Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Possibly a virus. [Solved]


  • This topic is locked This topic is locked

#1
Fatie32

Fatie32

    Member

  • Member
  • PipPipPip
  • 122 posts

Had a few strang pop ups as well as a process (my computers name).exe running at 100 percent cpu a few times.

 

OTL logfile created on: 10/25/2014 12:39:22 PM - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = D:\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17358)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
7.95 Gb Total Physical Memory | 5.40 Gb Available Physical Memory | 67.91% Memory free
7.94 Gb Paging File | 5.12 Gb Available in Paging File | 64.40% Paging File free
Paging file location(s):  [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 55.68 Gb Total Space | 6.71 Gb Free Space | 12.06% Space Free | Partition Type: NTFS
Drive D: | 1667.70 Gb Total Space | 1290.96 Gb Free Space | 77.41% Space Free | Partition Type: NTFS
Unable to calculate disk information.
Drive F: | 6.32 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
 
Computer Name: MIKEY-PC | User Name: Mikey | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2014/10/25 12:31:39 | 000,602,112 | ---- | M] (OldTimer Tools) -- D:\Downloads\OTL.exe
PRC - [2014/10/22 16:38:03 | 002,664,227 | -HS- | M] () -- C:\Users\Mikey\AppData\Roaming\amde.exe
PRC - [2014/10/21 13:22:40 | 001,529,536 | ---- | M] (Valve Corporation) -- D:\Program Files (x86)\Steam\bin\steamwebhelper.exe
PRC - [2014/10/21 13:22:38 | 001,938,624 | ---- | M] (Valve Corporation) -- D:\Program Files (x86)\Steam\Steam.exe
PRC - [2014/10/20 23:51:28 | 002,973,600 | ---- | M] (MicroStudio) -- C:\Program Files (x86)\Windows Network Accelerater\v3\winvxm.exe
PRC - [2014/10/09 20:04:06 | 000,854,344 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2014/09/17 18:49:10 | 001,017,856 | ---- | M] (eRightSoft) -- C:\Program Files (x86)\eRightSoft\SUPER\SUPER.exe
PRC - [2014/09/16 20:15:08 | 002,460,488 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
PRC - [2014/09/16 20:14:57 | 001,795,912 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
PRC - [2014/09/13 14:12:58 | 000,411,968 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2014/09/05 23:22:44 | 002,284,128 | ---- | M] (MicroTools) -- C:\Program Files (x86)\YouTube Downloader Services\youtubeserv.exe
PRC - [2014/09/02 09:35:36 | 000,281,448 | ---- | M] (Binary Fortress Software) -- C:\Program Files (x86)\DisplayFusion\DisplayFusionHookAppWIN6032.exe
PRC - [2014/06/25 05:23:46 | 000,804,472 | ---- | M] () -- C:\Program Files (x86)\System Optimizer Pro\SystemOptimizerPro.exe
PRC - [2014/04/17 20:07:28 | 004,672,920 | ---- | M] (Akamai Technologies, Inc.) -- C:\Users\Mikey\AppData\Local\Akamai\netsession_win.exe
PRC - [2014/03/11 22:36:06 | 000,247,968 | ---- | M] (Microsoft Corporation.) -- C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.EXE
PRC - [2013/12/30 15:07:06 | 000,307,928 | ---- | M] () -- C:\Program Files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe
PRC - [2013/10/22 17:38:50 | 001,103,712 | ---- | M] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) -- C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
PRC - [2013/04/07 10:31:26 | 000,075,136 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2013/03/12 06:32:58 | 000,506,744 | ---- | M] (Oracle Corporation) -- C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
PRC - [2012/05/21 01:26:26 | 000,291,648 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2014/10/22 16:38:03 | 002,664,227 | -HS- | M] () -- C:\Users\Mikey\AppData\Roaming\amde.exe
MOD - [2014/10/21 13:22:58 | 002,226,880 | ---- | M] () -- D:\Program Files (x86)\Steam\video.dll
MOD - [2014/10/21 13:22:40 | 000,682,176 | ---- | M] () -- D:\Program Files (x86)\Steam\bin\chromehtml.dll
MOD - [2014/10/16 03:34:19 | 001,051,136 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\99cdfef98595ed91f14936cf52a49c54\System.Management.ni.dll
MOD - [2014/10/16 03:29:17 | 006,638,592 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\4b335bfaa07fc54f2d72213d33f53e97\System.Data.ni.dll
MOD - [2014/10/16 03:28:59 | 012,435,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\1453d9e9a4989833ef3db4b22549ba1a\System.Windows.Forms.ni.dll
MOD - [2014/10/16 03:28:53 | 001,593,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\836e10dfd0811b303553216f5cb092ef\System.Drawing.ni.dll
MOD - [2014/10/16 03:28:50 | 005,467,648 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\2cf12fa95900b4488a6cb9e4aac51c5c\System.Xml.ni.dll
MOD - [2014/10/16 03:28:47 | 000,978,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\237d509a79aeef6e4635b09450d98f2a\System.Configuration.ni.dll
MOD - [2014/10/16 03:28:36 | 007,991,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\908ba9e296e92b4e14bdc2437edac603\System.ni.dll
MOD - [2014/10/11 13:05:58 | 001,044,776 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2014/10/09 20:04:02 | 008,910,664 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\pdf.dll
MOD - [2014/10/09 20:03:56 | 001,042,760 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\libglesv2.dll
MOD - [2014/10/09 20:03:54 | 000,211,272 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\libegl.dll
MOD - [2014/10/09 20:03:53 | 001,681,224 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\ffmpegsumo.dll
MOD - [2014/10/01 17:16:02 | 000,774,656 | ---- | M] () -- D:\Program Files (x86)\Steam\SDL2.dll
MOD - [2014/09/18 17:03:44 | 000,025,600 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\0483c93466914f3fbd5b44454b0c8a98\Accessibility.ni.dll
MOD - [2014/09/18 17:03:31 | 011,497,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll
MOD - [2014/09/17 18:46:40 | 000,923,648 | -HS- | M] () -- C:\Program Files (x86)\eRightSoft\SUPER\spk\flvdec.spk
MOD - [2014/09/04 17:29:26 | 034,589,376 | ---- | M] () -- D:\Program Files (x86)\Steam\bin\libcef.dll
MOD - [2014/09/04 17:29:26 | 000,837,824 | ---- | M] () -- D:\Program Files (x86)\Steam\bin\ffmpegsumo.dll
MOD - [2014/08/21 12:15:22 | 001,171,456 | ---- | M] () -- D:\Program Files (x86)\Steam\libavcodec-56.dll
MOD - [2014/08/21 12:15:22 | 000,485,888 | ---- | M] () -- D:\Program Files (x86)\Steam\libswscale-3.dll
MOD - [2014/08/21 12:15:22 | 000,442,368 | ---- | M] () -- D:\Program Files (x86)\Steam\libavutil-54.dll
MOD - [2014/08/21 12:15:22 | 000,403,968 | ---- | M] () -- D:\Program Files (x86)\Steam\libavformat-56.dll
MOD - [2014/08/21 12:15:22 | 000,332,800 | ---- | M] () -- D:\Program Files (x86)\Steam\libavresample-2.dll
MOD - [2014/06/25 05:23:46 | 000,804,472 | ---- | M] () -- C:\Program Files (x86)\System Optimizer Pro\SystemOptimizerPro.exe
MOD - [2014/03/20 16:49:19 | 002,952,704 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MOD - [2014/03/07 11:03:58 | 000,109,712 | -HS- | M] () -- C:\Windows\SysWOW64\libbluray.dll
MOD - [2014/01/20 13:17:04 | 000,073,544 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2013/09/26 13:50:14 | 000,433,664 | ---- | M] () -- C:\Program Files (x86)\Evernote\Evernote\libxml2.dll
MOD - [2013/09/26 13:49:28 | 000,315,392 | ---- | M] () -- C:\Program Files (x86)\Evernote\Evernote\libtidy.dll
MOD - [2012/10/05 19:54:00 | 000,188,416 | -HS- | M] () -- C:\Windows\SysWOW64\winDCE32.dll
MOD - [2011/06/14 20:05:10 | 000,121,344 | -HS- | M] () -- C:\Windows\SysWOW64\TAKDSDecoder.ax
MOD - [2011/02/11 10:26:20 | 000,112,128 | -HS- | M] () -- C:\Windows\SysWOW64\OptimFROG.dll
MOD - [2010/01/07 00:00:00 | 000,107,520 | -HS- | M] () -- C:\Windows\SysWOW64\TAKDSDecoder.dll
MOD - [2009/08/10 23:00:00 | 000,352,768 | -HS- | M] () -- C:\Windows\SysWOW64\ac3DX.ax
MOD - [2008/06/12 11:31:00 | 000,028,160 | -HS- | M] () -- C:\Program Files (x86)\eRightSoft\SUPER\spk\SmabT.spk
MOD - [2005/02/22 17:55:02 | 000,081,920 | -HS- | M] () -- C:\Windows\SysWOW64\aac_parser.ax
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2014/09/18 19:25:49 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2014/09/16 20:14:56 | 001,148,744 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe -- (GfExperienceService)
SRV:64bit: - [2014/09/16 20:14:52 | 019,439,944 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe -- (NvStreamSvc)
SRV:64bit: - [2014/08/22 14:14:34 | 000,368,624 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2014/08/22 14:14:34 | 000,023,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2013/05/26 23:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2014/10/20 23:51:28 | 002,973,600 | ---- | M] (MicroStudio) [Auto | Running] -- C:\Program Files (x86)\Windows Network Accelerater\v3\winvxm.exe -- (WindowsVNT_R3)
SRV - [2014/09/25 10:09:26 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/09/16 20:14:57 | 001,795,912 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe -- (NvNetworkService)
SRV - [2014/09/13 14:12:58 | 000,411,968 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2014/09/09 22:35:04 | 005,278,064 | ---- | M] (Binary Fortress Software) [Auto | Running] -- C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe -- (DisplayFusionService)
SRV - [2014/09/05 23:22:44 | 002,284,128 | ---- | M] (MicroTools) [Auto | Running] -- C:\Program Files (x86)\YouTube Downloader Services\youtubeserv.exe -- (YouTubeDownload)
SRV - [2014/07/18 12:13:20 | 000,009,216 | ---- | M] (Hi-Rez Studios) [Auto | Paused] -- D:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe -- (HiPatchService)
SRV - [2014/03/20 16:49:18 | 000,067,224 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2014/03/11 22:36:06 | 000,247,968 | ---- | M] (Microsoft Corporation.) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.EXE -- (BBUpdate)
SRV - [2014/03/11 22:36:06 | 000,193,696 | ---- | M] (Microsoft Corporation.) [Auto | Stopped] -- C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BBSvc.EXE -- (BBSvc)
SRV - [2014/02/25 15:57:46 | 000,568,512 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2014/01/19 12:50:33 | 000,049,152 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\BattlEye\BEService.exe -- (BEService)
SRV - [2013/12/30 15:07:06 | 000,307,928 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe -- (WSWNDA3100v2)
SRV - [2013/09/11 20:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2013/04/07 10:31:26 | 000,075,136 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2010/08/10 21:37:08 | 000,334,848 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\ASUS\Printer Utilities\UsbService64.exe -- (UsbService)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2014/09/16 22:51:20 | 000,197,408 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2014/09/16 20:14:52 | 000,019,272 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys -- (NvStreamKms)
DRV:64bit: - [2014/09/04 13:14:38 | 000,038,048 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvvad64v.sys -- (nvvad_WaveExtensible)
DRV:64bit: - [2014/07/28 13:52:00 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2014/07/17 17:05:06 | 000,125,584 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2014/07/01 15:26:21 | 000,283,064 | ---- | M] (Disc Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2014/04/13 13:06:19 | 000,031,232 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tap0901.sys -- (tap0901)
DRV:64bit: - [2013/10/01 20:22:20 | 000,056,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2013/09/25 21:10:12 | 002,975,960 | R--- | M] (Realtek Semiconductor Corporation                           ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rtwlane.sys -- (RTWlanE)
DRV:64bit: - [2013/07/25 15:53:46 | 000,023,040 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netaapl64.sys -- (Netaapl)
DRV:64bit: - [2013/01/18 23:52:08 | 000,046,568 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ISCTD64.sys -- (ISCT)
DRV:64bit: - [2012/11/07 18:00:32 | 000,102,400 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\XHCIdrv.sys -- (XHCIdrv)
DRV:64bit: - [2012/10/02 16:26:46 | 000,066,360 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGSHidFilt.Sys -- (LGSHidFilt)
DRV:64bit: - [2012/09/19 10:02:08 | 000,102,368 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus)
DRV:64bit: - [2012/09/19 10:02:06 | 000,203,104 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm)
DRV:64bit: - [2012/08/23 08:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012/08/21 13:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2012/07/17 18:12:08 | 000,062,784 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2012/05/21 01:25:30 | 000,789,824 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3xhc.sys -- (iusb3xhc)
DRV:64bit: - [2012/05/21 01:25:30 | 000,357,184 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3hub.sys -- (iusb3hub)
DRV:64bit: - [2012/05/21 01:25:30 | 000,019,264 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iusb3hcs.sys -- (iusb3hcs)
DRV:64bit: - [2012/03/01 00:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012/02/15 23:42:00 | 000,676,968 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011/12/26 15:27:24 | 000,015,288 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\ampa.sys -- (ampa)
DRV:64bit: - [2011/12/12 16:42:00 | 001,256,192 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\bcmwlhigh664.sys -- (BCMH43XX)
DRV:64bit: - [2011/03/11 00:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 00:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/11/20 07:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/02/03 10:21:56 | 000,047,632 | ---- | M] (CACE Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\npf.sys -- (NPF)
DRV:64bit: - [2009/11/23 19:38:00 | 000,016,008 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGVirHid.sys -- (LGVirHid)
DRV:64bit: - [2009/11/23 19:37:50 | 000,022,408 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGBusEnum.sys -- (LGBusEnum)
DRV:64bit: - [2009/10/22 20:45:40 | 001,155,072 | ---- | M] (C-Media Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\cmudax3.sys -- (cmuda3)
DRV:64bit: - [2009/07/13 19:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 19:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 19:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 14:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 14:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 14:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 14:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2008/05/06 16:06:00 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wdcsam64.sys -- (WDC_SAM)
DRV:64bit: - [2007/12/17 10:25:14 | 000,047,616 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vuhub.sys -- (vuhub)
DRV:64bit: - [2007/01/19 17:24:24 | 000,025,312 | R--- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\SCMNdisP.sys -- (SCMNdisP)
DRV - [2011/01/06 11:06:56 | 000,011,888 | ---- | M] (MSI) [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\Setup Files\Ms7758v270\NTIOLib_X64.sys -- (NTIOLib_1_0_6)
DRV - [2009/07/13 19:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 57 27 BB F1 6F 39 CE 01  [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {E6957116-DFE1-4A9E-9922-66747C34C5F0}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE11SR
IE - HKCU\..\SearchScopes\{E6957116-DFE1-4A9E-9922-66747C34C5F0}: "URL" = https://search.yahoo...p={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;<local>
 
 
========== FireFox ==========
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: D:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll File not found
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=2.1.2: C:\Program Files (x86)\Battlelog Web Plugins\2.1.2\npesnlaunch.dll File not found
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: D:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.6: D:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll File not found
 
 
 
========== Chrome  ==========
 
CHR - default_search_provider:  (Enabled)
CHR - default_search_provider: search_url = 
CHR - default_search_provider: suggest_url = 
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\pdf.dll
CHR - plugin: ESN Launch Mozilla Plugin (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\2.1.2\npesnlaunch.dll
CHR - plugin: ESN Sonar API (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 7 U17 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Java Deployment Toolkit 7.0.170.2 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: iTunes Application Detector (Enabled) = D:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - Extension: No name found = C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.7_0\
CHR - Extension: No name found = C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: No name found = C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\
CHR - Extension: No name found = C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: No name found = C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehdakiococlfmjcbebbkjkfjhbieknh\5.0.203.0_0\
CHR - Extension: No name found = C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: No name found = C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbangkleohkafngihneedemihgfeikcl\1.0_0\
CHR - Extension: No name found = C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\hehijbfgiekmjfkfjpbkbammjbdenadd\7.9.23.1_0\ietab_nm_
CHR - Extension: No name found = C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\hehijbfgiekmjfkfjpbkbammjbdenadd\7.9.23.1_0\
CHR - Extension: No name found = C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: No name found = C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc\6.2.6_0\
CHR - Extension: No name found = C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
CHR - Extension: No name found = C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\poknhlcknimnnbfcombaooklofipaibk\0.71_0\
 
O1 HOSTS File: ([2014/07/20 12:57:40 | 000,001,114 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1                   secure.tune-up.com
O1 - Hosts: 127.0.0.1                   www.order.tune-up.com
O1 - Hosts: 127.0.0.1                   www.tune-up.com
O1 - Hosts: 127.0.0.1                   www.tune-up.com/order
O1 - Hosts: 127.0.0.1                   www.registertuneup.com
O1 - Hosts: 127.0.0.1                   www.tuneup.de
O2:64bit: - BHO: (Bing Bar Helper) - {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Bing Bar Helper) - {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Evernote extension) - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (Bing Bar) - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
O4:64bit: - HKLM..\Run: [CmPCIaudio] C:\Windows\Syswow64\CMICNFG3.dll (C-Media Corporation)
O4:64bit: - HKLM..\Run: [Launch LCore] C:\Program Files\Logitech Gaming Software\LCore.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [NvBackend] C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [ShadowPlay] C:\Windows\SysNative\nvspcap64.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\Mikey\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
O4 - HKCU..\Run: [DAEMON Tools Lite] D:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (Disc Soft Ltd)
O4 - HKCU..\Run: [DisplayFusion] C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe (Binary Fortress Software)
O4 - HKCU..\Run: [MIKEY-PC] C:\Users\Mikey\AppData\Roaming\amde.exe ()
O4 - HKCU..\Run: [Polar FlowSync]  File not found
O4 - HKCU..\Run: [uTorrent] C:\Users\Mikey\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc.)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_15_0_0_152_Plugin.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Users\Mikey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk = C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
O4 - Startup: C:\Users\Mikey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Mikey.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Clip Image - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=4 File not found
O8:64bit: - Extra context menu item: Clip selection - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=3 File not found
O8:64bit: - Extra context menu item: Clip this page - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=1 File not found
O8:64bit: - Extra context menu item: Clip URL - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=0 File not found
O8:64bit: - Extra context menu item: New Note - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\NewNote.html ()
O8 - Extra context menu item: Clip Image - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=4 File not found
O8 - Extra context menu item: Clip selection - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=3 File not found
O8 - Extra context menu item: Clip this page - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=1 File not found
O8 - Extra context menu item: Clip URL - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=0 File not found
O8 - Extra context menu item: New Note - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\NewNote.html ()
O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html ()
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.76.76 75.75.75.75
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3BF4E769-46BD-4571-BB93-E872E083219D}: DhcpNameServer = 75.75.76.76 75.75.75.75
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7A7F8854-1B54-4F75-AA15-9231B94DF7DD}: DhcpNameServer = 172.20.10.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FC432855-1375-47CE-9F60-1E1BAA5928DB}: DhcpNameServer = 172.20.10.1
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2014/03/02 15:15:49 | 000,000,000 | ---D | M] - D:\Automatically Add to iTunes -- [ NTFS ]
O32 - AutoRun File - [2007/06/11 20:27:33 | 000,000,140 | R--- | M] () - F:\autorun.inf -- [ UDF ]
O33 - MountPoints2\{776c501c-0161-11e4-9536-d43d7e49cda2}\Shell - "" = AutoRun
O33 - MountPoints2\{776c501c-0161-11e4-9536-d43d7e49cda2}\Shell\AutoRun\command - "" = F:\Setup\rsrc\AUTORUN.EXE -- [2007/03/22 17:57:09 | 000,051,336 | R--- | M] ()
O33 - MountPoints2\{776c501c-0161-11e4-9536-d43d7e49cda2}\Shell\dinstall\command - "" = F:\DirectX\DXSETUP.exe -- [2007/05/31 21:23:56 | 000,503,144 | R--- | M] (Microsoft Corporation)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2014/10/25 12:41:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Miro Video Converter
[2014/10/25 12:41:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Participatory Culture Foundation
[2014/10/25 12:38:24 | 000,000,000 | ---D | C] -- C:\Users\Mikey\AppData\Roaming\VOPackage
[2014/10/25 12:38:24 | 000,000,000 | ---D | C] -- C:\Users\Mikey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
[2014/10/25 12:38:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Windows VXM
[2014/10/25 12:38:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Network Accelerater
[2014/10/25 12:37:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Optimizer
[2014/10/25 12:37:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\YouTube Downloader Services
[2014/10/25 12:37:26 | 000,764,416 | -HS- | C] (Abysmal Software) -- C:\Windows\SysWow64\devil.dll
[2014/10/25 12:37:25 | 000,415,744 | -HS- | C] (The Public) -- C:\Windows\SysWow64\avisynth.dll
[2014/10/25 12:37:24 | 000,070,656 | -HS- | C] (www.helixcommunity.org) -- C:\Windows\SysWow64\yv12vfw.dll
[2014/10/25 12:37:23 | 000,070,656 | -HS- | C] (www.helixcommunity.org) -- C:\Windows\SysWow64\i420vfw.dll
[2014/10/25 12:35:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\System Optimizer Pro
[2014/10/25 12:34:22 | 000,000,000 | ---D | C] -- C:\Users\Mikey\Documents\eRightSoft
[2014/10/25 12:34:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ver0BlockAndSurf
[2014/10/25 12:34:14 | 000,278,528 | ---- | C] (Real Networks, Inc) -- C:\Windows\SysWow64\pncrt.dll
[2014/10/25 12:34:13 | 000,550,032 | -HS- | C] (FFmpeg Project) -- C:\Windows\SysWow64\avformat-lav-55.dll
[2014/10/25 12:34:13 | 000,181,392 | -HS- | C] (FFmpeg Project) -- C:\Windows\SysWow64\avutil-lav-52.dll
[2014/10/25 12:34:13 | 000,118,416 | -HS- | C] (FFmpeg Project) -- C:\Windows\SysWow64\swscale-lav-2.dll
[2014/10/25 12:34:13 | 000,098,960 | -HS- | C] (FFmpeg Project) -- C:\Windows\SysWow64\avfilter-lav-4.dll
[2014/10/25 12:34:13 | 000,059,536 | -HS- | C] (FFmpeg Project) -- C:\Windows\SysWow64\avresample-lav-1.dll
[2014/10/25 12:34:12 | 003,109,520 | -HS- | C] (FFmpeg Project) -- C:\Windows\SysWow64\avcodec-lav-55.dll
[2014/10/25 12:34:12 | 000,313,520 | -HS- | C] (1f0.de - Hendrik Leppkes) -- C:\Windows\SysWow64\HLvideo.dll
[2014/10/25 12:34:12 | 000,203,408 | -HS- | C] (1f0.de - Hendrik Leppkes) -- C:\Windows\SysWow64\HLsplit.dll
[2014/10/25 12:34:12 | 000,122,512 | -HS- | C] (1f0.de - Hendrik Leppkes) -- C:\Windows\SysWow64\HLaudio.dll
[2014/10/25 12:34:11 | 000,017,408 | -HS- | C] (RadLight) -- C:\Windows\SysWow64\RLOFRDec.ax
[2014/10/25 12:33:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\eRightSoft
[2014/10/22 21:59:00 | 000,000,000 | -HSD | C] -- C:\Users\Mikey\AppData\Roaming\MIKEY-PC
[2014/10/21 19:16:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2014/10/21 19:15:39 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2014/10/21 19:15:38 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2014/10/21 19:15:38 | 000,000,000 | ---D | C] -- C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
[2014/10/18 16:44:05 | 000,000,000 | ---D | C] -- C:\Users\Mikey\AppData\Local\fontconfig
[2014/10/18 16:42:41 | 000,000,000 | ---D | C] -- C:\Users\Mikey\Documents\convertedVideos
[2014/10/18 16:42:40 | 000,000,000 | ---D | C] -- C:\Users\Mikey\AppData\Local\SkinSoft
[2014/10/18 16:42:07 | 000,000,000 | ---D | C] -- C:\Users\Mikey\AppData\Roaming\Convert Audio Free
[2014/10/16 03:03:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft ASP.NET
[2014/09/28 14:51:28 | 000,000,000 | ---D | C] -- D:\Desktop\Guild Wars 2
[2014/09/28 10:42:58 | 000,000,000 | ---D | C] -- C:\ProgramData\NexonUS
[2014/09/28 10:41:58 | 000,000,000 | ---D | C] -- C:\Users\Mikey\Documents\Vindictus
[2014/09/28 07:51:04 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2014/09/27 16:55:26 | 000,000,000 | ---D | C] -- D:\Desktop\hike
 
========== Files - Modified Within 30 Days ==========
 
[2014/10/25 12:41:50 | 000,002,385 | ---- | M] () -- C:\Users\Public\Desktop\Miro Video Converter.lnk
[2014/10/25 12:28:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/10/25 12:09:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/10/25 11:28:00 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/10/24 20:16:22 | 000,782,470 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014/10/24 20:16:22 | 000,662,384 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014/10/24 20:16:22 | 000,122,252 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014/10/24 20:11:23 | 000,000,222 | ---- | M] () -- D:\Desktop\DayZ.url
[2014/10/24 16:36:18 | 000,027,312 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/10/24 16:36:18 | 000,027,312 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/10/24 16:29:09 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/10/22 22:03:19 | 000,129,752 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014/10/22 18:08:08 | 000,001,106 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/10/22 16:38:03 | 002,664,227 | --S- | M] () -- C:\Users\Mikey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Mikey.exe
[2014/10/22 16:38:03 | 002,664,227 | -HS- | M] () -- C:\Users\Mikey\AppData\Roaming\amde.exe
[2014/10/21 19:16:06 | 000,001,578 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2014/10/18 16:42:41 | 000,000,096 | ---- | M] () -- C:\Users\Mikey\AppData\Roaming\settings.xml
[2014/10/16 03:22:33 | 000,295,216 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2014/10/04 11:21:29 | 000,000,921 | ---- | M] () -- D:\Desktop\Gw2.exe - Shortcut.lnk
[2014/10/01 11:11:26 | 000,063,704 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mwac.sys
[2014/10/01 11:11:16 | 000,093,400 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2014/10/01 11:11:12 | 000,025,816 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2014/09/28 07:51:09 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2014/09/28 07:43:05 | 000,001,026 | ---- | M] () -- D:\Desktop\TreeSize Free.lnk
 
========== Files Created - No Company Name ==========
 
[2014/10/25 12:37:25 | 000,032,256 | -HS- | C] () -- C:\Windows\SysWow64\AVSredirect.dll
[2014/10/25 12:34:13 | 000,109,712 | -HS- | C] () -- C:\Windows\SysWow64\libbluray.dll
[2014/10/25 12:34:12 | 000,188,416 | -HS- | C] () -- C:\Windows\SysWow64\winDCE32.dll
[2014/10/25 12:34:12 | 000,121,344 | -HS- | C] () -- C:\Windows\SysWow64\TAKDSDecoder.ax
[2014/10/25 12:34:12 | 000,107,520 | -HS- | C] () -- C:\Windows\SysWow64\TAKDSDecoder.dll
[2014/10/25 12:34:11 | 000,352,768 | -HS- | C] () -- C:\Windows\SysWow64\ac3DX.ax
[2014/10/25 12:34:11 | 000,112,128 | -HS- | C] () -- C:\Windows\SysWow64\OptimFROG.dll
[2014/10/25 12:34:11 | 000,081,920 | -HS- | C] () -- C:\Windows\SysWow64\aac_parser.ax
[2014/10/24 20:11:23 | 000,000,222 | ---- | C] () -- D:\Desktop\DayZ.url
[2014/10/22 21:58:52 | 002,664,227 | --S- | C] () -- C:\Users\Mikey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Mikey.exe
[2014/10/22 21:58:48 | 002,664,227 | -HS- | C] () -- C:\Users\Mikey\AppData\Roaming\amde.exe
[2014/10/22 18:08:08 | 000,001,106 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/10/18 16:42:41 | 000,000,096 | ---- | C] () -- C:\Users\Mikey\AppData\Roaming\settings.xml
[2014/10/04 11:21:29 | 000,000,921 | ---- | C] () -- D:\Desktop\Gw2.exe - Shortcut.lnk
[2014/09/28 07:51:09 | 000,000,822 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2014/09/28 07:43:05 | 000,001,026 | ---- | C] () -- D:\Desktop\TreeSize Free.lnk
[2014/08/23 23:46:46 | 000,053,299 | ---- | C] () -- C:\Windows\SysWow64\pthreadVC.dll
[2014/06/30 10:46:28 | 000,000,037 | -HS- | C] () -- C:\Users\Mikey\AppData\Local\70149b02515b3bb20dd492.47983420
[2014/06/29 12:27:31 | 000,000,038 | -HS- | C] () -- C:\Users\Mikey\AppData\Local\134e6589520e51682091c0.32666518
[2014/05/29 12:56:36 | 000,451,072 | ---- | C] () -- C:\Windows\SysWow64\ISSRemoveSP.exe
[2014/03/30 10:41:03 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2013/04/07 11:47:18 | 000,000,045 | ---- | C] () -- C:\Users\Mikey\jagex_cl_runescape_LIVE1.dat
[2013/04/07 11:44:51 | 000,000,046 | ---- | C] () -- C:\Users\Mikey\jagex_cl_loginapplet_LIVE.dat
[2013/04/07 11:40:32 | 000,000,044 | ---- | C] () -- C:\Users\Mikey\jagex_cl_runescape_LIVE.dat
[2013/04/07 11:40:32 | 000,000,024 | ---- | C] () -- C:\Users\Mikey\random.dat
[2013/02/24 18:50:58 | 000,270,240 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2013/02/24 18:50:57 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2013/02/03 12:02:16 | 000,122,900 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
[2013/01/26 13:05:40 | 000,000,262 | ---- | C] () -- C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2012/12/15 01:28:05 | 000,018,038 | ---- | C] () -- C:\Users\Mikey\whisper_notify.wav
[2012/12/12 20:49:54 | 000,774,592 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/12/12 20:15:50 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\VmixP6.dll
[2012/12/12 20:15:50 | 000,000,188 | ---- | C] () -- C:\Windows\Cmicnfg3.ini.cfl
[2012/12/12 20:15:49 | 000,002,641 | ---- | C] () -- C:\Windows\cmudax3.ini
[2012/12/12 20:15:49 | 000,002,123 | ---- | C] () -- C:\Windows\Cmicnfg3.ini.cfg
[2012/12/12 20:15:49 | 000,000,124 | ---- | C] () -- C:\Windows\Cmicnfg3.ini.imi
 
========== ZeroAccess Check ==========
 
[2009/07/13 22:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014/06/24 20:05:42 | 014,175,744 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/06/24 19:41:30 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2012/08/21 07:11:31 | 000,857,088 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2012/08/21 07:37:44 | 000,636,928 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2012/08/21 07:08:38 | 000,453,120 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2013/11/29 10:58:18 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\.minecraft
[2014/03/02 11:33:34 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\8BitMMO
[2014/09/23 21:07:42 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\Arrowhead
[2013/12/25 13:55:20 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\Battle.net
[2014/09/23 21:36:11 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\Bitdreamers
[2014/10/18 16:42:07 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\Convert Audio Free
[2014/09/28 07:54:33 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\DAEMON Tools Lite
[2013/04/06 15:09:51 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\DAoC Portal
[2013/04/27 08:57:11 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\Darkfall
[2014/09/23 07:24:32 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\DisplayFusion
[2013/04/06 15:00:24 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\Electronic Arts
[2013/05/01 19:40:48 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\EVEMon
[2014/09/28 07:54:33 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\FileZilla
[2013/04/27 08:07:03 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\Foxit Software
[2014/09/28 14:53:00 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\Guild Wars 2
[2013/02/24 17:15:26 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\JAM Software
[2013/01/01 15:41:49 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\Leadertech
[2014/10/22 21:59:02 | 000,000,000 | -HSD | M] -- C:\Users\Mikey\AppData\Roaming\MIKEY-PC
[2014/03/29 10:09:15 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\Mumble
[2014/07/20 13:02:44 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\MusicBrainz
[2012/12/23 10:19:52 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\OpenOffice.org
[2014/03/01 14:07:48 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\Origin
[2013/06/07 22:52:32 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\RIFT
[2014/03/02 17:34:25 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\steamvr
[2012/12/12 19:55:35 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\SystemRequirementsLab
[2014/04/13 13:06:59 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\Titanium
[2014/07/20 12:59:16 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\TuneUpMedia
[2014/10/25 12:22:49 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\uTorrent
[2014/10/25 12:38:24 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\VOPackage
[2013/05/27 14:05:55 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\{950EB46C-6AC7-4ACC-AB36-9A6A77C08B6A}
 
========== Purity Check ==========
 
 
 
========== Files - Unicode (All) ==========
[2013/03/02 01:42:31 | 000,000,000 | ---D | M](C:\Users\Mikey\Documents\?? ???) -- C:\Users\Mikey\Documents\넥슨 플러그
[2013/03/02 01:42:31 | 000,000,000 | ---D | C](C:\Users\Mikey\Documents\?? ???) -- C:\Users\Mikey\Documents\넥슨 플러그
 
< End of report >

OTL logfile created on: 10/25/2014 12:39:22 PM - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = D:\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17358)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
7.95 Gb Total Physical Memory | 5.40 Gb Available Physical Memory | 67.91% Memory free
7.94 Gb Paging File | 5.12 Gb Available in Paging File | 64.40% Paging File free
Paging file location(s):  [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 55.68 Gb Total Space | 6.71 Gb Free Space | 12.06% Space Free | Partition Type: NTFS
Drive D: | 1667.70 Gb Total Space | 1290.96 Gb Free Space | 77.41% Space Free | Partition Type: NTFS
Unable to calculate disk information.
Drive F: | 6.32 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
 
Computer Name: MIKEY-PC | User Name: Mikey | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2014/10/25 12:31:39 | 000,602,112 | ---- | M] (OldTimer Tools) -- D:\Downloads\OTL.exe
PRC - [2014/10/22 16:38:03 | 002,664,227 | -HS- | M] () -- C:\Users\Mikey\AppData\Roaming\amde.exe
PRC - [2014/10/21 13:22:40 | 001,529,536 | ---- | M] (Valve Corporation) -- D:\Program Files (x86)\Steam\bin\steamwebhelper.exe
PRC - [2014/10/21 13:22:38 | 001,938,624 | ---- | M] (Valve Corporation) -- D:\Program Files (x86)\Steam\Steam.exe
PRC - [2014/10/20 23:51:28 | 002,973,600 | ---- | M] (MicroStudio) -- C:\Program Files (x86)\Windows Network Accelerater\v3\winvxm.exe
PRC - [2014/10/09 20:04:06 | 000,854,344 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2014/09/17 18:49:10 | 001,017,856 | ---- | M] (eRightSoft) -- C:\Program Files (x86)\eRightSoft\SUPER\SUPER.exe
PRC - [2014/09/16 20:15:08 | 002,460,488 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
PRC - [2014/09/16 20:14:57 | 001,795,912 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
PRC - [2014/09/13 14:12:58 | 000,411,968 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2014/09/05 23:22:44 | 002,284,128 | ---- | M] (MicroTools) -- C:\Program Files (x86)\YouTube Downloader Services\youtubeserv.exe
PRC - [2014/09/02 09:35:36 | 000,281,448 | ---- | M] (Binary Fortress Software) -- C:\Program Files (x86)\DisplayFusion\DisplayFusionHookAppWIN6032.exe
PRC - [2014/06/25 05:23:46 | 000,804,472 | ---- | M] () -- C:\Program Files (x86)\System Optimizer Pro\SystemOptimizerPro.exe
PRC - [2014/04/17 20:07:28 | 004,672,920 | ---- | M] (Akamai Technologies, Inc.) -- C:\Users\Mikey\AppData\Local\Akamai\netsession_win.exe
PRC - [2014/03/11 22:36:06 | 000,247,968 | ---- | M] (Microsoft Corporation.) -- C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.EXE
PRC - [2013/12/30 15:07:06 | 000,307,928 | ---- | M] () -- C:\Program Files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe
PRC - [2013/10/22 17:38:50 | 001,103,712 | ---- | M] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) -- C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
PRC - [2013/04/07 10:31:26 | 000,075,136 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2013/03/12 06:32:58 | 000,506,744 | ---- | M] (Oracle Corporation) -- C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
PRC - [2012/05/21 01:26:26 | 000,291,648 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2014/10/22 16:38:03 | 002,664,227 | -HS- | M] () -- C:\Users\Mikey\AppData\Roaming\amde.exe
MOD - [2014/10/21 13:22:58 | 002,226,880 | ---- | M] () -- D:\Program Files (x86)\Steam\video.dll
MOD - [2014/10/21 13:22:40 | 000,682,176 | ---- | M] () -- D:\Program Files (x86)\Steam\bin\chromehtml.dll
MOD - [2014/10/16 03:34:19 | 001,051,136 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\99cdfef98595ed91f14936cf52a49c54\System.Management.ni.dll
MOD - [2014/10/16 03:29:17 | 006,638,592 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\4b335bfaa07fc54f2d72213d33f53e97\System.Data.ni.dll
MOD - [2014/10/16 03:28:59 | 012,435,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\1453d9e9a4989833ef3db4b22549ba1a\System.Windows.Forms.ni.dll
MOD - [2014/10/16 03:28:53 | 001,593,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\836e10dfd0811b303553216f5cb092ef\System.Drawing.ni.dll
MOD - [2014/10/16 03:28:50 | 005,467,648 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\2cf12fa95900b4488a6cb9e4aac51c5c\System.Xml.ni.dll
MOD - [2014/10/16 03:28:47 | 000,978,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\237d509a79aeef6e4635b09450d98f2a\System.Configuration.ni.dll
MOD - [2014/10/16 03:28:36 | 007,991,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\908ba9e296e92b4e14bdc2437edac603\System.ni.dll
MOD - [2014/10/11 13:05:58 | 001,044,776 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2014/10/09 20:04:02 | 008,910,664 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\pdf.dll
MOD - [2014/10/09 20:03:56 | 001,042,760 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\libglesv2.dll
MOD - [2014/10/09 20:03:54 | 000,211,272 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\libegl.dll
MOD - [2014/10/09 20:03:53 | 001,681,224 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\ffmpegsumo.dll
MOD - [2014/10/01 17:16:02 | 000,774,656 | ---- | M] () -- D:\Program Files (x86)\Steam\SDL2.dll
MOD - [2014/09/18 17:03:44 | 000,025,600 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\0483c93466914f3fbd5b44454b0c8a98\Accessibility.ni.dll
MOD - [2014/09/18 17:03:31 | 011,497,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll
MOD - [2014/09/17 18:46:40 | 000,923,648 | -HS- | M] () -- C:\Program Files (x86)\eRightSoft\SUPER\spk\flvdec.spk
MOD - [2014/09/04 17:29:26 | 034,589,376 | ---- | M] () -- D:\Program Files (x86)\Steam\bin\libcef.dll
MOD - [2014/09/04 17:29:26 | 000,837,824 | ---- | M] () -- D:\Program Files (x86)\Steam\bin\ffmpegsumo.dll
MOD - [2014/08/21 12:15:22 | 001,171,456 | ---- | M] () -- D:\Program Files (x86)\Steam\libavcodec-56.dll
MOD - [2014/08/21 12:15:22 | 000,485,888 | ---- | M] () -- D:\Program Files (x86)\Steam\libswscale-3.dll
MOD - [2014/08/21 12:15:22 | 000,442,368 | ---- | M] () -- D:\Program Files (x86)\Steam\libavutil-54.dll
MOD - [2014/08/21 12:15:22 | 000,403,968 | ---- | M] () -- D:\Program Files (x86)\Steam\libavformat-56.dll
MOD - [2014/08/21 12:15:22 | 000,332,800 | ---- | M] () -- D:\Program Files (x86)\Steam\libavresample-2.dll
MOD - [2014/06/25 05:23:46 | 000,804,472 | ---- | M] () -- C:\Program Files (x86)\System Optimizer Pro\SystemOptimizerPro.exe
MOD - [2014/03/20 16:49:19 | 002,952,704 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MOD - [2014/03/07 11:03:58 | 000,109,712 | -HS- | M] () -- C:\Windows\SysWOW64\libbluray.dll
MOD - [2014/01/20 13:17:04 | 000,073,544 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2013/09/26 13:50:14 | 000,433,664 | ---- | M] () -- C:\Program Files (x86)\Evernote\Evernote\libxml2.dll
MOD - [2013/09/26 13:49:28 | 000,315,392 | ---- | M] () -- C:\Program Files (x86)\Evernote\Evernote\libtidy.dll
MOD - [2012/10/05 19:54:00 | 000,188,416 | -HS- | M] () -- C:\Windows\SysWOW64\winDCE32.dll
MOD - [2011/06/14 20:05:10 | 000,121,344 | -HS- | M] () -- C:\Windows\SysWOW64\TAKDSDecoder.ax
MOD - [2011/02/11 10:26:20 | 000,112,128 | -HS- | M] () -- C:\Windows\SysWOW64\OptimFROG.dll
MOD - [2010/01/07 00:00:00 | 000,107,520 | -HS- | M] () -- C:\Windows\SysWOW64\TAKDSDecoder.dll
MOD - [2009/08/10 23:00:00 | 000,352,768 | -HS- | M] () -- C:\Windows\SysWOW64\ac3DX.ax
MOD - [2008/06/12 11:31:00 | 000,028,160 | -HS- | M] () -- C:\Program Files (x86)\eRightSoft\SUPER\spk\SmabT.spk
MOD - [2005/02/22 17:55:02 | 000,081,920 | -HS- | M] () -- C:\Windows\SysWOW64\aac_parser.ax
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2014/09/18 19:25:49 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2014/09/16 20:14:56 | 001,148,744 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe -- (GfExperienceService)
SRV:64bit: - [2014/09/16 20:14:52 | 019,439,944 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe -- (NvStreamSvc)
SRV:64bit: - [2014/08/22 14:14:34 | 000,368,624 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2014/08/22 14:14:34 | 000,023,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2013/05/26 23:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2014/10/20 23:51:28 | 002,973,600 | ---- | M] (MicroStudio) [Auto | Running] -- C:\Program Files (x86)\Windows Network Accelerater\v3\winvxm.exe -- (WindowsVNT_R3)
SRV - [2014/09/25 10:09:26 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/09/16 20:14:57 | 001,795,912 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe -- (NvNetworkService)
SRV - [2014/09/13 14:12:58 | 000,411,968 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2014/09/09 22:35:04 | 005,278,064 | ---- | M] (Binary Fortress Software) [Auto | Running] -- C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe -- (DisplayFusionService)
SRV - [2014/09/05 23:22:44 | 002,284,128 | ---- | M] (MicroTools) [Auto | Running] -- C:\Program Files (x86)\YouTube Downloader Services\youtubeserv.exe -- (YouTubeDownload)
SRV - [2014/07/18 12:13:20 | 000,009,216 | ---- | M] (Hi-Rez Studios) [Auto | Paused] -- D:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe -- (HiPatchService)
SRV - [2014/03/20 16:49:18 | 000,067,224 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2014/03/11 22:36:06 | 000,247,968 | ---- | M] (Microsoft Corporation.) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.EXE -- (BBUpdate)
SRV - [2014/03/11 22:36:06 | 000,193,696 | ---- | M] (Microsoft Corporation.) [Auto | Stopped] -- C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BBSvc.EXE -- (BBSvc)
SRV - [2014/02/25 15:57:46 | 000,568,512 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2014/01/19 12:50:33 | 000,049,152 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\BattlEye\BEService.exe -- (BEService)
SRV - [2013/12/30 15:07:06 | 000,307,928 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe -- (WSWNDA3100v2)
SRV - [2013/09/11 20:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2013/04/07 10:31:26 | 000,075,136 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2010/08/10 21:37:08 | 000,334,848 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\ASUS\Printer Utilities\UsbService64.exe -- (UsbService)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2014/09/16 22:51:20 | 000,197,408 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2014/09/16 20:14:52 | 000,019,272 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys -- (NvStreamKms)
DRV:64bit: - [2014/09/04 13:14:38 | 000,038,048 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvvad64v.sys -- (nvvad_WaveExtensible)
DRV:64bit: - [2014/07/28 13:52:00 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2014/07/17 17:05:06 | 000,125,584 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2014/07/01 15:26:21 | 000,283,064 | ---- | M] (Disc Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2014/04/13 13:06:19 | 000,031,232 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tap0901.sys -- (tap0901)
DRV:64bit: - [2013/10/01 20:22:20 | 000,056,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2013/09/25 21:10:12 | 002,975,960 | R--- | M] (Realtek Semiconductor Corporation                           ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rtwlane.sys -- (RTWlanE)
DRV:64bit: - [2013/07/25 15:53:46 | 000,023,040 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netaapl64.sys -- (Netaapl)
DRV:64bit: - [2013/01/18 23:52:08 | 000,046,568 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ISCTD64.sys -- (ISCT)
DRV:64bit: - [2012/11/07 18:00:32 | 000,102,400 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\XHCIdrv.sys -- (XHCIdrv)
DRV:64bit: - [2012/10/02 16:26:46 | 000,066,360 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGSHidFilt.Sys -- (LGSHidFilt)
DRV:64bit: - [2012/09/19 10:02:08 | 000,102,368 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus)
DRV:64bit: - [2012/09/19 10:02:06 | 000,203,104 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm)
DRV:64bit: - [2012/08/23 08:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012/08/21 13:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2012/07/17 18:12:08 | 000,062,784 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2012/05/21 01:25:30 | 000,789,824 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3xhc.sys -- (iusb3xhc)
DRV:64bit: - [2012/05/21 01:25:30 | 000,357,184 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3hub.sys -- (iusb3hub)
DRV:64bit: - [2012/05/21 01:25:30 | 000,019,264 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iusb3hcs.sys -- (iusb3hcs)
DRV:64bit: - [2012/03/01 00:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012/02/15 23:42:00 | 000,676,968 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011/12/26 15:27:24 | 000,015,288 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\ampa.sys -- (ampa)
DRV:64bit: - [2011/12/12 16:42:00 | 001,256,192 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\bcmwlhigh664.sys -- (BCMH43XX)
DRV:64bit: - [2011/03/11 00:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 00:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/11/20 07:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/02/03 10:21:56 | 000,047,632 | ---- | M] (CACE Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\npf.sys -- (NPF)
DRV:64bit: - [2009/11/23 19:38:00 | 000,016,008 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGVirHid.sys -- (LGVirHid)
DRV:64bit: - [2009/11/23 19:37:50 | 000,022,408 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGBusEnum.sys -- (LGBusEnum)
DRV:64bit: - [2009/10/22 20:45:40 | 001,155,072 | ---- | M] (C-Media Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\cmudax3.sys -- (cmuda3)
DRV:64bit: - [2009/07/13 19:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 19:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 19:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 14:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 14:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 14:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 14:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2008/05/06 16:06:00 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wdcsam64.sys -- (WDC_SAM)
DRV:64bit: - [2007/12/17 10:25:14 | 000,047,616 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vuhub.sys -- (vuhub)
DRV:64bit: - [2007/01/19 17:24:24 | 000,025,312 | R--- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\SCMNdisP.sys -- (SCMNdisP)
DRV - [2011/01/06 11:06:56 | 000,011,888 | ---- | M] (MSI) [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\Setup Files\Ms7758v270\NTIOLib_X64.sys -- (NTIOLib_1_0_6)
DRV - [2009/07/13 19:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 57 27 BB F1 6F 39 CE 01  [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {E6957116-DFE1-4A9E-9922-66747C34C5F0}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE11SR
IE - HKCU\..\SearchScopes\{E6957116-DFE1-4A9E-9922-66747C34C5F0}: "URL" = https://search.yahoo...p={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;<local>
 
 
========== FireFox ==========
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: D:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll File not found
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=2.1.2: C:\Program Files (x86)\Battlelog Web Plugins\2.1.2\npesnlaunch.dll File not found
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: D:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.6: D:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll File not found
 
 
 
========== Chrome  ==========
 
CHR - default_search_provider:  (Enabled)
CHR - default_search_provider: search_url = 
CHR - default_search_provider: suggest_url = 
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\pdf.dll
CHR - plugin: ESN Launch Mozilla Plugin (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\2.1.2\npesnlaunch.dll
CHR - plugin: ESN Sonar API (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 7 U17 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Java Deployment Toolkit 7.0.170.2 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: iTunes Application Detector (Enabled) = D:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - Extension: No name found = C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.7_0\
CHR - Extension: No name found = C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: No name found = C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\
CHR - Extension: No name found = C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: No name found = C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehdakiococlfmjcbebbkjkfjhbieknh\5.0.203.0_0\
CHR - Extension: No name found = C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: No name found = C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbangkleohkafngihneedemihgfeikcl\1.0_0\
CHR - Extension: No name found = C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\hehijbfgiekmjfkfjpbkbammjbdenadd\7.9.23.1_0\ietab_nm_
CHR - Extension: No name found = C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\hehijbfgiekmjfkfjpbkbammjbdenadd\7.9.23.1_0\
CHR - Extension: No name found = C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: No name found = C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc\6.2.6_0\
CHR - Extension: No name found = C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
CHR - Extension: No name found = C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\poknhlcknimnnbfcombaooklofipaibk\0.71_0\
 
O1 HOSTS File: ([2014/07/20 12:57:40 | 000,001,114 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1                   secure.tune-up.com
O1 - Hosts: 127.0.0.1                   www.order.tune-up.com
O1 - Hosts: 127.0.0.1                   www.tune-up.com
O1 - Hosts: 127.0.0.1                   www.tune-up.com/order
O1 - Hosts: 127.0.0.1                   www.registertuneup.com
O1 - Hosts: 127.0.0.1                   www.tuneup.de
O2:64bit: - BHO: (Bing Bar Helper) - {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Bing Bar Helper) - {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Evernote extension) - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (Bing Bar) - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
O4:64bit: - HKLM..\Run: [CmPCIaudio] C:\Windows\Syswow64\CMICNFG3.dll (C-Media Corporation)
O4:64bit: - HKLM..\Run: [Launch LCore] C:\Program Files\Logitech Gaming Software\LCore.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [NvBackend] C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [ShadowPlay] C:\Windows\SysNative\nvspcap64.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\Mikey\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
O4 - HKCU..\Run: [DAEMON Tools Lite] D:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (Disc Soft Ltd)
O4 - HKCU..\Run: [DisplayFusion] C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe (Binary Fortress Software)
O4 - HKCU..\Run: [MIKEY-PC] C:\Users\Mikey\AppData\Roaming\amde.exe ()
O4 - HKCU..\Run: [Polar FlowSync]  File not found
O4 - HKCU..\Run: [uTorrent] C:\Users\Mikey\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc.)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_15_0_0_152_Plugin.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Users\Mikey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk = C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
O4 - Startup: C:\Users\Mikey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Mikey.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Clip Image - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=4 File not found
O8:64bit: - Extra context menu item: Clip selection - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=3 File not found
O8:64bit: - Extra context menu item: Clip this page - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=1 File not found
O8:64bit: - Extra context menu item: Clip URL - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=0 File not found
O8:64bit: - Extra context menu item: New Note - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\NewNote.html ()
O8 - Extra context menu item: Clip Image - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=4 File not found
O8 - Extra context menu item: Clip selection - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=3 File not found
O8 - Extra context menu item: Clip this page - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=1 File not found
O8 - Extra context menu item: Clip URL - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=0 File not found
O8 - Extra context menu item: New Note - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\NewNote.html ()
O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html ()
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.76.76 75.75.75.75
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3BF4E769-46BD-4571-BB93-E872E083219D}: DhcpNameServer = 75.75.76.76 75.75.75.75
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7A7F8854-1B54-4F75-AA15-9231B94DF7DD}: DhcpNameServer = 172.20.10.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FC432855-1375-47CE-9F60-1E1BAA5928DB}: DhcpNameServer = 172.20.10.1
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2014/03/02 15:15:49 | 000,000,000 | ---D | M] - D:\Automatically Add to iTunes -- [ NTFS ]
O32 - AutoRun File - [2007/06/11 20:27:33 | 000,000,140 | R--- | M] () - F:\autorun.inf -- [ UDF ]
O33 - MountPoints2\{776c501c-0161-11e4-9536-d43d7e49cda2}\Shell - "" = AutoRun
O33 - MountPoints2\{776c501c-0161-11e4-9536-d43d7e49cda2}\Shell\AutoRun\command - "" = F:\Setup\rsrc\AUTORUN.EXE -- [2007/03/22 17:57:09 | 000,051,336 | R--- | M] ()
O33 - MountPoints2\{776c501c-0161-11e4-9536-d43d7e49cda2}\Shell\dinstall\command - "" = F:\DirectX\DXSETUP.exe -- [2007/05/31 21:23:56 | 000,503,144 | R--- | M] (Microsoft Corporation)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2014/10/25 12:41:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Miro Video Converter
[2014/10/25 12:41:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Participatory Culture Foundation
[2014/10/25 12:38:24 | 000,000,000 | ---D | C] -- C:\Users\Mikey\AppData\Roaming\VOPackage
[2014/10/25 12:38:24 | 000,000,000 | ---D | C] -- C:\Users\Mikey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
[2014/10/25 12:38:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Windows VXM
[2014/10/25 12:38:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Network Accelerater
[2014/10/25 12:37:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Optimizer
[2014/10/25 12:37:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\YouTube Downloader Services
[2014/10/25 12:37:26 | 000,764,416 | -HS- | C] (Abysmal Software) -- C:\Windows\SysWow64\devil.dll
[2014/10/25 12:37:25 | 000,415,744 | -HS- | C] (The Public) -- C:\Windows\SysWow64\avisynth.dll
[2014/10/25 12:37:24 | 000,070,656 | -HS- | C] (www.helixcommunity.org) -- C:\Windows\SysWow64\yv12vfw.dll
[2014/10/25 12:37:23 | 000,070,656 | -HS- | C] (www.helixcommunity.org) -- C:\Windows\SysWow64\i420vfw.dll
[2014/10/25 12:35:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\System Optimizer Pro
[2014/10/25 12:34:22 | 000,000,000 | ---D | C] -- C:\Users\Mikey\Documents\eRightSoft
[2014/10/25 12:34:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ver0BlockAndSurf
[2014/10/25 12:34:14 | 000,278,528 | ---- | C] (Real Networks, Inc) -- C:\Windows\SysWow64\pncrt.dll
[2014/10/25 12:34:13 | 000,550,032 | -HS- | C] (FFmpeg Project) -- C:\Windows\SysWow64\avformat-lav-55.dll
[2014/10/25 12:34:13 | 000,181,392 | -HS- | C] (FFmpeg Project) -- C:\Windows\SysWow64\avutil-lav-52.dll
[2014/10/25 12:34:13 | 000,118,416 | -HS- | C] (FFmpeg Project) -- C:\Windows\SysWow64\swscale-lav-2.dll
[2014/10/25 12:34:13 | 000,098,960 | -HS- | C] (FFmpeg Project) -- C:\Windows\SysWow64\avfilter-lav-4.dll
[2014/10/25 12:34:13 | 000,059,536 | -HS- | C] (FFmpeg Project) -- C:\Windows\SysWow64\avresample-lav-1.dll
[2014/10/25 12:34:12 | 003,109,520 | -HS- | C] (FFmpeg Project) -- C:\Windows\SysWow64\avcodec-lav-55.dll
[2014/10/25 12:34:12 | 000,313,520 | -HS- | C] (1f0.de - Hendrik Leppkes) -- C:\Windows\SysWow64\HLvideo.dll
[2014/10/25 12:34:12 | 000,203,408 | -HS- | C] (1f0.de - Hendrik Leppkes) -- C:\Windows\SysWow64\HLsplit.dll
[2014/10/25 12:34:12 | 000,122,512 | -HS- | C] (1f0.de - Hendrik Leppkes) -- C:\Windows\SysWow64\HLaudio.dll
[2014/10/25 12:34:11 | 000,017,408 | -HS- | C] (RadLight) -- C:\Windows\SysWow64\RLOFRDec.ax
[2014/10/25 12:33:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\eRightSoft
[2014/10/22 21:59:00 | 000,000,000 | -HSD | C] -- C:\Users\Mikey\AppData\Roaming\MIKEY-PC
[2014/10/21 19:16:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2014/10/21 19:15:39 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2014/10/21 19:15:38 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2014/10/21 19:15:38 | 000,000,000 | ---D | C] -- C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
[2014/10/18 16:44:05 | 000,000,000 | ---D | C] -- C:\Users\Mikey\AppData\Local\fontconfig
[2014/10/18 16:42:41 | 000,000,000 | ---D | C] -- C:\Users\Mikey\Documents\convertedVideos
[2014/10/18 16:42:40 | 000,000,000 | ---D | C] -- C:\Users\Mikey\AppData\Local\SkinSoft
[2014/10/18 16:42:07 | 000,000,000 | ---D | C] -- C:\Users\Mikey\AppData\Roaming\Convert Audio Free
[2014/10/16 03:03:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft ASP.NET
[2014/09/28 14:51:28 | 000,000,000 | ---D | C] -- D:\Desktop\Guild Wars 2
[2014/09/28 10:42:58 | 000,000,000 | ---D | C] -- C:\ProgramData\NexonUS
[2014/09/28 10:41:58 | 000,000,000 | ---D | C] -- C:\Users\Mikey\Documents\Vindictus
[2014/09/28 07:51:04 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2014/09/27 16:55:26 | 000,000,000 | ---D | C] -- D:\Desktop\hike
 
========== Files - Modified Within 30 Days ==========
 
[2014/10/25 12:41:50 | 000,002,385 | ---- | M] () -- C:\Users\Public\Desktop\Miro Video Converter.lnk
[2014/10/25 12:28:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/10/25 12:09:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/10/25 11:28:00 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/10/24 20:16:22 | 000,782,470 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014/10/24 20:16:22 | 000,662,384 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014/10/24 20:16:22 | 000,122,252 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014/10/24 20:11:23 | 000,000,222 | ---- | M] () -- D:\Desktop\DayZ.url
[2014/10/24 16:36:18 | 000,027,312 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/10/24 16:36:18 | 000,027,312 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/10/24 16:29:09 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/10/22 22:03:19 | 000,129,752 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014/10/22 18:08:08 | 000,001,106 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/10/22 16:38:03 | 002,664,227 | --S- | M] () -- C:\Users\Mikey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Mikey.exe
[2014/10/22 16:38:03 | 002,664,227 | -HS- | M] () -- C:\Users\Mikey\AppData\Roaming\amde.exe
[2014/10/21 19:16:06 | 000,001,578 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2014/10/18 16:42:41 | 000,000,096 | ---- | M] () -- C:\Users\Mikey\AppData\Roaming\settings.xml
[2014/10/16 03:22:33 | 000,295,216 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2014/10/04 11:21:29 | 000,000,921 | ---- | M] () -- D:\Desktop\Gw2.exe - Shortcut.lnk
[2014/10/01 11:11:26 | 000,063,704 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mwac.sys
[2014/10/01 11:11:16 | 000,093,400 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2014/10/01 11:11:12 | 000,025,816 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2014/09/28 07:51:09 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2014/09/28 07:43:05 | 000,001,026 | ---- | M] () -- D:\Desktop\TreeSize Free.lnk
 
========== Files Created - No Company Name ==========
 
[2014/10/25 12:37:25 | 000,032,256 | -HS- | C] () -- C:\Windows\SysWow64\AVSredirect.dll
[2014/10/25 12:34:13 | 000,109,712 | -HS- | C] () -- C:\Windows\SysWow64\libbluray.dll
[2014/10/25 12:34:12 | 000,188,416 | -HS- | C] () -- C:\Windows\SysWow64\winDCE32.dll
[2014/10/25 12:34:12 | 000,121,344 | -HS- | C] () -- C:\Windows\SysWow64\TAKDSDecoder.ax
[2014/10/25 12:34:12 | 000,107,520 | -HS- | C] () -- C:\Windows\SysWow64\TAKDSDecoder.dll
[2014/10/25 12:34:11 | 000,352,768 | -HS- | C] () -- C:\Windows\SysWow64\ac3DX.ax
[2014/10/25 12:34:11 | 000,112,128 | -HS- | C] () -- C:\Windows\SysWow64\OptimFROG.dll
[2014/10/25 12:34:11 | 000,081,920 | -HS- | C] () -- C:\Windows\SysWow64\aac_parser.ax
[2014/10/24 20:11:23 | 000,000,222 | ---- | C] () -- D:\Desktop\DayZ.url
[2014/10/22 21:58:52 | 002,664,227 | --S- | C] () -- C:\Users\Mikey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Mikey.exe
[2014/10/22 21:58:48 | 002,664,227 | -HS- | C] () -- C:\Users\Mikey\AppData\Roaming\amde.exe
[2014/10/22 18:08:08 | 000,001,106 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/10/18 16:42:41 | 000,000,096 | ---- | C] () -- C:\Users\Mikey\AppData\Roaming\settings.xml
[2014/10/04 11:21:29 | 000,000,921 | ---- | C] () -- D:\Desktop\Gw2.exe - Shortcut.lnk
[2014/09/28 07:51:09 | 000,000,822 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2014/09/28 07:43:05 | 000,001,026 | ---- | C] () -- D:\Desktop\TreeSize Free.lnk
[2014/08/23 23:46:46 | 000,053,299 | ---- | C] () -- C:\Windows\SysWow64\pthreadVC.dll
[2014/06/30 10:46:28 | 000,000,037 | -HS- | C] () -- C:\Users\Mikey\AppData\Local\70149b02515b3bb20dd492.47983420
[2014/06/29 12:27:31 | 000,000,038 | -HS- | C] () -- C:\Users\Mikey\AppData\Local\134e6589520e51682091c0.32666518
[2014/05/29 12:56:36 | 000,451,072 | ---- | C] () -- C:\Windows\SysWow64\ISSRemoveSP.exe
[2014/03/30 10:41:03 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2013/04/07 11:47:18 | 000,000,045 | ---- | C] () -- C:\Users\Mikey\jagex_cl_runescape_LIVE1.dat
[2013/04/07 11:44:51 | 000,000,046 | ---- | C] () -- C:\Users\Mikey\jagex_cl_loginapplet_LIVE.dat
[2013/04/07 11:40:32 | 000,000,044 | ---- | C] () -- C:\Users\Mikey\jagex_cl_runescape_LIVE.dat
[2013/04/07 11:40:32 | 000,000,024 | ---- | C] () -- C:\Users\Mikey\random.dat
[2013/02/24 18:50:58 | 000,270,240 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2013/02/24 18:50:57 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2013/02/03 12:02:16 | 000,122,900 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
[2013/01/26 13:05:40 | 000,000,262 | ---- | C] () -- C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2012/12/15 01:28:05 | 000,018,038 | ---- | C] () -- C:\Users\Mikey\whisper_notify.wav
[2012/12/12 20:49:54 | 000,774,592 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/12/12 20:15:50 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\VmixP6.dll
[2012/12/12 20:15:50 | 000,000,188 | ---- | C] () -- C:\Windows\Cmicnfg3.ini.cfl
[2012/12/12 20:15:49 | 000,002,641 | ---- | C] () -- C:\Windows\cmudax3.ini
[2012/12/12 20:15:49 | 000,002,123 | ---- | C] () -- C:\Windows\Cmicnfg3.ini.cfg
[2012/12/12 20:15:49 | 000,000,124 | ---- | C] () -- C:\Windows\Cmicnfg3.ini.imi
 
========== ZeroAccess Check ==========
 
[2009/07/13 22:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014/06/24 20:05:42 | 014,175,744 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/06/24 19:41:30 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2012/08/21 07:11:31 | 000,857,088 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2012/08/21 07:37:44 | 000,636,928 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2012/08/21 07:08:38 | 000,453,120 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2013/11/29 10:58:18 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\.minecraft
[2014/03/02 11:33:34 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\8BitMMO
[2014/09/23 21:07:42 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\Arrowhead
[2013/12/25 13:55:20 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\Battle.net
[2014/09/23 21:36:11 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\Bitdreamers
[2014/10/18 16:42:07 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\Convert Audio Free
[2014/09/28 07:54:33 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\DAEMON Tools Lite
[2013/04/06 15:09:51 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\DAoC Portal
[2013/04/27 08:57:11 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\Darkfall
[2014/09/23 07:24:32 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\DisplayFusion
[2013/04/06 15:00:24 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\Electronic Arts
[2013/05/01 19:40:48 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\EVEMon
[2014/09/28 07:54:33 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\FileZilla
[2013/04/27 08:07:03 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\Foxit Software
[2014/09/28 14:53:00 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\Guild Wars 2
[2013/02/24 17:15:26 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\JAM Software
[2013/01/01 15:41:49 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\Leadertech
[2014/10/22 21:59:02 | 000,000,000 | -HSD | M] -- C:\Users\Mikey\AppData\Roaming\MIKEY-PC
[2014/03/29 10:09:15 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\Mumble
[2014/07/20 13:02:44 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\MusicBrainz
[2012/12/23 10:19:52 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\OpenOffice.org
[2014/03/01 14:07:48 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\Origin
[2013/06/07 22:52:32 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\RIFT
[2014/03/02 17:34:25 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\steamvr
[2012/12/12 19:55:35 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\SystemRequirementsLab
[2014/04/13 13:06:59 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\Titanium
[2014/07/20 12:59:16 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\TuneUpMedia
[2014/10/25 12:22:49 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\uTorrent
[2014/10/25 12:38:24 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\VOPackage
[2013/05/27 14:05:55 | 000,000,000 | ---D | M] -- C:\Users\Mikey\AppData\Roaming\{950EB46C-6AC7-4ACC-AB36-9A6A77C08B6A}
 
========== Purity Check ==========
 
 
 
========== Files - Unicode (All) ==========
[2013/03/02 01:42:31 | 000,000,000 | ---D | M](C:\Users\Mikey\Documents\?? ???) -- C:\Users\Mikey\Documents\넥슨 플러그
[2013/03/02 01:42:31 | 000,000,000 | ---D | C](C:\Users\Mikey\Documents\?? ???) -- C:\Users\Mikey\Documents\넥슨 플러그
 
< End of report >
 
 

OTL Extras logfile created on: 10/25/2014 12:39:22 PM - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = D:\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17358)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
7.95 Gb Total Physical Memory | 5.40 Gb Available Physical Memory | 67.91% Memory free
7.94 Gb Paging File | 5.12 Gb Available in Paging File | 64.40% Paging File free
Paging file location(s):  [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 55.68 Gb Total Space | 6.71 Gb Free Space | 12.06% Space Free | Partition Type: NTFS
Drive D: | 1667.70 Gb Total Space | 1290.96 Gb Free Space | 77.41% Space Free | Partition Type: NTFS
Unable to calculate disk information.
Drive F: | 6.32 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
 
Computer Name: MIKEY-PC | User Name: Mikey | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "D:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "D:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "D:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "D:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0495B608-82AC-4627-9864-3268D47D911A}" = lport=80 | protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe | 
"{09D4D232-9FCB-47D9-B4D2-DC81624E0521}" = lport=445 | protocol=6 | dir=in | app=system | 
"{0F52A7A3-9F20-4E07-BDB9-AF8A725CE296}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe | 
"{132EC1D6-28FB-4F1A-AC68-E15310EE9566}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe | 
"{18CB58B3-F98D-44A7-81B6-3F57C573B19B}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{1B178731-FFB0-443A-BCC0-6AAF38BE6878}" = rport=137 | protocol=17 | dir=out | app=system | 
"{26EAA20C-9CA8-4CD1-B1B7-04B0D332255D}" = lport=47987 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe | 
"{27CB4210-07F9-45B1-B7CD-F43518E744BF}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{34252907-7996-4C3B-8EE5-BEBDCC2D62B6}" = lport=48000 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | 
"{3E26F0DA-CD5D-45FA-A3F4-479E5D78F1D9}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe | 
"{41A6DABA-848A-4476-A729-B0457EA77CAC}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe | 
"{43CF54BB-71C3-48E4-A012-009E273598FC}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{52A5792F-19D1-4F68-AA8E-D0CBD6DEBF5A}" = lport=80 | protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe | 
"{593DFAE3-4B16-4653-8DD1-67E67565CD11}" = lport=137 | protocol=17 | dir=in | app=system | 
"{5C2ABF7D-861A-4A3D-A393-649EE325A309}" = lport=48000 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | 
"{606B3FEC-5444-4A15-B3BF-2671EE1A6D25}" = rport=445 | protocol=6 | dir=out | app=system | 
"{6709132C-39EC-4CBE-BC14-51790DF4168E}" = rport=139 | protocol=6 | dir=out | app=system | 
"{6B956448-BA13-4045-919C-A8624FCBC598}" = rport=138 | protocol=17 | dir=out | app=system | 
"{77884975-76AB-44CD-A44C-8431660AAB95}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{78F01D12-857F-4701-8E18-0E8F5F189E17}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{7B5CC970-9C34-4FAB-B942-ED96E636C73A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{92E9AFFA-7373-4F89-A13E-EA26E7A85FA3}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{9944D869-298E-4E38-9583-25B3A612D721}" = lport=48000 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | 
"{9DA5E8F2-3CC2-49A8-9A5E-41F7B162CD98}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{A108FC62-72DB-4A39-8C31-09D99B8E46B3}" = lport=138 | protocol=17 | dir=in | app=system | 
"{A3B802FF-115C-45AB-A7CC-944242B75497}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{A4F69296-FCDF-44DA-8E62-87CB0BC2C573}" = lport=47987 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe | 
"{B4650D6A-D9DD-4C14-9D43-4E8A2BDDF18C}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | [email protected],-28539 | 
"{B4B6512C-37EC-44E0-B9F7-6B20DB4A1671}" = lport=47984 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe | 
"{BBF17C91-9099-4B2D-98F9-2ECA3F8B4639}" = lport=443 | protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe | 
"{BF925158-E37A-4ABD-A8A9-832576B72819}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{C298A033-6517-4BDE-9ADF-C2ACACF1BFFB}" = lport=47991 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | 
"{C403073D-061A-4E79-BC7B-4F4CF3C072ED}" = lport=47991 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | 
"{D0663FE8-9B1D-47FD-BCC3-098BF4A27A56}" = lport=47991 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | 
"{D4CF0EA8-83D8-4589-8492-C82EC7423C78}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{DFEDE310-4C5F-40D7-A33E-34BF90349DF3}" = lport=443 | protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe | 
"{F50023C8-EEB8-484B-90CE-ED9FB49C62CA}" = lport=3389 | protocol=6 | dir=in | app=system | 
"{F5D64482-1EF0-43C0-BBE9-09F135C4C9DE}" = rport=10243 | protocol=6 | dir=out | app=system | 
"{F8A3C25F-B90A-43A5-ABD5-8AD8153BEFFA}" = lport=10243 | protocol=6 | dir=in | app=system | 
"{F9C9BE82-F8E2-4597-886F-C477B7057FAB}" = lport=139 | protocol=6 | dir=in | app=system | 
"{FA683605-CC68-4576-90A3-D3C511A47D25}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01503D84-42C4-4507-83C5-498DC0BE6155}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{06FEFEDA-D1D8-40D4-A7B9-BF8C2CE04258}" = protocol=6 | dir=in | app=c:\users\mikey\appdata\roaming\utorrent\utorrent.exe | 
"{0DA192C5-549F-463F-AFCF-A6D93739EBD4}" = protocol=1 | dir=out | [email protected],-28544 | 
"{0ECF87F7-5F89-436C-996B-F60B6E37E90A}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | 
"{1693A5A1-D5BC-445F-AE03-6315B5A120BC}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{1754F0E2-AF64-4455-8874-B51DCCD8CDCC}" = protocol=6 | dir=in | app=d:\program files (x86)\steam\steamapps\common\dayz\dayz.exe | 
"{1B568891-51F4-41FB-BEFC-BA956374F18D}" = protocol=6 | dir=in | app=d:\program files (x86)\steam\steamapps\common\vindictus\en-us\nxsteam.exe | 
"{1DE76912-0B9F-43CA-B380-D7DF79E67C6A}" = protocol=6 | dir=in | app=d:\program files (x86)\steam\steam.exe | 
"{1EFACA7D-4049-49B0-B7AB-1C54CA7D8DFC}" = protocol=6 | dir=in | app=c:\program files (x86)\asus\printer utilities\usbservice64.exe | 
"{208CE29F-8312-42DC-841D-8EAC71714E83}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{22A40D2F-D535-4487-84A1-617FDDA5F340}" = protocol=17 | dir=in | app=d:\program files (x86)\steam\steamapps\common\vindictus\en-us\nxsteam.exe | 
"{25859AD9-27C1-4B11-AE89-AD2C3CA95A45}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3235\agent.exe | 
"{296F1F7A-FB0F-4D5F-807E-A72BEB5ECE4B}" = protocol=17 | dir=in | app=c:\program files (x86)\asus\printer utilities\usbservice64.exe | 
"{2BB7948A-83E7-4CD6-B641-8CAB477F1D0B}" = protocol=6 | dir=in | app=c:\program files (x86)\battle.net\battle.net.exe | 
"{2E8ED404-E91A-4942-8E3B-1B4FB36BB7F5}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe | 
"{2F5295B0-856B-454C-AFC5-FECA5A6A73A0}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2737\agent.exe | 
"{2F9FDB64-ACCA-4C1A-AE5D-99BB54CA8D7A}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{30D2A878-FFF3-4FB1-BC7E-988A890E165D}" = protocol=17 | dir=in | app=c:\users\mikey\appdata\roaming\utorrent\utorrent.exe | 
"{3371BD99-53F5-4014-8F82-DC86948CCF50}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | 
"{33B09970-B48F-46A8-81F0-DF803B85A53D}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | 
"{34D79CC8-5E84-438F-847F-4AC45497E845}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{40278579-7551-4DA2-B7DF-4B8E25CBCA84}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\rust\legacy\rust.exe | 
"{42632264-913B-4BFC-8FFF-8712E4507262}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3235\agent.exe | 
"{4D429DCA-63AB-4F52-AD6B-DDDFE8CA3D27}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{4FF83209-5CFD-4A75-A0E5-BC5BC3EFD159}" = protocol=17 | dir=in | app=d:\program files (x86)\steam\steamapps\common\vindictus\en-us\nmservice.exe | 
"{510448D7-D99B-49FA-91B1-EDF5E374CB4B}" = protocol=17 | dir=in | app=d:\program files (x86)\steam\steamapps\common\dayz\dayz.exe | 
"{515E10F1-09D1-4707-929A-78C617FFD61B}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{52466371-C792-4763-8EB7-C70985A38C43}" = protocol=17 | dir=in | app=c:\users\mikey\appdata\roaming\utorrent\utorrent.exe | 
"{59F93B3B-6E84-4D43-B2E8-04E4E37C333A}" = protocol=1 | dir=in | [email protected],-28543 | 
"{5AEAEEEF-2A42-42F5-A330-368D7E20C4BE}" = protocol=58 | dir=out | [email protected],-28546 | 
"{5BA18EF4-3CF9-4E98-A92B-5C27CB20374C}" = protocol=6 | dir=in | app=d:\program files (x86)\steam\bin\steamwebhelper.exe | 
"{614CB5D3-712F-45C1-A3B4-EE52079E9682}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3235\agent.exe | 
"{6186DC71-7361-4BEE-8897-4BFAE07DE9CE}" = protocol=58 | dir=in | [email protected],-28545 | 
"{669100E6-3430-4878-83E7-A3B67C2AF755}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | 
"{682A60C7-B738-431B-9AA4-CA91E551F0F5}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{770B07A4-D47D-4A9C-92E8-E95A81147923}" = protocol=17 | dir=in | app=d:\program files (x86)\steam\steamapps\common\gauntlet\binaries\gauntlet.exe | 
"{78A62B10-3972-4AF6-9C0A-F413813CFBE8}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | 
"{802A1295-E3CA-4658-ABD6-D375BC93B427}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{81C37439-D69A-4380-BBDE-43ACE313E993}" = protocol=6 | dir=in | app=f:\games\starcraft ii\starcraft ii public test.exe | 
"{8932C491-FAC4-4260-8908-FC5F286B35CB}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe | 
"{8C511FA8-F36C-473C-ACE6-FEAAA9C4316E}" = protocol=6 | dir=in | app=d:\program files (x86)\steam\steamapps\common\vindictus\en-us\nmservice.exe | 
"{8D402E82-C736-4482-979D-FFDFC097AFF6}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{919F07DF-E9CA-497C-993D-932CF5062D68}" = protocol=17 | dir=in | app=f:\games\starcraft ii\starcraft ii.exe | 
"{93269172-58DA-4941-9E44-4F40D91AEE6B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{95152D9E-C33C-4532-A933-139E2A4B9C67}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | 
"{9F8821F7-3696-434B-A5CA-9D0848EB2FBA}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{A109746D-E497-4BE6-A27D-421EB70DADCE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\rust\experimental\rust.exe | 
"{A1190FB1-FD52-4EC8-8987-296B3C976E0E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\rust\legacy\rust.exe | 
"{A9BB6E24-6056-45EA-A974-161838BE178B}" = protocol=6 | dir=in | app=d:\program files (x86)\steam\steamapps\common\gauntlet\binaries\gauntlet.exe | 
"{AA0EF079-97CF-429C-9C9D-8A756DE2E9F0}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{AAC58648-DDAB-4765-90FF-06D917DCC1AA}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe | 
"{AB76C0DA-AC3E-4ADC-9DD4-67E87B7F4947}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{AF50AB2C-6D63-4BA0-9400-38963B49149B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{AF62DE58-8883-4D06-8058-D330A3CB8D09}" = protocol=17 | dir=in | app=d:\program files (x86)\steam\bin\steamwebhelper.exe | 
"{B308CBE5-C2F0-4FB6-BCF8-DA40170A8D3F}" = protocol=6 | dir=in | app=d:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe | 
"{B53184B3-5D52-4B60-B2C1-ED8BDB1F2BA4}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{B60BA122-4326-4362-8919-FC3EF35068F8}" = dir=in | app=d:\program files (x86)\itunes\itunes.exe | 
"{BD33A60F-AEFA-4F21-98E8-AB60EDA580C9}" = protocol=6 | dir=out | app=system | 
"{BD7EDB5D-7353-470A-BB4F-EFBD3A0167EE}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2737\agent.exe | 
"{C6C80C26-2A78-42DB-AA72-71DE4D5E0836}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\rust\experimental\rust.exe | 
"{CF42766B-0614-4B7E-BD07-A3C5B164615E}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2753\agent.exe | 
"{CF5E8270-1154-494E-8D58-56485009A506}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3286\agent.exe | 
"{D1A46C86-5919-4988-9EA5-5DBC4FFE8097}" = protocol=6 | dir=in | app=c:\users\mikey\appdata\roaming\utorrent\utorrent.exe | 
"{D8EFF464-6743-4FFB-A7C7-799E1583C9B0}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe | 
"{DA6D4472-BA67-45E5-854F-DC111CCE7B83}" = protocol=6 | dir=in | app=f:\games\starcraft ii\starcraft ii.exe | 
"{E2E8703D-AE39-45CB-B5FD-576A950642AF}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3286\agent.exe | 
"{E3FED4B6-C4E6-4AA8-B0FF-28EA35C078DA}" = protocol=17 | dir=in | app=d:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe | 
"{E41DBFD7-F57B-4D29-91B5-9A7CE4BC921A}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3235\agent.exe | 
"{E5D8D06B-1B59-4676-8833-1A6ACAD8E675}" = protocol=17 | dir=in | app=f:\games\starcraft ii\starcraft ii public test.exe | 
"{ECC203FF-3EA5-4F59-9DD8-95A2103F5BE1}" = protocol=17 | dir=in | app=c:\program files (x86)\battle.net\battle.net.exe | 
"{FAF8DC2A-5E07-47B9-8935-920B6F6A2853}" = dir=out | name=4jxr4b3r3du76ina39a98x8k2 | 
"{FB109778-CDF0-4D14-90FD-6C3262D4E1C7}" = protocol=17 | dir=in | app=d:\program files (x86)\steam\steam.exe | 
"{FF72711D-74F4-4CDB-8A1C-93FD5B8E449D}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2753\agent.exe | 
"TCP Query User{02F21CC7-4072-4881-ADE9-1B56F28A9B51}C:\users\mikey\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\mikey\appdata\local\akamai\netsession_win.exe | 
"TCP Query User{05D094F3-6A17-4067-95DD-AA5EBD7EAE38}D:\program files (x86)\musicbrainz picard\picard.exe" = protocol=6 | dir=in | app=d:\program files (x86)\musicbrainz picard\picard.exe | 
"TCP Query User{6559B66A-C710-42E2-AA83-3A8C674C4302}D:\program files (x86)\steam\steamapps\mcwolves3232\source sdk base 2007\hl2.exe" = protocol=6 | dir=in | app=d:\program files (x86)\steam\steamapps\mcwolves3232\source sdk base 2007\hl2.exe | 
"TCP Query User{78454D36-EA02-4CD0-8009-0516F0961C92}D:\program files (x86)\supraball\binaries\win32\udk.exe" = protocol=6 | dir=in | app=d:\program files (x86)\supraball\binaries\win32\udk.exe | 
"TCP Query User{9384B5CB-D105-4E39-B3F1-F07E78EE4A28}C:\program files (x86)\activision\call of duty 2\cod2mp_s.exe" = protocol=6 | dir=in | app=c:\program files (x86)\activision\call of duty 2\cod2mp_s.exe | 
"TCP Query User{9C5862CC-12C4-4BBB-8F9A-C31AB59A0C9E}C:\program files (x86)\steam\steam.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe | 
"TCP Query User{A5FFCCD0-86AD-45C1-BABE-FF4644627A51}D:\program files (x86)\steam\steamapps\common\tribes\binaries\win32\tribesascend.exe" = protocol=6 | dir=in | app=d:\program files (x86)\steam\steamapps\common\tribes\binaries\win32\tribesascend.exe | 
"TCP Query User{CBF93B1C-3C24-4F35-868F-35C123CAB04F}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe | 
"TCP Query User{F25EF59B-903D-40E9-908A-D45FCF7064CE}D:\program files (x86)\diablo iii\diablo iii.exe" = protocol=6 | dir=in | app=d:\program files (x86)\diablo iii\diablo iii.exe | 
"TCP Query User{F809652E-C022-4B76-B7FB-9F345F7DDC45}C:\users\mikey\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\mikey\appdata\local\akamai\netsession_win.exe | 
"UDP Query User{1513B328-BAF0-4D2A-A34D-5441D51129D6}C:\users\mikey\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\mikey\appdata\local\akamai\netsession_win.exe | 
"UDP Query User{1F26D172-677C-4E79-8B8F-BE87E8EB09A1}C:\users\mikey\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\mikey\appdata\local\akamai\netsession_win.exe | 
"UDP Query User{2E210950-B7A8-4637-8780-CACB4126733C}D:\program files (x86)\supraball\binaries\win32\udk.exe" = protocol=17 | dir=in | app=d:\program files (x86)\supraball\binaries\win32\udk.exe | 
"UDP Query User{5C9CA6AF-9892-494A-8142-832AEB6038E3}D:\program files (x86)\diablo iii\diablo iii.exe" = protocol=17 | dir=in | app=d:\program files (x86)\diablo iii\diablo iii.exe | 
"UDP Query User{A046AD20-BF06-4C64-82C8-7BBD58B81CCE}C:\program files (x86)\steam\steam.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe | 
"UDP Query User{B9C32606-F391-453D-98F2-B62115BBCDD5}D:\program files (x86)\steam\steamapps\mcwolves3232\source sdk base 2007\hl2.exe" = protocol=17 | dir=in | app=d:\program files (x86)\steam\steamapps\mcwolves3232\source sdk base 2007\hl2.exe | 
"UDP Query User{C44E1E0E-ACFB-4CE3-B560-E7B76C84CD3B}D:\program files (x86)\steam\steamapps\common\tribes\binaries\win32\tribesascend.exe" = protocol=17 | dir=in | app=d:\program files (x86)\steam\steamapps\common\tribes\binaries\win32\tribesascend.exe | 
"UDP Query User{D084FDEF-A51A-4766-B694-4450D706A561}C:\program files (x86)\activision\call of duty 2\cod2mp_s.exe" = protocol=17 | dir=in | app=c:\program files (x86)\activision\call of duty 2\cod2mp_s.exe | 
"UDP Query User{F8A55FCA-A301-44D1-8E66-0ED62B60504F}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe | 
"UDP Query User{FBE40728-07E4-4D29-8080-2A8F9B437C90}D:\program files (x86)\musicbrainz picard\picard.exe" = protocol=17 | dir=in | app=d:\program files (x86)\musicbrainz picard\picard.exe | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP490_series" = Canon MP490 series MP Drivers
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
"{23F2C78C-E131-4CA0-8F84-3473FB7728BA}" = Microsoft Security Client
"{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}" = iTunes
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{690285C2-2481-44FB-8402-162EA970A6DD}" = Logitech Gaming Software
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}" = Microsoft .NET Framework 4.5.1
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 344.11
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 344.11
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 344.11
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience" = NVIDIA GeForce Experience 2.1.2
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 344.11
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.14.0702
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 16.13.42
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.LEDVisualizer" = NVIDIA LED Visualizer 1.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv" = SHIELD Streaming
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GfExperienceService" = NVIDIA GeForce Experience Service
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver 1.3.32.1
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Network.Service" = NVIDIA Network Service
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShadowPlay" = NVIDIA ShadowPlay 16.13.42
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShieldWirelessController" = SHIELD Wireless Controller Driver
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core" = NVIDIA Update Core
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver" = NVIDIA Virtual Audio 1.2.25
"{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}" = Apple Mobile Device Support
"{D4C70FF4-03C9-41AD-A73F-0DFEC53BC09E}" = USB 3.0 Command Verifier - x64 (1.0.1.1)
"{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}" = Ventrilo Client for Windows x64
"CCleaner" = CCleaner
"C-Media PCI Audio Driver" = C-Media PCI Audio Device
"Logitech Gaming Software" = Logitech Gaming Software 8.40
"Microsoft Security Client" = Microsoft Security Essentials
"UDK-4159a9ab-5864-43f5-ad5e-b89c04e861e0" = My Game Long Name
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}" = Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{240C3DDD-C5E9-4029-9DF7-95650D040CF2}" = Intel® USB 3.0 eXtensible Host Controller Driver
"{26A24AE4-039D-4CA4-87B4-2F83217021FF}" = Java 7 Update 21
"{32D39568-3B77-11E3-88CE-00163E98E7D0}" = Evernote v. 5.0.3
"{3365E735-48A6-4194-9988-CE59AC5AE503}" = Bing Bar
"{3C7839E7-21F4-49E0-B4D5-AC8ED818CCB0}" = NETGEAR WNDA3100v2 wireless USB 2.0 driver
"{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}" = Hi-Rez Studios Authenticate and Update Service
"{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}" = Microsoft ASP.NET MVC 4 Runtime
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module
"{556BEFE2-30FF-4113-98F4-01234396DF2B}" = ASUS PCE-N15 WLAN Card Utilities & Driver
"{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79B1FF35-9EA8-48ED-98D6-19ABE004BE89}" = DefianceRuntimes
"{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}" = Apple Application Support
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{8C127DE3-EC36-4BA3-A6EE-6DC4A9B6C526}" = inSSIDer Office
"{975e7799-c584-47f0-9c12-c1551f3e95f2}_is1" = Genesis version Genesis Launcher 1.006
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F1F2AEA-C72A-4DD6-991E-C5506A5625E4}" = OpenOffice.org 3.4.1
"{A1538F5C-7B65-4DB6-9FFB-FFC0DF2E85D8}_is1" = Polar FlowSync version 2.1.5
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{B455E95A-B804-439F-B533-336B1635AE97}" = NVIDIA PhysX
"{B4E343DD-BAAB-4D59-AD9C-DEA0AFE09DF1}" = Mumble 1.2.3
"{ce085a78-074e-4823-8dc1-8a721b94b76d}" = Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005
"{D0A05794-48C2-4424-A15A-9F20FCFDD374}" = Call of Duty® 2
"{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F3FCB08B-E752-444D-86A0-0634A4F3B23D}" = System Requirements Lab CYRI
"{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}" = Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"7-Zip" = 7-Zip 9.20
"Adobe Flash Player ActiveX" = Adobe Flash Player 15 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 15 Plugin
"B076073A-5527-4f4f-B46B-B10692277DA2_is1" = DisplayFusion 6.1.2
"Battle.net" = Battle.net
"DAEMON Tools Lite" = DAEMON Tools Lite
"Dark Age of Camelot" = Dark Age of Camelot
"Diablo III" = Diablo III
"EVEMon" = EVEMon
"FileZilla Client" = FileZilla Client 3.6.0.2
"Foxit Reader_is1" = Foxit Reader
"Google Chrome" = Google Chrome
"Hm4win" = Handicap Manager for Windows
"InstallShield_{D0A05794-48C2-4424-A15A-9F20FCFDD374}" = Call of Duty® 2
"Malwarebytes Anti-Malware_is1" = Malwarebytes Anti-Malware version 2.0.3.1025
"Miro Video Converter" = Miro Video Converter
"MusicBrainz Picard" = MusicBrainz Picard
"Network Stumbler" = Network Stumbler 0.4.0 (remove only)
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Origin" = Origin
"Revo Uninstaller" = Revo Uninstaller 1.94
"SpeedFan" = SpeedFan (remove only)
"StarCraft II" = StarCraft II
"Steam App 221100" = DayZ
"Steam App 258970" = Gauntlet™ 
"Steam App 730" = Counter-Strike: Global Offensive
"SUPER COD2 Mod Remover_is1" = SUPER COD2 Mod Remover v1
"Supraball" = Supraball
"TimeComX Basic 64-Bit" = TimeComX Basic (64-Bit)
"TreeSize Free_is1" = TreeSize Free V2.7
"VLC media player" = VLC media player 2.1.3
"VOPackage" = Remote Desktop Access (VuuPC)
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Akamai" = Akamai NetSession Interface
"RIFT" = RIFT
"SOE-C:/Users/Mikey/AppData/Local/Sony Online Entertainment/ApplicationUpdater" = applicationupdater
"SOE-C:/Users/Public/Sony Online Entertainment/Installed Games/PlanetSide 2" = gamelauncher-ps2-live
"soe-PlanetSide 2" = PlanetSide 2
"uTorrent" = µTorrent
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 9/29/2014 7:50:43 AM | Computer Name = Mikey-PC | Source = ESENT | ID = 455
Description = Windows (2240) Windows: Error -1811 occurred while opening logfile
 C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00666.log.
 
Error - 9/29/2014 7:50:43 AM | Computer Name = Mikey-PC | Source = Windows Search Service | ID = 9000
Description = 
 
Error - 9/29/2014 7:50:44 AM | Computer Name = Mikey-PC | Source = Windows Search Service | ID = 7040
Description = 
 
Error - 9/29/2014 7:50:44 AM | Computer Name = Mikey-PC | Source = Windows Search Service | ID = 7042
Description = 
 
Error - 9/29/2014 7:50:44 AM | Computer Name = Mikey-PC | Source = Windows Search Service | ID = 9002
Description = 
 
Error - 9/29/2014 7:50:44 AM | Computer Name = Mikey-PC | Source = Windows Search Service | ID = 3029
Description = 
 
Error - 9/29/2014 7:50:44 AM | Computer Name = Mikey-PC | Source = Windows Search Service | ID = 3029
Description = 
 
Error - 9/29/2014 7:50:44 AM | Computer Name = Mikey-PC | Source = Windows Search Service | ID = 3028
Description = 
 
Error - 9/29/2014 7:50:44 AM | Computer Name = Mikey-PC | Source = Windows Search Service | ID = 3058
Description = 
 
Error - 9/29/2014 7:50:44 AM | Computer Name = Mikey-PC | Source = Windows Search Service | ID = 7010
Description = 
 
[ System Events ]
Error - 10/21/2014 8:48:53 PM | Computer Name = Mikey-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!
 
Error - 10/21/2014 9:18:40 PM | Computer Name = Mikey-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!
 
Error - 10/22/2014 9:53:22 AM | Computer Name = Mikey-PC | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
 storage could not grow due to a user imposed limit.
 
Error - 10/22/2014 8:04:44 PM | Computer Name = Mikey-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!
 
Error - 10/22/2014 10:46:22 PM | Computer Name = Mikey-PC | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
 storage could not grow due to a user imposed limit.
 
Error - 10/23/2014 9:00:36 AM | Computer Name = Mikey-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!
 
Error - 10/24/2014 6:29:05 PM | Computer Name = Mikey-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!
 
Error - 10/25/2014 2:23:31 PM | Computer Name = Mikey-PC | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
 storage could not grow due to a user imposed limit.
 
Error - 10/25/2014 2:37:40 PM | Computer Name = Mikey-PC | Source = Service Control Manager | ID = 7030
Description = The YouTube Downloader Services service is marked as an interactive
 service.  However, the system is configured to not allow interactive services. 
 This service may not function properly.
 
Error - 10/25/2014 2:38:16 PM | Computer Name = Mikey-PC | Source = Service Control Manager | ID = 7030
Description = The Windows Virtual Network (WVN3) service is marked as an interactive
 service.  However, the system is configured to not allow interactive services. 
 This service may not function properly.
 
 
< End of report >
 
 
 

 


  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi you have a worm that needs removing. Do you have an antivirus programme ?

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL

:Commands
[CREATERESTOREPOINT]

:OTL
O4 - HKCU..\Run: [MIKEY-PC] C:\Users\Mikey\AppData\Roaming\amde.exe ()
O4 - HKCU..\Run: [Polar FlowSync] File not found
[2014/10/25 12:38:24 | 000,000,000 | ---D | C] -- C:\Users\Mikey\AppData\Roaming\VOPackage
[2014/10/25 12:38:24 | 000,000,000 | ---D | C] -- C:\Users\Mikey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
[2014/10/25 12:38:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Windows VXM
[2014/10/25 12:38:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Network Accelerater
[2014/10/25 12:37:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Optimizer
[2014/10/25 12:35:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\System Optimizer Pro
[2014/10/25 12:34:22 | 000,000,000 | ---D | C] -- C:\Users\Mikey\Documents\eRightSoft
[2014/10/25 12:34:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ver0BlockAndSurf
[2014/10/22 21:58:52 | 002,664,227 | --S- | C] () -- C:\Users\Mikey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Mikey.exe
[2014/10/22 21:58:48 | 002,664,227 | -HS- | C] () -- C:\Users\Mikey\AppData\Roaming\amde.exe

:Files
C:\Users\Mikey\AppData\Roaming\amde.exe

:Commands
[resethosts]
[emptytemp]
[Reboot]
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    OTL_Fix.GIF
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
  • THEN

    Download and Install Combofix

    Download ComboFix from one of the following locations:
    Link 1
    Link 2

    VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

    * IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here NSIS_extraction.png
    • When finished, it shall produce a log for you.
    • Please include the C:\ComboFix.txt in your next reply.
      Notes:
      1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
      2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

      3. If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.


      Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

      FINALLY

      Please download AdwCleaner by Xplode onto your desktop.
      • Close all open programs and internet browsers.
      • Double click on AdwCleaner.exe to run the tool.
      • Click on Scan.
      • After the scan is complete click on "Clean"
      • Confirm each time with Ok.
      • Your computer will be rebooted automatically. A text file will open after the restart.
      • Please post the content of that logfile with your next answer.
      • You can find the logfile at C:\AdwCleaner[S1].txt as well.

  • 0

#3
Fatie32

Fatie32

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 122 posts
All processes killed
========== COMMANDS ==========
System Restore Service not available.
========== OTL ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\MIKEY-PC deleted successfully.
C:\Users\Mikey\AppData\Roaming\amde.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Polar FlowSync deleted successfully.
Folder C:\Users\Mikey\AppData\Roaming\VOPackage\ not found.
Folder C:\Users\Mikey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage\ not found.
C:\ProgramData\Windows VXM\Images folder moved successfully.
C:\ProgramData\Windows VXM folder moved successfully.
C:\Program Files (x86)\Windows Network Accelerater\v3\config folder moved successfully.
Folder move failed. C:\Program Files (x86)\Windows Network Accelerater\v3 scheduled to be moved on reboot.
Folder move failed. C:\Program Files (x86)\Windows Network Accelerater scheduled to be moved on reboot.
C:\ProgramData\Optimizer\program folder moved successfully.
C:\ProgramData\Optimizer folder moved successfully.
C:\Program Files (x86)\System Optimizer Pro folder moved successfully.
C:\Users\Mikey\Documents\eRightSoft\OutPut folder moved successfully.
C:\Users\Mikey\Documents\eRightSoft folder moved successfully.
Folder C:\Program Files (x86)\ver0BlockAndSurf\ not found.
C:\Users\Mikey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Mikey.exe moved successfully.
File C:\Users\Mikey\AppData\Roaming\amde.exe not found.
========== FILES ==========
File\Folder C:\Users\Mikey\AppData\Roaming\amde.exe not found.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Mikey
->Temp folder emptied: 180616606 bytes
->Temporary Internet Files folder emptied: 231628633 bytes
->Java cache emptied: 6786065 bytes
->Google Chrome cache emptied: 13994640 bytes
->Flash cache emptied: 1260 bytes
 
User: Mommy
->Temp folder emptied: 4455822 bytes
->Temporary Internet Files folder emptied: 20549421 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 7860860 bytes
 
User: Public
 
User: UpdatusUser
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 12812111 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 42303946 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 497.00 mb
 
 
OTL by OldTimer - Version 3.2.69.0 log created on 10262014_081454
 
Files\Folders moved on Reboot...
Folder move failed. C:\Program Files (x86)\Windows Network Accelerater\v3 scheduled to be moved on reboot.
Folder move failed. C:\Program Files (x86)\Windows Network Accelerater\v3 scheduled to be moved on reboot.
Folder move failed. C:\Program Files (x86)\Windows Network Accelerater scheduled to be moved on reboot.
File move failed. C:\Users\Mikey\AppData\Local\Temp\NVIDIA Corporation\NV_Cache\ff25a4f67ecc2f28d6a304bc5c26dbf_fce8395f8fd8a848_6229ccd76215aea1_0_0.bin scheduled to be moved on reboot.
File move failed. C:\Users\Mikey\AppData\Local\Temp\NVIDIA Corporation\NV_Cache\ff25a4f67ecc2f28d6a304bc5c26dbf_fce8395f8fd8a848_6229ccd76215aea1_0_0.toc scheduled to be moved on reboot.
File\Folder C:\Users\Mikey\AppData\Local\Temp\etilqs_74idMyWpB9dJUfr not found!
C:\Users\Mikey\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\Mikey\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.
C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Cache\data_0 moved successfully.
C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Cache\data_1 moved successfully.
C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Cache\data_2 moved successfully.
C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Cache\data_3 moved successfully.
C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Cache\index moved successfully.
 
PendingFileRenameOperations files...
 
Registry entries deleted on Reboot...
 
 
 
ComboFix 14-10-24.01 - Mikey 10/26/2014   8:28.1.4 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.8137.5748 [GMT -6:00]
Running from: d:\desktop\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
SP: Microsoft Security Essentials *Enabled/Updated* {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Created a new restore point
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Mikey\AppData\Roaming\MIKEY-PC
c:\users\Mikey\AppData\Roaming\MIKEY-PC\coinutil.dll
c:\users\Mikey\AppData\Roaming\MIKEY-PC\cryp.dll
c:\users\Mikey\AppData\Roaming\MIKEY-PC\MIKEY-PC.exe
c:\users\Mikey\AppData\Roaming\MIKEY-PC\miner.dll
c:\users\Mikey\AppData\Roaming\MIKEY-PC\mpir.dll
c:\users\Mikey\AppData\Roaming\MIKEY-PC\scrypt.cl
c:\users\Mikey\AppData\Roaming\MIKEY-PC\sqlite3.exe
c:\users\Mikey\AppData\Roaming\MIKEY-PC\usft_ext.dll
c:\windows\SysWow64\Packet.dll
c:\windows\SysWow64\pthreadVC.dll
c:\windows\SysWow64\wpcap.dll
.
.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_NPF
.
.
(((((((((((((((((((((((((   Files Created from 2014-09-26 to 2014-10-26  )))))))))))))))))))))))))))))))
.
.
2014-10-26 14:40 . 2014-10-26 14:40 75888 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{4F9AC8EA-246D-429F-8922-80C6B47ABDC9}\offreg.dll
2014-10-26 14:21 . 2014-10-26 14:21 -------- d-----w- c:\programdata\Windows VXM
2014-10-26 14:21 . 2014-10-26 14:21 -------- d-----w- c:\programdata\Optimizer
2014-10-25 22:40 . 2014-10-14 19:59 11627712 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{4F9AC8EA-246D-429F-8922-80C6B47ABDC9}\mpengine.dll
2014-10-25 18:41 . 2014-10-25 18:41 -------- d-----w- c:\program files (x86)\Participatory Culture Foundation
2014-10-25 18:38 . 2014-10-25 18:38 -------- d-----w- c:\program files (x86)\Windows Network Accelerater
2014-10-25 18:37 . 2014-10-25 18:37 -------- d-----w- c:\program files (x86)\YouTube Downloader Services
2014-10-25 18:37 . 2004-02-22 16:11 764416 --sh--w- c:\windows\SysWow64\devil.dll
2014-10-25 18:37 . 2009-09-27 15:39 415744 --sh--w- c:\windows\SysWow64\avisynth.dll
2014-10-25 18:37 . 2005-07-14 18:31 32256 --sh--w- c:\windows\SysWow64\AVSredirect.dll
2014-10-25 18:37 . 2004-01-25 06:00 70656 --sh--w- c:\windows\SysWow64\yv12vfw.dll
2014-10-25 18:37 . 2004-01-25 06:00 70656 --sh--w- c:\windows\SysWow64\i420vfw.dll
2014-10-25 18:33 . 2014-10-25 18:33 -------- d-----w- c:\program files (x86)\eRightSoft
2014-10-24 22:40 . 2014-10-14 19:59 11627712 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-10-22 01:15 . 2014-10-22 01:15 -------- d-----w- c:\program files\iPod
2014-10-22 01:15 . 2014-10-22 01:16 -------- d-----w- c:\programdata\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2014-10-22 01:15 . 2014-10-22 01:16 -------- d-----w- c:\program files\iTunes
2014-10-18 22:44 . 2014-10-18 22:44 -------- d-----w- c:\users\Mikey\AppData\Local\fontconfig
2014-10-18 22:42 . 2014-10-18 22:42 -------- d-----w- c:\users\Mikey\AppData\Local\SkinSoft
2014-10-18 22:42 . 2014-10-18 22:42 -------- d-----w- c:\users\Mikey\AppData\Roaming\Convert Audio Free
2014-10-16 09:03 . 2014-10-16 09:03 -------- d-----w- c:\program files (x86)\Microsoft ASP.NET
2014-10-16 07:56 . 2014-09-29 00:58 3198976 ----a-w- c:\windows\system32\win32k.sys
2014-10-16 07:56 . 2014-06-18 22:23 73880 ----a-w- c:\windows\system32\mscories.dll
2014-10-16 07:56 . 2014-06-18 22:23 1943696 ----a-w- c:\windows\system32\dfshim.dll
2014-10-16 07:56 . 2014-06-18 22:23 156312 ----a-w- c:\windows\system32\mscorier.dll
2014-10-16 07:56 . 2014-06-18 22:23 81560 ----a-w- c:\windows\SysWow64\mscories.dll
2014-10-16 07:56 . 2014-06-18 22:23 156824 ----a-w- c:\windows\SysWow64\mscorier.dll
2014-10-16 07:56 . 2014-06-18 22:23 1131664 ----a-w- c:\windows\SysWow64\dfshim.dll
2014-10-16 07:53 . 2014-09-18 02:00 3241472 ----a-w- c:\windows\system32\msi.dll
2014-10-02 00:55 . 2014-09-18 23:04 1188440 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1CE18108-80D0-43B3-8E66-00FC03C407FB}\gapaengine.dll
2014-10-02 00:40 . 2014-09-25 02:08 371712 ----a-w- c:\windows\system32\qdvd.dll
2014-10-02 00:40 . 2014-09-25 01:40 519680 ----a-w- c:\windows\SysWow64\qdvd.dll
2014-09-28 16:42 . 2014-09-28 16:42 -------- d-----w- c:\programdata\NexonUS
2014-09-28 13:51 . 2014-09-28 13:51 -------- d-----w- c:\program files\CCleaner
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-10-25 22:20 . 2014-08-06 00:05 129752 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-10-16 09:00 . 2012-12-13 02:15 103265616 ----a-w- c:\windows\system32\MRT.exe
2014-10-01 17:11 . 2014-08-06 00:05 63704 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-10-01 17:11 . 2014-08-06 00:05 93400 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-10-01 17:11 . 2012-12-20 01:50 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-09-25 16:09 . 2014-07-01 21:30 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-09-25 16:09 . 2014-07-01 21:30 701104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-09-23 13:21 . 2013-01-01 21:41 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2014-09-22 06:42 . 2012-12-13 01:45 278152 ------w- c:\windows\system32\MpSigStub.exe
2014-09-18 23:04 . 2013-03-13 21:47 1188440 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2014-09-17 04:51 . 2014-09-24 03:34 31520 ----a-w- c:\windows\system32\nvhdap64.dll
2014-09-17 04:51 . 2014-09-24 03:34 197408 ----a-w- c:\windows\system32\drivers\nvhda64v.sys
2014-09-17 04:51 . 2014-02-02 16:25 1538880 ----a-w- c:\windows\system32\nvhdagenco6420103.dll
2014-09-17 02:13 . 2014-06-12 15:02 1291280 ----a-w- c:\windows\SysWow64\nvspbridge.dll
2014-09-17 02:13 . 2013-12-29 22:11 2193560 ----a-w- c:\windows\SysWow64\nvspcap.dll
2014-09-17 02:12 . 2013-12-29 22:11 2799784 ----a-w- c:\windows\system32\nvspcap64.dll
2014-09-17 02:12 . 2014-06-12 15:02 1715224 ----a-w- c:\windows\system32\nvspbridge64.dll
2014-09-13 23:48 . 2014-09-24 03:34 957584 ----a-w- c:\windows\system32\NvIFR64.dll
2014-09-13 23:48 . 2014-09-24 03:34 925896 ----a-w- c:\windows\system32\NvFBC64.dll
2014-09-13 23:48 . 2014-09-24 03:34 919240 ----a-w- c:\windows\SysWow64\NvIFR.dll
2014-09-13 23:48 . 2014-09-24 03:34 894096 ----a-w- c:\windows\SysWow64\NvFBC.dll
2014-09-13 23:48 . 2014-09-24 03:34 867528 ----a-w- c:\windows\SysWow64\nvumdshim.dll
2014-09-13 23:48 . 2014-09-24 03:34 501064 ----a-w- c:\windows\system32\nvEncodeAPI64.dll
2014-09-13 23:48 . 2014-09-24 03:34 4287296 ----a-w- c:\windows\system32\nvcuvid.dll
2014-09-13 23:48 . 2014-09-24 03:34 417096 ----a-w- c:\windows\SysWow64\nvEncodeAPI.dll
2014-09-13 23:48 . 2014-09-24 03:34 4008592 ----a-w- c:\windows\SysWow64\nvcuvid.dll
2014-09-13 23:48 . 2014-09-24 03:34 393024 ----a-w- c:\windows\system32\NvIFROpenGL.dll
2014-09-13 23:48 . 2014-09-24 03:34 352016 ----a-w- c:\windows\system32\nvoglshim64.dll
2014-09-13 23:48 . 2014-09-24 03:34 348304 ----a-w- c:\windows\SysWow64\NvIFROpenGL.dll
2014-09-13 23:48 . 2014-09-24 03:34 303600 ----a-w- c:\windows\SysWow64\nvoglshim32.dll
2014-09-13 23:48 . 2014-09-24 03:34 2838424 ----a-w- c:\windows\SysWow64\nvapi.dll
2014-09-13 23:48 . 2014-09-24 03:34 24552592 ----a-w- c:\windows\SysWow64\nvoglv32.dll
2014-09-13 23:48 . 2014-09-24 03:34 20922512 ----a-w- c:\windows\system32\nvcompiler.dll
2014-09-13 23:48 . 2014-09-24 03:34 19954520 ----a-w- c:\windows\system32\nvd3dumx.dll
2014-09-13 23:48 . 2014-09-24 03:34 1876296 ----a-w- c:\windows\system32\nvdispco6434411.dll
2014-09-13 23:48 . 2014-09-24 03:34 174856 ----a-w- c:\windows\system32\nvinitx.dll
2014-09-13 23:48 . 2014-09-24 03:34 17259664 ----a-w- c:\windows\SysWow64\nvcompiler.dll
2014-09-13 23:48 . 2014-09-24 03:34 156840 ----a-w- c:\windows\SysWow64\nvinit.dll
2014-09-13 23:48 . 2014-09-24 03:34 1539272 ----a-w- c:\windows\system32\nvdispgenco6434411.dll
2014-09-13 23:48 . 2014-09-24 03:34 14026304 ----a-w- c:\windows\system32\nvopencl.dll
2014-09-13 23:48 . 2014-09-24 03:34 13939272 ----a-w- c:\windows\system32\nvcuda.dll
2014-09-13 23:48 . 2014-09-24 03:34 13157696 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2014-09-13 23:48 . 2014-09-24 03:34 11392576 ----a-w- c:\windows\SysWow64\nvopencl.dll
2014-09-13 23:48 . 2014-09-24 03:34 11330776 ----a-w- c:\windows\SysWow64\nvcuda.dll
2014-09-13 23:48 . 2014-06-12 15:04 18106152 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2014-09-13 23:48 . 2013-04-27 14:50 16875856 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2014-09-13 23:48 . 2013-02-09 20:34 31887680 ----a-w- c:\windows\system32\nvoglv64.dll
2014-09-13 23:48 . 2013-02-09 20:34 20589536 ----a-w- c:\windows\system32\nvwgf2umx.dll
2014-09-13 23:48 . 2012-12-13 01:43 73872 ----a-w- c:\windows\system32\OpenCL.dll
2014-09-13 23:48 . 2012-12-13 01:43 60560 ----a-w- c:\windows\SysWow64\OpenCL.dll
2014-09-13 23:48 . 2012-12-13 01:43 984424 ----a-w- c:\windows\system32\nvumdshimx.dll
2014-09-13 23:48 . 2012-12-13 01:43 3223120 ----a-w- c:\windows\system32\nvapi64.dll
2014-09-13 21:53 . 2013-02-09 20:32 6890696 ----a-w- c:\windows\system32\nvcpl.dll
2014-09-13 21:53 . 2013-02-09 20:32 3529872 ----a-w- c:\windows\system32\nvsvc64.dll
2014-09-13 21:53 . 2013-02-09 20:32 934216 ----a-w- c:\windows\system32\nvvsvc.exe
2014-09-13 21:53 . 2013-02-09 20:32 62608 ----a-w- c:\windows\system32\nvshext.dll
2014-09-13 21:53 . 2013-02-09 20:32 385168 ----a-w- c:\windows\system32\nvmctray.dll
2014-09-13 20:13 . 2014-09-24 03:36 613696 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2014-09-11 15:37 . 2013-02-09 20:32 3961833 ----a-w- c:\windows\system32\nvcoproc.bin
2014-09-09 22:11 . 2014-09-24 12:17 2048 ----a-w- c:\windows\system32\tzres.dll
2014-09-09 21:47 . 2014-09-24 12:17 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2014-09-04 19:14 . 2014-09-23 20:03 38048 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
2014-09-04 19:14 . 2014-09-23 20:03 32416 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
2014-09-04 19:14 . 2013-12-29 22:09 34976 ----a-w- c:\windows\system32\nvaudcap64v.dll
2014-08-23 02:07 . 2014-08-27 19:33 404480 ----a-w- c:\windows\system32\gdi32.dll
2014-08-23 01:45 . 2014-08-27 19:33 311808 ----a-w- c:\windows\SysWow64\gdi32.dll
2014-08-01 11:53 . 2014-09-10 23:13 1031168 ----a-w- c:\windows\system32\TSWorkspace.dll
2014-08-01 11:35 . 2014-09-10 23:13 793600 ----a-w- c:\windows\SysWow64\TSWorkspace.dll
2014-07-28 19:52 . 2014-07-28 19:52 6112072 ----a-w- c:\windows\system32\usbaaplrc.dll
2014-07-28 19:52 . 2014-07-28 19:52 54784 ----a-w- c:\windows\system32\drivers\usbaapl64.sys
2014-03-07 17:03 3109520 --sha-w- c:\windows\SysWOW64\avcodec-lav-55.dll
2014-03-07 17:03 98960 --sha-w- c:\windows\SysWOW64\avfilter-lav-4.dll
2014-03-07 17:03 550032 --sha-w- c:\windows\SysWOW64\avformat-lav-55.dll
2009-09-27 15:39 415744 --sh--w- c:\windows\SysWOW64\avisynth.dll
2014-03-07 17:03 59536 --sha-w- c:\windows\SysWOW64\avresample-lav-1.dll
2005-07-14 18:31 32256 --sh--w- c:\windows\SysWOW64\AVSredirect.dll
2014-03-07 17:03 181392 --sha-w- c:\windows\SysWOW64\avutil-lav-52.dll
2004-02-22 16:11 764416 --sh--w- c:\windows\SysWOW64\devil.dll
2014-03-07 17:03 122512 --sha-w- c:\windows\SysWOW64\HLaudio.dll
2014-03-07 17:03 203408 --sha-w- c:\windows\SysWOW64\HLsplit.dll
2014-03-07 17:03 313520 --sha-w- c:\windows\SysWOW64\HLvideo.dll
2004-01-25 06:00 70656 --sh--w- c:\windows\SysWOW64\i420vfw.dll
2014-03-07 17:03 109712 --sha-w- c:\windows\SysWOW64\libbluray.dll
2011-02-11 16:26 112128 --sha-w- c:\windows\SysWOW64\OptimFROG.dll
2014-03-07 17:03 118416 --sha-w- c:\windows\SysWOW64\swscale-lav-2.dll
2010-01-07 06:00 107520 --sha-w- c:\windows\SysWOW64\TAKDSDecoder.dll
2012-10-06 01:54 188416 --sha-w- c:\windows\SysWOW64\winDCE32.dll
2004-01-25 06:00 70656 --sh--w- c:\windows\SysWOW64\yv12vfw.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Akamai NetSession Interface"="c:\users\Mikey\AppData\Local\Akamai\netsession_win.exe" [2014-04-18 4672920]
"DisplayFusion"="c:\program files (x86)\DisplayFusion\DisplayFusion.exe" [2014-09-10 8854880]
"DAEMON Tools Lite"="d:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2014-03-04 3696912]
"uTorrent"="c:\users\Mikey\AppData\Roaming\uTorrent\uTorrent.exe" [2014-10-10 1385808]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"USB3MON"="c:\program files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-05-21 291648]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2014-10-11 60712]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
"iTunesHelper"="d:\program files (x86)\iTunes\iTunesHelper.exe" [2014-10-15 157480]
.
c:\users\Mommy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.4.1.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2012-8-13 1199104]
.
c:\users\Mikey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
EvernoteClipper.lnk - c:\program files (x86)\Evernote\Evernote\EvernoteClipper.exe [2013-10-22 1103712]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 WSWNDA3100v2;WSWNDA3100v2;c:\program files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe;c:\program files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe [x]
R3 ampa;ampa;c:\windows\system32\ampa.sys;c:\windows\SYSNATIVE\ampa.sys [x]
R3 BEService;BattlEye Service;c:\program files (x86)\Common Files\BattlEye\BEService.exe;c:\program files (x86)\Common Files\BattlEye\BEService.exe [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]
R3 ESEADriver2;ESEADriver2;c:\users\Mikey\AppData\Local\Temp\ESEADriver2.sys;c:\users\Mikey\AppData\Local\Temp\ESEADriver2.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507;d:\program files (x86)\MSI\Live Update 5\msibios64_100507.sys;d:\program files (x86)\MSI\Live Update 5\msibios64_100507.sys [x]
R3 MSICDSetup;MSICDSetup;e:\cdriver64.sys;e:\CDriver64.sys [x]
R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys;c:\windows\SYSNATIVE\DRIVERS\netaapl64.sys [x]
R3 NTIOLib_1_0_4;NTIOLib_1_0_4;d:\program files (x86)\MSI\Live Update 5\NTIOLib_X64.sys;d:\program files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [x]
R3 NTIOLib_1_0_6;NTIOLib_1_0_6;c:\program files (x86)\Setup Files\Ms7758v270\NTIOLib_X64.sys;c:\program files (x86)\Setup Files\Ms7758v270\NTIOLib_X64.sys [x]
R3 NTIOLib_1_0_C;NTIOLib_1_0_C;e:\ntiolib_x64.sys;e:\NTIOLib_X64.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RTWlanE;Realtek Wireless LAN 802.11n PCI-E Network Adapter;c:\windows\system32\DRIVERS\rtwlane.sys;c:\windows\SYSNATIVE\DRIVERS\rtwlane.sys [x]
R3 ssudmdm;SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys;c:\windows\SYSNATIVE\DRIVERS\wdcsam64.sys [x]
R3 XHCIdrv;xHCI Compliance Test Host Controller;c:\windows\system32\DRIVERS\XHCIdrv.sys;c:\windows\SYSNATIVE\DRIVERS\XHCIdrv.sys [x]
R3 xhunter1;xhunter1;c:\windows\xhunter1.sys;c:\windows\xhunter1.sys [x]
S0 iusb3hcs;Intel® USB 3.0 Host Controller Switch Driver;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
S0 SCMNdisP;General NDIS Protocol Driver;c:\windows\system32\DRIVERS\scmndisp.sys;c:\windows\SYSNATIVE\DRIVERS\scmndisp.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 BBSvc;BingBar Service;c:\program files (x86)\Microsoft\BingBar\7.3.132.0\BBSvc.exe;c:\program files (x86)\Microsoft\BingBar\7.3.132.0\BBSvc.exe [x]
S2 DisplayFusionService;DisplayFusionService;c:\program files (x86)\DisplayFusion\DisplayFusionService.exe;c:\program files (x86)\DisplayFusion\DisplayFusionService.exe [x]
S2 GfExperienceService;NVIDIA GeForce Experience Service;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [x]
S2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 UsbService;ASUS Virtual MFP Service;c:\program files (x86)\ASUS\Printer Utilities\UsbService64.exe;c:\program files (x86)\ASUS\Printer Utilities\UsbService64.exe [x]
S2 WindowsVNT_R3;Windows Virtual Network (WVN3);c:\program files (x86)\Windows Network Accelerater\v3\winvxm.exe;c:\program files (x86)\Windows Network Accelerater\v3\winvxm.exe [x]
S2 YouTubeDownload;YouTube Downloader Services;c:\program files (x86)\YouTube Downloader Services\youtubeserv.exe;c:\program files (x86)\YouTube Downloader Services\youtubeserv.exe [x]
S3 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.exe;c:\program files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.exe [x]
S3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;c:\windows\system32\DRIVERS\bcmwlhigh664.sys;c:\windows\SYSNATIVE\DRIVERS\bcmwlhigh664.sys [x]
S3 ISCT;Intel® Smart Connect Technology Device Driver;c:\windows\system32\DRIVERS\ISCTD64.sys;c:\windows\SYSNATIVE\DRIVERS\ISCTD64.sys [x]
S3 iusb3hub;Intel® USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
S3 iusb3xhc;Intel® USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
S3 LGSHidFilt;Logitech Gaming KMDF HID Filter Driver;c:\windows\system32\DRIVERS\LGSHidFilt.Sys;c:\windows\SYSNATIVE\DRIVERS\LGSHidFilt.Sys [x]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
S3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
S3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 vuhub;Virtual Usb Hub;c:\windows\system32\DRIVERS\vuhub.sys;c:\windows\SYSNATIVE\DRIVERS\vuhub.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-10-18 08:23 1089352 ----a-w- c:\program files (x86)\Google\Chrome\Application\38.0.2125.104\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2014-10-26 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-01 16:09]
.
2014-10-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-12-13 15:32]
.
2014-10-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-12-13 15:32]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CmPCIaudio"="c:\windows\Syswow64\CMICNFG3.dll" [2009-10-23 8151040]
"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2012-11-29 7406392]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2014-08-22 1331288]
"ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2014-09-17 2799784]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-09-17 2460488]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local;<local>
IE: Clip Image - c:\program files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=4
IE: Clip selection - c:\program files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=3
IE: Clip this page - c:\program files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=1
IE: Clip URL - c:\program files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=0
IE: New Note - c:\program files (x86)\Evernote\Evernote\\EvernoteIERes\NewNote.html
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 75.75.76.76 75.75.75.75
.
- - - - ORPHANS REMOVED - - - -
.
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
AddRemove-RIFT - c:\program files (x86)\RIFT\riftuninstall.exe
AddRemove-PlanetSide 2 - c:\users\Public\Sony Online Entertainment\Installed Games\PlanetSide 2\Uninstaller.exe
AddRemove-soe-PlanetSide 2 - c:\sony online entertainment\Installed Games\PlanetSide 2\Uninstaller.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_15_0_0_167_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_15_0_0_167_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_15_0_0_167_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_15_0_0_167_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_167.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.15"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_167.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_167.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_167.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\windows\SysWOW64\rundll32.exe
c:\program files (x86)\Common Files\Java\Java Update\jucheck.exe
c:\program files (x86)\Google\Chrome\Application\chrome.exe
c:\program files (x86)\Google\Chrome\Application\chrome.exe
c:\program files (x86)\Google\Chrome\Application\chrome.exe
c:\program files (x86)\Google\Chrome\Application\chrome.exe
c:\program files (x86)\Google\Chrome\Application\chrome.exe
c:\program files (x86)\Google\Chrome\Application\chrome.exe
.
**************************************************************************
.
Completion time: 2014-10-26  09:08:46 - machine was rebooted
ComboFix-quarantined-files.txt  2014-10-26 15:08
.
Pre-Run: 358,150,144 bytes free
Post-Run: 1,281,101,824 bytes free
.
- - End Of File - - D3D91481F510052EE785489FC6FFED41
5FB38429D5D77768867C76DCBDB35194
 
 
# AdwCleaner v4.001 - Report created 26/10/2014 at 09:54:46
# DB v2014-10-26.2
# Updated 20/10/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Mikey - MIKEY-PC
# Running from : D:\Downloads\AdwCleaner.exe
# Option : Clean
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
 
***** [ Scheduled Tasks ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Key Deleted : HKLM\SOFTWARE\PIP
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GoogleUpdate.exe
 
***** [ Browsers ] *****
 
-\\ Internet Explorer v11.0.9600.17344
 
 
-\\ Google Chrome v38.0.2125.104
 
 
*************************
 
AdwCleaner[R0].txt - [868 octets] - [26/10/2014 09:09:44]
AdwCleaner[S0].txt - [787 octets] - [26/10/2014 09:54:46]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [846 octets] ##########
 

 


  • 0

#4
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
How is the computer behaving now ?

Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Select additions at the bottom
  • Press Scan button.
    frst.JPG
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please attach both logs generated.

  • 0

#5
Fatie32

Fatie32

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 122 posts
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 26-10-2014
Ran by Mikey at 2014-10-26 11:10:46
Running from D:\Downloads
Boot Mode: Normal
==========================================================
 
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Canon MP490 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP490_series) (Version:  - Canon Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 4.17 - Piriform)
C-Media PCI Audio Device (HKLM\...\C-Media PCI Audio Driver) (Version:  - )
Logitech Gaming Software 8.40 (HKLM\...\Logitech Gaming Software) (Version: 8.40.83 - Logitech Inc.)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
My Game Long Name (HKLM\...\UDK-4159a9ab-5864-43f5-ad5e-b89c04e861e0) (Version:  - Epic Games, Inc.)
 
==================== Custom CLSID (selected items): ==========================
 
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
 
CustomCLSID: HKU\S-1-5-21-1720781654-3047350990-1079063203-1000_Classes\CLSID\{6511a5d7-b538-4c3d-b3c1-3ef7f01253f7}\InprocServer32 -> C:\Windows\system32\dfshim.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1720781654-3047350990-1079063203-1000_Classes\CLSID\{8b31738c-da7b-42c4-a691-608581d23ad2}\InprocServer32 -> C:\Windows\system32\dfshim.dll (Microsoft Corporation)
 
==================== Restore Points  =========================
 
26-10-2014 16:01:06 Installed DirectX
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 20:34 - 2014-10-26 08:52 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
 
==================== Scheduled Tasks (whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
 
Task: {058E328F-6305-4874-889E-0A986AC82E19} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-12-13] (Google Inc.)
Task: {19300029-A9F7-4A58-8CE1-4658D1FA62E8} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-12-13] (Google Inc.)
Task: {604C7960-B984-40E2-BA40-9A50EB2C1B73} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-08-21] (Piriform Ltd)
Task: {8362683D-CC52-46A2-8DAA-4534F2E25157} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-25] (Adobe Systems Incorporated)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (whitelisted) =============
 
2013-02-09 14:32 - 2014-09-13 15:53 - 00116880 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2013-02-24 18:50 - 2013-04-07 10:31 - 00075136 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-02-07 16:15 - 2010-08-10 21:37 - 00334848 _____ () C:\Program Files (x86)\ASUS\Printer Utilities\UsbService64.exe
 
==================== Safe Mode (whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== EXE Association (whitelisted) =============
 
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
 
 
==================== MSCONFIG/TASK MANAGER disabled items =========
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\startupfolder: C:^Users^Mikey^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.4.1.lnk => C:\Windows\pss\OpenOffice.org 3.4.1.lnk.Startup
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: iTunesHelper => "D:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\steam.exe" -silent
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
 
========================= Accounts: ==========================
 
Administrator (S-1-5-21-1720781654-3047350990-1079063203-500 - Administrator - Disabled)
Guest (S-1-5-21-1720781654-3047350990-1079063203-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1720781654-3047350990-1079063203-1003 - Limited - Enabled)
Mikey (S-1-5-21-1720781654-3047350990-1079063203-1000 - Administrator - Enabled) => C:\Users\Mikey
 
==================== Faulty Device Manager Devices =============
 
Name: ASUS PCE-N15 11n Wireless LAN PCI-E Card
Description: ASUS PCE-N15 11n Wireless LAN PCI-E Card
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: ASUSTeK Computer Inc.
Service: RTWlanE
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (10/26/2014 09:03:53 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1533) (User: Mikey-PC)
Description: Windows cannot delete the profile directory C:\Users\Mommy. This error may be caused by files in this directory being used by another program. 
 
 DETAIL - The directory is not empty.
 
Error: (10/26/2014 08:15:08 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\Windows\system32\wbem\wmiprvse.exe; Description = OTL Restore Point - 10/26/2014 8:15:05 AM; Error = 0x8004231f).
 
Error: (10/26/2014 08:09:14 AM) (Source: System Restore) (EventID: 8211) (User: )
Description: The scheduled restore point could not be created.  Additional information: (0x80070070).
 
Error: (10/26/2014 08:09:14 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\Windows\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation; Description = Scheduled Checkpoint; Error = 0x80070070).
 
Error: (10/26/2014 08:02:18 AM) (Source: Application Error) (EventID: 1005) (User: )
Description: Windows cannot access the file C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\mpcache-AFABC0C75B5E288A9B61462814EE0A01A6DF853E.bin.VE0 for one of the following reasons:
there is a problem with the network connection, the disk that the file is stored on, or the storage
drivers installed on this computer; or the disk is missing.
Windows closed the program Antimalware Service Executable because of this error.
 
Program: Antimalware Service Executable
File: C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\mpcache-AFABC0C75B5E288A9B61462814EE0A01A6DF853E.bin.VE0
 
The error value is listed in the Additional Data section.
User Action
1. Open the file again.
This situation might be a temporary problem that corrects itself when the program runs again.
2.
If the file still cannot be accessed and
- It is on the network,
your network administrator should verify that there is not a problem with the network and that the server can be contacted.
- It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.
3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.
4. If the problem persists, restore the file from a backup copy.
5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for
further assistance.
 
Additional Data
Error value: C000007F
Disk type: 3
 
Error: (10/26/2014 08:02:18 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: MsMpEng.exe, version: 4.6.305.0, time stamp: 0x53f7bfb6
Faulting module name: mpengine.dll, version: 1.1.11104.0, time stamp: 0x543d795d
Exception code: 0xc0000006
Fault offset: 0x000000000011bc2e
Faulting process id: 0x1440
Faulting application start time: 0xMsMpEng.exe0
Faulting application path: MsMpEng.exe1
Faulting module path: MsMpEng.exe2
Report Id: MsMpEng.exe3
 
Error: (10/26/2014 08:02:17 AM) (Source: Application Error) (EventID: 1005) (User: )
Description: Windows cannot access the file C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\mpcache-AFABC0C75B5E288A9B61462814EE0A01A6DF853E.bin.VE0 for one of the following reasons:
there is a problem with the network connection, the disk that the file is stored on, or the storage
drivers installed on this computer; or the disk is missing.
Windows closed the program Antimalware Service Executable because of this error.
 
Program: Antimalware Service Executable
File: C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\mpcache-AFABC0C75B5E288A9B61462814EE0A01A6DF853E.bin.VE0
 
The error value is listed in the Additional Data section.
User Action
1. Open the file again.
This situation might be a temporary problem that corrects itself when the program runs again.
2.
If the file still cannot be accessed and
- It is on the network,
your network administrator should verify that there is not a problem with the network and that the server can be contacted.
- It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.
3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.
4. If the problem persists, restore the file from a backup copy.
5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for
further assistance.
 
Additional Data
Error value: C000007F
Disk type: 3
 
Error: (10/26/2014 08:02:17 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: MsMpEng.exe, version: 4.6.305.0, time stamp: 0x53f7bfb6
Faulting module name: mpengine.dll, version: 1.1.11104.0, time stamp: 0x543d795d
Exception code: 0xc0000006
Fault offset: 0x0000000000047f02
Faulting process id: 0x3dc
Faulting application start time: 0xMsMpEng.exe0
Faulting application path: MsMpEng.exe1
Faulting module path: MsMpEng.exe2
Report Id: MsMpEng.exe3
 
Error: (09/29/2014 05:50:44 AM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description: The index cannot be initialized.
 
 
Details:
The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)
 
Error: (09/29/2014 05:50:44 AM) (Source: Windows Search Service) (EventID: 3058) (User: )
Description: The application cannot be initialized.
 
Context: Windows Application
 
 
Details:
The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)
 
 
System errors:
=============
Error: (10/26/2014 09:55:19 AM) (Source: volmgr) (EventID: 46) (User: )
Description: Crash dump initialization failed!
 
Error: (10/26/2014 09:07:55 AM) (Source: volsnap) (EventID: 36) (User: )
Description: The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.
 
Error: (10/26/2014 09:03:51 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Windows Biometric Service service depends on the Credential Manager service which failed to start because of the following error: 
%%112
 
Error: (10/26/2014 09:03:51 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Credential Manager service terminated with the following error: 
%%112
 
Error: (10/26/2014 09:03:51 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Windows Biometric Service service depends on the Credential Manager service which failed to start because of the following error: 
%%112
 
Error: (10/26/2014 09:03:51 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Credential Manager service terminated with the following error: 
%%112
 
Error: (10/26/2014 08:39:44 AM) (Source: volmgr) (EventID: 46) (User: )
Description: Crash dump initialization failed!
 
Error: (10/26/2014 08:32:38 AM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: The PEVSystemStart service is marked as an interactive service.  However, the system is configured to not allow interactive services.  This service may not function properly.
 
Error: (10/26/2014 08:32:35 AM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: The PEVSystemStart service is marked as an interactive service.  However, the system is configured to not allow interactive services.  This service may not function properly.
 
Error: (10/26/2014 08:32:14 AM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
 
 
Microsoft Office Sessions:
=========================
Error: (10/26/2014 09:03:53 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1533) (User: Mikey-PC)
Description: C:\Users\MommyThe directory is not empty.
 
Error: (10/26/2014 08:15:08 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: C:\Windows\system32\wbem\wmiprvse.exeOTL Restore Point - 10/26/2014 8:15:05 AM0x8004231f
 
Error: (10/26/2014 08:09:14 AM) (Source: System Restore) (EventID: 8211) (User: )
Description: 0x80070070
 
Error: (10/26/2014 08:09:14 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: C:\Windows\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreationScheduled Checkpoint0x80070070
 
Error: (10/26/2014 08:02:18 AM) (Source: Application Error) (EventID: 1005) (User: )
Description: C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\mpcache-AFABC0C75B5E288A9B61462814EE0A01A6DF853E.bin.VE0Antimalware Service ExecutableC000007F3
 
Error: (10/26/2014 08:02:18 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: MsMpEng.exe4.6.305.053f7bfb6mpengine.dll1.1.11104.0543d795dc0000006000000000011bc2e144001cff12574027600C:\Program Files\Microsoft Security Client\MsMpEng.exeC:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{4F9AC8EA-246D-429F-8922-80C6B47ABDC9}\mpengine.dllb2255c2e-5d18-11e4-909a-d43d7e49cda2
 
Error: (10/26/2014 08:02:17 AM) (Source: Application Error) (EventID: 1005) (User: )
Description: C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\mpcache-AFABC0C75B5E288A9B61462814EE0A01A6DF853E.bin.VE0Antimalware Service ExecutableC000007F3
 
Error: (10/26/2014 08:02:17 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: MsMpEng.exe4.6.305.053f7bfb6mpengine.dll1.1.11104.0543d795dc00000060000000000047f023dc01cfefd9ee3d250fC:\Program Files\Microsoft Security Client\MsMpEng.exeC:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{4F9AC8EA-246D-429F-8922-80C6B47ABDC9}\mpengine.dllb13c1677-5d18-11e4-909a-d43d7e49cda2
 
Error: (09/29/2014 05:50:44 AM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description: 
Details:
The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)
 
Error: (09/29/2014 05:50:44 AM) (Source: Windows Search Service) (EventID: 3058) (User: )
Description: Context: Windows Application
 
 
Details:
The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)
 
 
CodeIntegrity Errors:
===================================
  Date: 2014-10-26 08:32:14.549
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2014-10-26 08:32:14.483
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2012-12-23 09:53:30.847
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\XHCIdrv.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2012-12-23 09:53:30.825
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\XHCIdrv.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i5-2500K CPU @ 3.30GHz
Percentage of memory in use: 33%
Total physical RAM: 8136.58 MB
Available physical RAM: 5418.39 MB
Total Pagefile: 8134.76 MB
Available Pagefile: 5070.86 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:55.68 GB) (Free:0 GB) NTFS
Drive d: (New Volume) (Fixed) (Total:1667.7 GB) (Free:1290.49 GB) NTFS
Drive f: (COD4MW) (CDROM) (Total:6.32 GB) (Free:0 GB) UDF
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 55.9 GB) (Disk ID: 909A2A0E)
 
Partition: GPT Partition Type.
 
========================================================
Disk: 1 (Size: 1863 GB) (Disk ID: 000DE149)
 
Partition: GPT Partition Type.
 
==================== End Of Log ============================
 
 
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-10-2014
Ran by Mikey (administrator) on MIKEY-PC on 26-10-2014 11:10:16
Running from D:\Downloads
Loaded Profile: Mikey (Available profiles: Mikey)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe
(Hi-Rez Studios) D:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Program Files (x86)\ASUS\Printer Utilities\UsbService64.exe
(MicroStudio) C:\Program Files (x86)\Windows Network Accelerater\v3\winvxm.exe
(MicroTools) C:\Program Files (x86)\YouTube Downloader Services\youtubeserv.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Akamai Technologies, Inc.) C:\Users\Mikey\AppData\Local\Akamai\netsession_win.exe
(Akamai Technologies, Inc.) C:\Users\Mikey\AppData\Local\Akamai\netsession_win.exe
(Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe
(BitTorrent Inc.) C:\Users\Mikey\AppData\Roaming\uTorrent\uTorrent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) D:\Program Files (x86)\iTunes\iTunesHelper.exe
(Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusionHookAppWIN6064.exe
(Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusionHookAppWIN6032.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\GFExperience.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Blackfish Software) C:\Users\Mikey\AppData\Local\IE Tab\7.10.21.1\ietabhelper.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [CmPCIaudio] => C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\CMICNFG3.dll,CMICtrlWnd
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [7406392 2012-11-28] (Logitech Inc.)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2463552 2014-10-04] (NVIDIA Corporation)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-21] (Intel Corporation)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2014-10-11] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [iTunesHelper] => D:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKU\S-1-5-21-1720781654-3047350990-1079063203-1000\...\Run: [Akamai NetSession Interface] => C:\Users\Mikey\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.)
HKU\S-1-5-21-1720781654-3047350990-1079063203-1000\...\Run: [DisplayFusion] => C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe [8854880 2014-09-09] (Binary Fortress Software)
HKU\S-1-5-21-1720781654-3047350990-1079063203-1000\...\Run: [DAEMON Tools Lite] => D:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-1720781654-3047350990-1079063203-1000\...\Run: [uTorrent] => C:\Users\Mikey\AppData\Roaming\uTorrent\uTorrent.exe [1385808 2014-10-09] (BitTorrent Inc.)
Startup: C:\Users\Mikey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x5727BBF16F39CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - {E6957116-DFE1-4A9E-9922-66747C34C5F0} URL = https://search.yahoo...p={searchTerms}
BHO: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.)
BHO-x32: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
Tcpip\Parameters: [DhcpNameServer] 75.75.76.76 75.75.75.75
 
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> D:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll No File
FF Plugin-x32: @esn/esnlaunch,version=2.1.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.1.2\npesnlaunch.dll No File
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> D:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll No File
FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 -> C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.6 -> D:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin HKCU: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll No File
 
Chrome: 
=======
CHR Profile: C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-03-24]
CHR Extension: (Google Drive) - C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-03-24]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-05-31]
CHR Extension: (YouTube) - C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-03-24]
CHR Extension: (Battlefield Heroes) - C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehdakiococlfmjcbebbkjkfjhbieknh [2013-04-07]
CHR Extension: (Google Search) - C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-03-24]
CHR Extension: (Pandora) - C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbangkleohkafngihneedemihgfeikcl [2014-06-12]
CHR Extension: (IE Tab) - C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\hehijbfgiekmjfkfjpbkbammjbdenadd [2014-08-12]
CHR Extension: (Google Wallet) - C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-06]
CHR Extension: (Evernote Web Clipper) - C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc [2013-12-08]
CHR Extension: (Gmail) - C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-03-24]
CHR Extension: (Canvas Rider) - C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default\Extensions\poknhlcknimnnbfcombaooklofipaibk [2013-05-16]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2014-01-19] () [File not signed]
R2 DisplayFusionService; C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe [5278064 2014-09-09] (Binary Fortress Software)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1149760 2014-10-04] (NVIDIA Corporation)
U2 HiPatchService; D:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9216 2014-07-18] (Hi-Rez Studios) [File not signed]
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1796928 2014-10-04] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19440960 2014-10-04] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [75136 2013-04-07] ()
R2 UsbService; C:\Program Files (x86)\ASUS\Printer Utilities\UsbService64.exe [334848 2010-08-10] () [File not signed]
R2 WindowsVNT_R3; C:\Program Files (x86)\Windows Network Accelerater\v3\winvxm.exe [2973600 2014-10-20] (MicroStudio) [File not signed]
S2 WSWNDA3100v2; C:\Program Files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe [307928 2013-12-30] ()
R2 YouTubeDownload; C:\Program Files (x86)\YouTube Downloader Services\youtubeserv.exe [2284128 2014-09-05] (MicroTools)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 ampa; C:\Windows\system32\ampa.sys [15288 2011-12-26] () [File not signed]
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)
R3 cmuda3; C:\Windows\System32\drivers\cmudax3.sys [1155072 2009-10-22] (C-Media Inc)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-07-01] (Disc Soft Ltd)
R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [46568 2013-01-18] ()
R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [66360 2012-10-02] (Logitech Inc.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
S3 NTIOLib_1_0_6; C:\Program Files (x86)\Setup Files\Ms7758v270\NTIOLib_X64.sys [11888 2011-01-06] (MSI) [File not signed]
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20288 2014-10-04] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38048 2014-09-04] (NVIDIA Corporation)
S3 RTWlanE; C:\Windows\System32\DRIVERS\rtwlane.sys [2975960 2013-09-25] (Realtek Semiconductor Corporation                           )
R3 vuhub; C:\Windows\System32\DRIVERS\vuhub.sys [47616 2007-12-17] ()
S3 XHCIdrv; C:\Windows\System32\DRIVERS\XHCIdrv.sys [102400 2012-11-07] (Windows ® Win 7 DDK provider)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 ESEADriver2; \??\C:\Users\Mikey\AppData\Local\Temp\ESEADriver2.sys [X]
S3 MSICDSetup; \??\E:\CDriver64.sys [X]
S3 MSI_MSIBIOS_010507; \??\D:\Program Files (x86)\MSI\Live Update 5\msibios64_100507.sys [X]
S3 NTIOLib_1_0_4; \??\D:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [X]
S3 NTIOLib_1_0_C; \??\E:\NTIOLib_X64.sys [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-10-26 11:10 - 2014-10-26 11:10 - 00000000 ____D () C:\FRST
2014-10-26 09:09 - 2014-10-26 09:54 - 00000000 ____D () C:\AdwCleaner
2014-10-26 09:08 - 2014-10-26 09:08 - 00029869 _____ () C:\ComboFix.txt
2014-10-26 08:39 - 2014-10-26 08:36 - 53215232 _____ () C:\Windows\system32\config\COMPONENTS.bak
2014-10-26 08:27 - 2014-10-26 09:08 - 00000000 ____D () C:\Qoobox
2014-10-26 08:27 - 2011-06-26 00:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-10-26 08:27 - 2010-11-07 11:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-10-26 08:27 - 2009-04-19 22:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-10-26 08:27 - 2000-08-30 18:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-10-26 08:27 - 2000-08-30 18:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-10-26 08:27 - 2000-08-30 18:00 - 00098816 _____ () C:\Windows\sed.exe
2014-10-26 08:27 - 2000-08-30 18:00 - 00080412 _____ () C:\Windows\grep.exe
2014-10-26 08:27 - 2000-08-30 18:00 - 00068096 _____ () C:\Windows\zip.exe
2014-10-26 08:26 - 2014-10-26 08:53 - 00000000 ____D () C:\Windows\erdnt
2014-10-26 08:21 - 2014-10-26 09:55 - 00011804 _____ () C:\Windows\PFRO.log
2014-10-26 08:21 - 2014-10-26 09:55 - 00000000 ____D () C:\ProgramData\Windows VXM
2014-10-26 08:21 - 2014-10-26 08:21 - 00000000 ____D () C:\ProgramData\Optimizer
2014-10-26 08:13 - 2014-10-26 08:13 - 00000218 _____ () C:\Users\Mikey\AppData\Local\recently-used.xbel
2014-10-25 12:41 - 2014-10-25 12:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Miro Video Converter
2014-10-25 12:41 - 2014-10-25 12:41 - 00000000 ____D () C:\Program Files (x86)\Participatory Culture Foundation
2014-10-25 12:38 - 2014-10-25 12:38 - 00000000 ____D () C:\Program Files (x86)\Windows Network Accelerater
2014-10-25 12:37 - 2014-10-25 12:37 - 00000000 ____D () C:\Program Files (x86)\YouTube Downloader Services
2014-10-25 12:37 - 2009-09-27 09:39 - 00415744 ___SH (The Public) C:\Windows\SysWOW64\avisynth.dll
2014-10-25 12:37 - 2005-07-14 12:31 - 00032256 ___SH () C:\Windows\SysWOW64\AVSredirect.dll
2014-10-25 12:37 - 2004-02-22 10:11 - 00764416 ___SH (Abysmal Software) C:\Windows\SysWOW64\devil.dll
2014-10-25 12:37 - 2004-01-25 00:00 - 00070656 ___SH (www.helixcommunity.org) C:\Windows\SysWOW64\yv12vfw.dll
2014-10-25 12:37 - 2004-01-25 00:00 - 00070656 ___SH (www.helixcommunity.org) C:\Windows\SysWOW64\i420vfw.dll
2014-10-25 12:34 - 2014-03-07 11:03 - 03109520 ___SH (FFmpeg Project) C:\Windows\SysWOW64\avcodec-lav-55.dll
2014-10-25 12:34 - 2014-03-07 11:03 - 00550032 ___SH (FFmpeg Project) C:\Windows\SysWOW64\avformat-lav-55.dll
2014-10-25 12:34 - 2014-03-07 11:03 - 00313520 ___SH (1f0.de - Hendrik Leppkes) C:\Windows\SysWOW64\HLvideo.dll
2014-10-25 12:34 - 2014-03-07 11:03 - 00203408 ___SH (1f0.de - Hendrik Leppkes) C:\Windows\SysWOW64\HLsplit.dll
2014-10-25 12:34 - 2014-03-07 11:03 - 00181392 ___SH (FFmpeg Project) C:\Windows\SysWOW64\avutil-lav-52.dll
2014-10-25 12:34 - 2014-03-07 11:03 - 00122512 ___SH (1f0.de - Hendrik Leppkes) C:\Windows\SysWOW64\HLaudio.dll
2014-10-25 12:34 - 2014-03-07 11:03 - 00118416 ___SH (FFmpeg Project) C:\Windows\SysWOW64\swscale-lav-2.dll
2014-10-25 12:34 - 2014-03-07 11:03 - 00109712 ___SH () C:\Windows\SysWOW64\libbluray.dll
2014-10-25 12:34 - 2014-03-07 11:03 - 00098960 ___SH (FFmpeg Project) C:\Windows\SysWOW64\avfilter-lav-4.dll
2014-10-25 12:34 - 2014-03-07 11:03 - 00059536 ___SH (FFmpeg Project) C:\Windows\SysWOW64\avresample-lav-1.dll
2014-10-25 12:34 - 2012-10-05 19:54 - 00188416 ___SH () C:\Windows\SysWOW64\winDCE32.dll
2014-10-25 12:34 - 2011-06-14 20:05 - 00121344 ___SH () C:\Windows\SysWOW64\TAKDSDecoder.ax
2014-10-25 12:34 - 2011-02-11 10:26 - 00112128 ___SH () C:\Windows\SysWOW64\OptimFROG.dll
2014-10-25 12:34 - 2010-01-07 00:00 - 00107520 ___SH () C:\Windows\SysWOW64\TAKDSDecoder.dll
2014-10-25 12:34 - 2009-08-10 23:00 - 00352768 ___SH () C:\Windows\SysWOW64\ac3DX.ax
2014-10-25 12:34 - 2005-02-22 17:55 - 00081920 ___SH () C:\Windows\SysWOW64\aac_parser.ax
2014-10-25 12:34 - 2004-10-10 09:50 - 00278528 _____ (Real Networks, Inc) C:\Windows\SysWOW64\pncrt.dll
2014-10-25 12:34 - 2004-07-02 17:33 - 00327749 _____ (RealNetworks, Inc.) C:\Windows\SysWOW64\drvc.dll
2014-10-25 12:34 - 2004-04-27 16:03 - 00017408 ___SH (RadLight) C:\Windows\SysWOW64\RLOFRDec.ax
2014-10-25 12:34 - 2004-04-05 10:31 - 00499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll
2014-10-25 12:33 - 2014-10-25 12:33 - 00000000 ____D () C:\Program Files (x86)\eRightSoft
2014-10-21 19:16 - 2014-10-21 19:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-10-21 19:15 - 2014-10-21 19:16 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2014-10-21 19:15 - 2014-10-21 19:16 - 00000000 ____D () C:\Program Files\iTunes
2014-10-21 19:15 - 2014-10-21 19:15 - 00000000 ____D () C:\Program Files\iPod
2014-10-18 16:42 - 2014-10-18 16:42 - 00000096 _____ () C:\Users\Mikey\AppData\Roaming\settings.xml
2014-10-18 16:42 - 2014-10-18 16:42 - 00000000 ____D () C:\Users\Mikey\AppData\Roaming\Convert Audio Free
2014-10-18 16:42 - 2014-10-18 16:42 - 00000000 ____D () C:\Users\Mikey\AppData\Local\SkinSoft
2014-10-16 03:03 - 2014-10-16 03:03 - 00000000 ____D () C:\Program Files (x86)\Microsoft ASP.NET
2014-10-16 01:56 - 2014-09-28 18:58 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-10-16 01:56 - 2014-06-18 16:23 - 01943696 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2014-10-16 01:56 - 2014-06-18 16:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll
2014-10-16 01:56 - 2014-06-18 16:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll
2014-10-16 01:56 - 2014-06-18 16:23 - 00156312 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2014-10-16 01:56 - 2014-06-18 16:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll
2014-10-16 01:56 - 2014-06-18 16:23 - 00073880 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-10-26 11:10 - 2012-12-23 10:38 - 00000000 ____D () C:\Users\Mikey\AppData\Roaming\uTorrent
2014-10-26 11:09 - 2014-08-09 09:26 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-10-26 10:28 - 2012-12-13 09:32 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-10-26 10:02 - 2009-07-13 22:45 - 00027312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-10-26 10:02 - 2009-07-13 22:45 - 00027312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-10-26 10:01 - 2009-07-13 23:13 - 00782470 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-10-26 09:58 - 2012-12-13 09:32 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-10-26 09:58 - 2012-12-13 09:27 - 01921423 _____ () C:\Windows\WindowsUpdate.log
2014-10-26 09:55 - 2013-02-09 14:32 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-10-26 09:55 - 2009-07-13 23:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-26 09:08 - 2009-07-13 21:20 - 00000000 __RHD () C:\Users\Default
2014-10-26 09:04 - 2014-04-06 18:36 - 00000000 ____D () C:\Users\Mommy
2014-10-26 08:52 - 2009-07-13 20:34 - 00000215 _____ () C:\Windows\system.ini
2014-10-26 08:39 - 2009-07-13 20:34 - 19398656 _____ () C:\Windows\system32\config\SYSTEM.bak
2014-10-26 08:39 - 2009-07-13 20:34 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak
2014-10-26 08:39 - 2009-07-13 20:34 - 00262144 _____ () C:\Windows\system32\config\SAM.bak
2014-10-26 08:39 - 2009-07-13 20:34 - 00262144 _____ () C:\Windows\system32\config\DEFAULT.bak
2014-10-25 16:20 - 2014-08-05 18:05 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-10-25 14:35 - 2014-08-12 15:03 - 00000000 ____D () C:\Users\Mikey\AppData\Local\IE Tab
2014-10-25 12:48 - 2013-05-27 14:13 - 00000000 ____D () C:\Users\Mikey\AppData\Roaming\vlc
2014-10-22 18:08 - 2014-08-05 18:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-10-22 18:08 - 2014-08-05 18:05 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
 
Files to move or delete:
====================
C:\Users\Mikey\jagex_cl_loginapplet_LIVE.dat
C:\Users\Mikey\jagex_cl_runescape_LIVE.dat
C:\Users\Mikey\jagex_cl_runescape_LIVE1.dat
C:\Users\Mikey\random.dat
 
 
Some content of TEMP:
====================
C:\Users\Mikey\AppData\Local\Temp\Quarantine.exe
C:\Users\Mikey\AppData\Local\Temp\sqlite3.dll
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2014-10-16 00:47
 
==================== End Of Log ============================

  • 0

#6
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
How is the computer now, any further problems ?
  • 0

#7
Fatie32

Fatie32

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 122 posts

Looks to be running solidly again. None that im aware of. Thank you for all the help i appreciate it.


  • 0

#8
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Subject to no further problems :)

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems

Now the best part of the day ----- Your log now appears clean :thumbsup:

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset System Restore points:

Click Start then Run.
On Windows7 or Vista you may use Start Search field if Run is not available.
In the box copy/paste the following command:

ComboFix /Uninstall

Note that there is a space between " ComboFix " and " /Uninstall " .

Then click OK (or press Enter ).
Wait for the uninstall process to complete.

Download and run Delfix

delfix.JPG

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:

CryptoPrevent install this programme to lock down and prevent crypto ransome ware

CryptoPrevent.JPG

Malwarebytes.

Update and run weekly to keep your system clean


It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To learn more about how to protect yourself while on the internet read this little guide Best security practices Keep safe :wave:
  • 0

#9
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP