplugin4.dll
2013-10-19 01:37:08 159744 ----a-w- C:\Program Files (x86)\Mozilla Firefox\Plugins\npqtplugin3.dll
2013-10-19 01:37:08 159744 ----a-w- C:\Program Files (x86)\Mozilla Firefox\Plugins\npqtplugin2.dll
2013-10-19 01:37:08 159744 ----a-w- C:\Program Files (x86)\Mozilla Firefox\Plugins\npqtplugin.dll
2013-10-19 01:37:08 153736 ----a-w- C:\Program Files (x86)\Mozilla Firefox\Plugins\nppl3260.dll
2013-10-19 01:37:08 153712 ----a-w- C:\Program Files (x86)\Mozilla Firefox\softokn3.dll
2013-10-19 01:37:08 131696 ----a-w- C:\Program Files (x86)\Mozilla Firefox\mozglue.dll
2013-10-19 01:37:08 124504 ----a-w- C:\Program Files (x86)\Mozilla Firefox\Plugins\nprpplugin.dll
2013-10-19 01:37:08 119808 ----a-w- C:\Program Files (x86)\Mozilla Firefox\components\GoogleDesktopMozilla.dll
2013-10-19 01:37:08 119408 ----a-w- C:\Program Files (x86)\Mozilla Firefox\maintenanceservice.exe
2013-10-19 01:37:08 117360 ----a-w- C:\Program Files (x86)\Mozilla Firefox\crashreporter.exe
2013-10-19 01:37:08 108144 ----a-w- C:\Program Files (x86)\Mozilla Firefox\webapprt-stub.exe
2013-10-19 01:37:07 75376 ----a-w- C:\Program Files (x86)\Mozilla Firefox\breakpadinjector.dll
2013-10-19 01:37:07 4806016 ----a-w- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
2013-10-19 01:37:07 272496 ----a-w- C:\Program Files (x86)\Mozilla Firefox\browser\components\browsercomps.dll
2013-10-19 01:37:07 248192 ----a-w- C:\Program Files (x86)\Mozilla Firefox\browser\plugins\npMozCouponPrinter.dll
2013-10-19 01:37:07 20080 ----a-w- C:\Program Files (x86)\Mozilla Firefox\AccessibleMarshal.dll
2013-10-19 01:37:07 -------- d-----w- C:\Program Files (x86)\Mozilla Firefox
2013-10-19 01:18:12 10280728 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{74CFAABD-1D40-409D-B9EF-6F83995910CD}\mpengine.dll
2013-10-16 22:22:48 -------- d-----w- C:\Program Files (x86)\Common Files\Java
2013-10-16 22:22:41 264616 ----a-w- C:\Windows\SysWow64\javaws.exe
2013-10-16 22:22:37 96168 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-10-16 22:22:37 175016 ----a-w- C:\Windows\SysWow64\javaw.exe
2013-10-16 22:22:37 174504 ----a-w- C:\Windows\SysWow64\java.exe
2013-10-16 22:19:20 -------- d-----w- C:\ProgramData\Oracle
2013-10-16 22:19:03 312744 ----a-w- C:\Windows\System32\javaws.exe
2013-10-16 22:19:00 189352 ----a-w- C:\Windows\System32\javaw.exe
2013-10-16 22:19:00 189352 ----a-w- C:\Windows\System32\java.exe
2013-10-16 22:19:00 108968 ----a-w- C:\Windows\System32\WindowsAccessBridge-64.dll
2013-10-16 22:18:50 -------- d-----w- C:\Program Files\Java
2013-10-14 00:33:29 31264 ----a-w- C:\Windows\System32\drivers\gfiutil.sys
2013-10-14 00:33:28 41032 ----a-w- C:\Windows\System32\drivers\gfiark.sys
2013-10-11 23:14:08 99840 ----a-w- C:\Windows\System32\drivers\usbccgp.sys
2013-10-11 23:14:08 7808 ----a-w- C:\Windows\System32\drivers\usbd.sys
2013-10-11 23:14:08 52736 ----a-w- C:\Windows\System32\drivers\usbehci.sys
2013-10-11 23:14:08 343040 ----a-w- C:\Windows\System32\drivers\usbhub.sys
2013-10-11 23:14:08 325120 ----a-w- C:\Windows\System32\drivers\usbport.sys
2013-10-11 23:14:08 30720 ----a-w- C:\Windows\System32\drivers\usbuhci.sys
2013-10-11 23:14:08 25600 ----a-w- C:\Windows\System32\drivers\usbohci.sys
2013-10-10 00:51:09 96768 ----a-w- C:\Windows\System32\mshtmled.dll
2013-10-10 00:51:09 768512 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll
2013-10-10 00:51:09 73216 ----a-w- C:\Windows\SysWow64\mshtmled.dll
2013-10-10 00:51:09 420864 ----a-w- C:\Windows\SysWow64\vbscript.dll
2013-10-10 00:51:09 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2013-10-10 00:51:09 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2013-10-10 00:51:08 996352 ----a-w- C:\Program Files\Common Files\Microsoft Shared\VGX\VGX.dll
2013-10-10 00:51:08 757400 ----a-w- C:\Program Files (x86)\Internet Explorer\iexplore.exe
2013-10-10 00:51:08 305152 ----a-w- C:\Program Files\Internet Explorer\IEShims.dll
2013-10-10 00:51:08 248320 ----a-w- C:\Windows\System32\ieui.dll
2013-10-10 00:51:08 237056 ----a-w- C:\Windows\System32\url.dll
2013-10-10 00:51:08 231936 ----a-w- C:\Windows\SysWow64\url.dll
2013-10-10 00:51:08 194560 ----a-w- C:\Program Files (x86)\Internet Explorer\IEShims.dll
2013-10-10 00:51:08 182936 ----a-w- C:\Program Files\Internet Explorer\sqmapi.dll
2013-10-10 00:51:08 176640 ----a-w- C:\Windows\SysWow64\ieui.dll
2013-10-10 00:51:08 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2013-10-10 00:51:08 149656 ----a-w- C:\Program Files (x86)\Internet Explorer\sqmapi.dll
2013-10-10 00:51:08 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2013-10-10 00:51:08 1392128 ----a-w- C:\Windows\System32\wininet.dll
2013-10-10 00:51:08 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2013-10-10 00:51:07 85504 ----a-w- C:\Windows\System32\jsproxy.dll
2013-10-10 00:51:07 763544 ----a-w- C:\Program Files\Internet Explorer\iexplore.exe
2013-10-10 00:51:07 729088 ----a-w- C:\Windows\System32\msfeeds.dll
2013-10-10 00:51:07 607744 ----a-w- C:\Windows\SysWow64\msfeeds.dll
2013-10-10 00:51:07 548864 ----a-w- C:\Program Files\Internet Explorer\ieproxy.dll
2013-10-10 00:51:07 2312704 ----a-w- C:\Windows\System32\jscript9.dll
2013-10-10 00:51:07 2147840 ----a-w- C:\Windows\System32\iertutil.dll
2013-10-10 00:51:07 194560 ----a-w- C:\Program Files (x86)\Internet Explorer\ieproxy.dll
2013-10-10 00:51:07 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2013-10-10 00:51:07 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2013-10-10 00:51:07 141312 ----a-w- C:\Program Files\Internet Explorer\jsdebuggeride.dll
2013-10-10 00:51:07 1346560 ----a-w- C:\Windows\System32\urlmon.dll
2013-10-10 00:51:07 1104896 ----a-w- C:\Windows\SysWow64\urlmon.dll
2013-10-10 00:51:06 887808 ----a-w- C:\Program Files\Internet Explorer\iedvtool.dll
2013-10-10 00:51:06 816640 ----a-w- C:\Windows\System32\jscript.dll
2013-10-10 00:51:06 717824 ----a-w- C:\Windows\SysWow64\jscript.dll
2013-10-10 00:51:06 678912 ----a-w- C:\Program Files (x86)\Internet Explorer\iedvtool.dll
2013-10-10 00:51:06 65024 ----a-w- C:\Windows\SysWow64\jsproxy.dll
2013-10-10 00:51:06 599040 ----a-w- C:\Windows\System32\vbscript.dll
2013-10-10 00:51:06 499200 ----a-w- C:\Program Files\Internet Explorer\jsdbgui.dll
2013-10-10 00:51:06 387584 ----a-w- C:\Program Files (x86)\Internet Explorer\jsdbgui.dll
2013-10-10 00:51:06 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll
2013-10-10 00:51:06 1796096 ----a-w- C:\Windows\SysWow64\iertutil.dll
2013-10-10 00:51:06 104448 ----a-w- C:\Program Files (x86)\Internet Explorer\jsdebuggeride.dll
2013-10-10 00:51:05 12336128 ----a-w- C:\Windows\SysWow64\mshtml.dll
2013-10-10 00:51:04 17833984 ----a-w- C:\Windows\System32\mshtml.dll
2013-10-10 00:51:03 9739264 ----a-w- C:\Windows\SysWow64\ieframe.dll
2013-10-10 00:51:03 10926080 ----a-w- C:\Windows\System32\ieframe.dll
2013-10-10 00:36:59 81920 ----a-w- C:\Windows\SysWow64\davclnt.dll
2013-10-10 00:36:59 259584 ----a-w- C:\Windows\System32\WebClnt.dll
2013-10-10 00:36:59 205824 ----a-w- C:\Windows\SysWow64\WebClnt.dll
2013-10-10 00:36:59 140800 ----a-w- C:\Windows\System32\drivers\mrxdav.sys
2013-10-10 00:36:59 102400 ----a-w- C:\Windows\System32\davclnt.dll
2013-10-10 00:36:58 878080 ----a-w- C:\Windows\System32\advapi32.dll
2013-10-10 00:36:58 5549504 ----a-w- C:\Windows\System32\ntoskrnl.exe
2013-10-10 00:36:58 3969472 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2013-10-10 00:36:57 859648 ----a-w- C:\Windows\System32\tdh.dll
2013-10-10 00:36:57 640512 ----a-w- C:\Windows\SysWow64\advapi32.dll
2013-10-10 00:36:57 619520 ----a-w- C:\Windows\SysWow64\tdh.dll
2013-10-10 00:36:57 3914176 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2013-10-10 00:36:57 243712 ----a-w- C:\Windows\System32\wow64.dll
2013-10-10 00:36:57 1732032 ----a-w- C:\Windows\System32\ntdll.dll
2013-10-10 00:36:57 1292192 ----a-w- C:\Windows\SysWow64\ntdll.dll
2013-10-10 00:36:56 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2013-10-10 00:36:56 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2013-10-10 00:36:56 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2013-10-10 00:36:56 2048 ----a-w- C:\Windows\SysWow64\user.exe
2013-10-10 00:36:56 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2013-10-10 00:36:53 785624 ----a-w- C:\Windows\System32\drivers\Wdf01000.sys
2013-10-10 00:36:51 497152 ----a-w- C:\Windows\System32\drivers\afd.sys
2013-10-10 00:36:51 327168 ----a-w- C:\Windows\System32\mswsock.dll
2013-10-10 00:36:51 231424 ----a-w- C:\Windows\SysWow64\mswsock.dll
2013-10-10 00:36:51 1903552 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2013-10-10 00:36:49 76800 ----a-w- C:\Windows\System32\drivers\hidclass.sys
2013-10-10 00:36:49 42496 ----a-w- C:\Windows\System32\drivers\usbscan.sys
2013-10-10 00:36:49 32896 ----a-w- C:\Windows\System32\drivers\hidparse.sys
2013-10-10 00:36:45 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
2013-10-10 00:36:45 46080 ----a-w- C:\Windows\System32\atmlib.dll
2013-10-10 00:36:45 41472 ----a-w- C:\Windows\System32\lpk.dll
2013-10-10 00:36:45 368128 ----a-w- C:\Windows\System32\atmfd.dll
2013-10-10 00:36:45 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2013-10-10 00:36:45 295424 ----a-w- C:\Windows\SysWow64\atmfd.dll
2013-10-10 00:36:45 25600 ----a-w- C:\Windows\SysWow64\lpk.dll
2013-10-10 00:36:45 14336 ----a-w- C:\Windows\System32\dciman32.dll
2013-10-10 00:36:45 10240 ----a-w- C:\Windows\SysWow64\dciman32.dll
2013-10-10 00:36:45 100864 ----a-w- C:\Windows\System32\fontsub.dll
2013-10-10 00:36:42 3155968 ----a-w- C:\Windows\System32\win32k.sys
2013-10-10 00:36:34 100864 ----a-w- C:\Windows\System32\drivers\usbcir.sys
2013-10-10 00:36:33 633856 ----a-w- C:\Windows\System32\comctl32.dll
2013-10-10 00:36:33 530432 ----a-w- C:\Windows\SysWow64\comctl32.dll
2013-10-10 00:36:19 461312 ----a-w- C:\Windows\System32\scavengeui.dll
2013-10-10 00:36:11 124112 ----a-w- C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
2013-10-10 00:36:11 102608 ----a-w- C:\Windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2013-10-10 00:33:56 983488 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys
2013-10-04 22:37:11 -------- d-----w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-10-04 22:37:11 -------- d-----w- C:\Program Files\iTunes
2013-10-04 01:15:47 150256 ----a-w- C:\Windows\System32\drivers\gzflt.sys
2013-09-26 18:00:39 208760 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\nppdf32.dll
2013-09-18 23:09:24 17226632 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe
2013-09-14 00:46:30 155584 ----a-w- C:\Windows\System32\drivers\ataport.sys
2013-09-14 00:46:26 424448 ----a-w- C:\Windows\System32\KernelBase.dll
2013-09-14 00:46:25 6144 ---ha-w- C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
2013-09-14 00:46:25 5120 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
2013-09-14 00:46:25 5120 ---ha-w- C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
2013-09-14 00:46:25 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-14 00:46:25 4608 ---ha-w- C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-14 00:46:25 4608 ---ha-w- C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-14 00:46:25 43520 ----a-w- C:\Windows\System32\csrsrv.dll
2013-09-14 00:46:25 4096 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-14 00:46:25 4096 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
2013-09-14 00:46:25 4096 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
2013-09-14 00:46:25 4096 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-14 00:46:25 4096 ---ha-w- C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-14 00:46:25 4096 ---ha-w- C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
2013-09-14 00:46:25 4096 ---ha-w- C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-14 00:46:25 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-14 00:46:25 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-14 00:46:25 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
2013-09-14 00:46:25 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-14 00:46:25 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-14 00:46:25 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
2013-09-14 00:46:25 3584 ---ha-w- C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-14 00:46:25 3584 ---ha-w- C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-14 00:46:25 3584 ---ha-w- C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-14 00:46:25 3584 ---ha-w- C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
2013-09-14 00:46:25 3584 ---ha-w- C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
2013-09-14 00:46:25 3584 ---ha-w- C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-14 00:46:25 338432 ----a-w- C:\Windows\System32\conhost.exe
2013-09-14 00:46:25 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
2013-09-14 00:46:25 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-14 00:46:25 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
2013-09-14 00:46:25 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
2013-09-14 00:46:25 3072 ---ha-w- C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
2013-09-14 00:46:25 3072 ---ha-w- C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
2013-09-14 00:46:25 3072 ---ha-w- C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
2013-09-14 00:46:25 3072 ---ha-w- C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
2013-09-14 00:46:25 3072 ---ha-w- C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
2013-09-14 00:46:25 3072 ---ha-w- C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-14 00:46:25 274944 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2013-09-14 00:46:25 215040 ----a-w- C:\Windows\System32\winsrv.dll
2013-09-14 00:46:25 1161216 ----a-w- C:\Windows\System32\kernel32.dll
2013-09-14 00:46:25 112640 ----a-w- C:\Windows\System32\smss.exe
2013-09-14 00:46:25 1114112 ----a-w- C:\Windows\SysWow64\kernel32.dll
2013-09-14 00:46:24 6656 ----a-w- C:\Windows\SysWow64\apisetschema.dll
2013-09-14 00:46:24 6656 ----a-w- C:\Windows\System32\apisetschema.dll
2013-09-14 00:46:24 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2013-09-14 00:46:24 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-14 00:46:24 4096 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
2013-09-14 00:46:24 4096 ---ha-w- C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
2013-09-14 00:46:24 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2013-09-14 00:46:24 3584 ---ha-w- C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
2013-09-14 00:46:24 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2013-09-14 00:46:24 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
2013-09-14 00:46:24 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
2013-09-14 00:46:24 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-14 00:46:24 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
2013-09-14 00:46:24 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
2013-09-14 00:46:24 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
2013-09-14 00:46:24 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
2013-09-14 00:46:24 3072 ---ha-w- C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
2013-09-14 00:46:24 3072 ---ha-w- C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
2013-09-14 00:46:24 3072 ---ha-w- C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-14 00:46:24 3072 ---ha-w- C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
2013-09-14 00:46:24 3072 ---ha-w- C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
2013-09-14 00:46:24 3072 ---ha-w- C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
2013-09-14 00:46:24 3072 ---ha-w- C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
2013-09-14 00:46:19 14172672 ----a-w- C:\Windows\System32\shell32.dll
2013-09-14 00:46:18 197120 ----a-w- C:\Windows\System32\shdocvw.dll
2013-09-14 00:46:18 180224 ----a-w- C:\Windows\SysWow64\shdocvw.dll
2013-09-14 00:46:18 12872704 ----a-w- C:\Windows\SysWow64\shell32.dll
2013-09-12 18:14:42 18612928 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSO.DLL
2013-08-26 09:13:02 354656 ----a-w- C:\Windows\SysWow64\DivXControlPanelApplet.cpl
2013-08-24 23:31:12 53248 ----a-r- C:\Users\Brain\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2013-08-24 23:18:21 -------- d-----w- C:\Users\Brain\AppData\Roaming\VS Revo Group
.
==================== Find6M ====================
.
2013-10-10 00:44:19 80541720 ----a-w- C:\Windows\System32\MRT.exe
2013-10-09 23:09:22 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-10-09 23:09:22 692616 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-10-04 01:15:36 389240 ----a-w- C:\Windows\System32\drivers\trufos.sys
2013-09-03 19:35:10 278800 ------w- C:\Windows\System32\MpSigStub.exe
2013-08-29 01:48:15 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2013-08-23 01:03:14 201872 ----a-w- C:\Windows\SysWow64\rmoc3260.dll
2013-08-23 01:03:08 6656 ----a-w- C:\Windows\SysWow64\pndx5016.dll
2013-08-23 01:03:08 5632 ----a-w- C:\Windows\SysWow64\pndx5032.dll
2013-08-23 01:03:07 272896 ----a-w- C:\Windows\SysWow64\pncrt.dll
2013-08-23 01:03:03 499712 ----a-w- C:\Windows\SysWow64\msvcp71.dll
2013-08-23 01:03:03 348160 ----a-w- C:\Windows\SysWow64\msvcr71.dll
2013-08-07 22:54:02 94208 ----a-w- C:\Windows\SysWow64\dpl100.dll
2013-08-03 00:48:37 652160 ----a-w- C:\Windows\couponprinter_x64.ocx
2013-08-03 00:48:28 440704 ----a-w- C:\Windows\CouponPrinter.ocx
2013-08-02 01:06:10 601360 ----a-w- C:\Windows\System32\drivers\avckf.sys
2013-08-02 01:06:07 82824 ----a-w- C:\Windows\System32\drivers\bdsandbox.sys
2013-08-02 01:06:03 727592 ----a-w- C:\Windows\System32\drivers\avc3.sys
2013-07-25 09:25:54 1888768 ----a-w- C:\Windows\System32\WMVDECOD.DLL
2013-07-25 08:57:27 1620992 ----a-w- C:\Windows\SysWow64\WMVDECOD.DLL
2013-07-19 01:58:42 2048 ----a-w- C:\Windows\System32\tzres.dll
2013-07-19 01:41:01 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2013-07-09 05:52:52 224256 ----a-w- C:\Windows\System32\wintrust.dll
2013-07-09 05:51:16 1217024 ----a-w- C:\Windows\System32\rpcrt4.dll
2013-07-09 05:46:20 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
2013-07-09 05:46:20 1472512 ----a-w- C:\Windows\System32\crypt32.dll
2013-07-09 05:46:20 139776 ----a-w- C:\Windows\System32\cryptnet.dll
2013-07-09 04:52:33 663552 ----a-w- C:\Windows\SysWow64\rpcrt4.dll
2013-07-09 04:52:10 175104 ----a-w- C:\Windows\SysWow64\wintrust.dll
2013-07-09 04:46:31 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2013-07-09 04:46:31 1166848 ----a-w- C:\Windows\SysWow64\crypt32.dll
2013-07-09 04:46:31 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
2013-06-15 04:32:16 39936 ----a-w- C:\Windows\System32\drivers\tssecsrv.sys
2013-06-04 06:00:13 624128 ----a-w- C:\Windows\System32\qedit.dll
2013-06-04 04:53:07 509440 ----a-w- C:\Windows\SysWow64\qedit.dll
2013-05-13 20:36:12 828872 ----a-w- C:\Windows\System32\msvcr110.dll
2013-05-13 20:36:12 661448 ----a-w- C:\Windows\System32\msvcp110.dll
2013-05-13 20:36:12 354264 ----a-w- C:\Windows\System32\vccorlib110.dll
2013-05-13 20:36:12 251864 ----a-w- C:\Windows\SysWow64\vccorlib110.dll
2013-05-13 20:36:10 862664 ----a-w- C:\Windows\SysWow64\msvcr110.dll
2013-05-13 20:36:10 534480 ----a-w- C:\Windows\SysWow64\msvcp110.dll
2013-05-13 20:36:06 50864 ----a-w- C:\Windows\System32\drivers\point64.sys
2013-05-13 05:50:40 52224 ----a-w- C:\Windows\System32\certenc.dll
2013-05-13 03:43:55 1192448 ----a-w- C:\Windows\System32\certutil.exe
2013-05-13 03:08:10 903168 ----a-w- C:\Windows\SysWow64\certutil.exe
2013-05-13 03:08:06 43008 ----a-w- C:\Windows\SysWow64\certenc.dll
2013-05-10 05:49:27 30720 ----a-w- C:\Windows\System32\cryptdlg.dll
2013-05-10 03:20:54 24576 ----a-w- C:\Windows\SysWow64\cryptdlg.dll
2013-05-02 15:22:04 2274480 ----a-w- C:\Windows\System32\coin94.dll
2013-05-01 08:59:12 94208 ----a-w- C:\Windows\SysWow64\QuickTimeVR.qtx
2013-05-01 08:59:12 69632 ----a-w- C:\Windows\SysWow64\QuickTime.qts
2013-04-26 05:51:36 751104 ----a-w- C:\Windows\System32\win32spl.dll
2013-04-26 04:55:21 492544 ----a-w- C:\Windows\SysWow64\win32spl.dll
2013-04-25 23:30:32 1505280 ----a-w- C:\Windows\SysWow64\d3d11.dll
.
============= FINISH: 22:38:02.39 ===============


.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 7/21/2011 8:43:56 PM
System Uptime: 10/21/2013 6:47:25 PM (4 hours ago)
.
Motherboard: PEGATRON CORPORATION | | 2AC2
Processor: Intel® Core™ i5-2400S CPU @ 2.50GHz | CPU 1 | 1575/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 849 GiB total, 694.5 GiB free.
D: is FIXED (NTFS) - 11 GiB total, 1.341 GiB free.
E: is CDROM ()
G: is Removable
H: is Removable
I: is Removable
J: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP617: 10/16/2013 5:17:26 PM - Installed Java 7 Update 45 (64-bit)
RP618: 10/16/2013 5:21:31 PM - Installed Java 7 Update 45
RP620: 10/21/2013 7:27:18 AM - Revo Uninstaller Pro's restore point - Google Chrome
.
==== Installed Programs ======================
.
Acronis True Image Personal
Adobe AIR
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader XI (11.0.05)
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ATI Stream SDK v2 Developer
Bing Bar
Bing Desktop
Bitdefender Total Security 2013
Blio
Bonjour
ccc-utility64
CCleaner
CheckIt Diagnostics 8
Coupon Printer for Windows
Crawler Toolbar
Cubby
D3DX10
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
DetectorTools
Diskeeper 12 Professional
DivX Setup
Do Not Track Plus Add-on (64bit) 2.2.2.1022
Do Not Track Plus Add-on 1.0.5289.0208
Dogpile Toolbar
eReg
erLT
Facebook Messenger 2.1.4814.0
FileHippo.com Update Checker
Google Desktop
Google Drive
Google Talk Plugin
Google Update Helper
Hewlett-Packard ACLM.NET v1.2.1.1
HP Auto
HP Client Services
HP Customer Experience Enhancements
HP LinkUp
HP MediaSmart/TouchSmart Netflix
HP MovieStore
HP Odometer
HP Officejet 6500 E710a-f Basic Device Software
HP Officejet 6500 E710a-f Help
HP Officejet 6500 E710a-f Product Improvement Study
HP Photo Creations
HP Power Assistant
HP Product Detection
HP Setup
HP Setup Manager
HP Support Information
HP Update
HP Vision Hardware Diagnostics
HPDiagnosticAlert
Hulu Desktop
I.R.I.S. OCR
iCloud
Intel® Management Engine Components
iTunes
Java 7 Update 45
Java 7 Update 45 (64-bit)
Java Auto Updater
Junk Mail filter update
Logitech Harmony Remote Software 7
Malwarebytes Anti-Malware version 1.75.0.1300
Marketsplash Print Software
Marketsplash Shortcuts
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Application Error Reporting
Microsoft Mouse and Keyboard Center
Microsoft Office 2010
Microsoft Office Access MUI (English) 2010
Microsoft Office Access Setup Metadata MUI (English) 2010
Microsoft Office Excel MUI (English) 2010
Microsoft Office Home and Business 2010
Microsoft Office Office 64-bit Components 2010
Microsoft Office OneNote MUI (English) 2010
Microsoft Office Outlook Connector
Microsoft Office Outlook MUI (English) 2010
Microsoft Office PowerPoint MUI (English) 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proofing (English) 2010
Microsoft Office Publisher MUI (English) 2010
Microsoft Office Shared 64-bit MUI (English) 2010
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
Microsoft Office Shared MUI (English) 2010
Microsoft Office Shared Setup Metadata MUI (English) 2010
Microsoft Office Single Image 2010
Microsoft Office Word MUI (English) 2010
Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bit
Microsoft Silverlight
Microsoft SkyDrive
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable (x64)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft WSE 3.0 Runtime
Movie Maker
Mozilla Firefox 25.0 (x86 en-US)
Mozilla Maintenance Service
MSVCRT
MSVCRT_amd64
MSVCRT110
MSVCRT110_amd64
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
PDF Complete Special Edition
Photo Common
Photo Gallery
PlayReady PC Runtime amd64
PlayReady PC Runtime x86
QuickTime
RealDownloader
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealNetworks - Microsoft Visual C++ 2010 Runtime
RealPlayer
RealUpgrade 1.1
Revo Uninstaller Pro 3.0.7
RoxioNow Player
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2858302v2)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Microsoft .NET Framework 4 Extended (KB2736428)
Security Update for Microsoft .NET Framework 4 Extended (KB2742595)
Security Update for Microsoft .NET Framework 4 Extended (KB2858302v2)
Security Update for Microsoft Excel 2010 (KB2826033) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2687423) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2826023) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2826035) 32-Bit Edition
Security Update for Microsoft Outlook 2010 (KB2794707) 32-Bit Edition
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition
Skype Click to Call
Skype™ 6.9
Smile Desktop version 1.0.4.259
SpywareBlaster 5.0
SUPERAntiSpyware
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2836939)
Update for Microsoft .NET Framework 4 Extended (KB2836939v3)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition
Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition
Update for Microsoft Office 2010 (KB2494150)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition
Update for Microsoft Office 2010 (KB2826026) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition
Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition
Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition
Update for Microsoft Word 2010 (KB2827323) 32-Bit Edition
uRex DVD Ripper Platinum
VC80CRTRedist - 8.0.50727.6195
Windows Driver Package - ESCORT Inc. (WinUSB) MyDeviceClass (05/21/2013 )
Windows Driver Package - ESCORT, Inc. (usbser) Ports (01/15/2013 1.0.0.0)
Windows Driver Package - ESCORT, Inc. (usbser) Ports (04/24/2013 1.0.0.0)
Windows Driver Package - Escort, Inc. (usbser) Ports (07/28/2010 1.0.0.0)
Windows Driver Package - Escort, Inc. (usbser) Ports (11/09/2012 1.0.0.0)
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Mail
Windows Live Messenger
Windows Live MIME IFilter
Windows Live Photo Common
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Windows Media Player 64-bit Plug-in Fix
Windows Media Player Firefox Plugin
Windows Media Player Plus! 2.1
WinX Blu-ray Decrypter 3.0.0
YoWindow
Zinio Reader 4
.
==== Event Viewer Messages From Past Week ========
.
10/21/2013 6:48:00 PM, Error: Microsoft-Windows-Time-Service [4] - The time provider 'VMICTimeProvider' failed to start due to the following error: The specified module could not be found. (0x8007007E)
10/21/2013 6:16:34 PM, Error: Service Control Manager [7000] - The Diskeeper service failed to start due to the following error: The pipe has been ended.
10/20/2013 8:52:24 PM, Error: Service Control Manager [7034] - The Bitdefender Virus Shield service terminated unexpectedly. It has done this 1 time(s).
10/15/2013 5:32:16 PM, Error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume OS.
.
==== End Of File ===========================


Attached Files


  • 0

#5
Braind

Braind

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 246 posts
I am going to call it a night now. I will be back here, after work, around 5:00 PM CDT. Thanks for all your help on this.
  • 0

#6
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,012 posts
  • MVP
Looks like you have some hard drive damage:

10/15/2013 5:32:16 PM, Error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume OS.


1. Double-click My Computer, and then right-click the hard disk that you want to check. C:
2. Click Properties, and then click Tools.
3. Under Error-checking, click Check Now. A dialog box that shows the Check disk options is displayed,
4. Check both boxes and then click Start.
You will receive the following message:
The disk check could not be performed because the disk check utility needs exclusive access to some Windows files on the disk. These files can be accessed by restarting Windows. Do you want to schedule the disk check to occur the next time you restart the computer?
Click Yes to schedule the disk check, but don't restart yet.

Right click on (My) Computer and select Manage (Continue) Then the Event Viewer. Next select Windows Logs. Right click on System and Clear Log, Clear. Repeat for Application. Reboot. The disk check will run and will probably take an hour or more to finish.


Start, All Programs, Accessories then right click on Command Prompt and Run as Administrator. Then type (with an Enter after each line).

sfc /scannow

(SPACE after sfc. This will check your critical system files. Does this finish without complaint? IF it says it couldn't fix everything then:

Copy the next two lines:

findstr /c:"[SR]" \windows\logs\cbs\cbs.log > \windows\logs\cbs\junk.txt
notepad \windows\logs\cbs\junk.txt

Start, All Programs, Accessories, right click on Command Prompt and Run as Administrator, Continue. Right click and Paste or Edit then Paste and the copied line should appear.
Hit Enter if notepad does not open. Copy and paste the text from notepad into a reply. Close notepad. Close the Command Window. Go on to the next step.)

(In any case continue with the next step)

1. Please download the Event Viewer Tool by Vino Rosso
http://images.malwar...om/vino/VEW.exe
and save it to your Desktop:
2. Right-click VEW.exe and Run AS Administrator
3. Under 'Select log to query', select:

* System
4. Under 'Select type to list', select:
* Error
* Warning


Then use the 'Number of events' as follows:


1. Click the radio button for 'Number of events'
Type 20 in the 1 to 20 box
Then click the Run button.
Notepad will open with the output log.


Please post the Output log in your next reply then repeat but select Application.

Uninstall this junk:


Bing Bar
Crawler Toolbar
Dogpile Toolbar
Skype Click to Call



Something has uninstalled Sendori and done a poor job of removing it. This messed up the winsock stack so may be the cause of your Firefox problem.

Winsock: Catalog9 01 C:\Windows\system32\Sendori.dll File Not found ()
Winsock: Catalog9 02 C:\Windows\system32\Sendori.dll File Not found ()
Winsock: Catalog9 03 C:\Windows\system32\Sendori.dll File Not found ()
Winsock: Catalog9 04 C:\Windows\system32\Sendori.dll File Not found ()
Winsock: Catalog9 15 C:\Windows\system32\Sendori.dll File Not found ()


I think we can fix it with FRST.
Download the attached fixlist.txt to the same location as FRST
Run FRST and press Fix
A fix log will be generated please post that.

There is also an error with the time service but the disk check and sfc may fix it so I'll wait until after you run those to see if we need to figure out what is wrong there.

Error: (10/21/2013 06:19:09 PM) (Source: Microsoft-Windows-Time-Service) (User: NT AUTHORITY)
Description: The time provider 'VMICTimeProvider' failed to start due to the following error: The specified module could not be found. (0x8007007E)


  • 0

#7
Braind

Braind

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 246 posts
I did as instucted and did not run into any problems that I could see.

Here are the logs you requested:

Vino's Event Viewer v01c run on Windows 2008 in English

Report run at 22/10/2013 4:50:27 PM



Note: All dates below are in the format dd/mm/yyyy



~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

'System' Log - Critical Type

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

'System' Log - Error Type

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Log: 'System' Date/Time: 22/10/2013 9:31:40 PM

Type: Error Category: 0

Event: 4 Source: Microsoft-Windows-Time-Service

The time provider 'VMICTimeProvider' failed to start due to the following error: The specified module could not be found. (0x8007007E)



~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

'System' Log - Warning Type

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Log: 'System' Date/Time: 22/10/2013 9:31:42 PM

Type: Warning Category: 212

Event: 219 Source: Microsoft-Windows-Kernel-PnP

The driver \Driver\WUDFRd failed to load for the device WpdBusEnumRoot\UMB\2&37c186b&1&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_GENERIC-&PROD_COMPACT_FLASH&REV_1.01#058F63626476&1#.



Log: 'System' Date/Time: 22/10/2013 9:30:48 PM

Type: Warning Category: 0

Event: 4001 Source: Microsoft-Windows-WLAN-AutoConfig

WLAN AutoConfig service has successfully stopped.





Vino's Event Viewer v01c run on Windows 2008 in English

Report run at 22/10/2013 4:52:40 PM



Note: All dates below are in the format dd/mm/yyyy



~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

'Application' Log - Critical Type

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

'Application' Log - Error Type

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Log: 'Application' Date/Time: 22/10/2013 9:33:04 PM

Type: Error Category: 0

Event: 10 Source: Microsoft-Windows-WMI

Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.



~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

'Application' Log - Warning Type



Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 22-10-2013

Ran by Brain at 2013-10-22 17:07:06 Run:1

Running from C:\Users\Brain\Downloads

Boot Mode: Normal

==============================================



Content of fixlist:

*****************

S4 Application Sendori; C:\Program Files (x86)\Sendori\SendoriSvc.exe [x]

S4 Service Sendori; C:\Program Files (x86)\Sendori\Sendori.Service.exe [x]

S4 sndappv2; C:\Program Files (x86)\Sendori\sndappv2.exe [x]

Winsock: Catalog9 01 C:\Windows\system32\Sendori.dll File Not found ()

Winsock: Catalog9 02 C:\Windows\system32\Sendori.dll File Not found ()

Winsock: Catalog9 03 C:\Windows\system32\Sendori.dll File Not found ()

Winsock: Catalog9 04 C:\Windows\system32\Sendori.dll File Not found ()

Winsock: Catalog9 15 C:\Windows\system32\Sendori.dll File Not found ()

cmd: netsh winsock reset

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => ?

Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-649025149-514020257-970770016-1000Core.job => ?

Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-649025149-514020257-970770016-1000UA.job => ?

Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => ?

Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => ?

Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-649025149-514020257-970770016-1000Core.job => ?

Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-649025149-514020257-970770016-1000UA.job => ?

Task: C:\Windows\Tasks\HPCeeScheduleForBRAIN-HP$.job => ?

Task: C:\Windows\Tasks\HPCeeScheduleForBrain.job => ?

C:\Program Files (x86)\Sendori







*****************



Application Sendori => Service deleted successfully.

Service Sendori => Service deleted successfully.

sndappv2 => Service deleted successfully.

Winsock: Catalog entry 000000000001 => Deleted successfully.

Winsock: Catalog entry 000000000002 => Deleted successfully.

Winsock: Catalog entry 000000000003 => Deleted successfully.

Winsock: Catalog entry 000000000004 => Deleted successfully.

Winsock: Catalog entry 000000000015 => Deleted successfully.



========= netsh winsock reset =========





Sucessfully reset the Winsock Catalog.

You must restart the computer in order to complete the reset.





========= End of CMD: =========



C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.

C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-649025149-514020257-970770016-1000Core.job => Moved successfully.

C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-649025149-514020257-970770016-1000UA.job => Moved successfully.

C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.

C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.

C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-649025149-514020257-970770016-1000Core.job => Moved successfully.

C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-649025149-514020257-970770016-1000UA.job => Moved successfully.

C:\Windows\Tasks\HPCeeScheduleForBRAIN-HP$.job => Moved successfully.

C:\Windows\Tasks\HPCeeScheduleForBrain.job => Moved successfully.

C:\Program Files (x86)\Sendori => Moved successfully.



==== End of Fixlog ====


  • 0

#8
Braind

Braind

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 246 posts
update: Everything seems to be working fine now. Firefox and Outlook 2010 are working and I was able to reinstall Chrome.

Two quick questions:

1.) Is there a program that you recommend that I can run to find what other junk I have on my PC that I could remove safely?
2.) What anti-malware software would you recommend for my PC?

Thanks again for all of your help. It is greatly appreciated.
  • 0

#9
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,012 posts
  • MVP
The following two programs are very handy for removing adware which your anti-virus may not see as malware.


Download : ADWCleaner to your desktop. Make sure you get the correct Download button. Sometimes the ads on BleepingComputer will mimic the real Download button which should say: Download Now @BleepingComputer

NOTE: If using Internet Explorer and you get an alert that stops the program downloading, click on the warning and allow the download to complete.

Close all programs, pause your anti-virus and run AdwCleaner (Vista or Win 7 => right click and Run As Administrator).

Posted Image

Click on Scan and follow the prompts. Let it run unhindered. When done, click on the Clean button, and follow the prompts. Allow the system to reboot. You will then be presented with the report. Copy & Paste this report on your next reply.

The report will be saved in the C:\AdwCleaner folder.



Junkware-Removal-Tool

Please download Junkware Removal Tool to your desktop. Make sure you get the correct Download button. Sometimes the ads on BleepingComputer will mimic the real Download button which should say: Download Now @Author's site
  • Pause your anti-virus. Close all browsers.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

We run both almost every time we see adware present and they seem to be safe and very effective.


BitDefender is one of the better anti-viruses. Appears to me that VIPRE may have removed something it shouldn't have. Did VIPRE leave a log of what it had done? Did BitDefender?

We need to figure out why you are still getting the error:

The time provider 'VMICTimeProvider' failed to start due to the following error: The specified module could not be found. (0x8007007E)


Is this some kind of Virtual Machine? If not then copy the next 4 lines:

reg query HKLM\SYSTEM\CurrentControlSet\Services\W32Time /s > %userprofile%\desktop\junk.txt
dir %SystemRoot%\System32\vmictimeprovider.dll >> %userprofile%\desktop\junk.txt
sc query w32time >> %userprofile%\desktop\junk.txt
notepad %userprofile%\desktop\junk.txt

Start, All Programs, Accessories, right click on Command Prompt and Run as Administrator, Continue. Right click and Paste or Edit then Paste and the copied lines should appear.
Hit Enter if notepad does not open. Copy and paste the text from notepad into a reply. Close notepad. Close the Command Window.

Is your time synchronized to the Internet? Right click on the clock and select Adjust Date/Time then Internet Time. IT should normally look something like this and say that time is synchronized:

If not: Change Settings then click on Update Now. Does it tell you it synchronized or does it give you an error?
  • 0

#10
Braind

Braind

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 246 posts
VIPRE did most likely clean something it should not have cleaned. The reboot after the VIPRE scan took a long, many minutes, time to complete. Bitdefender and VIPRE probably have logs, but I did not save them at the time the scans were done.
Here are the logs you requested:

# AdwCleaner v3.010 - Report created 22/10/2013 at 20:15:41

# Updated 20/10/2013 by Xplode

# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)

# Username : Brain - BRAIN-HP

# Running from : C:\Users\Brain\Downloads\AdwCleaner.exe

# Option : Scan



***** [ Services ] *****





***** [ Files / Folders ] *****



File Found : C:\END

File Found : C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\esuzx5jl.default\searchplugins\Askcom.xml

File Found : C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\esuzx5jl.default\searchplugins\Search_Results.xml

File Found : C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\esuzx5jl.default\user.js

File Found : C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\x1ft5x1x.default-1340583930802\searchplugins\my-web-search.xml

File Found : C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\x1ft5x1x.default-1340583930802\searchplugins\safesearch.xml

File Found : C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\x1ft5x1x.default-1340583930802\searchplugins\web-search.xml

File Found : C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\x1ft5x1x.default-1340583930802\user.js

File Found : C:\Windows\System32\Tasks\Scheduled Update for Ask Toolbar

Folder Found : C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\x1ft5x1x.default-1340583930802\Extensions\{465fcfbb-47a4-4866-a5d5-d12f9a77da00}

Folder Found C:\Program Files (x86)\Conduit

Folder Found C:\Program Files (x86)\Ilivid

Folder Found C:\ProgramData\AGI

Folder Found C:\ProgramData\Ask

Folder Found C:\ProgramData\boost_interprocess

Folder Found C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ilivid

Folder Found C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ilivid

Folder Found C:\Users\Brain\AppData\Local\Conduit

Folder Found C:\Users\Brain\AppData\Local\Ilivid Player

Folder Found C:\Users\Brain\AppData\Local\PackageAware

Folder Found C:\Users\Brain\AppData\LocalLow\AGI

Folder Found C:\Users\Brain\AppData\LocalLow\AskToolbar

Folder Found C:\Users\Brain\AppData\LocalLow\boost_interprocess

Folder Found C:\Users\Brain\AppData\LocalLow\Conduit

Folder Found C:\Users\Brain\AppData\Roaming\DriverCure

Folder Found C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\esuzx5jl.default\FCTB

Folder Found C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\x1ft5x1x.default-1340583930802\CT3279411

Folder Found C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\x1ft5x1x.default-1340583930802\FCTB

Folder Found C:\Windows\installer\{86d4b82a-abed-442a-be86-96357b70f4fe}



***** [ Shortcuts ] *****





***** [ Registry ] *****



Key Found : HKCU\Software\AGI

Key Found : HKCU\Software\APN

Key Found : HKCU\Software\AppDataLow\Software\AskToolbar

Key Found : HKCU\Software\AppDataLow\Software\Conduit

Key Found : HKCU\Software\AppDataLow\Software\ConduitSearchScopes

Key Found : HKCU\Software\AppDataLow\Software\Freecause

Key Found : HKCU\Software\AppDataLow\Software\smartbar

Key Found : HKCU\Software\Conduit

Key Found : HKCU\Software\ilivid

Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0BC6E3FA-78EF-4886-842C-5A1258C4455A}

Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}

Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}

Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E}

Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}

Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6E45F3E8-2683-4824-A6BE-08108022FB36}

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6E45F3E8-2683-4824-A6BE-08108022FB36}

Key Found : HKCU\Software\Softonic

Key Found : [x64] HKCU\Software\AGI

Key Found : [x64] HKCU\Software\APN

Key Found : [x64] HKCU\Software\Conduit

Key Found : [x64] HKCU\Software\ilivid

Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0BC6E3FA-78EF-4886-842C-5A1258C4455A}

Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}

Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}

Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E}

Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}

Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}

Key Found : [x64] HKCU\Software\Softonic

Key Found : HKLM\Software\AGI

Key Found : HKLM\Software\APN

Key Found : HKLM\SOFTWARE\Classes\AppID\{19D2F415-D58B-46BC-9390-C03DCBC21EB2}

Key Found : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}

Key Found : HKLM\SOFTWARE\Classes\AppID\ButtonSite.DLL

Key Found : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL

Key Found : HKLM\SOFTWARE\Classes\AppID\PropertySync.EXE

Key Found : HKLM\SOFTWARE\Classes\AppID\ScriptHost.DLL

Key Found : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe

Key Found : HKLM\SOFTWARE\Classes\CLSID\{19D2F415-D58B-46BC-9390-C03DCBC21EB2}

Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}

Key Found : HKLM\SOFTWARE\Classes\CLSID\{6E45F3E8-2683-4824-A6BE-08108022FB36}

Key Found : HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}

Key Found : HKLM\SOFTWARE\Classes\CLSID\{9F0F16DD-4E76-4049-A9B1-7A91E48F0323}

Key Found : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}

Key Found : HKLM\SOFTWARE\Classes\CLSID\{F4288797-CB12-49CE-9DF8-7CDFA1143BEA}

Key Found : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}

Key Found : HKLM\SOFTWARE\Classes\ilivid

Key Found : HKLM\Software\Classes\Installer\Features\2B1E51D87B2D71A44BB42DDD5E894160

Key Found : HKLM\Software\Classes\Installer\Products\2B1E51D87B2D71A44BB42DDD5E894160

Key Found : HKLM\SOFTWARE\Classes\ScriptHost.Tool

Key Found : HKLM\SOFTWARE\Classes\ScriptHost.Tool.1

Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3279411

Key Found : HKLM\SOFTWARE\Classes\TypeLib\{212C2C4F-C845-4FBC-9561-C833A13D8DCE}

Key Found : HKLM\SOFTWARE\Classes\TypeLib\{3C5D1D57-16C8-473C-A552-37B8D88596FE}

Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4A115D8A-6A7B-4C72-92B1-2E2D01F36979}

Key Found : HKLM\SOFTWARE\Classes\TypeLib\{99DF8440-814E-497F-BDDD-FB93E9E9DF96}

Key Found : HKLM\Software\Conduit

Key Found : HKLM\Software\Freeze.com

Key Found : HKLM\Software\ilivid

Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}

Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83CAD530-387D-40FD-82EA-B9E863D92A9B}

Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{87A0B80B-5BA7-4CB0-9553-105D68777D60}

Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}

Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0BC6E3FA-78EF-4886-842C-5A1258C4455A}

Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}

Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}

Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASAPI32

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASMANCS

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\HPSF_Tasks_RASAPI32

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\HPSF_Tasks_RASMANCS

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASAPI32

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASMANCS

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_windows-media-player-plus_RASAPI32

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_windows-media-player-plus_RASMANCS

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASAPI32

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASMANCS

Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6E45F3E8-2683-4824-A6BE-08108022FB36}

Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8D15E1B2-D2B7-4A17-B44B-D2DDE5981406}

Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ilivid

Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Toolbar Cleaner

Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{19D2F415-D58B-46BC-9390-C03DCBC21EB2}

Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{6E45F3E8-2683-4824-A6BE-08108022FB36}

Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{9F0F16DD-4E76-4049-A9B1-7A91E48F0323}

Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{F4288797-CB12-49CE-9DF8-7CDFA1143BEA}

Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991}

Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}

Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}

Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}

Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83CAD530-387D-40FD-82EA-B9E863D92A9B}

Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}

Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}

Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}

Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6E45F3E8-2683-4824-A6BE-08108022FB36}

Key Found : [x64] HKLM\SOFTWARE\Tarma Installer

Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{0BC6E3FA-78EF-4886-842C-5A1258C4455A}]



***** [ Browsers ] *****



-\\ Internet Explorer v11.0.9600.16384





-\\ Mozilla Firefox v25.0 (en-US)



[ File : C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\esuzx5jl.default\prefs.js ]





[ File : C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\x1ft5x1x.default-1340583930802\prefs.js ]





-\\ Google Chrome v30.0.1599.101



[ File : C:\Users\Brain\AppData\Local\Google\Chrome\User Data\Default\preferences ]





*************************



AdwCleaner[R0].txt - [24663 octets] - [22/10/2013 20:00:00]

AdwCleaner[R1].txt - [11196 octets] - [22/10/2013 20:15:41]

AdwCleaner[S0].txt - [25734 octets] - [22/10/2013 20:12:13]



########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [11318 octets] ##########





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Junkware Removal Tool (JRT) by Thisisu

Version: 6.0.7 (10.15.2013:3)

OS: Windows 7 Home Premium x64

Ran by Brain on Tue 10/22/2013 at 20:21:09.87

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~









~~~ Services







~~~ Registry Values







~~~ Registry Keys



Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\buttonsite.dll

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\genericasktoolbar.dll

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\propertysync.exe

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\scripthost.dll

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}

Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\ilivid

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\softonic

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\conduit

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\conduitsearchscopes

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\freecause

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\smartbar

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\freeze.com

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\ilivid

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\applications\ilividsetupv1.exe

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\ilivid

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\scripthost.tool

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\scripthost.tool.1

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\adawarebp_rasapi32

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\adawarebp_rasmancs

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\apnstub_rasapi32

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\apnstub_rasmancs

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\askpartnercobrandingtool_rasapi32

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\askpartnercobrandingtool_rasmancs

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\au__rasapi32

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\au__rasmancs

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ilividsetupv1_rasapi32

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ilividsetupv1_rasmancs

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\webcakedesktop_rasapi32

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\webcakedesktop_rasmancs

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\ilivid

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{8d15e1b2-d2b7-4a17-b44b-d2dde5981406}

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT3279411

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ask_RASAPI32

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ask_RASMANCS

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\HPSF_Tasks_RASAPI32

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\HPSF_Tasks_RASMANCS

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_for_windows-media-player-plus_RASAPI32

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_for_windows-media-player-plus_RASMANCS

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\ApnToolbarInstaller_RASAPI32

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\ApnToolbarInstaller_RASMANCS

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\ask_RASAPI32

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\ask_RASMANCS

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\HPSF_Tasks_RASAPI32

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\HPSF_Tasks_RASMANCS

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_for_windows-media-player-plus_RASAPI32

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_for_windows-media-player-plus_RASMANCS

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{22DE9C45-49D6-4693-9023-90CCAA229927}

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{B2E038B0-81C7-454F-B105-49E183CED4DF}

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{C46296C9-9FB6-4509-8294-68FA8F44E6DB}

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{C46296C9-9FB6-4509-8294-68FA8F44E6DB}

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}

Successfully deleted: [Registry Key] "hkey_current_user\software\apn"

Successfully deleted: [Registry Key] "hkey_current_user\software\appdatalow\software\asktoolbar"

Successfully deleted: [Registry Key] "hkey_current_user\software\microsoft\internet explorer\low rights\elevationpolicy\{a5aa24ea-11b8-4113-95ae-9ed71deaf12a}"

Successfully deleted: [Registry Key] "hkey_local_machine\software\apn"

Successfully deleted: [Registry Key] "hkey_local_machine\software\classes\appid\{9b0cb95c-933a-4b8c-b6d4-edcd19a43874}"







~~~ Files



Successfully deleted: [File] "C:\end"







~~~ Folders



Successfully deleted: [Folder] "C:\ProgramData\agi"

Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess"

Successfully deleted: [Folder] "C:\Users\Brain\AppData\Roaming\drivercure"

Successfully deleted: [Folder] "C:\Users\Brain\appdata\local\conduit"

Successfully deleted: [Folder] "C:\Users\Brain\appdata\local\cre"

Successfully deleted: [Folder] "C:\Users\Brain\appdata\local\ilivid player"

Successfully deleted: [Folder] "C:\Users\Brain\appdata\locallow\agi"

Successfully deleted: [Folder] "C:\Users\Brain\appdata\locallow\boost_interprocess"

Successfully deleted: [Folder] "C:\Users\Brain\appdata\locallow\conduit"

Successfully deleted: [Folder] "C:\Users\Brain\appdata\locallow\datamngr"

Successfully deleted: [Folder] "C:\Program Files (x86)\conduit"

Successfully deleted: [Folder] "C:\Program Files (x86)\coupons"

Successfully deleted: [Folder] "C:\Program Files (x86)\ilivid"

Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ilivid"

Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"

Successfully deleted: [Empty Folder] C:\Users\Brain\appdata\local\{1FCD42FE-0305-4EA6-8E98-98D8270C56B2}

Successfully deleted: [Empty Folder] C:\Users\Brain\appdata\local\{A2B03C9F-0DCF-4595-B080-D8625E626CCC}

Successfully deleted: [Empty Folder] C:\Users\Brain\appdata\local\{AFACD438-EB56-49CF-BA10-A647BFC9570E}

Successfully deleted: [Empty Folder] C:\Users\Brain\appdata\local\{BC64888F-58F0-448B-B344-F86B43AAEA4E}

Successfully deleted: [Empty Folder] C:\Users\Brain\appdata\local\{D9085594-8917-454C-919E-78CE13203DA7}

Successfully deleted: [Folder] "C:\ProgramData\ask"

Successfully deleted: [Folder] "C:\Users\Brain\appdata\locallow\asktoolbar"

Successfully deleted: [Folder] "C:\Windows\installer\{86d4b82a-abed-442a-be86-96357b70f4fe}"







~~~ FireFox



Successfully deleted: [File] C:\Users\Brain\AppData\Roaming\mozilla\firefox\profiles\esuzx5jl.default\user.js

Successfully deleted: [File] C:\Users\Brain\AppData\Roaming\mozilla\firefox\profiles\x1ft5x1x.default-1340583930802\user.js

Successfully deleted: [File] C:\Users\Brain\AppData\Roaming\mozilla\firefox\profiles\esuzx5jl.default\searchplugins\askcom.xml

Successfully deleted: [File] C:\Users\Brain\AppData\Roaming\mozilla\firefox\profiles\x1ft5x1x.default-1340583930802\searchplugins\my-web-search.xml

Successfully deleted: [File] C:\Users\Brain\AppData\Roaming\mozilla\firefox\profiles\x1ft5x1x.default-1340583930802\searchplugins\safesearch.xml

Successfully deleted: [File] C:\Users\Brain\AppData\Roaming\mozilla\firefox\profiles\esuzx5jl.default\searchplugins\search_results.xml

Successfully deleted: [Folder] C:\Users\Brain\AppData\Roaming\mozilla\firefox\profiles\esuzx5jl.default\fctb

Successfully deleted: [Folder] C:\Users\Brain\AppData\Roaming\mozilla\firefox\profiles\x1ft5x1x.default-1340583930802\fctb

Successfully deleted the following from C:\Users\Brain\AppData\Roaming\mozilla\firefox\profiles\esuzx5jl.default\prefs.js



user_pref("extensions.sahtb.url.merchants.data", "<?xml version=\"1.0\" ?><MerchantSettings><v n=\"177\" /><GlobalSuppresses><s u=\".7eer.net\" g=\"1\" i=\"1853\" /><s u=\".ca

user_pref("keyword.URL", "hxxp://safesearchr.lavasoft.com/?source=3336ca5f&tbp=url&toolbarid=adawaretb&u=82FDDE804350450F99A9E34F7BAFEFE8&q=");

user_pref("browser.startup.homepage", "hxxp://safesearchr.lavasoft.com/?source=3336ca5f&tbp=homepage&toolbarid=adawaretb&v=2_2&u=82FDDE804350450F99A9E350EA002600");

Successfully deleted the following from C:\Users\Brain\AppData\Roaming\mozilla\firefox\profiles\x1ft5x1x.default-1340583930802\prefs.js



user_pref("browser.startup.homepage", "hxxp://www.dogpile.com/");

Emptied folder: C:\Users\Brain\AppData\Roaming\mozilla\firefox\profiles\esuzx5jl.default\minidumps [4 files]

Emptied folder: C:\Users\Brain\AppData\Roaming\mozilla\firefox\profiles\x1ft5x1x.default-1340583930802\minidumps [8 files]







~~~ Chrome



Successfully deleted: [Folder] C:\Users\Brain\appdata\local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda







~~~ Event Viewer Logs were cleared











~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Scan was completed on Tue 10/22/2013 at 20:26:32.47

End of JRT log

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

I do not know what a virtual machine is, so I do not think I have one on my PC.

here is the log from the command prompt:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time
Type REG_DWORD 0x20
Start REG_DWORD 0x2
ErrorControl REG_DWORD 0x1
ImagePath REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k LocalService
DisplayName REG_SZ @%SystemRoot%\system32\w32time.dll,-200
ObjectName REG_SZ NT AUTHORITY\LocalService
Description REG_SZ @%SystemRoot%\system32\w32time.dll,-201
FailureActions REG_BINARY 80510100000000000000000003000000140000000100000060EA000001000000C0D401000000000000000000
ServiceSidType REG_DWORD 0x1
RequiredPrivileges REG_MULTI_SZ SeAuditPrivilege\0SeChangeNotifyPrivilege\0SeCreateGlobalPrivilege\0SeSystemTimePrivilege


HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Config
FrequencyCorrectRate REG_DWORD 0x4
PollAdjustFactor REG_DWORD 0x5
LargePhaseOffset REG_DWORD 0x2faf080
SpikeWatchPeriod REG_DWORD 0x384
HoldPeriod REG_DWORD 0x5
LocalClockDispersion REG_DWORD 0xa
EventLogFlags REG_DWORD 0x2
TimeJumpAuditOffset REG_DWORD 0x7080
PhaseCorrectRate REG_DWORD 0x1
MinPollInterval REG_DWORD 0xa
MaxPollInterval REG_DWORD 0xf
UpdateInterval REG_DWORD 0x57e40
MaxNegPhaseCorrection REG_DWORD 0xd2f0
MaxPosPhaseCorrection REG_DWORD 0xd2f0
AnnounceFlags REG_DWORD 0xa
MaxAllowedPhaseOffset REG_DWORD 0x1


HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Parameters
ServiceDllUnloadOnStop REG_DWORD 0x1
ServiceMain REG_SZ SvchostEntry_W32Time
ServiceDll REG_EXPAND_SZ C:\Windows\system32\w32time.DLL
NtpServer REG_SZ time.nist.gov,0x9
Type REG_SZ NTP


HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpClient
Enabled REG_DWORD 0x1
InputProvider REG_DWORD 0x1
AllowNonstandardModeCombinations REG_DWORD 0x1
CrossSiteSyncFlags REG_DWORD 0x2
ResolvePeerBackoffMinutes REG_DWORD 0xf
ResolvePeerBackoffMaxTimes REG_DWORD 0x7
CompatibilityFlags REG_DWORD 0x80000000
EventLogFlags REG_DWORD 0x1
LargeSampleSkew REG_DWORD 0x3
DllName REG_EXPAND_SZ C:\Windows\system32\w32time.DLL
SpecialPollTimeRemaining REG_MULTI_SZ time.nist.gov,7c3c1bf
SpecialPollInterval REG_DWORD 0x93a80


HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpServer
InputProvider REG_DWORD 0x0
AllowNonstandardModeCombinations REG_DWORD 0x1
EventLogFlags REG_DWORD 0x0
DllName REG_EXPAND_SZ C:\Windows\system32\w32time.DLL
Enabled REG_DWORD 0x0


HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\VMICTimeProvider
Enabled REG_DWORD 0x1
InputProvider REG_DWORD 0x1
DllName REG_EXPAND_SZ %SystemRoot%\System32\vmictimeprovider.dll


HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\VMICTimeProvider\Parameters

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\TriggerInfo

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\TriggerInfo\0
Type REG_DWORD 0x3
Action REG_DWORD 0x1
Guid REG_BINARY BA0AE21C5198214494301DDEB766E809


HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\TriggerInfo\1
Type REG_DWORD 0x3
Action REG_DWORD 0x2
Guid REG_BINARY 6E51AFDDC25866489574C3B615D42EA1


Volume in drive C is OS
Volume Serial Number is E27A-0241


Directory of C:\Windows\System32


SERVICE_NAME: w32time
TYPE : 20 WIN32_SHARE_PROCESS
STATE : 1 STOPPED
WIN32_EXIT_CODE : 0 (0x0)
SERVICE_EXIT_CODE : 0 (0x0)
CHECKPOINT : 0x0
WAIT_HINT : 0x0

My PC clock said it is synchronized after I followed your instructions.




Edited by Braind, 22 October 2013 - 07:50 PM.

  • 0

Advertisements


#11
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,012 posts
  • MVP
I think I'd stay away from Vipre.

Your Adware Cleaner log does not show that stuff was deleted just that it was found. After you ran Scan did you:

When done, click on the Clean button, and follow the prompts.




If your time is working then I'm not going to worry about the error.
  • 0

#12
Braind

Braind

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 246 posts
I'll run Adware Cleaner again.
  • 0

#13
Braind

Braind

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 246 posts
Here are the latest Adware Cleaner results:

# AdwCleaner v3.010 - Report created 22/10/2013 at 21:28:46
# Updated 20/10/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Brain - BRAIN-HP
# Running from : C:\Users\Brain\Downloads\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Users\Brain\AppData\Local\PackageAware
Folder Deleted : C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\x1ft5x1x.default-1340583930802\CT3279411
Folder Deleted : C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\x1ft5x1x.default-1340583930802\Extensions\{465fcfbb-47a4-4866-a5d5-d12f9a77da00}
File Deleted : C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\x1ft5x1x.default-1340583930802\searchplugins\web-search.xml
File Deleted : C:\Windows\System32\Tasks\Scheduled Update for Ask Toolbar

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{19D2F415-D58B-46BC-9390-C03DCBC21EB2}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{19D2F415-D58B-46BC-9390-C03DCBC21EB2}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E45F3E8-2683-4824-A6BE-08108022FB36}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9F0F16DD-4E76-4049-A9B1-7A91E48F0323}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F4288797-CB12-49CE-9DF8-7CDFA1143BEA}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{212C2C4F-C845-4FBC-9561-C833A13D8DCE}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{3C5D1D57-16C8-473C-A552-37B8D88596FE}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4A115D8A-6A7B-4C72-92B1-2E2D01F36979}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{99DF8440-814E-497F-BDDD-FB93E9E9DF96}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6E45F3E8-2683-4824-A6BE-08108022FB36}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6E45F3E8-2683-4824-A6BE-08108022FB36}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6E45F3E8-2683-4824-A6BE-08108022FB36}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83CAD530-387D-40FD-82EA-B9E863D92A9B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{87A0B80B-5BA7-4CB0-9553-105D68777D60}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0BC6E3FA-78EF-4886-842C-5A1258C4455A}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0BC6E3FA-78EF-4886-842C-5A1258C4455A}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{0BC6E3FA-78EF-4886-842C-5A1258C4455A}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{19D2F415-D58B-46BC-9390-C03DCBC21EB2}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{6E45F3E8-2683-4824-A6BE-08108022FB36}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{9F0F16DD-4E76-4049-A9B1-7A91E48F0323}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{F4288797-CB12-49CE-9DF8-7CDFA1143BEA}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6E45F3E8-2683-4824-A6BE-08108022FB36}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83CAD530-387D-40FD-82EA-B9E863D92A9B}
Key Deleted : HKCU\Software\AGI
Key Deleted : HKLM\Software\AGI
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Toolbar Cleaner
Key Deleted : [x64] HKLM\SOFTWARE\Tarma Installer
Key Deleted : HKLM\Software\Classes\Installer\Features\2B1E51D87B2D71A44BB42DDD5E894160
Key Deleted : HKLM\Software\Classes\Installer\Products\2B1E51D87B2D71A44BB42DDD5E894160

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16384


-\\ Mozilla Firefox v25.0 (en-US)

[ File : C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\esuzx5jl.default\prefs.js ]


[ File : C:\Users\Brain\AppData\Roaming\Mozilla\Firefox\Profiles\x1ft5x1x.default-1340583930802\prefs.js ]


-\\ Google Chrome v30.0.1599.101

[ File : C:\Users\Brain\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [24663 octets] - [22/10/2013 20:00:00]
AdwCleaner[R1].txt - [11499 octets] - [22/10/2013 20:15:41]
AdwCleaner[R2].txt - [5817 octets] - [22/10/2013 21:28:14]
AdwCleaner[S0].txt - [25734 octets] - [22/10/2013 20:12:13]
AdwCleaner[S1].txt - [5515 octets] - [22/10/2013 21:28:46]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [5575 octets] ##########



  • 0

#14
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,012 posts
  • MVP
OK. I think we are done and can clean up:


You can uninstall or delete any tools we had you download and their logs.

OTL has a cleanup tab but DO NOT USE IT!. There are reports that it leaves the PC unbootable. Instead just delete OTL.exe and the folder c:\_OTL.

To hide hidden files again:

Vista or Win7

# Open the Control Panel menu and click Folder Options.
# After the new window appears select the View tab.
# Remove the check in the checkbox labeled Display the contents of system folders.
# Under the Hidden files and folders section select the radio button labeled Do not Show hidden files and folders.
# Check the checkbox labeled Hide protected operating system files.
# Press the Apply button and then the OK button and exit My Computer.

Also make sure you have the latest versions of any adobe.com products you use like Shockwave, Flash or Acrobat.

Whether you use adobe reader, acrobat or fox-it to read pdf files you need to disable Javascript in the program. There is an exploit out there now that can use it to get on your PC. For Adobe Reader: Start, All Programs, Adobe Reader, Edit, Preferences, Click on Javascript in the left column and uncheck Enable Acrobat Javascript. OK Close program. It's the same for Foxit reader except you uncheck Enable Javascript Actions.

Unless you have the latest version of Avast which has its own update checker: To help keep your programs up-to-date you should download and run the UpdateChecker:
http://www.filehippo.../updatechecker/
(You don't need to download Betas and if there is a program you don't use you can just uninstall it rather than update it. Exception is MSN messenger which appears to be part of Windows.)
If you get a blocked program notice after installing updatechecker then change it to not run at start then manually run it once a week.
Seems to work best if Firefox is the default browser. Windows always hides its icon so you need to unhide it. Click on the up arrow to the left of the clock. Then click on Customize. Maximize the window so you can see all of the options. Scroll Down and find the File Hippo UpdateChecker and change its Behaviors to Show Icon and Notifications. OK. When you reboot you should see the icon. It will take it a minute to finish checking then it will put up a bubble if you need to update something. Click on the bubble and it should open in your browser. (Seems to work best if it uses Firefox. If you do not use Firefox as your default browser then right click on the icon and click on Settings. Then on Results. Change the Open Results in Default Browser to Custom Browser and then select the line that has Firefox.exe in it. While there, also check Hide Beta Versions. OK. ) You will see a list of programs that have updates with green down arrows next to them. You do not need to download any Beta Versions. There is an option Settings to Hide Beta Versions. I do not advise updating Windows Messenger unless you really use it so I right click on the Icon and Customize Results then find Microsoft Messenger and change Show All Releases to Hide All Releases. OK.

You can also try Secunia PSI http://secunia.com/v...l/download_psi/ Same kind of info. You don't need both.
If you use Firefox or Chrome then get the AdBlock Plus Add-on.
Adblock Plus is now available for IE too. https://adblockplus....plorer-released

If Firefox is slow loading make sure it only has the current Java add-on. Then download and run Speedy Fox.
http://www.crystalidea.com/speedyfox . You can run it any time that Firefox seems slow.

Be warned: If you use Limewire, utorrent or any of the other P2P programs you will almost certain be coming back to the Malware Removal forum. If you must use P2P then submit any files you get to http://virustotal.com before you open them.


If you have a router, log on to it today and change the default password! If using a Wireless router you really should be using encryption on the link. Use the strongest (newest) encryption method that your router and PC wireless adapter support especially if you own a business. See http://www.king5.com...-120637284.html and http://www.seattlepi...ted-1344185.php for why encryption is important. If you don't know how, visit the router maker's website. They all have detailed step by step instructions or a wizard you can download.

Special note on Java. Old Java versions should be removed after first clearing the Java Cache by following the instructions in:
http://www.java.com/...lugin_cache.xml
Then remove the old versions by going to Control Panel, Programs and Features and Uninstall all Java programs which are not Java Version 7 update 25 or better. These may call themselves: Java Runtime, Runtime Environment, Runtime, JRE, Java Virtual Machine, Virtual Machine, Java VM, JVM, VM, J2RE, J2SE. Get the latest version from Java.com. They will usually attempt to foist some garbage like the Ask toolbar, Yahoo toolbar or McAfee Security Scan on you as part of the download. Just uncheck the garbage before the download (or install) starts. If you use a 64-bit browser and want the 64-bit version of Java you need to use it to visit java.com.
Due to multiple security problems with Java we are now recommending that it not be installed unless you absolutely know you need it. IF that is the case then go to Control Panel, Java, Security and slide it up to the highest level. OK.

Make sure Windows Updates is turned and that it works. Go to Control panel, Windows Updates and see if it works.

If you are feeling especially paranoid you can install the free firewall called Online Armor:
http://www.online-armor.com/


My help is free but if you wish to show your appreciation, please donate to Kwiaht instead of me. It's a local environmental organization that I volunteer with: http://www.kwiaht.org/donate.htm
(The name means something like "clean place" in one of the local native-American dialects)

Ron
  • 0

#15
Braind

Braind

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 246 posts
Thank you for your help and advice. I greatly appreciate it all. I am already doing 90 % or more of your suggestions and I will keep the information to make sure I get all 100% done. Thanks again.
  • 0






Similar Topics

1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP