This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Recurring "Freezes and Crashes"

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have just run Microsoft Security Essentials, which scanned 4,917,014 items and reported NO problem. Meanwhile, in recent weeks, my system has suffered frequent "freeze ups" and two "Blue Screens". In following your instruction to use OTL, the following two files have been derived:

OTL logfile created on: 10/22/2011 8:41:54 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Jim\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.87 Gb Total Physical Memory | 1.59 Gb Available Physical Memory | 55.36% Memory free
8.77 Gb Paging File | 6.48 Gb Available in Paging File | 73.82% Paging File free
Paging file location(s): [Binary data over 100 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 286.60 Gb Total Space | 173.66 Gb Free Space | 60.59% Space Free | Partition Type: NTFS
Drive D: | 11.49 Gb Total Space | 1.11 Gb Free Space | 9.65% Space Free | Partition Type: NTFS
Drive J: | 74.53 Gb Total Space | 3.02 Gb Free Space | 4.05% Space Free | Partition Type: NTFS

Computer Name: JIM-PC | User Name: Jim | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Jim\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Ninite Updater\NiniteUpdater.exe (Secure By Design Inc.)
PRC - C:\Program Files\IObit\Advanced SystemCare 4\ASC.exe (IObit)
PRC - C:\Program Files\Soluto\Soluto.exe (Soluto)
PRC - C:\Program Files\Soluto\SolutoService.exe (Soluto)
PRC - C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe (Siber Systems)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\DAP\DAP.exe (SpeedBit Ltd.)
PRC - C:\Program Files\FreeClip\FreeClip.exe (M8 Software)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AWSC.exe ()
PRC - C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe (IObit)
PRC - C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
PRC - C:\Program Files\iolo\System Mechanic\SystemGuardAlerter.exe (iolo technologies, LLC)
PRC - C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe (iolo technologies, LLC)
PRC - C:\Program Files\SpeedBit Video Accelerator\VideoAcceleratorService.exe (SpeedBit Ltd.)
PRC - C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe (SpeedBit LTD)
PRC - C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe (IObit)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Vista Start Menu\VistaStartMenu.exe (OrdinarySoft)
PRC - C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Secunia\PSI\sua.exe (Secunia)
PRC - C:\Program Files\IObit\Smart Defrag 2\SmartDefrag.exe (IObit)
PRC - C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\[removed]\firefox_wrapper.exe ()
PRC - C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe (Carbonite, Inc. (www.carbonite.com))
PRC - C:\Program Files\Fighters\FighterSuiteService.exe (SPAMfighter ApS)
PRC - C:\Program Files\Fighters\SPAMfighter\sfus.exe (SPAMfighter ApS)
PRC - C:\Program Files\Fighters\SPAMfighter\sfagent.exe (SPAMfighter ApS)
PRC - C:\Program Files\SureWest Communications\SureWest Internet Security 2010\avp.exe (SureWest Communications)
PRC - C:\Program Files\Immunet Protect\1.0.18\agent.exe (Immunet Corporation)
PRC - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (CANON INC.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Volumouse\volumouse.exe (NirSoft)
PRC - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
PRC - c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
PRC - C:\WINDOWS\System32\lxbkcoms.exe ( )


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCGPostBootResources\4308e3b9891080987bd9a0a028f226e0\PCGPostBootResources.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCGHIDProbe\7f13332e303075f587ce51a5eb561258\PCGHIDProbe.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCGRSPProbe\c762fb2e7c659f1ca101b72945e5af4e\PCGRSPProbe.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCGWuInfo\162eb71288ae8578de7c60d6cacff2fe\PCGWuInfo.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Community.CsharpSql#\b0ef79b55912bf82ff7018da5efeed83\Community.CsharpSqlite.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Interop.IWshRuntime#\2dadac7311c15d47aeec1ca4b05cfc88\Interop.IWshRuntimeLibrary.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCGUsersCenter\fa1d0c9ec676be6e717150c7a78c67aa\PCGUsersCenter.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCGClientCommon\fc8a6713f642ff836131396e2893b608\PCGClientCommon.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCGBootVisualizingC#\dcac1616a31423616b1627d907d47c05\PCGBootVisualizingCommon.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCGConfiguration\a868536378e29aae6ec1b01230014f4c\PCGConfiguration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCGDatabase\e0f576e8b7e1737b38f17dac047c780e\PCGDatabase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCGAzureEntityFrame#\313484677ad267f48f06d5a045196656\PCGAzureEntityFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCGAzureShared\8a50003f51951b204f0d28a213b158d7\PCGAzureShared.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCGCommunication\d9bb99c719e2a568661fd2929575e0fa\PCGCommunication.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCGDriverProbe\abe64bcfac50e7b7fb9f1fd646d00fe5\PCGDriverProbe.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCGPreCompiled\6254998814b7a2c7f6b83b02b1872bfa\PCGPreCompiled.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCGPrestoSerializer\3947368cc5af163e17f0c176421ba640\PCGPrestoSerializer.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Ionic.Zip.Reduced\665558e07cf0ad29a1ac85b8efa55e34\Ionic.Zip.Reduced.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCGFramework\e1055d072a7882f83b87b6e32397df58\PCGFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Soluto\eb505a1407b611b674249fb0efc2b35b\Soluto.ni.exe ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\1363115565fff5a641243a48f396f107\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8645de531003807d00822e03986a075d\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\367c4043efc2f32d843cb588b0dc97fc\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\c1c06a392871267db27f7cbc40e1c4fb\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\40da9084d0863e07d7ce55953833b8b0\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\eb04eb9fcd7c99e16d63515d08636a3f\System.Data.Linq.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\8adb45c62e4c797bd4c706afe9e8bfb9\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\f9c36ea806e77872dce891c77b68fac3\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\b6632a8b2f276a8e31f5b0f6b2006cd1\mscorlib.ni.dll ()
MOD - C:\WINDOWS\System32\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Program Files\Soluto\PCGDllExportInspector.dll ()
MOD - C:\Program Files\IObit\Advanced SystemCare 4\Scan.dll ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files\DAP\zlib.dll ()
MOD - C:\Program Files\IObit\Advanced SystemCare 4\ASCv4ExtMenu.dll ()
MOD - C:\Program Files\IObit\Advanced SystemCare 4\sqlite3.dll ()
MOD - C:\Program Files\IObit\Advanced SystemCare 4\NtfsData.dll ()
MOD - C:\Program Files\IObit\Advanced SystemCare 4\DiskMap.dll ()
MOD - C:\Program Files\Fighters\SPAMfighter\sfse.dll ()
MOD - C:\Program Files\BillP Studios\WinPatrol\sqlite3.dll ()
MOD - C:\Program Files\IObit\Smart Defrag 2\NtfsData.dll ()
MOD - C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\[removed]\firefox_wrapper.exe ()
MOD - C:\Program Files\Fighters\SPAMfighter\sfsg.dll ()
MOD - C:\Program Files\IObit\Smart Defrag 2\madbasic_.bpl ()
MOD - C:\Program Files\IObit\Smart Defrag 2\maddisAsm_.bpl ()
MOD - C:\Program Files\IObit\Smart Defrag 2\madexcept_.bpl ()
MOD - C:\Windows\assembly\GAC_MSIL\HP.ActiveSupportLibrary\2.0.0.1__01a974bc1760f423\HP.ActiveSupportLibrary.dll ()


========== Win32 Services (SafeList) ==========

SRV - (nosGetPlusHelper) getPlus® – File not found
SRV - (getPlusHelper) – File not found
SRV - (SolutoService) – C:\Program Files\Soluto\SolutoService.exe (Soluto)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (AdvancedSystemCareService) – C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
SRV - (ioloSystemService) – C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe (iolo technologies, LLC)
SRV - (Updater Service for StartNow Toolbar) – C:\Program Files\StartNow Toolbar\ToolbarUpdaterService.exe ()
SRV - (scan) – C:\Program Files\Immunet\tetra\scan.dll (S.C. BitDefender S.R.L)
SRV - (VideoAcceleratorService) – C:\Program Files\SpeedBit Video Accelerator\VideoAcceleratorService.exe (SpeedBit Ltd.)
SRV - (IMFservice) – C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe (IObit)
SRV - (NisSrv) – c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (Secunia PSI Agent) – C:\Program Files\Secunia\PSI\PSIA.exe (Secunia)
SRV - (Secunia Update Agent) – C:\Program Files\Secunia\PSI\sua.exe (Secunia)
SRV - (Firefox Service) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\[removed]\svc.exe ()
SRV - (CarboniteService) – C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe (Carbonite, Inc. (www.carbonite.com))
SRV - (Suite Service) – C:\Program Files\Fighters\FighterSuiteService.exe (SPAMfighter ApS)
SRV - (SPAMfighter Update Service) – C:\Program Files\Fighters\SPAMfighter\sfus.exe (SPAMfighter ApS)
SRV - (IntuitUpdateService) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (Common Toolkit Service) – C:\Program Files\Common Files\Common Toolkit Suite\FighterSuiteService.exe (SPAMfighter)
SRV - (AVP) – C:\Program Files\SureWest Communications\SureWest Internet Security 2010\avp.exe (SureWest Communications)
SRV - (ImmunetProtect) – C:\Program Files\Immunet Protect\1.0.18\agent.exe (Immunet Corporation)
SRV - (PCPitstop Scheduling) – C:\Program Files\PCPitstop\PCPitstopScheduleService.exe (PC Pitstop LLC)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (IJPLMSVC) – C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
SRV - (lxbk_device) – C:\Windows\System32\lxbkcoms.exe ( )
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (MpKsl15dc7566) – c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{CFB1B810-E16A-43A2-8422-3EFD06E91208}\MpKsl15dc7566.sys (Microsoft Corporation)
DRV - (Soluto) – C:\Windows\system32\DRIVERS\Soluto.sys (Soluto LTD.)
DRV - (Lbd) – C:\Windows\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (Lavasoft Kernexplorer) – C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys ()
DRV - (Trufos) – C:\WINDOWS\System32\drivers\Trufos.sys (BitDefender S.R.L.)
DRV - (NisDrv) – C:\WINDOWS\System32\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV - (MpNWMon) – C:\WINDOWS\System32\drivers\MpNWMon.sys (Microsoft Corporation)
DRV - (PfFilter) – C:\Program Files\IObit\Protected Folder\pffilter.sys (IObit Information Technology)
DRV - (SmartDefragDriver) – C:\Windows\System32\Drivers\SmartDefragDriver.sys ()
DRV - (VBoxNetAdp) – C:\WINDOWS\System32\drivers\VBoxNetAdp.sys (Oracle Corporation)
DRV - (cpuz135) – C:\WINDOWS\System32\drivers\cpuz135_x32.sys (CPUID)
DRV - (PSI) – C:\WINDOWS\System32\drivers\psi_mf.sys (Secunia)
DRV - (KLIF) – C:\WINDOWS\System32\drivers\klif.sys (Kaspersky Lab)
DRV - (ImmunetProtectDriver) – C:\WINDOWS\System32\drivers\ImmunetProtect.sys (Windows ® Codename Longhorn DDK provider)
DRV - (ImmunetSelfProtectDriver) – C:\WINDOWS\System32\drivers\ImmunetSelfProtect.sys (Windows ® Codename Longhorn DDK provider)
DRV - (ImmunetMonitorDriver) – C:\WINDOWS\System32\drivers\ImmunetMonitor.sys (Windows ® Codename Longhorn DDK provider)
DRV - (klbg) – C:\Windows\system32\drivers\klbg.sys (Kaspersky Lab)
DRV - (klmouflt) – C:\WINDOWS\System32\drivers\klmouflt.sys (Kaspersky Lab)
DRV - (KLIM6) – C:\WINDOWS\System32\drivers\klim6.sys (Kaspersky Lab)
DRV - (ElRawDisk) – C:\WINDOWS\System32\drivers\ElRawDsk.sys (EldoS Corporation)
DRV - (kl1) – C:\WINDOWS\System32\drivers\kl1.sys (Kaspersky Lab)
DRV - (nvsmu) – C:\WINDOWS\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (nvlddmkm) – C:\WINDOWS\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (HSXHWBS3) – C:\WINDOWS\System32\drivers\HSXHWBS3.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\System32\drivers\HSX_DP.sys (Conexant Systems, Inc.)
DRV - (XAudio) – C:\WINDOWS\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (Ps2) – C:\WINDOWS\System32\drivers\PS2.sys (Hewlett-Packard Company)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cndt
IE - HKLM\..\URLSearchHook: {3ba34663-845a-4931-a6f3-1e033ec342a7} - No CLSID value found
IE - HKLM\..\URLSearchHook: {e917fc61-7f80-4f1f-a882-cdffffbe4c8d} - No CLSID value found

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.bing.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid;=CT2475029
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.defaultthis.engineName: "Thoosje Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2434356&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..browser.search.openintab: true
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.order.2: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.msn.com/?pc=Z192&install;_date=20111005"
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.8
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20110323
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {F17C1572-C9EC-4e5c-A542-D05CBB5C5A08}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.6.2
FF - prefs.js..extensions.enabledItems: {0329E7D6-6F54-462D-93F6-F5C3118BADF2}:2.3.1
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.10.1
FF - prefs.js..extensions.enabledItems: [removed]:0.9.8.0
FF - prefs.js..extensions.enabledItems: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}:1.49
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "http://www.bing.com/search?pc=Z192&form;=ZGAADF&install;_date=20111005&q;="
FF - prefs.js..network.proxy.type: 0

FF - user.js..browser.search.openintab: true

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: File not found
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@mozilla.zeniko.ch/SumatraPDF_Browser_Plugin: C:\Program Files\SumatraPDF\npPdfViewer.dll (Simon Bünzli)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.666: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.666: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.666: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.666: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.666: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@mozilla.zeniko.ch/SumatraPDF_Browser_Plugin: C:\Program Files\SumatraPDF\npPdfViewer.dll (Simon Bünzli)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Jim\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Jim\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}: C:\Program Files\SpeedBit Video Downloader\SPFireFox [2011/09/19 23:08:41 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\SearchPredict\PRFireFox [2011/09/19 23:08:28 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/10/16 20:11:11 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2011/10/04 15:56:55 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/10/19 13:06:26 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/20 22:17:44 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 7.0.1\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011/10/03 11:14:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\Program Files\SureWest Communications\SureWest Internet Security 2010\THBExt [2010/06/04 00:22:07 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{F17C1572-C9EC-4e5c-A542-D05CBB5C5A08}: C:\Program Files\DAP\DAPFireFox [2011/09/20 09:36:11 | 000,000,000 | —D | M]

[2009/12/11 12:38:52 | 000,000,000 | —D | M] (No name found) – C:\Users\Jim\AppData\Roaming\Mozilla\Extensions
[2009/12/09 14:49:56 | 000,000,000 | —D | M] (No name found) – C:\Users\Jim\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2009/12/11 12:38:52 | 000,000,000 | —D | M] (No name found) – C:\Users\Jim\AppData\Roaming\Mozilla\Extensions\[removed]
[2011/10/20 23:34:34 | 000,000,000 | —D | M] (No name found) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions
[2010/11/03 16:04:56 | 000,000,000 | —D | M] (FlashGot) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}(108)
[2011/10/01 23:16:52 | 000,000,000 | —D | M] (Thoosje Community Toolbar) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\{3ba34663-845a-4931-a6f3-1e033ec342a7}(202)
[2011/10/05 11:23:15 | 000,000,000 | —D | M] (StartNow Toolbar) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}
[2011/07/02 18:11:43 | 000,000,000 | —D | M] (D-Link Toolbar) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\{926a10d2-4ce7-4331-b96f-ca4e22590fac}
[2011/07/09 11:32:29 | 000,000,000 | —D | M] (WOT) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2011/10/01 23:16:05 | 000,000,000 | —D | M] (MyAshampoo Community Toolbar) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}(203)
[2011/08/18 10:06:42 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/07/26 23:17:01 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}(239)
[2010/03/20 21:42:01 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}(279)
[2010/07/23 09:30:11 | 000,000,000 | —D | M] (No name found) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\Access Privileges Test
[2011/07/25 12:04:23 | 000,000,000 | —D | M] (Conduit Engine) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\[removed]
[2011/06/03 21:23:05 | 000,000,000 | —D | M] (F1 by Mozilla Labs) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\[removed]
[2010/11/13 17:18:14 | 000,000,000 | —D | M] (No name found) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\nostmp
[2011/03/23 16:32:42 | 000,000,000 | —D | M] (Personas) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\[removed]
[2010/06/11 23:44:53 | 000,000,000 | —D | M] (FastestFox) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\smarterwiki@wikiatic(324).com
[2011/04/05 21:44:43 | 000,000,000 | —D | M] (startup.service) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\[removed]
[2011/07/02 13:03:36 | 000,002,569 | —- | M] () – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\searchplugins\askcom.xml
[2011/10/05 11:23:10 | 000,001,945 | —- | M] () – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\searchplugins\bing-zugo.xml
[2011/03/21 16:06:42 | 000,000,917 | —- | M] () – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\searchplugins\conduit.xml
[2011/10/19 13:10:43 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/12/22 02:09:26 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/02/22 10:29:38 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/10/19 13:10:43 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2011/09/20 09:36:11 | 000,000,000 | —D | M] (Download Accelerator Plus (DAP) extension) – C:\PROGRAM FILES\DAP\DAPFIREFOX
[2011/10/16 20:11:11 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\PROGRAMDATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
() (No name found) – C:\USERS\JIM\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2B9587RE.DEFAULT\EXTENSIONS\{19503E42-CA3C-4C27-B1E2-9CDB2170EE34}.XPI
() (No name found) – C:\USERS\JIM\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2B9587RE.DEFAULT\EXTENSIONS\{AD48108D-92A6-4EB9-87E4-978ACA1DBAE4}.XPI
() (No name found) – C:\USERS\JIM\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2B9587RE.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\USERS\JIM\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2B9587RE.DEFAULT\EXTENSIONS\{D40F5E7B-D2CF-4856-B441-CC613EEFFBE3}.XPI
() (No name found) – C:\USERS\JIM\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2B9587RE.DEFAULT\EXTENSIONS\{D4DD63FA-01E4-46A7-B6B1-EDAB7D6AD389}.XPI
() (No name found) – C:\USERS\JIM\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2B9587RE.DEFAULT\EXTENSIONS\{DAF44BF7-A45E-4450-979C-91CF07434C3D}.XPI
() (No name found) – C:\USERS\JIM\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2B9587RE.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\JIM\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2B9587RE.DEFAULT\EXTENSIONS\[removed]
[2011/09/28 23:53:40 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/10/19 13:09:56 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/09/28 17:26:50 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Jim\AppData\Local\Google\Chrome\Application\14.0.835.202\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Disabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Disabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Disabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Jim\AppData\Local\Google\Chrome\Application\14.0.835.202\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Jim\AppData\Local\Google\Chrome\Application\14.0.835.202\pdf.dll
CHR - plugin: RoboForm Plugin for Google Chrome/Opera/etc. (Enabled) = C:\Program Files\Siber Systems\AI RoboForm\Chrome\plugin/rf-np-plugin.dll
CHR - plugin: downloadUpdater (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdnu.dll
CHR - plugin: downloadUpdater2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdnupdater2.dll
CHR - plugin: RealJukebox NS Plugin (Disabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Disabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Disabled) = C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: SumatraPDF Browser Plugin (Enabled) = C:\Program Files\SumatraPDF\npPdfViewer.dll
CHR - plugin: RealNetworks™ Chrome Background Extension Plug-In (32-bit) (Disabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: Windows Presentation Foundation (Disabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Jim\AppData\Local\Google\Chrome\Application\13.0.782.220\pdf.dll
CHR - Extension: TrackMeNot = C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgllkjmdafllcidaehjejjhpfkmanmka\0.2.1_0\
CHR - Extension: Download Accelerator Plus (DAP) = C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffdcfjdljhbehggjdkdioajnknjcpbjb\2.0.8_0\
CHR - Extension: UnSearch = C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\jojanedhfpmmjlkakmkhkgalbaokiphp\0.1_0\
CHR - Extension: RoboForm Lite = C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\kidhjpmgjfbkmcfpfakmdddddgfbhahj\2.7.0_0\

O1 HOSTS File: ([2011/09/05 11:37:33 | 000,437,206 | R— | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 15040 more lines…
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Reg Error: Value error.) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (SBCONVERT Class) - {92A9ACF4-9333-43AE-9698-DB283326F87F} - C:\Program Files\SpeedBit Video Downloader\TBUDD\tbcore3.dll ()
O2 - BHO: (GrabberObj Class) - {FF7C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\SpeedBit Video Downloader\TBUDD\Grabber.dll (SpeedBit)
O2 - BHO: (no name) - Disabled:{30F9B915-B755-4826-820B-08FBA6BD249D} - No CLSID value found.
O2 - BHO: (no name) - Disabled:{9030D464-4C02-4ABF-8ECC-5164760863C6} - No CLSID value found.
O2 - BHO: (no name) - Disabled:{DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O3 - HKLM\..\Toolbar: (SpeedBit Video Downloader) - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - C:\Program Files\SpeedBit Video Downloader\TBUDD\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - Reg Error: Value error. File not found
O3 - HKLM\..\Toolbar: (no name) - {3ba34663-845a-4931-a6f3-1e033ec342a7} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {61874dfa-9adf-44e5-8e61-f3913707e7d7} - No CLSID value found.
O3 - HKLM\..\Toolbar: (&RoboForm;) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (SpeedBit) - {EBFCD017-BCAD-42C3-9ED5-89DBDFC59171} - C:\Program Files\SpeedBit Toolbar\Toolbar\tbcore3.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - Reg Error: Value error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (SpeedBit) - {EBFCD017-BCAD-42C3-9ED5-89DBDFC59171} - C:\Program Files\SpeedBit Toolbar\Toolbar\tbcore3.dll ()
O4 - HKLM..\Run: [AVP] C:\Program Files\SureWest Communications\SureWest Internet Security 2010\avp.exe (SureWest Communications)
O4 - HKLM..\Run: [iolo Startup] C:\Program Files\iolo\Common\Lib\ioloLManager.exe (iolo technologies, LLC)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Ninite Updater] C:\Program Files\Ninite Updater\NiniteUpdater.exe (Secure By Design Inc.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [Advanced SystemCare 4] C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe (IObit)
O4 - HKLM..\RunOnce: [SMRequiresRestart] File not found
O4 - Startup: C:\Users\Jim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FreeClip.lnk = C:\Program Files\FreeClip\FreeClip.exe (M8 Software)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: TaskbarNoThumbnail = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCANetwork = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCABattery = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisallowCpl = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: 4 = Phone and Modem Options
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: 6 = Regional and Language Options
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\SearchExtensions: InternetExtensionName =
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\SearchExtensions: InternetExtensionAction =
O8 - Extra context menu item: &Download; with &DAP; - C:\Program Files\DAP\dapextie.htm ()
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\SureWest Communications\SureWest Internet Security 2010\ie_banner_deny.htm ()
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Download &all; with DAP - C:\Program Files\DAP\dapextie2.htm ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm TaskBar Icon - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComTaskBarIcon.html ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: &Virtual; keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\SureWest Communications\SureWest Internet Security 2010\klwtbbho.dll (SureWest Communications)
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: URLs c&heck; - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\SureWest Communications\SureWest Internet Security 2010\klwtbbho.dll (SureWest Communications)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\SpeedBit Video Accelerator\LSP3.2.2.4\SBLSP.dll (SpeedBit)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\SpeedBit Video Accelerator\LSP3.2.2.4\SBLSP.dll (SpeedBit)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\SpeedBit Video Accelerator\LSP3.2.2.4\SBLSP.dll (SpeedBit)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\SpeedBit Video Accelerator\LSP3.2.2.4\SBLSP.dll (SpeedBit)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\SpeedBit Video Accelerator\LSP3.2.2.4\SBLSP.dll (SpeedBit)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\SpeedBit Video Accelerator\LSP3.2.2.4\SBLSP.dll (SpeedBit)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\SpeedBit Video Accelerator\LSP3.2.2.4\SBLSP.dll (SpeedBit)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\SpeedBit Video Accelerator\LSP3.2.2.4\SBLSP.dll (SpeedBit)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Program Files\SpeedBit Video Accelerator\LSP3.2.2.4\SBLSP.dll (SpeedBit)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Value error.)
O16 - DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCMaticVer Class)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} https://signin3.valueactive.eu/Register/Bra…OCX/flashax.cab (Reg Error: Value error.)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll (PCPitstop Exam)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6121B89B-995D-4FCD-A93A-4F08A562CFB9}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\inbox - No CLSID value found
O20 - AppInit_DLLs: (C:\PROGRA~1\SUREWE~1\SUREWE~2\mzvkbd3.dll) -C:\Program Files\SureWest Communications\SureWest Internet Security 2010\mzvkbd3.dll (SureWest Communications)
O20 - AppInit_DLLs: (C:\PROGRA~1\SUREWE~1\SUREWE~2\kloehk.dll) -C:\Program Files\SureWest Communications\SureWest Internet Security 2010\kloehk.dll (SureWest Communications)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\WINDOWS\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Program Files\Soluto\soluto.exe /userinit) -C:\Program Files\Soluto\soluto.exe (Soluto)
O20 - Winlogon\Notify\klogon: DllName - (C:\Windows\system32\klogon.dll) - C:\WINDOWS\System32\klogon.dll (SureWest Communications)
O27 - HKLM IFEO\HPWUSCHD2.EXE: Debugger - C:\Windows\System32\rundll32.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/11/06 17:42:00 | 000,000,074 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2008/11/06 17:42:00 | 000,000,074 | —- | M] () - J:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{31781e86-83bb-11de-9628-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{31781e86-83bb-11de-9628-806e6f6e6963}\Shell\AutoRun\command - "" = E:\PCWorld_Tune-Up_All-Stars.exe
O34 - HKLM BootExecute: (autocheck autochk /p \??\C:)
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (autocheck smrgdf C:\Users\Jim\AppData\Roaming\iolo\)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/10/22 20:37:10 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Jim\Desktop\OTL.exe
[2011/10/21 23:37:34 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2011/10/21 10:22:58 | 030,515,552 | —- | C] (IObit ) – C:\Users\Jim\Desktop\asc-setup.exe
[2011/10/20 23:48:46 | 038,808,920 | —- | C] (Microsoft Corporation) – C:\Users\Jim\Desktop\FileFormatConverters.exe
[2011/10/19 13:10:39 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/10/19 13:10:38 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/10/19 13:10:38 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2011/10/19 13:02:19 | 000,000,000 | —D | C] – C:\Users\Jim\AppData\Local\uTorrent
[2011/10/19 11:20:16 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 2.7
[2011/10/19 11:18:29 | 000,000,000 | —D | C] – C:\Python27
[2011/10/19 11:14:42 | 000,000,000 | —D | C] – C:\Program Files\Ninite Updater
[2011/10/19 10:50:09 | 000,000,000 | —D | C] – C:\Users\Jim\AppData\Local\Microsoft_Corporation
[2011/10/18 08:16:33 | 000,051,144 | —- | C] (Soluto LTD.) – C:\Windows\System32\drivers\Soluto.sys
[2011/10/18 08:16:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Soluto
[2011/10/18 08:16:14 | 000,000,000 | —D | C] – C:\Program Files\Soluto
[2011/10/18 03:02:30 | 000,000,000 | —D | C] – C:\ec57b2eead344e99551033e21d
[2011/10/17 10:33:26 | 000,555,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAutomationCore.dll
[2011/10/17 10:33:25 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\oleaccrc.dll
[2011/10/17 03:10:18 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/10/17 03:10:15 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/10/17 03:10:13 | 001,798,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/10/17 03:10:13 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/10/17 03:10:11 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/10/16 20:46:57 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisdecd.dll
[2011/10/16 20:46:57 | 000,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisrndr.ax
[2011/10/16 20:46:56 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Mpeg2Data.ax
[2011/10/16 20:46:55 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSDvbNP.ax
[2011/10/16 20:46:53 | 002,043,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2011/10/07 13:23:25 | 000,000,000 | —D | C] – C:\Users\Jim\AppData\Local\{C1CCF178-C310-467C-B5FD-1E6B622366AB}
[2011/10/07 13:23:24 | 000,000,000 | —D | C] – C:\Users\Jim\AppData\Local\{5D4DE31F-9136-40D5-98D6-916924141022}
[2011/10/07 13:23:10 | 000,000,000 | —D | C] – C:\Users\Jim\Documents\My Weblog Posts
[2011/10/07 13:23:09 | 000,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\Windows Live Writer
[2011/10/07 13:23:09 | 000,000,000 | —D | C] – C:\Users\Jim\AppData\Local\Windows Live Writer
[2011/10/05 16:45:47 | 000,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\PC Cleaners
[2011/10/05 16:45:31 | 005,356,304 | —- | C] (PC Cleaners) – C:\Windows\uninst.exe
[2011/10/05 16:45:31 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Cleaners
[2011/10/05 16:45:30 | 000,000,000 | —D | C] – C:\ProgramData\PC1Data
[2011/10/05 16:45:30 | 000,000,000 | —D | C] – C:\Program Files\PC Cleaners
[2011/10/05 16:34:11 | 000,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MenuUninstaller
[2011/10/05 16:34:10 | 000,000,000 | —D | C] – C:\Program Files\LeizerSoft
[2011/10/05 11:23:11 | 000,000,000 | —D | C] – C:\Program Files\StartNow Toolbar
[2011/10/04 16:12:35 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2011/10/04 15:56:52 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RoboForm
[2011/10/01 23:54:09 | 000,000,000 | —D | C] – C:\Program Files\Holdem Indicator(1)
[2011/10/01 22:18:45 | 000,000,000 | —D | C] – C:\Users\Jim\AppData\Local\Immunet
[2011/10/01 22:18:44 | 000,000,000 | —D | C] – C:\ProgramData\Immunet
[2011/09/30 10:57:11 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter(115)
[2011/09/24 10:17:58 | 000,000,000 | —D | C] – C:\Program Files\Yamicsoft
[2011/09/24 10:17:58 | 000,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Vista Manager
[2011/05/11 00:38:00 | 009,302,016 | —- | C] (IGSoft Ltd.) – C:\Program Files\ClientRuntime.dll
[2011/05/11 00:21:36 | 001,052,672 | —- | C] (The OpenSSL Project, http://www.openssl.org/) – C:\Program Files\libeay32.dll
[2011/05/11 00:21:36 | 000,764,928 | —- | C] (Microsoft Corporation) – C:\Program Files\dbghelp.dll
[2011/05/11 00:21:36 | 000,204,800 | —- | C] (The OpenSSL Project, http://www.openssl.org/) – C:\Program Files\ssleay32.dll
[2010/06/04 20:26:08 | 000,413,696 | —- | C] ( ) – C:\Windows\System32\lxbkinpa.dll
[2010/06/04 20:26:08 | 000,397,312 | —- | C] ( ) – C:\Windows\System32\lxbkiesc.dll
[2010/06/04 20:26:08 | 000,323,584 | —- | C] ( ) – C:\Windows\System32\LXBKhcp.dll
[2010/06/04 20:26:07 | 001,224,704 | —- | C] ( ) – C:\Windows\System32\lxbkserv.dll
[2010/06/04 20:26:07 | 000,991,232 | —- | C] ( ) – C:\Windows\System32\lxbkusb1.dll
[2010/06/04 20:26:06 | 000,163,840 | —- | C] ( ) – C:\Windows\System32\lxbkprox.dll
[2010/06/04 20:26:06 | 000,094,208 | —- | C] ( ) – C:\Windows\System32\lxbkpplc.dll
[2010/06/04 20:26:05 | 000,643,072 | —- | C] ( ) – C:\Windows\System32\lxbkpmui.dll
[2010/06/04 20:26:04 | 000,585,728 | —- | C] ( ) – C:\Windows\System32\lxbklmpm.dll
[2010/06/04 20:26:03 | 000,696,320 | —- | C] ( ) – C:\Windows\System32\lxbkhbn3.dll
[2010/06/04 20:26:03 | 000,385,704 | —- | C] ( ) – C:\Windows\System32\lxbkih.exe
[2010/06/04 20:26:01 | 000,537,256 | —- | C] ( ) – C:\Windows\System32\lxbkcoms.exe
[2010/06/04 20:26:00 | 000,684,032 | —- | C] ( ) – C:\Windows\System32\lxbkcomc.dll
[2010/06/04 20:26:00 | 000,421,888 | —- | C] ( ) – C:\Windows\System32\lxbkcomm.dll
[2010/06/04 20:25:59 | 000,381,608 | —- | C] ( ) – C:\Windows\System32\lxbkcfg.exe
[2006/12/02 06:22:52 | 000,479,232 | —- | C] (Microsoft Corporation) – C:\Program Files\msvcm80.dll
[2006/12/01 22:03:36 | 000,626,688 | —- | C] (Microsoft Corporation) – C:\Program Files\msvcr80.dll
[2006/12/01 22:03:36 | 000,548,864 | —- | C] (Microsoft Corporation) – C:\Program Files\msvcp80.dll
[2006/09/03 23:08:01 | 000,131,072 | —- | C] ( ) – C:\Windows\System32\Interop.SHDocVw.dll
[2006/09/03 23:08:01 | 000,049,152 | —- | C] ( ) – C:\Windows\System32\AxInterop.SHDocVw.dll

========== Files - Modified Within 30 Days ==========

[2011/10/22 20:37:18 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Jim\Desktop\OTL.exe
[2011/10/22 20:31:00 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-685319607-627844835-723040629-1000UA.job
[2011/10/22 20:19:00 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/10/22 20:05:52 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/10/22 16:24:20 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/10/22 16:24:20 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/10/22 08:34:37 | 000,002,479 | —- | M] () – C:\Users\Jim\Desktop\HiJackThis.lnk
[2011/10/21 23:37:34 | 000,002,035 | —- | M] () – C:\Users\Public\Desktop\Google Earth.lnk
[2011/10/21 20:55:01 | 000,000,402 | —- | M] () – C:\Windows\tasks\WebUpdate.job
[2011/10/21 14:14:17 | 000,000,876 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/10/21 10:54:06 | 000,000,084 | —- | M] () – C:\Users\Jim\Desktop\RC Willey - My Account.URL
[2011/10/21 10:28:49 | 000,000,998 | —- | M] () – C:\Users\Public\Desktop\Quick Care.lnk
[2011/10/21 10:28:48 | 000,001,000 | —- | M] () – C:\Users\Jim\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced SystemCare 4.lnk
[2011/10/21 10:28:48 | 000,000,976 | —- | M] () – C:\Users\Public\Desktop\Advanced SystemCare 4.lnk
[2011/10/21 10:26:11 | 030,515,552 | —- | M] (IObit ) – C:\Users\Jim\Desktop\asc-setup.exe
[2011/10/20 23:51:37 | 038,808,920 | —- | M] (Microsoft Corporation) – C:\Users\Jim\Desktop\FileFormatConverters.exe
[2011/10/20 16:38:49 | 000,000,064 | —- | M] () – C:\Windows\System32\rp_stats.dat
[2011/10/20 16:38:48 | 000,000,044 | —- | M] () – C:\Windows\System32\rp_rules.dat
[2011/10/20 16:34:29 | 000,011,260 | —- | M] () – C:\Windows\System32\.rsp
[2011/10/20 16:34:29 | 000,001,563 | —- | M] () – C:\Windows\System32\.lck
[2011/10/20 16:30:37 | 000,000,378 | —- | M] () – C:\Windows\tasks\AutoSmartDefrag.job
[2011/10/20 16:30:16 | 3084,025,856 | -HS- | M] () – C:\hiberfil.sys
[2011/10/20 00:41:14 | 000,000,046 | —- | M] () – C:\Windows\System32\_WKERNEL.FRE
[2011/10/19 20:52:28 | 000,000,085 | —- | M] () – C:\Users\Jim\Desktop\USAA.URL
[2011/10/19 13:11:22 | 000,001,019 | —- | M] () – C:\Users\Jim\Desktop\Revo Uninstaller.lnk
[2011/10/19 13:09:28 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/10/19 13:09:27 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/10/19 13:09:24 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2011/10/19 13:09:14 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2011/10/19 13:07:09 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/10/19 13:06:39 | 000,000,832 | —- | M] () – C:\Users\Jim\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/10/19 12:38:31 | 000,000,384 | —- | M] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2011/10/19 12:36:09 | 000,000,308 | —- | M] () – C:\Windows\tasks\GlaryInitialize.job
[2011/10/19 11:14:52 | 000,000,921 | —- | M] () – C:\Users\Public\Desktop\Ninite Updater.lnk
[2011/10/18 16:30:41 | 000,000,727 | —- | M] () – C:\Users\Public\Desktop\WinUtilities.lnk
[2011/10/18 08:15:37 | 000,000,193 | —- | M] () – C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2011/10/17 08:42:42 | 000,000,380 | —- | M] () – C:\Windows\tasks\SmartDefrag.job
[2011/10/17 08:39:22 | 000,339,584 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/10/15 11:53:10 | 000,012,036 | —- | M] () – C:\Users\Jim\Documents\111115 McClintock ltr.odt
[2011/10/11 16:33:24 | 000,051,144 | —- | M] (Soluto LTD.) – C:\Windows\System32\drivers\Soluto.sys
[2011/10/07 21:18:42 | 000,018,737 | —- | M] () – C:\Users\Jim\Desktop\FINRA CASE LOG.ods
[2011/10/07 11:25:31 | 000,602,222 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/10/07 11:25:31 | 000,103,020 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/10/05 16:43:53 | 005,356,304 | —- | M] (PC Cleaners) – C:\Windows\uninst.exe
[2011/10/05 11:18:11 | 000,000,766 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2011/10/05 11:08:30 | 000,000,849 | —- | M] () – C:\Users\Jim\Application Data\Microsoft\Internet Explorer\Quick Launch\Glary Utilities.lnk
[2011/10/04 23:28:24 | 000,000,881 | —- | M] () – C:\Users\Jim\Application Data\Microsoft\Internet Explorer\Quick Launch\Holdem Indicator.lnk
[2011/10/04 23:28:24 | 000,000,857 | —- | M] () – C:\Users\Jim\Desktop\Holdem Indicator.lnk
[2011/10/04 16:13:07 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif
[2011/10/04 10:02:04 | 000,002,034 | —- | M] () – C:\Users\Jim\Desktop\Google Chrome.lnk
[2011/10/04 10:02:04 | 000,001,996 | —- | M] () – C:\Users\Jim\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/10/04 09:15:28 | 000,000,258 | RHS- | M] () – C:\ProgramData\ntuser.pol
[2011/10/04 00:12:03 | 000,010,853 | —- | M] () – C:\Users\Jim\Desktop\ENVELOPE.odt
[2011/10/02 00:38:19 | 000,000,058 | —- | M] () – C:\Users\Jim\Desktop\SF Giants and Football.URL
[2011/09/29 00:30:35 | 001,359,824 | —- | M] () – C:\Users\Jim\Desktop\pc-decrapifier-2.2.8.exe
[2011/09/27 23:26:56 | 000,000,750 | —- | M] () – C:\Users\Jim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FreeClip.lnk
[2011/09/27 10:29:36 | 000,006,796 | —- | M] () – C:\Users\Jim\Documents\ALLO CATION 1012.ods
[2011/09/25 23:43:57 | 000,000,134 | —- | M] () – C:\Users\Jim\Desktop\Microsoft Fix it.url
[2011/09/24 11:08:52 | 665,916,918 | —- | M] () – C:\Users\Jim\Documents\BackupRegistry(20110924).reg
[2011/09/24 10:18:56 | 000,002,009 | —- | M] () – C:\Users\Jim\Desktop\1-Click Cleaner.lnk
[2011/09/24 10:18:56 | 000,001,955 | —- | M] () – C:\Users\Jim\Desktop\Vista Manager.lnk

========== Files Created - No Company Name ==========

[2011/10/21 23:37:34 | 000,002,035 | —- | C] () – C:\Users\Public\Desktop\Google Earth.lnk
[2011/10/19 20:52:28 | 000,000,085 | —- | C] () – C:\Users\Jim\Desktop\USAA.URL
[2011/10/19 11:14:52 | 000,000,933 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ninite Updater.lnk
[2011/10/19 11:14:52 | 000,000,921 | —- | C] () – C:\Users\Public\Desktop\Ninite Updater.lnk
[2011/10/16 20:15:07 | 3084,025,856 | -HS- | C] () – C:\hiberfil.sys
[2011/10/15 11:19:55 | 000,012,036 | —- | C] () – C:\Users\Jim\Documents\111115 McClintock ltr.odt
[2011/10/05 11:08:30 | 000,000,849 | —- | C] () – C:\Users\Jim\Application Data\Microsoft\Internet Explorer\Quick Launch\Glary Utilities.lnk
[2011/10/04 16:12:39 | 000,001,770 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011/10/03 00:19:33 | 000,000,881 | —- | C] () – C:\Users\Jim\Application Data\Microsoft\Internet Explorer\Quick Launch\Holdem Indicator.lnk
[2011/10/03 00:19:33 | 000,000,857 | —- | C] () – C:\Users\Jim\Desktop\Holdem Indicator.lnk
[2011/10/02 00:38:19 | 000,000,058 | —- | C] () – C:\Users\Jim\Desktop\SF Giants and Football.URL
[2011/09/29 00:30:27 | 001,359,824 | —- | C] () – C:\Users\Jim\Desktop\pc-decrapifier-2.2.8.exe
[2011/09/28 16:36:20 | 000,000,766 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2011/09/27 23:26:56 | 000,000,726 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeClip.lnk
[2011/09/27 10:29:36 | 000,006,796 | —- | C] () – C:\Users\Jim\Documents\ALLO CATION 1012.ods
[2011/09/25 23:43:57 | 000,000,134 | —- | C] () – C:\Users\Jim\Desktop\Microsoft Fix it.url
[2011/09/24 11:07:48 | 665,916,918 | —- | C] () – C:\Users\Jim\Documents\BackupRegistry(20110924).reg
[2011/09/24 10:18:56 | 000,001,955 | —- | C] () – C:\Users\Jim\Desktop\Vista Manager.lnk
[2011/09/24 10:18:55 | 000,002,009 | —- | C] () – C:\Users\Jim\Desktop\1-Click Cleaner.lnk
[2011/09/08 11:31:11 | 000,000,193 | —- | C] () – C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2011/09/06 00:40:21 | 000,000,064 | —- | C] () – C:\Windows\System32\rp_stats.dat
[2011/09/06 00:40:21 | 000,000,044 | —- | C] () – C:\Windows\System32\rp_rules.dat
[2011/07/08 15:54:15 | 000,102,912 | —- | C] () – C:\Windows\System32\EasyHook64.dll
[2011/07/08 15:54:15 | 000,084,480 | —- | C] () – C:\Windows\System32\EasyHook32.dll
[2011/05/21 08:12:34 | 000,004,984 | —- | C] () – C:\Windows\System32\drivers\nvphy.bin
[2011/05/11 01:34:36 | 000,101,230 | —- | C] () – C:\Program Files\frname.xml
[2011/05/04 19:05:08 | 000,000,207 | —- | C] () – C:\Program Files\pokerclient.ini
[2011/04/01 00:40:18 | 000,029,520 | —- | C] () – C:\Windows\System32\SmartDefragBootTime.exe
[2011/04/01 00:40:18 | 000,016,184 | —- | C] () – C:\Windows\System32\drivers\SmartDefragDriver.sys
[2011/01/01 01:59:39 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/10/09 21:50:52 | 000,000,272 | —- | C] () – C:\Windows\SysMech.INI
[2010/08/27 22:15:59 | 000,000,109 | —- | C] () – C:\ProgramData\avalon2.2.ini
[2010/06/30 21:53:49 | 000,074,703 | —- | C] () – C:\Windows\System32\mfc45.dll
[2010/06/18 01:47:05 | 000,002,560 | —- | C] () – C:\Windows\_MSRSTRT.EXE
[2010/06/04 20:26:08 | 000,413,696 | —- | C] () – C:\Windows\System32\lxbkutil.dll
[2010/06/04 20:26:08 | 000,274,432 | —- | C] () – C:\Windows\System32\LXBKinst.dll
[2010/06/04 00:22:33 | 000,115,369 | —- | C] () – C:\Windows\System32\drivers\klin.dat
[2010/06/04 00:22:33 | 000,097,961 | —- | C] () – C:\Windows\System32\drivers\klick.dat
[2010/05/21 22:31:03 | 000,000,197 | —- | C] () – C:\Windows\ODBCINST.INI
[2010/04/17 22:19:23 | 000,219,136 | —- | C] () – C:\Windows\System32\sqlite3_engine.dll
[2010/02/13 21:48:21 | 000,000,046 | —- | C] () – C:\Windows\System32\DonationCoder_findrunrobot_InstallInfo.dat
[2010/02/13 21:48:21 | 000,000,046 | —- | C] () – C:\Users\Jim\AppData\Local\DonationCoder_findrunrobot_InstallInfo.dat
[2009/11/26 13:47:52 | 000,000,032 | —- | C] () – C:\Windows\wwwbatch.ini
[2009/10/08 23:14:56 | 000,000,060 | —- | C] () – C:\Windows\mhses.dat
[2009/09/09 18:01:40 | 000,027,675 | —- | C] () – C:\Windows\System32\drivers\klopp.dat
[2009/08/26 00:14:28 | 000,000,063 | —- | C] () – C:\Windows\wininit.ini
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\Windows\System32\OGAEXEC.exe
[2009/07/17 22:04:25 | 000,016,432 | —- | C] () – C:\Windows\System32\lsdelete.exe
[2009/07/03 22:08:37 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2009/06/07 15:42:59 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/06/07 15:42:31 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/05/03 16:13:28 | 000,000,120 | —- | C] () – C:\Windows\QUICKEN.INI
[2009/04/24 23:04:14 | 000,107,547 | —- | C] () – C:\Windows\System32\drivers\klin(730).dat
[2009/04/24 23:04:14 | 000,095,259 | —- | C] () – C:\Windows\System32\drivers\klick(729).dat
[2009/04/24 23:03:14 | 001,794,080 | -HS- | C] () – C:\Windows\System32\drivers\fidbox2.dat
[2009/04/24 23:03:14 | 001,679,392 | -HS- | C] () – C:\Windows\System32\drivers\fidbox2(28).dat
[2009/04/24 23:03:14 | 001,581,088 | -HS- | C] () – C:\Windows\System32\drivers\fidbox2(369).dat
[2009/04/24 23:03:14 | 001,482,784 | -HS- | C] () – C:\Windows\System32\drivers\fidbox2(161).dat
[2009/04/24 23:03:14 | 001,466,400 | -HS- | C] () – C:\Windows\System32\drivers\fidbox2(77).dat
[2009/04/24 23:03:14 | 001,433,632 | -HS- | C] () – C:\Windows\System32\drivers\fidbox2(335).dat
[2009/04/24 23:03:14 | 001,376,288 | -HS- | C] () – C:\Windows\System32\drivers\fidbox2(157).dat
[2009/04/24 23:03:14 | 001,359,904 | -HS- | C] () – C:\Windows\System32\drivers\fidbox2(108).dat
[2009/04/24 23:03:14 | 001,171,488 | -HS- | C] () – C:\Windows\System32\drivers\fidbox2(727).dat
[2009/04/24 23:03:14 | 001,146,912 | -HS- | C] () – C:\Windows\System32\drivers\fidbox2(156).dat
[2009/04/24 23:03:14 | 000,802,848 | -HS- | C] () – C:\Windows\System32\drivers\fidbox2(26).dat
[2009/04/24 23:03:14 | 000,753,696 | -HS- | C] () – C:\Windows\System32\drivers\fidbox2(184).dat
[2009/04/24 23:03:14 | 000,409,632 | -HS- | C] () – C:\Windows\System32\drivers\fidbox2(56).dat
[2009/04/22 16:23:24 | 000,007,168 | —- | C] () – C:\Users\Jim\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/21 23:56:18 | 000,219,136 | —- | C] () – C:\Windows\sqlite3_engine.dll
[2009/04/20 08:43:00 | 026,553,888 | —- | C] () – C:\Windows\System32\drivers\fidbox.dat
[2009/04/20 08:43:00 | 026,353,184 | —- | C] () – C:\Windows\System32\drivers\fidbox(367).dat
[2009/04/20 08:43:00 | 026,353,184 | —- | C] () – C:\Windows\System32\drivers\fidbox(27).dat
[2009/04/20 08:43:00 | 025,844,256 | —- | C] () – C:\Windows\System32\drivers\fidbox(159).dat
[2009/04/20 08:43:00 | 025,833,504 | —- | C] () – C:\Windows\System32\drivers\fidbox(75).dat
[2009/04/20 08:43:00 | 022,267,424 | —- | C] () – C:\Windows\System32\drivers\fidbox(333).dat
[2009/04/20 08:43:00 | 022,263,840 | —- | C] () – C:\Windows\System32\drivers\fidbox(155).dat
[2009/04/20 08:43:00 | 022,235,168 | —- | C] () – C:\Windows\System32\drivers\fidbox(107).dat
[2009/04/20 08:43:00 | 014,343,200 | —- | C] () – C:\Windows\System32\drivers\fidbox(725).dat
[2009/04/20 08:43:00 | 014,307,360 | —- | C] () – C:\Windows\System32\drivers\fidbox(154).dat
[2009/04/20 08:43:00 | 013,522,464 | —- | C] () – C:\Windows\System32\drivers\fidbox(25).dat
[2009/04/20 08:43:00 | 013,515,296 | —- | C] () – C:\Windows\System32\drivers\fidbox(182).dat
[2009/04/20 08:43:00 | 012,400,672 | -HS- | C] () – C:\Windows\System32\drivers\fidbox(55).dat
[2009/04/19 23:28:56 | 000,003,580 | —- | C] () – C:\Users\Jim\AppData\Roaming\wklnhst.dat
[2009/04/19 18:37:17 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2009/04/19 15:38:11 | 000,001,356 | —- | C] () – C:\Users\Jim\AppData\Local\d3d9caps.dat
[2009/04/19 15:23:02 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/04/19 15:08:17 | 000,000,400 | —- | C] () – C:\Windows\Lexstat.ini
[2008/11/06 17:42:45 | 000,107,357 | —- | C] () – C:\Windows\hpqins13.dat
[2008/11/06 17:21:21 | 000,327,680 | —- | C] () – C:\Windows\System32\pythoncom25.dll
[2008/11/06 17:21:21 | 000,102,400 | —- | C] () – C:\Windows\System32\pywintypes25.dll
[2007/02/07 18:57:50 | 000,039,899 | —- | C] () – C:\Windows\System32\rtsicis.ini
[2007/01/22 08:49:34 | 000,344,064 | —- | C] () – C:\Windows\System32\lxbkcoin.dll
[2006/11/02 05:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 05:47:37 | 000,339,584 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 05:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:33:01 | 000,602,222 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 03:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 03:33:01 | 000,103,020 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 03:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 03:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 01:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 01:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 00:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 00:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2005/10/05 12:19:32 | 000,040,960 | —- | C] () – C:\Windows\System32\lxbkvs.dll
[2005/09/13 17:27:10 | 000,061,440 | —- | C] () – C:\Windows\System32\lxbkcnv5.dll
[2005/09/13 16:27:10 | 000,061,440 | —- | C] () – C:\Windows\System32\lxbkcnv4.dll

========== LOP Check ==========

[2011/05/11 16:01:23 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\Amazon
[2010/06/26 09:32:44 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\Canon
[2011/07/25 13:11:05 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\Clipdiary
[2009/07/28 21:23:24 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/12/17 02:48:44 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\CyberMatrix
[2010/02/13 21:48:21 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\DonationCoder
[2011/07/08 15:04:01 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\EurekaLog
[2010/11/03 09:51:41 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\Fighters
[2009/06/26 12:50:33 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\Foxit
[2009/12/26 01:57:55 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\Foxit Software
[2011/10/14 11:17:33 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\GetRightToGo
[2011/03/13 20:42:21 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\GlarySoft
[2011/07/06 09:29:34 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\GoodSync
[2010/06/02 22:36:15 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\IMSIDesign
[2011/10/19 17:02:47 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\IObit
[2011/03/11 12:48:51 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\iolo
[2011/06/11 23:03:42 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\Jumping Bytes
[2011/02/07 11:42:44 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\LibreOffice
[2011/04/15 01:18:13 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\M8 Software
[2009/06/06 21:26:52 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\Microgaming
[2009/05/07 20:55:19 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\OpenOffice.org
[2009/04/20 00:35:54 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\Orca Profiles
[2009/04/21 07:42:11 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\ParetoLogic
[2009/09/15 21:14:33 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\Participatory Culture Foundation
[2011/10/05 16:45:47 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\PC Cleaners
[2009/12/11 12:36:42 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\Postbox
[2010/02/20 10:45:47 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\r2 Studios
[2010/04/08 09:18:26 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\Returnil
[2011/06/12 23:27:41 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\RoboForm
[2009/06/24 09:06:10 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\SeriousBit
[2009/08/25 09:46:16 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\Smart PC Solutions
[2010/07/23 11:08:47 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\Smart PC Utilities
[2009/08/13 21:46:51 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\SPAMfighter
[2011/04/20 22:22:10 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\Spamihilator
[2011/04/01 11:26:32 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\Stardock
[2011/10/13 23:07:14 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\STGU
[2011/06/11 18:16:56 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\SumatraPDF
[2010/07/01 01:21:51 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\System Tweaker
[2009/04/19 23:31:19 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\Template
[2011/03/10 22:45:59 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\Thunderbird
[2011/08/25 11:19:28 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\Uniblue
[2011/10/20 01:35:08 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\uTorrent
[2011/07/15 09:46:38 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\Vista Start Menu
[2011/01/24 13:37:28 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\WFDS
[2009/04/30 20:19:15 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\WinBatch
[2011/10/07 13:23:09 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\Windows Live Writer
[2010/11/05 22:40:45 | 000,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\WinPatrol
[2011/10/19 12:38:31 | 000,000,384 | —- | M] () – C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2011/10/20 16:30:37 | 000,000,378 | —- | M] () – C:\Windows\Tasks\AutoSmartDefrag.job
[2011/10/19 12:36:09 | 000,000,308 | —- | M] () – C:\Windows\Tasks\GlaryInitialize.job
[2011/10/19 11:27:15 | 000,032,628 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/10/17 08:42:42 | 000,000,380 | —- | M] () – C:\Windows\Tasks\SmartDefrag.job
[2011/10/21 20:55:01 | 000,000,402 | —- | M] () – C:\Windows\Tasks\WebUpdate.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/09/06 16:42:23 | 000,014,987 | —- | M] () – C:\2011PORTFOLIO.ods
[2011/08/28 00:26:15 | 000,000,443 | —- | M] () – C:\aaw7boot.log
[2008/11/06 17:42:00 | 000,000,074 | —- | M] () – C:\autoexec.bat
[2011/03/12 11:21:15 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2008/11/06 17:03:43 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 14:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2011/04/28 08:23:52 | 000,000,672 | —- | M] () – C:\EventLOG.txt
[2011/10/20 16:30:16 | 3084,025,856 | -HS- | M] () – C:\hiberfil.sys
[2009/08/16 00:51:35 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/11/20 16:20:58 | 000,025,214 | —- | M] () – C:\MercadoLibre.ico
[2009/08/16 00:51:35 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2011/10/20 16:30:13 | 3219,128,320 | -HS- | M] () – C:\pagefile.sys
[2010/01/15 13:34:42 | 000,000,322 | —- | M] () – C:\Public.lnk
[2009/07/26 08:38:38 | 000,000,440 | —- | M] () – C:\RoboFormDataHere.txt
[2008/04/30 15:32:00 | 000,107,596 | —- | M] () – C:\toolkit_widget.gif
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2006/11/02 05:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 05:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 05:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/06/07 15:52:29 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 14:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/02/15 17:35:42 | 000,102,400 | —- | M] (Lexmark International Inc.) – C:\Windows\system32\spool\prtprocs\w32x86\1_lxbkpp5c.dll
[2009/04/25 05:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:\Windows\system32\spool\prtprocs\w32x86\CNMPD9P.DLL
[2009/04/25 05:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:\Windows\system32\spool\prtprocs\w32x86\CNMPP9P.DLL
[2006/11/02 05:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2008/02/15 16:35:42 | 000,102,400 | —- | M] (Lexmark International Inc.) – C:\Windows\system32\spool\prtprocs\w32x86\lxbkpp5c.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2011/05/11 00:38:00 | 009,302,016 | —- | M] (IGSoft Ltd.) – C:\Program Files\ClientRuntime.dll
[2011/05/11 00:21:36 | 000,764,928 | —- | M] (Microsoft Corporation) – C:\Program Files\dbghelp.dll
[2008/01/20 19:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
[2011/05/11 01:34:36 | 000,101,230 | —- | M] () – C:\Program Files\frname.xml
[2011/05/11 23:15:47 | 000,051,897 | —- | M] () – C:\Program Files\INSTALL.LOG
[2011/05/11 00:21:36 | 001,052,672 | —- | M] (The OpenSSL Project, http://www.openssl.org/) – C:\Program Files\libeay32.dll
[2006/12/02 06:22:52 | 000,479,232 | —- | M] (Microsoft Corporation) – C:\Program Files\msvcm80.dll
[2006/12/01 22:03:36 | 000,548,864 | —- | M] (Microsoft Corporation) – C:\Program Files\msvcp80.dll
[2006/12/01 22:03:36 | 000,626,688 | —- | M] (Microsoft Corporation) – C:\Program Files\msvcr80.dll
[2011/05/04 19:05:08 | 000,000,207 | —- | M] () – C:\Program Files\pokerclient.ini
[2011/05/11 00:21:36 | 000,204,800 | —- | M] (The OpenSSL Project, http://www.openssl.org/) – C:\Program Files\ssleay32.dll
[2011/05/11 23:16:19 | 000,004,662 | —- | M] () – C:\Program Files\updater1.log

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/01/20 20:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 20:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 20:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 03:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 03:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/03/16 21:59:26 | 000,000,548 | -HS- | M] () – C:\Users\Jim\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/10/21 10:26:11 | 030,515,552 | —- | M] (IObit ) – C:\Users\Jim\Desktop\asc-setup.exe
[2011/10/20 23:51:37 | 038,808,920 | —- | M] (Microsoft Corporation) – C:\Users\Jim\Desktop\FileFormatConverters.exe
[2011/06/15 15:16:48 | 000,997,920 | —- | M] (Microsoft Corporation) – C:\Users\Jim\Desktop\msseces.exe
[2011/10/22 20:37:18 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Jim\Desktop\OTL.exe
[2011/09/29 00:30:35 | 001,359,824 | —- | M] () – C:\Users\Jim\Desktop\pc-decrapifier-2.2.8.exe
[2010/01/06 14:01:52 | 000,791,040 | —- | M] (UntameDkreationZ) – C:\Users\Jim\Desktop\RESTORE POINT.exe
[2009/07/12 12:20:22 | 000,353,280 | —- | M] () – C:\Users\Jim\Desktop\Ultimate Windows Tweaker.exe
[2010/08/20 01:04:02 | 012,049,864 | —- | M] (Microsoft Corporation) – C:\Users\Jim\Desktop\windows sftware check.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-10-22 10:08:50

========== Files - Unicode (All) ==========
[2010/07/28 10:24:30 | 000,000,177 | —- | M] ()(C:\Users\Jim\Desktop\FINRA Education ? Sites ? Catalog ? Search Results.URL) – C:\Users\Jim\Desktop\FINRA Education → Sites → Catalog → Search Results.URL
[2010/07/28 10:24:30 | 000,000,177 | —- | C] ()(C:\Users\Jim\Desktop\FINRA Education ? Sites ? Catalog ? Search Results.URL) – C:\Users\Jim\Desktop\FINRA Education → Sites → Catalog → Search Results.URL

========== Alternate Data Streams ==========

@Alternate Data Stream - 81 bytes -> C:\Program Files\Cake Poker 2.0:MID
@Alternate Data Stream - 8 bytes -> C:\WINDOWS:
@Alternate Data Stream - 378 bytes -> C:\Windows\System32\drivers\brnewddh.sys:changelist
@Alternate Data Stream - 260 bytes -> C:\ProgramData\TEMP:010ADD2C
@Alternate Data Stream - 256 bytes -> C:\ProgramData\TEMP:2B11E0DF
@Alternate Data Stream - 252 bytes -> C:\ProgramData\TEMP:553CA6CA
@Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:E138854D
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:56E2E879

< End of report >


OTL Extras logfile created on: 10/22/2011 8:41:54 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Jim\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.87 Gb Total Physical Memory | 1.59 Gb Available Physical Memory | 55.36% Memory free
8.77 Gb Paging File | 6.48 Gb Available in Paging File | 73.82% Paging File free
Paging file location(s): [Binary data over 100 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 286.60 Gb Total Space | 173.66 Gb Free Space | 60.59% Space Free | Partition Type: NTFS
Drive D: | 11.49 Gb Total Space | 1.11 Gb Free Space | 9.65% Space Free | Partition Type: NTFS
Drive J: | 74.53 Gb Total Space | 3.02 Gb Free Space | 4.05% Space Free | Partition Type: NTFS

Computer Name: JIM-PC | User Name: Jim | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [open] – "C:\Program Files\explorer2_lite\xplorer2_lite.exe" /M "%1" (ZabKat)
Directory [Shred With Tracks Eraser Pro] – C:\Program Files\Acesoft\Tracks Eraser Pro\fileshred.exe %1 (Acesoft)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – Reg Error: Value error.

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"AntiVirusOverride" = 0
"UpdatesDisableNotify" = 0
"FirstRunDisabled" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1
"" =

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0AD2FF3B-9593-41E2-83E5-55B585524EBA}" = protocol=6 | dir=in | app=c:\program files\soluto\solutoconsole.exe |
"{0B683396-2A13-4A09-BE88-5EF73E1E4EE7}" = protocol=6 | dir=in | app=c:\program files\smart pc utilities\vista services optimizer\webupdate.exe |
"{26F21443-62AD-40CA-860E-84E0C1AAFAD1}" = protocol=17 | dir=in | app=c:\program files\holdem indicator\holdemindicator.exe |
"{2E7D0521-F656-4D43-83FA-451D28268238}" = protocol=6 | dir=in | app=c:\program files\holdem indicator\holdemindicator.exe |
"{3F73660D-A48A-44EF-A3C7-8DA422758F0F}" = protocol=6 | dir=in | app=c:\program files\holdem indicator\holdemindicator.exe |
"{53A0B09E-0800-4C93-9818-5EC9449BA21E}" = protocol=17 | dir=in | app=c:\program files\soluto\solutoupdateservice.exe |
"{5469E57D-8CB1-42E2-A63C-81D5B8310823}" = protocol=6 | dir=in | app=c:\program files\soluto\solutoupdateservice.exe |
"{5B70C534-29F0-4701-99C7-C922BC9D59C8}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxbkpswx.exe |
"{6C923107-4BD9-41ED-BB98-2036CAAC2A88}" = protocol=17 | dir=in | app=c:\program files\smart pc utilities\vista services optimizer\servicesoptimizer.exe |
"{6E3466D2-FD48-476E-AD65-E51EC8BA9546}" = protocol=6 | dir=in | app=c:\windows\system32\lxbkcoms.exe |
"{82572AAD-095B-4337-94D3-B298ACBAC577}" = protocol=6 | dir=in | app=c:\program files\soluto\solutoservice.exe |
"{8B11EB70-212D-4C1A-B2DD-4515D4E6FF71}" = protocol=17 | dir=in | app=c:\program files\holdem indicator\holdemindicator.exe |
"{9A3E09EA-8B4C-44BA-8833-155D5C2D61BB}" = protocol=17 | dir=in | app=c:\program files\soluto\solutoservice.exe |
"{A6038578-1196-4840-AA10-13FFF140FF7F}" = protocol=6 | dir=in | app=c:\program files\soluto\soluto.exe |
"{CC549F78-1CD1-470D-88F2-7C72C7752D6D}" = protocol=17 | dir=in | app=c:\program files\soluto\soluto.exe |
"{D47B288D-4C9F-4AD2-A0B5-8BD6C3711443}" = protocol=17 | dir=in | app=c:\windows\system32\lxbkcoms.exe |
"{E6ADDEA9-8C61-4379-9E6B-F245D6CE39F9}" = protocol=17 | dir=in | app=c:\program files\smart pc utilities\vista services optimizer\webupdate.exe |
"{ED8243F7-87C4-4CCD-94C5-039696B72281}" = protocol=17 | dir=in | app=c:\program files\soluto\solutoconsole.exe |
"{F865EFE7-2831-43E0-8FF9-85D7B3D9B80D}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxbkpswx.exe |
"{FB044724-DF83-4795-8B44-B99EE7C82344}" = protocol=6 | dir=in | app=c:\program files\smart pc utilities\vista services optimizer\servicesoptimizer.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{007811BF-E310-4285-BFC6-55DB29B3EDDE}" = WinPatrol
"{05BDC796-3451-4F81-B91D-E98F7ADA76C2}" = TurboTax 2010 WinPerTaxSupport
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{09633A5E-3089-41A8-9FF1-382171423C5D}" = PSSWCORE
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0E521917-05E4-4051-9943-6CA8613BD003}" = Soluto
"{10CD364B-FFCC-48BE-B469-B9622A033075}" = Fences
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX330_series" = Canon MX330 series MP Drivers
"{15B8AFD9-92E9-4E86-96D9-83FAC510B82E}" = HPPhotoSmartPhotobookWebPack1
"{18A8E78B-9EF2-496E-B310-BCD8E4C1DAB3}" = iSEEK AnswerWorks English Runtime
"{1D0AB230-E7BC-41CB-A50C-F282273E897B}" = SPAMfighter Client
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{21A83F78-AE3B-4B90-865C-B045D5F3DA8D}" = Mail Attachment Downloader v1.8
"{22F761D1-8063-4170-ADF7-2D2F47834CA9}" = VideoToolkit01
"{26A24AE4-039D-4CA4-87B4-2F83216029FF}" = Java™ 6 Update 29
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2E295B5B-1AD4-4d36-97C2-A316084722CF}" = Python 2.7.2
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{343AB4F2-F1EF-4FF9-B0E6-CAAB680286A6}" = G Data LNK-Checker
"{35C08F46-BFC3-47BB-A388-44FE59A73A2F}" = Vista Manager
"{360EDFB0-EAA2-012B-AD16-000000000000}" = TurboTax 2009 wcaiper
"{3782EC09-4000-475E-8A59-9CABD6F03B4C}" = TurboTax 2010 WinPerFedFormset
"{385DD1DD-65AA-408D-8E70-74601C2DB7E6}" = Ad-Aware
"{3881DB80-EAA2-012B-ADAE-000000000000}" = TurboTax 2009 WinPerFedFormset
"{38975F50-EAA2-012B-ADB4-000000000000}" = TurboTax 2009 WinPerReleaseEngine
"{38A34630-EAA2-012B-ADB6-000000000000}" = TurboTax 2009 WinPerTaxSupport
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3C5A81D0-EAA2-012B-AE9F-000000000000}" = TurboTax 2009 wrapper
"{3E171899-0175-47CC-84C4-562ACDD4C021}" = OpenOffice.org 3.3
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4F2FCCCF-29F3-44B9-886F-6D16F8417522}" = TurboTax 2010 wrapper
"{529125EF-E3AC-4B74-97E6-F688A7C0F1BF}" = Paint.NET v3.5.10
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{55979C41-7D6A-49CC-B591-64AC1BBE2C8B}" = HP Picasso Media Center Add-In
"{55FD1D5A-7AEF-4DA3-8FAF-A71B2A52FFC7}_is1" = iolo technologies' System Mechanic
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{5FE545A1-D215-4216-9189-E7B39C9D1CC1}" = Quicken 2011
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6D14916C-EC29-40FC-8FFB-08A66576BE78}" = Spamihilator 0.9.9.53 (32 bit)
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{87FF0E39-8490-4EB4-A557-FF12F712EF7E}" = TurboTax 2010 wcaiper
"{8A5F34E2-37CF-4AD4-808C-2D413786E31A}" = Microsoft Visual C Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{95120000-003F-0409-0000-0000000FF1CE}" = Microsoft Office Excel Viewer
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9D8B0949-7C47-476F-9F06-F900D3B078EA}" = SureWest Internet Security 2010 Powered by Kaspersky
"{9DBA770F-BF73-4D39-B1DF-6035D95268FC}" = HP Customer Feedback
"{A0640EC2-B97E-4FC1-AD14-227C9E386BB4}" = HP Recovery Manager RSS
"{A525E00B-6609-442E-9DCD-64453C233E8D}" = TurboTax 2010 WinPerReleaseEngine
"{A6EE99EA-420C-4FA6-8A7C-FDB60D278855}" = VS10Runtime
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B3C1579F-C9BB-4479-B343-B22C5C283D47}" = Vista Services Optimizer
"{C10680FA-AC9F-4FC0-8668-361420E153AE}" = TurboCAD Designer 17
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240C0}" = WinZip 15.0
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CFF8B8E8-E086-4DE0-935F-FE22CAB54F80}" = Microsoft Search Enhancement Pack
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}" = HP Photosmart Essential 2.5
"{D88C3E7C-1DA6-4AD7-97FC-75BC8705B266}" = runtime
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218
"{EA450D5D-95EA-4FD0-B8B0-6D8E68FBE2C7}" = Impulse
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{FC274982-5AAD-4C20-848D-4424A5043010}_is1" = WinUtilities 10.35 Free Edition
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Advanced SystemCare 4_is1" = Advanced SystemCare 4
"Agent Ransack_is1" = Agent Ransack Version 1.7.3
"AI RoboForm" = RoboForm 7-5-3 (All Users)
"Belarc Advisor" = Belarc Advisor 8.2
"Cake Poker 2.0" = Cake Poker 2.0
"Canon MX330 series User Registration" = Canon MX330 series User Registration
"CANONIJPLM100" = Canon Inkjet Printer/Scanner/Fax Extended Survey Program
"Carbonite Backup" = Carbonite
"CCleaner" = CCleaner
"CNXT_MODEM_PCI_HSF" = PCIe Soft Data Fax Modem with SmartCP
"CPUID HWMonitor_is1" = CPUID HWMonitor 1.18
"Download Accelerator Plus (DAP)" = Download Accelerator Plus (DAP)
"Duplicate Cleaner" = Duplicate Cleaner 2.0.6
"EnhanceMyVista Free_is1" = EnhanceMyVista Free
"File Shredder_is1" = File Shredder 2.0
"Glary Utilities_is1" = Glary Utilities 2.38.0.1288
"Holdem Indicator_is1" = Holdem Indicator 2.2.3
"HP Photosmart Essential" = HP Photosmart Essential 3.0
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"InstallWIX_{9D8B0949-7C47-476F-9F06-F900D3B078EA}" = SureWest Internet Security 2010 Powered by Kaspersky
"Karen's Replicator" = Karen's Replicator
"M8 Free Clipboard" = M8 Free Clipboard
"M8 Free Multi Clipboard" = M8 Free Multi Clipboard
"MenuUninstaller1.2.3" = MenuUninstaller
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 7.0.1 (x86 en-US)" = Mozilla Firefox 7.0.1 (x86 en-US)
"Mozilla Thunderbird (7.0.1)" = Mozilla Thunderbird (7.0.1)
"MP Navigator EX 2.1" = Canon MP Navigator EX 2.1
"NiniteUpdater" = Ninite Updater
"NVIDIA Drivers" = NVIDIA Drivers
"PC Cleaners" = PC Cleaners
"Picasa 3" = Picasa 3
"Postbox (2.5.2)" = Postbox (2.5.2)
"Prevent Restore 3" = Prevent Restore 3.17
"Protected Folder_is1" = Protected Folder
"RealPlayer 12.0" = RealPlayer
"Revo Uninstaller" = Revo Uninstaller 1.93
"Secunia PSI" = Secunia PSI (2.0.0.3003)
"Smart Defrag 2_is1" = Smart Defrag 2
"SPAMfighter" = SPAMfighter
"SpeedBit Toolbar" = SpeedBit Toolbar
"SpeedBit Video Accelerator" = SpeedBit Video Accelerator
"SpeedBit Video Downloader" = SpeedBit Video Downloader
"StartNow Toolbar" = StartNow Toolbar
"Startup Delayer" = Startup Delayer v3.0 (build 314)
"Startup Guard 3" = Startup Guard 3.31
"SumatraPDF" = SumatraPDF
"Surf Canyon" = Surf Canyon Search Engine Assistant
"The USNA Alumni Association Register of Alumni 2003" = The USNA Alumni Association Register of Alumni 2003
"Tracks Eraser Pro_is1" = Tracks Eraser Pro v8.6 build 1000
"Trusted Software Assistant_is1" = File Type Assistant
"TurboTax 2009" = TurboTax 2009
"TurboTax 2010" = TurboTax 2010
"Vista Start Menu_is1" = Vista Start Menu 3.88
"Volumouse" = Volumouse
"Web Tracks Eraser_is1" = Web Tracks Eraser
"WinLiveSuite" = Windows Live Essentials
"xplorer2l" = xplorer² lite 32 bit
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"73c5eeb6b8a49caa" = Mail Attachment Downloader
"Adobe Connect Add-in" = Adobe Connect Add-in
"CarbonPoker" = CarbonPoker
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 10/21/2011 6:00:39 AM | Computer Name = Jim-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 10/21/2011 6:30:03 AM | Computer Name = Jim-PC | Source = .NET Runtime Optimization Service | ID = 1101
Description =

Error - 10/21/2011 6:30:46 AM | Computer Name = Jim-PC | Source = .NET Runtime Optimization Service | ID = 1101
Description =

Error - 10/22/2011 12:05:47 AM | Computer Name = Jim-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 10/22/2011 6:00:57 AM | Computer Name = Jim-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 10/22/2011 12:34:25 PM | Computer Name = Jim-PC | Source = .NET Runtime Optimization Service | ID = 1101
Description =

Error - 10/22/2011 12:34:53 PM | Computer Name = Jim-PC | Source = .NET Runtime Optimization Service | ID = 1101
Description =

Error - 10/22/2011 12:39:22 PM | Computer Name = Jim-PC | Source = .NET Runtime Optimization Service | ID = 1101
Description =

Error - 10/22/2011 5:07:28 PM | Computer Name = Jim-PC | Source = VSS | ID = 12298
Description =

Error - 10/22/2011 7:39:07 PM | Computer Name = Jim-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

[ Media Center Events ]
Error - 6/27/2009 1:31:46 AM | Computer Name = Jim-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

[ System Events ]
Error - 10/23/2011 12:04:39 AM | Computer Name = Jim-PC | Source = Service Control Manager | ID = 7003
Description =

Error - 10/23/2011 12:04:40 AM | Computer Name = Jim-PC | Source = Service Control Manager | ID = 7003
Description =

Error - 10/23/2011 12:04:41 AM | Computer Name = Jim-PC | Source = Service Control Manager | ID = 7003
Description =

Error - 10/23/2011 12:04:42 AM | Computer Name = Jim-PC | Source = Service Control Manager | ID = 7003
Description =

Error - 10/23/2011 12:04:42 AM | Computer Name = Jim-PC | Source = Service Control Manager | ID = 7003
Description =

Error - 10/23/2011 12:04:43 AM | Computer Name = Jim-PC | Source = Service Control Manager | ID = 7003
Description =

Error - 10/23/2011 12:04:44 AM | Computer Name = Jim-PC | Source = Service Control Manager | ID = 7003
Description =

Error - 10/23/2011 12:04:45 AM | Computer Name = Jim-PC | Source = Service Control Manager | ID = 7003
Description =

Error - 10/23/2011 12:04:45 AM | Computer Name = Jim-PC | Source = Service Control Manager | ID = 7003
Description =

Error - 10/23/2011 12:04:46 AM | Computer Name = Jim-PC | Source = Service Control Manager | ID = 7003
Description =


< End of report >

Any help or advice would be greatly appreciated.
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post





Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)







Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
Mowman, Thanks for the reply. In following your instructions, I got as far as downloading TDSSKiller.zip to my desktop. I'm unable to extract it, however, since WINZIP is demanding $39.95 to be activated to extract it. I could download a free program, but think it best to ask you first, since you told me not to make any downloads. Jim
Unfortunately, the links in your initial reply and in this latest message are all to zip files. I searched Google and found one that was supposed to be to a .exe file, but when it got to the desktop, it's a .exe.dap file. That calls for a "file association", which is beyond me.
In the link above that I gave,you need to use External mirror 2 EXE. I have just tried it and it works fine. If you still can't get it to work,just run Combofix.
From TDSSKiller I got: REPORT 09:40:58.0992 3252 TDSS rootkit removing tool [removed] Oct 25 2011 13:56:21 09:40:59.0974 3252 ============================================================ 09:40:59.0974 3252 Current date / time: 2011/10/25 09:40:59.0974 09:40:59.0974 3252 SystemInfo: 09:40:59.0974 3252 09:40:59.0974 3252 OS Version: 6.0.6002 ServicePack: 2.0 09:40:59.0974 3252 Product type: Workstation 09:40:59.0974 3252 ComputerName: JIM-PC 09:40:59.0974 3252 UserName: Jim 09:40:59.0974 3252 Windows directory: C:\Windows 09:40:59.0974 3252 System windows directory: C:\Windows 09:40:59.0974 3252 Processor architecture: Intel x86 09:40:59.0974 3252 Number of processors: 2 09:40:59.0974 3252 Page size: 0x1000 09:40:59.0974 3252 Boot type: Normal boot 09:40:59.0974 3252 ============================================================ 09:41:02.0782 3252 Initialize success 09:41:30.0160 4416 ============================================================ 09:41:30.0160 4416 Scan started 09:41:30.0160 4416 Mode: Manual; 09:41:30.0160 4416 ============================================================ 09:41:31.0237 4416 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys 09:41:31.0268 4416 ACPI - ok 09:41:31.0408 4416 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys 09:41:31.0455 4416 adp94xx - ok 09:41:31.0627 4416 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys 09:41:31.0705 4416 adpahci - ok 09:41:31.0736 4416 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys 09:41:31.0798 4416 adpu160m - ok 09:41:31.0861 4416 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys 09:41:31.0923 4416 adpu320 - ok 09:41:32.0095 4416 AFD (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys 09:41:32.0235 4416 AFD - ok 09:41:32.0407 4416 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys 09:41:32.0438 4416 agp440 - ok 09:41:32.0516 4416 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys 09:41:32.0578 4416 aic78xx - ok 09:41:32.0625 4416 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys 09:41:32.0703 4416 aliide - ok 09:41:32.0875 4416 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys 09:41:32.0937 4416 amdagp - ok 09:41:33.0078 4416 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys 09:41:33.0109 4416 amdide - ok 09:41:33.0280 4416 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys 09:41:33.0343 4416 AmdK7 - ok 09:41:33.0374 4416 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys 09:41:33.0405 4416 AmdK8 - ok 09:41:33.0546 4416 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys 09:41:33.0592 4416 arc - ok 09:41:33.0826 4416 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys 09:41:33.0858 4416 arcsas - ok 09:41:34.0029 4416 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys 09:41:34.0060 4416 AsyncMac - ok 09:41:34.0185 4416 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys 09:41:34.0201 4416 atapi - ok 09:41:34.0341 4416 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys 09:41:34.0372 4416 Beep - ok 09:41:34.0435 4416 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys 09:41:34.0482 4416 blbdrive - ok 09:41:34.0606 4416 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys 09:41:34.0669 4416 bowser - ok 09:41:34.0887 4416 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys 09:41:34.0934 4416 BrFiltLo - ok 09:41:35.0090 4416 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys 09:41:35.0152 4416 BrFiltUp - ok 09:41:35.0230 4416 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys 09:41:35.0262 4416 Brserid - ok 09:41:35.0293 4416 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys 09:41:35.0340 4416 BrSerWdm - ok 09:41:35.0386 4416 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys 09:41:35.0402 4416 BrUsbMdm - ok 09:41:35.0464 4416 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys 09:41:35.0480 4416 BTHMODEM - ok 09:41:35.0527 4416 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys 09:41:35.0574 4416 cdfs - ok 09:41:35.0698 4416 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys 09:41:35.0761 4416 cdrom - ok 09:41:35.0854 4416 CFRMD - ok 09:41:36.0120 4416 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys 09:41:36.0135 4416 circlass - ok 09:41:36.0244 4416 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys 09:41:36.0260 4416 CLFS - ok 09:41:36.0447 4416 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys 09:41:36.0478 4416 cmdide - ok 09:41:36.0556 4416 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys 09:41:36.0572 4416 Compbatt - ok 09:41:36.0666 4416 cpuz135 (c2eb4539a4f6ab6edd01bdc191619975) C:\Windows\system32\drivers\cpuz135_x32.sys 09:41:36.0681 4416 cpuz135 - ok 09:41:36.0759 4416 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys 09:41:36.0775 4416 crcdisk - ok 09:41:36.0822 4416 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys 09:41:36.0853 4416 Crusoe - ok 09:41:37.0446 4416 DfsC (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys 09:41:37.0539 4416 DfsC - ok 09:41:37.0758 4416 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys 09:41:37.0804 4416 disk - ok 09:41:37.0992 4416 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys 09:41:38.0023 4416 drmkaud - ok 09:41:38.0288 4416 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys 09:41:38.0319 4416 DXGKrnl - ok 09:41:38.0460 4416 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys 09:41:38.0522 4416 E1G60 - ok 09:41:38.0772 4416 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys 09:41:38.0803 4416 Ecache - ok 09:41:38.0990 4416 ElRawDisk (9c64c2a950195f9bc3a09a499648b01c) C:\Windows\system32\drivers\ElRawDsk.sys 09:41:39.0052 4416 ElRawDisk - ok 09:41:39.0255 4416 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys 09:41:39.0302 4416 elxstor - ok 09:41:39.0364 4416 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys 09:41:39.0396 4416 ErrDev - ok 09:41:39.0458 4416 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys 09:41:39.0536 4416 exfat - ok 09:41:39.0598 4416 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys 09:41:39.0692 4416 fastfat - ok 09:41:39.0754 4416 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys 09:41:39.0786 4416 fdc - ok 09:41:39.0957 4416 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys 09:41:39.0973 4416 FileInfo - ok 09:41:40.0035 4416 FileMonitor - ok 09:41:40.0332 4416 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys 09:41:40.0347 4416 Filetrace - ok 09:41:40.0534 4416 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys 09:41:40.0566 4416 flpydisk - ok 09:41:40.0768 4416 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys 09:41:40.0800 4416 FltMgr - ok 09:41:40.0909 4416 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys 09:41:40.0940 4416 Fs_Rec - ok 09:41:41.0065 4416 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys 09:41:41.0096 4416 gagp30kx - ok 09:41:41.0346 4416 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys 09:41:41.0424 4416 HDAudBus - ok 09:41:41.0611 4416 HidBatt (1eea61828eb0263b97252842c07e5a1c) C:\Windows\system32\DRIVERS\HidBatt.sys 09:41:41.0642 4416 HidBatt - ok 09:41:41.0814 4416 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys 09:41:41.0845 4416 HidBth - ok 09:41:42.0157 4416 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys 09:41:42.0204 4416 HidIr - ok 09:41:42.0406 4416 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys 09:41:42.0438 4416 HidUsb - ok 09:41:42.0578 4416 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys 09:41:42.0594 4416 HpCISSs - ok 09:41:42.0734 4416 HSF_DP (617732f6c0f86df3757b1d39211c15e5) C:\Windows\system32\DRIVERS\HSX_DP.sys 09:41:42.0828 4416 HSF_DP - ok 09:41:43.0140 4416 HSXHWBS3 (b1322e002bc4a556f83e4edde8e2f30f) C:\Windows\system32\DRIVERS\HSXHWBS3.sys 09:41:43.0218 4416 HSXHWBS3 - ok 09:41:43.0514 4416 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys 09:41:43.0561 4416 HTTP - ok 09:41:43.0873 4416 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys 09:41:43.0920 4416 i2omp - ok 09:41:44.0076 4416 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys 09:41:44.0122 4416 i8042prt - ok 09:41:44.0169 4416 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys 09:41:44.0216 4416 iaStorV - ok 09:41:44.0434 4416 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys 09:41:44.0450 4416 iirsp - ok 09:41:44.0528 4416 ImmunetMonitorDriver (1ec89249dabf56104fea85b4718a5002) C:\Windows\system32\DRIVERS\ImmunetMonitor.sys 09:41:44.0606 4416 ImmunetMonitorDriver - ok 09:41:44.0637 4416 ImmunetProtectDriver (92834a34b46d9b3dd3ba668f4a39b647) C:\Windows\system32\DRIVERS\ImmunetProtect.sys 09:41:44.0668 4416 ImmunetProtectDriver - ok 09:41:44.0762 4416 ImmunetSelfProtectDriver (179b4a2de450e2fcf77951953bbd7f6f) C:\Windows\system32\DRIVERS\ImmunetSelfProtect.sys 09:41:44.0793 4416 ImmunetSelfProtectDriver - ok 09:41:45.0012 4416 IntcAzAudAddService (84ed2154239f9d013bbd3220755ada8b) C:\Windows\system32\drivers\RTKVHDA.sys 09:41:45.0136 4416 IntcAzAudAddService - ok 09:41:45.0308 4416 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys 09:41:45.0355 4416 intelide - ok 09:41:45.0448 4416 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys 09:41:45.0464 4416 intelppm - ok 09:41:45.0495 4416 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys 09:41:45.0526 4416 IpFilterDriver - ok 09:41:45.0620 4416 IpInIp - ok 09:41:45.0948 4416 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys 09:41:45.0979 4416 IPMIDRV - ok 09:41:46.0228 4416 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys 09:41:46.0244 4416 IPNAT - ok 09:41:46.0447 4416 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys 09:41:46.0478 4416 IRENUM - ok 09:41:46.0681 4416 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys 09:41:46.0712 4416 isapnp - ok 09:41:46.0884 4416 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys 09:41:46.0915 4416 iScsiPrt - ok 09:41:47.0102 4416 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys 09:41:47.0149 4416 iteatapi - ok 09:41:47.0320 4416 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys 09:41:47.0352 4416 iteraid - ok 09:41:47.0398 4416 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys 09:41:47.0461 4416 kbdclass - ok 09:41:47.0617 4416 kbdhid (18247836959ba67e3511b62846b9c2e0) C:\Windows\system32\drivers\kbdhid.sys 09:41:47.0664 4416 kbdhid - ok 09:41:47.0820 4416 kl1 (ce3958f58547454884e97bda78cd7040) C:\Windows\system32\DRIVERS\kl1.sys 09:41:47.0866 4416 kl1 - ok 09:41:47.0898 4416 klbg (53eedab3f0511321ac3ae8bc968b158c) C:\Windows\system32\drivers\klbg.sys 09:41:47.0929 4416 klbg - ok 09:41:48.0022 4416 KLIF (de6c14fb8438ef932d9f58f269a19b85) C:\Windows\system32\DRIVERS\klif.sys 09:41:48.0100 4416 KLIF - ok 09:41:48.0381 4416 KLIM6 (892cc162dc88ab084c86485879526c59) C:\Windows\system32\DRIVERS\klim6.sys 09:41:48.0397 4416 KLIM6 - ok 09:41:48.0444 4416 klmouflt (aa63a815876a76987b5dbce6af7478e9) C:\Windows\system32\DRIVERS\klmouflt.sys 09:41:48.0475 4416 klmouflt - ok 09:41:48.0537 4416 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys 09:41:48.0584 4416 KSecDD - ok 09:41:48.0709 4416 Lavasoft Kernexplorer (6c4a3804510ad8e0f0c07b5be3d44ddb) C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys 09:41:48.0756 4416 Lavasoft Kernexplorer - ok 09:41:48.0927 4416 Lbd (336abe8721cbc3110f1c6426da633417) C:\Windows\system32\DRIVERS\Lbd.sys 09:41:48.0943 4416 Lbd - ok 09:41:49.0052 4416 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys 09:41:49.0083 4416 lltdio - ok 09:41:49.0255 4416 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys 09:41:49.0286 4416 LSI_FC - ok 09:41:49.0442 4416 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys 09:41:49.0473 4416 LSI_SAS - ok 09:41:49.0567 4416 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys 09:41:49.0598 4416 LSI_SCSI - ok 09:41:49.0832 4416 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys 09:41:49.0910 4416 luafv - ok 09:41:50.0050 4416 MBAMSwissArmy - ok 09:41:50.0160 4416 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\Windows\system32\DRIVERS\mdmxsdk.sys 09:41:50.0238 4416 mdmxsdk - ok 09:41:50.0518 4416 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys 09:41:50.0534 4416 megasas - ok 09:41:50.0768 4416 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys 09:41:50.0815 4416 MegaSR - ok 09:41:50.0940 4416 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys 09:41:50.0971 4416 Modem - ok 09:41:51.0158 4416 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys 09:41:51.0189 4416 monitor - ok 09:41:51.0470 4416 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys 09:41:51.0501 4416 mouclass - ok 09:41:51.0673 4416 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\drivers\mouhid.sys 09:41:51.0688 4416 mouhid - ok 09:41:51.0720 4416 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys 09:41:51.0751 4416 MountMgr - ok 09:41:51.0782 4416 MpFilter (fee0baded54222e9f1dae9541212aab1) C:\Windows\system32\DRIVERS\MpFilter.sys 09:41:51.0844 4416 MpFilter - ok 09:41:51.0860 4416 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys 09:41:51.0891 4416 mpio - ok 09:41:51.0985 4416 MpKsl05b58d03 - ok 09:41:52.0125 4416 MpKsl0bf48414 - ok 09:41:52.0406 4416 MpKsl0d0bb27d - ok 09:41:52.0609 4416 MpKsl1245607a - ok 09:41:52.0718 4416 MpKsl15dc7566 - ok 09:41:52.0952 4416 MpKsl1992d301 - ok 09:41:53.0264 4416 MpKsl269603d0 - ok 09:41:53.0514 4416 MpKsl30d3aa3a - ok 09:41:53.0654 4416 MpKsl3b875f4c - ok 09:41:53.0716 4416 MpKsl3c5c4fe2 - ok 09:41:53.0732 4416 MpKsl3f588a4d - ok 09:41:53.0748 4416 MpKsl4b4adeca - ok 09:41:54.0013 4416 MpKsl4b5ddd5c - ok 09:41:54.0278 4416 MpKsl4b62adf7 - ok 09:41:54.0372 4416 MpKsl4d537305 - ok 09:41:54.0450 4416 MpKsl4e1a91ef - ok 09:41:54.0496 4416 MpKsl5352410b - ok 09:41:54.0512 4416 MpKsl53bad31f - ok 09:41:54.0528 4416 MpKsl57d7cffe - ok 09:41:54.0559 4416 MpKsl57ed18e1 - ok 09:41:54.0574 4416 MpKsl59ed7316 - ok 09:41:54.0668 4416 MpKsl5f17cfca - ok 09:41:54.0808 4416 MpKsl6c672c00 - ok 09:41:54.0964 4416 MpKsl6fd80a2d - ok 09:41:55.0401 4416 MpKsl81db7d42 - ok 09:41:55.0464 4416 MpKsl8232cca1 - ok 09:41:55.0526 4416 MpKsl8e33e29f - ok 09:41:55.0620 4416 MpKsl94c50ea4 - ok 09:41:55.0635 4416 MpKsl989f3e82 - ok 09:41:55.0807 4416 MpKsla4a2bfb1 - ok 09:41:56.0197 4416 MpKslb53c05e4 - ok 09:41:56.0368 4416 MpKslbcfbe12e - ok 09:41:56.0587 4416 MpKslc07eabda - ok 09:41:56.0618 4416 MpKslc0f2566b - ok 09:41:56.0836 4416 MpKslc6e71b1a (5f53edfead46fa7adb78eee9ecce8fdf) c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{80EF1948-126A-42A5-ADA9-37F8078436B7}\MpKslc6e71b1a.sys 09:41:56.0868 4416 MpKslc6e71b1a - ok 09:41:57.0164 4416 MpKslda271149 - ok 09:41:57.0398 4416 MpKsldc8d69db - ok 09:41:57.0523 4416 MpKsle4c1db99 - ok 09:41:57.0601 4416 MpKsle51f7480 - ok 09:41:57.0772 4416 MpKsle768390d - ok 09:41:57.0944 4416 MpKsle76b4e7d - ok 09:41:58.0178 4416 MpKsle855f36f - ok 09:41:58.0303 4416 MpKsle94a8179 - ok 09:41:58.0474 4416 MpKslec7ddecc - ok 09:41:58.0630 4416 MpKsleffa7301 - ok 09:41:58.0724 4416 MpKslf73bf050 - ok 09:41:58.0942 4416 MpNWMon (2c3489660d4a8d514c123c3f0d67df46) C:\Windows\system32\DRIVERS\MpNWMon.sys 09:41:58.0958 4416 MpNWMon - ok 09:41:59.0083 4416 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys 09:41:59.0114 4416 mpsdrv - ok 09:41:59.0145 4416 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys 09:41:59.0176 4416 Mraid35x - ok 09:41:59.0301 4416 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys 09:41:59.0348 4416 MRxDAV - ok 09:41:59.0442 4416 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys 09:41:59.0504 4416 mrxsmb - ok 09:41:59.0644 4416 mrxsmb10 (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys 09:41:59.0707 4416 mrxsmb10 - ok 09:41:59.0910 4416 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys 09:41:59.0972 4416 mrxsmb20 - ok 09:42:00.0034 4416 msahci (28023e86f17001f7cd9b15a5bc9ae07d) C:\Windows\system32\drivers\msahci.sys 09:42:00.0066 4416 msahci - ok 09:42:00.0112 4416 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys 09:42:00.0159 4416 msdsm - ok 09:42:00.0268 4416 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys 09:42:00.0300 4416 Msfs - ok 09:42:00.0378 4416 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys 09:42:00.0424 4416 msisadrv - ok 09:42:00.0596 4416 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys 09:42:00.0690 4416 MSKSSRV - ok 09:42:00.0814 4416 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys 09:42:00.0861 4416 MSPCLOCK - ok 09:42:00.0970 4416 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys 09:42:01.0002 4416 MSPQM - ok 09:42:01.0204 4416 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys 09:42:01.0251 4416 MsRPC - ok 09:42:01.0392 4416 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys 09:42:01.0423 4416 mssmbios - ok 09:42:01.0594 4416 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys 09:42:01.0626 4416 MSTEE - ok 09:42:01.0766 4416 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys 09:42:01.0844 4416 Mup - ok 09:42:01.0969 4416 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys 09:42:02.0031 4416 NativeWifiP - ok 09:42:02.0203 4416 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys 09:42:02.0250 4416 NDIS - ok 09:42:02.0296 4416 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys 09:42:02.0343 4416 NdisTapi - ok 09:42:02.0406 4416 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys 09:42:02.0437 4416 Ndisuio - ok 09:42:02.0562 4416 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys 09:42:02.0624 4416 NdisWan - ok 09:42:02.0718 4416 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys 09:42:02.0764 4416 NDProxy - ok 09:42:02.0858 4416 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys 09:42:02.0905 4416 NetBIOS - ok 09:42:02.0983 4416 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys 09:42:03.0076 4416 netbt - ok 09:42:03.0264 4416 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys 09:42:03.0310 4416 nfrd960 - ok 09:42:03.0388 4416 NisDrv (7b01c6172cfd0b10116175e09200d4b4) C:\Windows\system32\DRIVERS\NisDrvWFP.sys 09:42:03.0420 4416 NisDrv - ok 09:42:03.0544 4416 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys 09:42:03.0591 4416 Npfs - ok 09:42:03.0685 4416 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys 09:42:03.0732 4416 nsiproxy - ok 09:42:03.0919 4416 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys 09:42:03.0981 4416 Ntfs - ok 09:42:04.0184 4416 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys 09:42:04.0231 4416 ntrigdigi - ok 09:42:04.0683 4416 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys 09:42:04.0714 4416 Null - ok 09:42:05.0011 4416 NVENETFD (d958a2b5f6ad5c3b8ccdc4d7da62466c) C:\Windows\system32\DRIVERS\nvmfdx32.sys 09:42:05.0089 4416 NVENETFD - ok 09:42:06.0056 4416 nvlddmkm (fbba09782f2fac5a57619df378ba9372) C:\Windows\system32\DRIVERS\nvlddmkm.sys 09:42:06.0774 4416 nvlddmkm - ok 09:42:07.0148 4416 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys 09:42:07.0195 4416 nvraid - ok 09:42:07.0398 4416 nvsmu (be9039422a5ce976c03c5e2cf20106be) C:\Windows\system32\DRIVERS\nvsmu.sys 09:42:07.0413 4416 nvsmu - ok 09:42:07.0507 4416 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys 09:42:07.0554 4416 nvstor - ok 09:42:07.0694 4416 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys 09:42:07.0725 4416 nv_agp - ok 09:42:07.0741 4416 NwlnkFlt - ok 09:42:07.0772 4416 NwlnkFwd - ok 09:42:08.0037 4416 ohci1394 (6f310e890d46e246e0e261a63d9b36b4) C:\Windows\system32\DRIVERS\ohci1394.sys 09:42:08.0131 4416 ohci1394 - ok 09:42:08.0614 4416 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys 09:42:08.0661 4416 Parport - ok 09:42:08.0817 4416 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys 09:42:08.0848 4416 partmgr - ok 09:42:08.0911 4416 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys 09:42:08.0926 4416 Parvdm - ok 09:42:09.0020 4416 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys 09:42:09.0082 4416 pci - ok 09:42:09.0379 4416 pciide (1636d43f10416aeb483bc6001097b26c) C:\Windows\system32\drivers\pciide.sys 09:42:09.0394 4416 pciide - ok 09:42:09.0488 4416 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys 09:42:09.0535 4416 pcmcia - ok 09:42:09.0597 4416 pctplsg - ok 09:42:09.0660 4416 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys 09:42:09.0738 4416 PEAUTH - ok 09:42:09.0862 4416 PfFilter (56652af63296e1b0304162c5e7db5faf) C:\Program Files\IObit\Protected Folder\pffilter.sys 09:42:09.0909 4416 PfFilter - ok 09:42:10.0081 4416 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys 09:42:10.0143 4416 PptpMiniport - ok 09:42:10.0393 4416 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys 09:42:10.0424 4416 Processor - ok 09:42:10.0627 4416 Ps2 (390c204ced3785609ab24e9c52054a84) C:\Windows\system32\DRIVERS\PS2.sys 09:42:10.0658 4416 Ps2 - ok 09:42:10.0876 4416 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys 09:42:10.0908 4416 PSched - ok 09:42:11.0032 4416 PSI (d24dfd16a1e2a76034df5aa18125c35d) C:\Windows\system32\DRIVERS\psi_mf.sys 09:42:11.0079 4416 PSI - ok 09:42:11.0344 4416 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys 09:42:11.0500 4416 ql2300 - ok 09:42:11.0688 4416 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys 09:42:11.0734 4416 ql40xx - ok 09:42:11.0797 4416 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys 09:42:11.0812 4416 QWAVEdrv - ok 09:42:11.0859 4416 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys 09:42:11.0906 4416 RasAcd - ok 09:42:12.0015 4416 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys 09:42:12.0046 4416 Rasl2tp - ok 09:42:12.0124 4416 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys 09:42:12.0156 4416 RasPppoe - ok 09:42:12.0202 4416 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys 09:42:12.0234 4416 RasSstp - ok 09:42:12.0312 4416 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys 09:42:12.0374 4416 rdbss - ok 09:42:12.0421 4416 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys 09:42:12.0452 4416 RDPCDD - ok 09:42:12.0499 4416 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys 09:42:12.0546 4416 rdpdr - ok 09:42:12.0608 4416 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys 09:42:12.0639 4416 RDPENCDD - ok 09:42:12.0717 4416 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys 09:42:12.0826 4416 RDPWD - ok 09:42:12.0920 4416 RegFilter - ok 09:42:13.0060 4416 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys 09:42:13.0076 4416 rspndr - ok 09:42:13.0154 4416 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys 09:42:13.0185 4416 sbp2port - ok 09:42:13.0310 4416 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 09:42:13.0326 4416 secdrv - ok 09:42:13.0435 4416 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys 09:42:13.0450 4416 Serenum - ok 09:42:13.0513 4416 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys 09:42:13.0560 4416 Serial - ok 09:42:13.0606 4416 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys 09:42:13.0622 4416 sermouse - ok 09:42:13.0762 4416 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys 09:42:13.0794 4416 sffdisk - ok 09:42:13.0825 4416 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys 09:42:13.0840 4416 sffp_mmc - ok 09:42:13.0887 4416 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys 09:42:13.0934 4416 sffp_sd - ok 09:42:13.0981 4416 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys 09:42:14.0012 4416 sfloppy - ok 09:42:14.0090 4416 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys 09:42:14.0121 4416 sisagp - ok 09:42:14.0199 4416 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys 09:42:14.0215 4416 SiSRaid2 - ok 09:42:14.0262 4416 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys 09:42:14.0277 4416 SiSRaid4 - ok 09:42:14.0355 4416 SmartDefragDriver (cc48f88fe17bb8e5eb6fa1a8a9477006) C:\Windows\system32\Drivers\SmartDefragDriver.sys 09:42:14.0371 4416 SmartDefragDriver - ok 09:42:14.0433 4416 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys 09:42:14.0480 4416 Smb - ok 09:42:14.0652 4416 Soluto (ff35c2d01ac36b446a1b997f305f0fc2) C:\Windows\system32\DRIVERS\Soluto.sys 09:42:14.0652 4416 Soluto - ok 09:42:14.0761 4416 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys 09:42:14.0808 4416 spldr - ok 09:42:14.0886 4416 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys 09:42:14.0964 4416 srv - ok 09:42:15.0057 4416 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys 09:42:15.0104 4416 srv2 - ok 09:42:15.0182 4416 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys 09:42:15.0260 4416 srvnet - ok 09:42:15.0385 4416 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys 09:42:15.0400 4416 swenum - ok 09:42:15.0463 4416 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys 09:42:15.0478 4416 Symc8xx - ok 09:42:15.0588 4416 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys 09:42:15.0603 4416 Sym_hi - ok 09:42:15.0650 4416 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys 09:42:15.0681 4416 Sym_u3 - ok 09:42:15.0806 4416 Tcpip (6647fce6fc4970daafe5c64c794513d3) C:\Windows\system32\drivers\tcpip.sys 09:42:15.0853 4416 Tcpip - ok 09:42:15.0900 4416 Tcpip6 (6647fce6fc4970daafe5c64c794513d3) C:\Windows\system32\DRIVERS\tcpip.sys 09:42:15.0900 4416 Tcpip6 - ok 09:42:15.0962 4416 tcpipreg (36606b165d04a397bdf613096986d85d) C:\Windows\system32\drivers\tcpipreg.sys 09:42:16.0009 4416 tcpipreg - ok 09:42:16.0071 4416 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys 09:42:16.0087 4416 TDPIPE - ok 09:42:16.0134 4416 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys 09:42:16.0134 4416 TDTCP - ok 09:42:16.0196 4416 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys 09:42:16.0243 4416 tdx - ok 09:42:16.0336 4416 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys 09:42:16.0383 4416 TermDD - ok 09:42:16.0539 4416 Trufos (d391f1171a2e3a7080df6faae7a20c0b) C:\Windows\system32\DRIVERS\Trufos.sys 09:42:16.0648 4416 Trufos - ok 09:42:16.0742 4416 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys 09:42:16.0773 4416 tssecsrv - ok 09:42:16.0851 4416 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys 09:42:16.0867 4416 tunmp - ok 09:42:16.0929 4416 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys 09:42:16.0992 4416 tunnel - ok 09:42:17.0070 4416 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys 09:42:17.0085 4416 uagp35 - ok 09:42:17.0179 4416 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys 09:42:17.0210 4416 udfs - ok 09:42:17.0335 4416 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys 09:42:17.0366 4416 uliagpkx - ok 09:42:17.0413 4416 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys 09:42:17.0444 4416 uliahci - ok 09:42:17.0506 4416 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys 09:42:17.0538 4416 UlSata - ok 09:42:17.0584 4416 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys 09:42:17.0616 4416 ulsata2 - ok 09:42:17.0647 4416 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys 09:42:17.0662 4416 umbus - ok 09:42:17.0772 4416 UrlFilter - ok 09:42:17.0912 4416 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys 09:42:17.0990 4416 usbccgp - ok 09:42:18.0115 4416 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys 09:42:18.0146 4416 usbcir - ok 09:42:18.0255 4416 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys 09:42:18.0286 4416 usbehci - ok 09:42:18.0380 4416 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys 09:42:18.0458 4416 usbhub - ok 09:42:18.0552 4416 usbohci (ce697fee0d479290d89bec80dfe793b7) C:\Windows\system32\DRIVERS\usbohci.sys 09:42:18.0583 4416 usbohci - ok 09:42:18.0645 4416 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys 09:42:18.0676 4416 usbprint - ok 09:42:18.0723 4416 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys 09:42:18.0786 4416 usbscan - ok 09:42:18.0910 4416 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS 09:42:18.0926 4416 USBSTOR - ok 09:42:19.0051 4416 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys 09:42:19.0082 4416 usbuhci - ok 09:42:19.0238 4416 VBoxNetAdp (065f15e84f2cc4ef60594283e9d72617) C:\Windows\system32\DRIVERS\VBoxNetAdp.sys 09:42:19.0347 4416 VBoxNetAdp - ok 09:42:19.0410 4416 VBoxNetFlt - ok 09:42:19.0488 4416 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys 09:42:19.0503 4416 vga - ok 09:42:19.0566 4416 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys 09:42:19.0581 4416 VgaSave - ok 09:42:19.0628 4416 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys 09:42:19.0659 4416 viaagp - ok 09:42:19.0722 4416 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys 09:42:19.0753 4416 ViaC7 - ok 09:42:19.0800 4416 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys 09:42:19.0831 4416 viaide - ok 09:42:19.0893 4416 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys 09:42:19.0909 4416 volmgr - ok 09:42:20.0002 4416 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys 09:42:20.0034 4416 volmgrx - ok 09:42:20.0096 4416 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys 09:42:20.0127 4416 volsnap - ok 09:42:20.0190 4416 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys 09:42:20.0221 4416 vsmraid - ok 09:42:20.0346 4416 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys 09:42:20.0377 4416 WacomPen - ok 09:42:20.0424 4416 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 09:42:20.0455 4416 Wanarp - ok 09:42:20.0470 4416 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 09:42:20.0470 4416 Wanarpv6 - ok 09:42:20.0564 4416 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys 09:42:20.0580 4416 Wd - ok 09:42:20.0658 4416 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys 09:42:20.0673 4416 Wdf01000 - ok 09:42:20.0876 4416 winachsf (f1265727c078406299ff4b3b033e3132) C:\Windows\system32\DRIVERS\HSX_CNXT.sys 09:42:21.0016 4416 winachsf - ok 09:42:21.0219 4416 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys 09:42:21.0250 4416 WmiAcpi - ok 09:42:21.0562 4416 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys 09:42:21.0609 4416 ws2ifsl - ok 09:42:21.0781 4416 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys 09:42:21.0843 4416 WUDFRd - ok 09:42:21.0937 4416 XAudio (dab33cfa9dd24251aaa389ff36b64d4b) C:\Windows\system32\DRIVERS\xaudio.sys 09:42:21.0984 4416 XAudio - ok 09:42:22.0046 4416 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0 09:42:22.0077 4416 \Device\Harddisk0\DR0 - ok 09:42:22.0093 4416 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR1 09:42:22.0576 4416 \Device\Harddisk1\DR1 - ok 09:42:22.0576 4416 Boot (0x1200) (51c573efb358d688a1368cf9dfc838f4) \Device\Harddisk0\DR0\Partition0 09:42:22.0576 4416 \Device\Harddisk0\DR0\Partition0 - ok 09:42:22.0592 4416 Boot (0x1200) (7d41a0820edce67450d79a3455ec072a) \Device\Harddisk0\DR0\Partition1 09:42:22.0608 4416 \Device\Harddisk0\DR0\Partition1 - ok 09:42:22.0608 4416 Boot (0x1200) (58a3fba13af4413dbcd3729c2a97d7c7) \Device\Harddisk1\DR1\Partition0 09:42:22.0608 4416 \Device\Harddisk1\DR1\Partition0 - ok ComboFix ran through many files very quickly and produced no legible reports beyond 09:42:22.0608 4416 ============================================================ 09:42:22.0608 4416 Scan finished 09:42:22.0608 4416 ============================================================ 09:42:22.0623 4872 Detected object count: 0 09:42:22.0623 4872 Actual detected object count: 0 ComboFix came up with nothing but many, many repeats of: NIRKMD (and NIRCMD) Windows cannot find 'NIRCMD' ('NIRKMD'). Make sure you typed the name correctly and then try again. I made several tries. I appreciate your patience in this. Jim
See if you can find the log,it should be at C:\combofix.txt



Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the log please








Next

Run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
OK, I found the ComboFix Log: C:\ComboFix_1\en-US C:\ComboFix_1\SvcDrv.vbs C:\ComboFix_1\restore_pt.vbs C:\ComboFix_1\OSid.vbs C:\ComboFix_1\run2.sed C:\ComboFix_1\md5sum.pif C:\ComboFix_1\Prep.inf C:\ComboFix_1\w2k_sock.dll C:\ComboFix_1\xpreg.dat C:\ComboFix_1\xpmcode.dat C:\ComboFix_1\vun.dat C:\ComboFix_1\svchost.w7.dat C:\ComboFix_1\svchost.dat C:\ComboFix_1\Safeboot.def.w7.dat C:\ComboFix_1\rogues.dat C:\ComboFix_1\Purity.dat C:\ComboFix_1\NetworkService.dat C:\ComboFix_1\netsvc.xp.dat C:\ComboFix_1\netsvc.vista.dat C:\ComboFix_1\netsvc.dat C:\ComboFix_1\netsvc.bad.dat C:\ComboFix_1\ndis_combofix.dat C:\ComboFix_1\mynul.dat C:\ComboFix_1\pv.com C:\ComboFix_1\SuppScan.cmd C:\ComboFix_1\Rkey.cmd C:\ComboFix_1\P.cmd C:\ComboFix_1\NT-OS.cmd C:\ComboFix_1\NirCmd.chm C:\ComboFix_1\StartUpFile.cfx C:\ComboFix_1\StartMenuFolder.cfx C:\ComboFix_1\StartMenuFile.cfx C:\ComboFix_1\ProfilesFile.cfx C:\ComboFix_1\PersonalFolder.cfx C:\ComboFix_1\ND_64.bat C:\ComboFix_1\ND_.bat C:\ComboFix_1\MoveIt.bat C:\ComboFix_1\zip.3XE C:\ComboFix_1\swsc.3XE C:\ComboFix_1\swreg.3XE C:\ComboFix_1\rmbr.3XE C:\ComboFix_1\pevb.3XE C:\ComboFix_1\pev.3XE C:\ComboFix_1\pausep.3XE C:\ComboFix_1\NirCmdC.3XE C:\ComboFix_1\grep.3XE C:\ComboFix_1\cmd.3XE C:\ComboFix_1\CF11067.3XE C:\ComboFix_1\Start_dat C:\ComboFix_1\MUI And here's the Malwarebytes' Log: Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 8018 Windows 6.0.6002 Service Pack 2 Internet Explorer 9.0.8112.16421 10/25/2011 11:27:40 AM mbam-log-2011-10-25 (11-27-40).txt Scan type: Quick scan Objects scanned: 190640 Time elapsed: 4 minute(s), 13 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 2 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_CLASSES_ROOT\scrfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: ("%1" /S) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: (regedit.exe "%1") -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 8018 Windows 6.0.6002 Service Pack 2 Internet Explorer 9.0.8112.16421 10/25/2011 11:27:40 AM mbam-log-2011-10-25 (11-27-40).txt Scan type: Quick scan Objects scanned: 190640 Time elapsed: 4 minute(s), 13 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 2 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_CLASSES_ROOT\scrfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: ("%1" /S) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: (regedit.exe "%1") -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) I'm unable to open the E-Set scan
I was finally able to download and run ESET. It took a long time. The result is: C:\Program Files\StartNow Toolbar\Toolbar32.dll a variant of Win32/Toolbar.Zugo application cleaned by deleting - quarantined C:\Program Files\StartNow Toolbar\ToolbarUpdaterService.exe a variant of Win32/Toolbar.Zugo application cleaned by deleting - quarantined C:\Users\Jim\desktop\My Completed Downloads\registrybooster.exe Win32/RegistryBooster application deleted - quarantined C:\Users\Jim\Documents\My Completed Downloads\cnet_MailAttachmentDownloaderInstall_zip.exe a variant of Win32/InstallCore.D application cleaned by deleting - quarantined C:\Users\Jim\Documents\My Completed Downloads\cnet_MailAttachmentDownloaderInstall_zip_1.exe a variant of Win32/InstallCore.D application cleaned by deleting - quarantined C:\Users\Jim\Documents\My Completed Downloads\cnet_MailAttachmentDownloaderInstall_zip_2.exe a variant of Win32/InstallCore.D application cleaned by deleting - quarantined C:\Users\Jim\Documents\My Completed Downloads\registryboosterplc.exe Win32/RegistryBooster application deleted - quarantined C:\Users\Jim\Downloads\cnet_freeclip_exe.exe a variant of Win32/InstallCore.D application cleaned by deleting - quarantined C:\Users\Jim\Downloads\cnet_install_spartanhd_exe.exe a variant of Win32/InstallCore.D application cleaned by deleting - quarantined C:\Users\Jim\Downloads\cnet_wufinstall_exe.exe a variant of Win32/InstallCore.D application cleaned by deleting - quarantined C:\Users\Jim\Downloads\Unconfirmed 84491.crdownload a variant of Win32/InstallCore.D application cleaned by deleting - quarantined J:\ProgramData\SpeedBit\DAP\Offers\speedupmypc.exe Win32/SpeedUpMyPC application deleted - quarantined J:\Users\All Users\SpeedBit\DAP\Offers\speedupmypc.exe Win32/SpeedUpMyPC application deleted - quarantined J:\Users\Jim\desktop\My Completed Downloads\registrybooster.exe Win32/RegistryBooster application deleted - quarantined J:\Users\Jim\Documents\My Completed Downloads\cnet_MailAttachmentDownloaderInstall_zip.exe a variant of Win32/InstallCore.D application cleaned by deleting - quarantined J:\Users\Jim\Documents\My Completed Downloads\cnet_MailAttachmentDownloaderInstall_zip_1.exe a variant of Win32/InstallCore.D application cleaned by deleting - quarantined J:\Users\Jim\Documents\My Completed Downloads\cnet_MailAttachmentDownloaderInstall_zip_2.exe a variant of Win32/InstallCore.D application cleaned by deleting - quarantined J:\Users\Jim\Documents\My Completed Downloads\registrybooster.exe Win32/RegistryBooster application deleted - quarantined J:\Users\Jim\Documents\My Completed Downloads\registryboosterplc.exe Win32/RegistryBooster application deleted - quarantined Note that the J: drive is an external hard drive used for backup. I've never had the occasion to transfer anything from the J: drive to the C: derive. Do you still want me to run the f-secure scanner? Jim Jim
Sorry for the delayed response. The OTL log file follows. I don't know whether it's related or a coincidence, but after everything was running, smoothly indeed, a major catastrophe happened. I went to re-boot and on start-up was confronted with a message from Windows Boot Manager informing me that Windows failed to start. "A recent hardware or software change might be the cause". To fix the problem, I was directed to insert my Windows Activation Disc, which I don't have and never did. I spent a lot of time trying to get the blessed thing going, and got only frustration. I was advised to contact HP for help, but they turned me away years ago for being out of Warranty. Finally, I remember that I have a set of three HP Recovery discs, and the first one worked. My desktop, however, now states (in the corner) "This copy of Windows is not genuine". But it runs well.


OTL logfile created on: 10/26/2011 1:21:59 PM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Jim\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.87 Gb Total Physical Memory | 1.89 Gb Available Physical Memory | 65.91% Memory free
8.78 Gb Paging File | 7.04 Gb Available in Paging File | 80.21% Paging File free
Paging file location(s): [Binary data over 100 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 286.60 Gb Total Space | 177.63 Gb Free Space | 61.98% Space Free | Partition Type: NTFS
Drive D: | 11.49 Gb Total Space | 1.11 Gb Free Space | 9.65% Space Free | Partition Type: NTFS
Drive J: | 74.53 Gb Total Space | 3.05 Gb Free Space | 4.09% Space Free | Partition Type: NTFS

Computer Name: JIM-PC | User Name: Jim | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Jim\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe (Siber Systems)
PRC - C:\Program Files\Google\Update\1.3.21.79\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\Ninite Updater\NiniteUpdater.exe (Secure By Design Inc.)
PRC - C:\Program Files\Soluto\Soluto.exe (Soluto)
PRC - C:\Program Files\Soluto\SolutoService.exe (Soluto)
PRC - C:\Program Files\FreeClip\FreeClip.exe (M8 Software)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AWSC.exe ()
PRC - C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe (IObit)
PRC - C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
PRC - C:\Program Files\iolo\System Mechanic\SystemGuardAlerter.exe (iolo technologies, LLC)
PRC - C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe (iolo technologies, LLC)
PRC - C:\Program Files\SpeedBit Video Accelerator\VideoAcceleratorService.exe (SpeedBit Ltd.)
PRC - C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe (SpeedBit LTD)
PRC - C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe (IObit)
PRC - C:\Program Files\Vista Start Menu\VistaStartMenu.exe (OrdinarySoft)
PRC - C:\Program Files\explorer2_lite\xplorer2_lite.exe (ZabKat)
PRC - C:\Program Files\Secunia\PSI\sua.exe (Secunia)
PRC - C:\Program Files\IObit\Smart Defrag 2\SmartDefrag.exe (IObit)
PRC - C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe (Carbonite, Inc. (www.carbonite.com))
PRC - C:\Program Files\Fighters\FighterSuiteService.exe (SPAMfighter ApS)
PRC - C:\Program Files\Fighters\SPAMfighter\sfus.exe (SPAMfighter ApS)
PRC - C:\Program Files\Fighters\SPAMfighter\sfagent.exe (SPAMfighter ApS)
PRC - C:\Program Files\SureWest Communications\SureWest Internet Security 2010\avp.exe (SureWest Communications)
PRC - C:\Program Files\Immunet Protect\1.0.18\agent.exe (Immunet Corporation)
PRC - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (CANON INC.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Volumouse\volumouse.exe (NirSoft)
PRC - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
PRC - C:\WINDOWS\System32\lxbkcoms.exe ( )
PRC - C:\WINDOWS\System32\PING.EXE (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCGPostBootResources\4308e3b9891080987bd9a0a028f226e0\PCGPostBootResources.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCGHIDProbe\7f13332e303075f587ce51a5eb561258\PCGHIDProbe.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCGRSPProbe\c762fb2e7c659f1ca101b72945e5af4e\PCGRSPProbe.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCGWuInfo\162eb71288ae8578de7c60d6cacff2fe\PCGWuInfo.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Community.CsharpSql#\b0ef79b55912bf82ff7018da5efeed83\Community.CsharpSqlite.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Interop.IWshRuntime#\2dadac7311c15d47aeec1ca4b05cfc88\Interop.IWshRuntimeLibrary.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCGUsersCenter\fa1d0c9ec676be6e717150c7a78c67aa\PCGUsersCenter.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCGClientCommon\fc8a6713f642ff836131396e2893b608\PCGClientCommon.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCGBootVisualizingC#\dcac1616a31423616b1627d907d47c05\PCGBootVisualizingCommon.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCGConfiguration\a868536378e29aae6ec1b01230014f4c\PCGConfiguration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCGDatabase\e0f576e8b7e1737b38f17dac047c780e\PCGDatabase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCGAzureEntityFrame#\313484677ad267f48f06d5a045196656\PCGAzureEntityFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCGAzureShared\8a50003f51951b204f0d28a213b158d7\PCGAzureShared.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCGCommunication\d9bb99c719e2a568661fd2929575e0fa\PCGCommunication.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCGDriverProbe\abe64bcfac50e7b7fb9f1fd646d00fe5\PCGDriverProbe.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCGPreCompiled\6254998814b7a2c7f6b83b02b1872bfa\PCGPreCompiled.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCGPrestoSerializer\3947368cc5af163e17f0c176421ba640\PCGPrestoSerializer.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Ionic.Zip.Reduced\665558e07cf0ad29a1ac85b8efa55e34\Ionic.Zip.Reduced.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCGFramework\e1055d072a7882f83b87b6e32397df58\PCGFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Soluto\eb505a1407b611b674249fb0efc2b35b\Soluto.ni.exe ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\1363115565fff5a641243a48f396f107\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8645de531003807d00822e03986a075d\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\367c4043efc2f32d843cb588b0dc97fc\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\c1c06a392871267db27f7cbc40e1c4fb\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\40da9084d0863e07d7ce55953833b8b0\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\eb04eb9fcd7c99e16d63515d08636a3f\System.Data.Linq.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\8adb45c62e4c797bd4c706afe9e8bfb9\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\f9c36ea806e77872dce891c77b68fac3\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\b6632a8b2f276a8e31f5b0f6b2006cd1\mscorlib.ni.dll ()
MOD - C:\Program Files\Soluto\PCGDllExportInspector.dll ()
MOD - C:\Program Files\IObit\Advanced SystemCare 4\ASCv4ExtMenu.dll ()
MOD - C:\Program Files\Fighters\SPAMfighter\sfse.dll ()
MOD - C:\Program Files\IObit\Smart Defrag 2\NtfsData.dll ()
MOD - C:\Program Files\Fighters\SPAMfighter\sfsg.dll ()
MOD - C:\Program Files\IObit\Smart Defrag 2\madbasic_.bpl ()
MOD - C:\Program Files\IObit\Smart Defrag 2\maddisAsm_.bpl ()
MOD - C:\Program Files\IObit\Smart Defrag 2\madexcept_.bpl ()


========== Win32 Services (SafeList) ==========

SRV - (nosGetPlusHelper) getPlus® – File not found
SRV - (getPlusHelper) – File not found
SRV - (SolutoService) – C:\Program Files\Soluto\SolutoService.exe (Soluto)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (AdvancedSystemCareService) – C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
SRV - (ioloSystemService) – C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe (iolo technologies, LLC)
SRV - (scan) – C:\Program Files\Immunet\tetra\scan.dll (S.C. BitDefender S.R.L)
SRV - (VideoAcceleratorService) – C:\Program Files\SpeedBit Video Accelerator\VideoAcceleratorService.exe (SpeedBit Ltd.)
SRV - (IMFservice) – C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe (IObit)
SRV - (Secunia PSI Agent) – C:\Program Files\Secunia\PSI\PSIA.exe (Secunia)
SRV - (Secunia Update Agent) – C:\Program Files\Secunia\PSI\sua.exe (Secunia)
SRV - (Firefox Service) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\[removed]\svc.exe ()
SRV - (CarboniteService) – C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe (Carbonite, Inc. (www.carbonite.com))
SRV - (Suite Service) – C:\Program Files\Fighters\FighterSuiteService.exe (SPAMfighter ApS)
SRV - (SPAMfighter Update Service) – C:\Program Files\Fighters\SPAMfighter\sfus.exe (SPAMfighter ApS)
SRV - (IntuitUpdateService) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (Common Toolkit Service) – C:\Program Files\Common Files\Common Toolkit Suite\FighterSuiteService.exe (SPAMfighter)
SRV - (AVP) – C:\Program Files\SureWest Communications\SureWest Internet Security 2010\avp.exe (SureWest Communications)
SRV - (ImmunetProtect) – C:\Program Files\Immunet Protect\1.0.18\agent.exe (Immunet Corporation)
SRV - (PCPitstop Scheduling) – C:\Program Files\PCPitstop\PCPitstopScheduleService.exe (PC Pitstop LLC)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (IJPLMSVC) – C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
SRV - (lxbk_device) – C:\Windows\System32\lxbkcoms.exe ( )
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (Soluto) – C:\Windows\system32\DRIVERS\Soluto.sys (Soluto LTD.)
DRV - (Lbd) – C:\Windows\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (Lavasoft Kernexplorer) – C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys ()
DRV - (Trufos) – C:\WINDOWS\System32\drivers\Trufos.sys (BitDefender S.R.L.)
DRV - (PfFilter) – C:\Program Files\IObit\Protected Folder\pffilter.sys (IObit Information Technology)
DRV - (SmartDefragDriver) – C:\Windows\System32\Drivers\SmartDefragDriver.sys ()
DRV - (VBoxNetAdp) – C:\WINDOWS\System32\drivers\VBoxNetAdp.sys (Oracle Corporation)
DRV - (cpuz135) – C:\WINDOWS\System32\drivers\cpuz135_x32.sys (CPUID)
DRV - (PSI) – C:\WINDOWS\System32\drivers\psi_mf.sys (Secunia)
DRV - (KLIF) – C:\WINDOWS\System32\drivers\klif.sys (Kaspersky Lab)
DRV - (ImmunetProtectDriver) – C:\WINDOWS\System32\drivers\ImmunetProtect.sys (Windows ® Codename Longhorn DDK provider)
DRV - (ImmunetSelfProtectDriver) – C:\WINDOWS\System32\drivers\ImmunetSelfProtect.sys (Windows ® Codename Longhorn DDK provider)
DRV - (ImmunetMonitorDriver) – C:\WINDOWS\System32\drivers\ImmunetMonitor.sys (Windows ® Codename Longhorn DDK provider)
DRV - (klbg) – C:\Windows\system32\drivers\klbg.sys (Kaspersky Lab)
DRV - (klmouflt) – C:\WINDOWS\System32\drivers\klmouflt.sys (Kaspersky Lab)
DRV - (KLIM6) – C:\WINDOWS\System32\drivers\klim6.sys (Kaspersky Lab)
DRV - (ElRawDisk) – C:\WINDOWS\System32\drivers\ElRawDsk.sys (EldoS Corporation)
DRV - (kl1) – C:\WINDOWS\System32\drivers\kl1.sys (Kaspersky Lab)
DRV - (nvsmu) – C:\WINDOWS\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (nvlddmkm) – C:\WINDOWS\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (HSXHWBS3) – C:\WINDOWS\System32\drivers\HSXHWBS3.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\System32\drivers\HSX_DP.sys (Conexant Systems, Inc.)
DRV - (XAudio) – C:\WINDOWS\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (Ps2) – C:\WINDOWS\System32\drivers\PS2.sys (Hewlett-Packard Company)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cndt
IE - HKLM\..\URLSearchHook: {3ba34663-845a-4931-a6f3-1e033ec342a7} - No CLSID value found
IE - HKLM\..\URLSearchHook: {e917fc61-7f80-4f1f-a882-cdffffbe4c8d} - No CLSID value found

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.bing.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid;=CT2475029
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.defaultthis.engineName: "Thoosje Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2434356&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..browser.search.openintab: true
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.order.2: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.refdesk.com"
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.8
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20110323
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {F17C1572-C9EC-4e5c-A542-D05CBB5C5A08}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.6.2
FF - prefs.js..extensions.enabledItems: {0329E7D6-6F54-462D-93F6-F5C3118BADF2}:2.3.1
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.10.1
FF - prefs.js..extensions.enabledItems: [removed]:0.9.8.0
FF - prefs.js..extensions.enabledItems: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}:1.49
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "http://www.bing.com/search?pc=Z192&form;=ZGAADF&install;_date=20111005&q;="
FF - prefs.js..network.proxy.type: 0

FF - user.js..browser.search.openintab: true

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: File not found
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@mozilla.zeniko.ch/SumatraPDF_Browser_Plugin: C:\Program Files\SumatraPDF\npPdfViewer.dll (Simon Bünzli)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.666: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.666: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.666: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.666: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.666: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@mozilla.zeniko.ch/SumatraPDF_Browser_Plugin: C:\Program Files\SumatraPDF\npPdfViewer.dll (Simon Bünzli)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Jim\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Jim\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}: C:\Program Files\SpeedBit Video Downloader\SPFireFox [2011/09/19 23:08:41 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\SearchPredict\PRFireFox [2011/09/19 23:08:28 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/10/16 20:11:11 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2011/10/24 16:50:06 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/10/19 13:06:26 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/20 22:17:44 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 7.0.1\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011/10/03 11:14:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\Program Files\SureWest Communications\SureWest Internet Security 2010\THBExt [2010/06/04 00:22:07 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{F17C1572-C9EC-4e5c-A542-D05CBB5C5A08}: C:\Program Files\DAP\DAPFireFox [2011/09/20 09:36:11 | 000,000,000 | —D | M]

[2009/12/11 12:38:52 | 000,000,000 | —D | M] (No name found) – C:\Users\Jim\AppData\Roaming\Mozilla\Extensions
[2009/12/09 14:49:56 | 000,000,000 | —D | M] (No name found) – C:\Users\Jim\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2009/12/11 12:38:52 | 000,000,000 | —D | M] (No name found) – C:\Users\Jim\AppData\Roaming\Mozilla\Extensions\[removed]
[2011/10/20 23:34:34 | 000,000,000 | —D | M] (No name found) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions
[2010/11/03 16:04:56 | 000,000,000 | —D | M] (FlashGot) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}(108)
[2011/10/01 23:16:52 | 000,000,000 | —D | M] (Thoosje Community Toolbar) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\{3ba34663-845a-4931-a6f3-1e033ec342a7}(202)
[2011/10/05 11:23:15 | 000,000,000 | —D | M] (StartNow Toolbar) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}
[2011/07/02 18:11:43 | 000,000,000 | —D | M] (D-Link Toolbar) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\{926a10d2-4ce7-4331-b96f-ca4e22590fac}
[2011/07/09 11:32:29 | 000,000,000 | —D | M] (WOT) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2011/10/01 23:16:05 | 000,000,000 | —D | M] (MyAshampoo Community Toolbar) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}(203)
[2011/08/18 10:06:42 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/07/26 23:17:01 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}(239)
[2010/03/20 21:42:01 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}(279)
[2010/07/23 09:30:11 | 000,000,000 | —D | M] (No name found) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\Access Privileges Test
[2011/07/25 12:04:23 | 000,000,000 | —D | M] (Conduit Engine) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\[removed]
[2011/06/03 21:23:05 | 000,000,000 | —D | M] (F1 by Mozilla Labs) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\[removed]
[2010/11/13 17:18:14 | 000,000,000 | —D | M] (No name found) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\nostmp
[2011/03/23 16:32:42 | 000,000,000 | —D | M] (Personas) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\[removed]
[2010/06/11 23:44:53 | 000,000,000 | —D | M] (FastestFox) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\smarterwiki@wikiatic(324).com
[2011/04/05 21:44:43 | 000,000,000 | —D | M] (startup.service) – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\extensions\[removed]
[2011/07/02 13:03:36 | 000,002,569 | —- | M] () – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\searchplugins\askcom.xml
[2011/10/05 11:23:10 | 000,001,945 | —- | M] () – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\searchplugins\bing-zugo.xml
[2011/03/21 16:06:42 | 000,000,917 | —- | M] () – C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\2b9587re.default\searchplugins\conduit.xml
[2011/10/19 13:10:43 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/12/22 02:09:26 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/02/22 10:29:38 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/10/19 13:10:43 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2011/09/20 09:36:11 | 000,000,000 | —D | M] (Download Accelerator Plus (DAP) extension) – C:\PROGRAM FILES\DAP\DAPFIREFOX
[2011/10/16 20:11:11 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\PROGRAMDATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
() (No name found) – C:\USERS\JIM\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2B9587RE.DEFAULT\EXTENSIONS\{19503E42-CA3C-4C27-B1E2-9CDB2170EE34}.XPI
() (No name found) – C:\USERS\JIM\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2B9587RE.DEFAULT\EXTENSIONS\{AD48108D-92A6-4EB9-87E4-978ACA1DBAE4}.XPI
() (No name found) – C:\USERS\JIM\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2B9587RE.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\USERS\JIM\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2B9587RE.DEFAULT\EXTENSIONS\{D40F5E7B-D2CF-4856-B441-CC613EEFFBE3}.XPI
() (No name found) – C:\USERS\JIM\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2B9587RE.DEFAULT\EXTENSIONS\{D4DD63FA-01E4-46A7-B6B1-EDAB7D6AD389}.XPI
() (No name found) – C:\USERS\JIM\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2B9587RE.DEFAULT\EXTENSIONS\{DAF44BF7-A45E-4450-979C-91CF07434C3D}.XPI
() (No name found) – C:\USERS\JIM\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2B9587RE.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\JIM\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2B9587RE.DEFAULT\EXTENSIONS\[removed]
[2011/09/28 23:53:40 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/10/19 13:09:56 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/09/28 17:26:50 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Jim\AppData\Local\Google\Chrome\Application\14.0.835.202\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Disabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Disabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Disabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Jim\AppData\Local\Google\Chrome\Application\14.0.835.202\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Jim\AppData\Local\Google\Chrome\Application\14.0.835.202\pdf.dll
CHR - plugin: RoboForm Plugin for Google Chrome/Opera/etc. (Enabled) = C:\Program Files\Siber Systems\AI RoboForm\Chrome\plugin/rf-np-plugin.dll
CHR - plugin: downloadUpdater (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdnu.dll
CHR - plugin: downloadUpdater2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdnupdater2.dll
CHR - plugin: RealJukebox NS Plugin (Disabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Disabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Disabled) = C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: SumatraPDF Browser Plugin (Enabled) = C:\Program Files\SumatraPDF\npPdfViewer.dll
CHR - plugin: RealNetworks™ Chrome Background Extension Plug-In (32-bit) (Disabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: Windows Presentation Foundation (Disabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Jim\AppData\Local\Google\Chrome\Application\13.0.782.220\pdf.dll
CHR - Extension: TrackMeNot = C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgllkjmdafllcidaehjejjhpfkmanmka\0.2.1_0\
CHR - Extension: Download Accelerator Plus (DAP) = C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffdcfjdljhbehggjdkdioajnknjcpbjb\2.0.8_0\
CHR - Extension: UnSearch = C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\jojanedhfpmmjlkakmkhkgalbaokiphp\0.1_0\
CHR - Extension: RoboForm Lite = C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\kidhjpmgjfbkmcfpfakmdddddgfbhahj\2.7.0_0\

O1 HOSTS File: ([2011/09/05 11:37:33 | 000,437,206 | R— | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 15040 more lines…
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Reg Error: Value error.) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (SBCONVERT Class) - {92A9ACF4-9333-43AE-9698-DB283326F87F} - C:\Program Files\SpeedBit Video Downloader\TBUDD\tbcore3.dll ()
O2 - BHO: (GrabberObj Class) - {FF7C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\SpeedBit Video Downloader\TBUDD\Grabber.dll (SpeedBit)
O2 - BHO: (no name) - Disabled:{30F9B915-B755-4826-820B-08FBA6BD249D} - No CLSID value found.
O2 - BHO: (no name) - Disabled:{9030D464-4C02-4ABF-8ECC-5164760863C6} - No CLSID value found.
O2 - BHO: (no name) - Disabled:{DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O3 - HKLM\..\Toolbar: (SpeedBit Video Downloader) - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - C:\Program Files\SpeedBit Video Downloader\TBUDD\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - Reg Error: Value error. File not found
O3 - HKLM\..\Toolbar: (no name) - {3ba34663-845a-4931-a6f3-1e033ec342a7} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {61874dfa-9adf-44e5-8e61-f3913707e7d7} - No CLSID value found.
O3 - HKLM\..\Toolbar: (&RoboForm;) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (SpeedBit) - {EBFCD017-BCAD-42C3-9ED5-89DBDFC59171} - C:\Program Files\SpeedBit Toolbar\Toolbar\tbcore3.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - Reg Error: Value error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (SpeedBit) - {EBFCD017-BCAD-42C3-9ED5-89DBDFC59171} - C:\Program Files\SpeedBit Toolbar\Toolbar\tbcore3.dll ()
O4 - HKLM..\Run: [AVP] C:\Program Files\SureWest Communications\SureWest Internet Security 2010\avp.exe (SureWest Communications)
O4 - HKLM..\Run: [iolo Startup] C:\Program Files\iolo\Common\Lib\ioloLManager.exe (iolo technologies, LLC)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Ninite Updater] C:\Program Files\Ninite Updater\NiniteUpdater.exe (Secure By Design Inc.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [Advanced SystemCare 4] C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe (IObit)
O4 - HKCU..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\RunOnce: [SMRequiresRestart] File not found
O4 - Startup: C:\Users\Jim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FreeClip.lnk = C:\Program Files\FreeClip\FreeClip.exe (M8 Software)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: TaskbarNoThumbnail = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCANetwork = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCABattery = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisallowCpl = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: 4 = Phone and Modem Options
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: 6 = Regional and Language Options
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\SearchExtensions: InternetExtensionName =
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\SearchExtensions: InternetExtensionAction =
O8 - Extra context menu item: &Download; with &DAP; - C:\Program Files\DAP\dapextie.htm ()
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\SureWest Communications\SureWest Internet Security 2010\ie_banner_deny.htm ()
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Download &all; with DAP - C:\Program Files\DAP\dapextie2.htm ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm TaskBar Icon - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComTaskBarIcon.html ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: &Virtual; keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\SureWest Communications\SureWest Internet Security 2010\klwtbbho.dll (SureWest Communications)
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: URLs c&heck; - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\SureWest Communications\SureWest Internet Security 2010\klwtbbho.dll (SureWest Communications)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\SpeedBit Video Accelerator\LSP3.2.2.4\SBLSP.dll (SpeedBit)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\SpeedBit Video Accelerator\LSP3.2.2.4\SBLSP.dll (SpeedBit)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\SpeedBit Video Accelerator\LSP3.2.2.4\SBLSP.dll (SpeedBit)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\SpeedBit Video Accelerator\LSP3.2.2.4\SBLSP.dll (SpeedBit)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\SpeedBit Video Accelerator\LSP3.2.2.4\SBLSP.dll (SpeedBit)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\SpeedBit Video Accelerator\LSP3.2.2.4\SBLSP.dll (SpeedBit)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\SpeedBit Video Accelerator\LSP3.2.2.4\SBLSP.dll (SpeedBit)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\SpeedBit Video Accelerator\LSP3.2.2.4\SBLSP.dll (SpeedBit)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Program Files\SpeedBit Video Accelerator\LSP3.2.2.4\SBLSP.dll (SpeedBit)
O13 - gopher Prefix: missing
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Value error.)
O16 - DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCMaticVer Class)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} https://signin3.valueactive.eu/Register/Bra…OCX/flashax.cab (Reg Error: Value error.)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll (PCPitstop Exam)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6121B89B-995D-4FCD-A93A-4F08A562CFB9}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\inbox - No CLSID value found
O20 - AppInit_DLLs: (C:\PROGRA~1\SUREWE~1\SUREWE~2\mzvkbd3.dll) -C:\Program Files\SureWest Communications\SureWest Internet Security 2010\mzvkbd3.dll (SureWest Communications)
O20 - AppInit_DLLs: (C:\PROGRA~1\SUREWE~1\SUREWE~2\kloehk.dll) -C:\Program Files\SureWest Communications\SureWest Internet Security 2010\kloehk.dll (SureWest Communications)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\WINDOWS\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Program Files\Soluto\soluto.exe /userinit) -C:\Program Files\Soluto\soluto.exe (Soluto)
O20 - Winlogon\Notify\klogon: DllName - (C:\Windows\system32\klogon.dll) - C:\WINDOWS\System32\klogon.dll (SureWest Communications)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/11/06 17:42:00 | 000,000,074 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2008/11/06 17:42:00 | 000,000,074 | —- | M] () - J:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{31781e86-83bb-11de-9628-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{31781e86-83bb-11de-9628-806e6f6e6963}\Shell\AutoRun\command - "" = E:\PCWorld_Tune-Up_All-Stars.exe
O34 - HKLM BootExecute: (autocheck autochk /p \??\C:)
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (autocheck smrgdf C:\Users\Jim\AppData\Roaming\iolo\)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/10/26 13:14:21 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Jim\Desktop\OTL.exe
[2011/10/25 11:54:13 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/10/25 11:15:57 | 000,022,216 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2011/10/25 11:15:56 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/10/25 10:53:19 | 000,000,000 | –SD | C] – C:\ComboFix
[2011/10/25 10:36:57 | 000,000,000 | —D | C] – C:\ComboFix_1
[2011/10/25 09:57:53 | 004,273,906 | R— | C] (Swearware) – C:\Users\Jim\Desktop\ComboFix_1.exe
[2011/10/25 09:51:10 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/10/25 09:51:10 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/10/25 09:49:46 | 000,000,000 | —D | C] – C:\Qoobox
[2011/10/25 09:40:29 | 001,564,464 | —- | C] (Kaspersky Lab ZAO) – C:\Users\Jim\Desktop\tdsskiller_1.exe
[2011/10/24 16:50:03 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RoboForm
[2011/10/24 16:47:32 | 007,929,920 | —- | C] (Siber Systems) – C:\Users\Jim\Desktop\RoboForm-Setup.exe
[2011/10/24 10:11:07 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/10/24 09:22:19 | 000,000,000 | —D | C] – C:\Users\Jim\Desktop\Downloads
[2011/10/24 09:21:43 | 000,367,224 | —- | C] (RegNow.com) – C:\Users\Jim\Desktop\Download_RV-3Years-6.3.8.14.exe
[2011/10/21 23:37:34 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2011/10/20 23:48:46 | 038,808,920 | —- | C] (Microsoft Corporation) – C:\Users\Jim\Desktop\FileFormatConverters.exe
[2011/10/19 13:10:39 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/10/19 13:10:38 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/10/19 13:10:38 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2011/10/19 13:02:19 | 000,000,000 | —D | C] – C:\Users\Jim\AppData\Local\uTorrent
[2011/10/19 11:20:16 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 2.7
[2011/10/19 11:18:29 | 000,000,000 | —D | C] – C:\Python27
[2011/10/19 11:14:42 | 000,000,000 | —D | C] – C:\Program Files\Ninite Updater
[2011/10/19 10:50:09 | 000,000,000 | —D | C] – C:\Users\Jim\AppData\Local\Microsoft_Corporation
[2011/10/18 08:16:33 | 000,051,144 | —- | C] (Soluto LTD.) – C:\Windows\System32\drivers\Soluto.sys
[2011/10/18 08:16:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Soluto
[2011/10/18 08:16:14 | 000,000,000 | —D | C] – C:\Program Files\Soluto
[2011/10/18 03:02:30 | 000,000,000 | —D | C] – C:\ec57b2eead344e99551033e21d
[2011/10/17 10:33:26 | 000,555,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAutomationCore.dll
[2011/10/17 10:33:25 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\oleaccrc.dll
[2011/10/17 03:10:18 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/10/17 03:10:15 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/10/17 03:10:13 | 001,798,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/10/17 03:10:13 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/10/17 03:10:11 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/10/16 20:46:57 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisdecd.dll
[2011/10/16 20:46:57 | 000,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisrndr.ax
[2011/10/16 20:46:56 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Mpeg2Data.ax
[2011/10/16 20:46:55 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSDvbNP.ax
[2011/10/16 20:46:53 | 002,043,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2011/10/07 13:23:25 | 000,000,000 | —D | C] – C:\Users\Jim\AppData\Local\{C1CCF178-C310-467C-B5FD-1E6B622366AB}
[2011/10/07 13:23:24 | 000,000,000 | —D | C] – C:\Users\Jim\AppData\Local\{5D4DE31F-9136-40D5-98D6-916924141022}
[2011/10/07 13:23:10 | 000,000,000 | —D | C] – C:\Users\Jim\Documents\My Weblog Posts
[2011/10/07 13:23:09 | 000,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\Windows Live Writer
[2011/10/07 13:23:09 | 000,000,000 | —D | C] – C:\Users\Jim\AppData\Local\Windows Live Writer
[2011/10/05 16:45:47 | 000,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\PC Cleaners
[2011/10/05 16:45:31 | 005,356,304 | —- | C] (PC Cleaners) – C:\Windows\uninst.exe
[2011/10/05 16:45:31 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Cleaners
[2011/10/05 16:45:30 | 000,000,000 | —D | C] – C:\ProgramData\PC1Data
[2011/10/05 16:45:30 | 000,000,000 | —D | C] – C:\Program Files\PC Cleaners
[2011/10/05 16:34:11 | 000,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MenuUninstaller
[2011/10/05 16:34:10 | 000,000,000 | —D | C] – C:\Program Files\LeizerSoft
[2011/10/05 11:23:11 | 000,000,000 | —D | C] – C:\Program Files\StartNow Toolbar
[2011/10/01 23:54:09 | 000,000,000 | —D | C] – C:\Program Files\Holdem Indicator(1)
[2011/10/01 22:18:45 | 000,000,000 | —D | C] – C:\Users\Jim\AppData\Local\Immunet
[2011/10/01 22:18:44 | 000,000,000 | —D | C] – C:\ProgramData\Immunet
[2011/09/30 10:57:11 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter(115)
[2011/05/11 00:38:00 | 009,302,016 | —- | C] (IGSoft Ltd.) – C:\Program Files\ClientRuntime.dll
[2011/05/11 00:21:36 | 001,052,672 | —- | C] (The OpenSSL Project, http://www.openssl.org/) – C:\Program Files\libeay32.dll
[2011/05/11 00:21:36 | 000,764,928 | —- | C] (Microsoft Corporation) – C:\Program Files\dbghelp.dll
[2011/05/11 00:21:36 | 000,204,800 | —- | C] (The OpenSSL Project, http://www.openssl.org/) – C:\Program Files\ssleay32.dll
[2010/06/04 20:26:08 | 000,413,696 | —- | C] ( ) – C:\Windows\System32\lxbkinpa.dll
[2010/06/04 20:26:08 | 000,397,312 | —- | C] ( ) – C:\Windows\System32\lxbkiesc.dll
[2010/06/04 20:26:08 | 000,323,584 | —- | C] ( ) – C:\Windows\System32\LXBKhcp.dll
[2010/06/04 20:26:07 | 001,224,704 | —- | C] ( ) – C:\Windows\System32\lxbkserv.dll
[2010/06/04 20:26:07 | 000,991,232 | —- | C] ( ) – C:\Windows\System32\lxbkusb1.dll
[2010/06/04 20:26:06 | 000,163,840 | —- | C] ( ) – C:\Windows\System32\lxbkprox.dll
[2010/06/04 20:26:06 | 000,094,208 | —- | C] ( ) – C:\Windows\System32\lxbkpplc.dll
[2010/06/04 20:26:05 | 000,643,072 | —- | C] ( ) – C:\Windows\System32\lxbkpmui.dll
[2010/06/04 20:26:04 | 000,585,728 | —- | C] ( ) – C:\Windows\System32\lxbklmpm.dll
[2010/06/04 20:26:03 | 000,696,320 | —- | C] ( ) – C:\Windows\System32\lxbkhbn3.dll
[2010/06/04 20:26:03 | 000,385,704 | —- | C] ( ) – C:\Windows\System32\lxbkih.exe
[2010/06/04 20:26:01 | 000,537,256 | —- | C] ( ) – C:\Windows\System32\lxbkcoms.exe
[2010/06/04 20:26:00 | 000,684,032 | —- | C] ( ) – C:\Windows\System32\lxbkcomc.dll
[2010/06/04 20:26:00 | 000,421,888 | —- | C] ( ) – C:\Windows\System32\lxbkcomm.dll
[2010/06/04 20:25:59 | 000,381,608 | —- | C] ( ) – C:\Windows\System32\lxbkcfg.exe
[2006/12/02 06:22:52 | 000,479,232 | —- | C] (Microsoft Corporation) – C:\Program Files\msvcm80.dll
[2006/12/01 22:03:36 | 000,626,688 | —- | C] (Microsoft Corporation) – C:\Program Files\msvcr80.dll
[2006/12/01 22:03:36 | 000,548,864 | —- | C] (Microsoft Corporation) – C:\Program Files\msvcp80.dll
[2006/09/03 23:08:01 | 000,131,072 | —- | C] ( ) – C:\Windows\System32\Interop.SHDocVw.dll
[2006/09/03 23:08:01 | 000,049,152 | —- | C] ( ) – C:\Windows\System32\AxInterop.SHDocVw.dll

========== Files - Modified Within 30 Days ==========

[2011/10/26 13:31:01 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-685319607-627844835-723040629-1000UA.job
[2011/10/26 13:19:01 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/10/26 13:14:25 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Jim\Desktop\OTL.exe
[2011/10/26 12:52:15 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/10/26 05:17:12 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/10/26 05:17:12 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/10/25 11:48:26 | 000,014,678 | —- | M] () – C:\Users\Jim\Desktop\help
[2011/10/25 11:44:17 | 000,022,276 | —- | M] () – C:\Users\Jim\Desktop\online-scanner
[2011/10/25 11:16:06 | 000,000,868 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/10/25 09:58:29 | 004,273,906 | R— | M] (Swearware) – C:\Users\Jim\Desktop\ComboFix_1.exe
[2011/10/25 09:56:44 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif
[2011/10/25 09:55:19 | 000,600,122 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/10/25 09:55:19 | 000,102,020 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/10/25 09:54:41 | 000,000,258 | RHS- | M] () – C:\ProgramData\ntuser.pol
[2011/10/25 09:40:48 | 001,564,464 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Jim\Desktop\tdsskiller_1.exe
[2011/10/25 09:33:27 | 000,038,765 | —- | M] () – C:\Users\Jim\Desktop\tdsskiller.exe
[2011/10/25 09:32:53 | 001,545,338 | —- | M] () – C:\Users\Jim\Desktop\tdsskiller.zip
[2011/10/24 16:48:14 | 007,929,920 | —- | M] (Siber Systems) – C:\Users\Jim\Desktop\RoboForm-Setup.exe
[2011/10/24 13:29:32 | 000,007,764 | —- | M] () – C:\Windows\System32\.rsp
[2011/10/24 13:29:32 | 000,001,967 | —- | M] () – C:\Windows\System32\.lck
[2011/10/24 13:28:23 | 000,000,384 | —- | M] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2011/10/24 13:26:36 | 000,000,378 | —- | M] () – C:\Windows\tasks\AutoSmartDefrag.job
[2011/10/24 13:26:11 | 3084,042,240 | -HS- | M] () – C:\hiberfil.sys
[2011/10/24 09:36:50 | 000,000,065 | —- | M] () – C:\Users\Jim\Desktop\After Battery.URL
[2011/10/24 09:21:52 | 000,367,224 | —- | M] (RegNow.com) – C:\Users\Jim\Desktop\Download_RV-3Years-6.3.8.14.exe
[2011/10/23 22:15:32 | 000,000,064 | —- | M] () – C:\Windows\System32\rp_stats.dat
[2011/10/23 22:15:32 | 000,000,044 | —- | M] () – C:\Windows\System32\rp_rules.dat
[2011/10/23 16:11:42 | 000,000,876 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/10/23 00:00:43 | 000,000,083 | —- | M] () – C:\Users\Jim\Desktop\WHAT THE TECH.URL
[2011/10/22 21:33:29 | 000,017,191 | —- | M] () – C:\Users\Jim\Desktop\USNAAA SACTO DUES.ods
[2011/10/22 08:34:37 | 000,002,479 | —- | M] () – C:\Users\Jim\Desktop\HiJackThis.lnk
[2011/10/21 23:37:34 | 000,002,035 | —- | M] () – C:\Users\Public\Desktop\Google Earth.lnk
[2011/10/21 20:55:01 | 000,000,402 | —- | M] () – C:\Windows\tasks\WebUpdate.job
[2011/10/21 10:54:06 | 000,000,084 | —- | M] () – C:\Users\Jim\Desktop\RC Willey - My Account.URL
[2011/10/21 10:28:49 | 000,000,998 | —- | M] () – C:\Users\Public\Desktop\Quick Care.lnk
[2011/10/21 10:28:48 | 000,001,000 | —- | M] () – C:\Users\Jim\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced SystemCare 4.lnk
[2011/10/21 10:28:48 | 000,000,976 | —- | M] () – C:\Users\Public\Desktop\Advanced SystemCare 4.lnk
[2011/10/20 23:51:37 | 038,808,920 | —- | M] (Microsoft Corporation) – C:\Users\Jim\Desktop\FileFormatConverters.exe
[2011/10/20 00:41:14 | 000,000,046 | —- | M] () – C:\Windows\System32\_WKERNEL.FRE
[2011/10/19 20:52:28 | 000,000,085 | —- | M] () – C:\Users\Jim\Desktop\USAA.URL
[2011/10/19 13:11:22 | 000,001,019 | —- | M] () – C:\Users\Jim\Desktop\Revo Uninstaller.lnk
[2011/10/19 13:09:28 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/10/19 13:09:27 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/10/19 13:09:24 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2011/10/19 13:09:14 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2011/10/19 13:07:09 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/10/19 13:06:39 | 000,000,832 | —- | M] () – C:\Users\Jim\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/10/19 12:36:09 | 000,000,308 | —- | M] () – C:\Windows\tasks\GlaryInitialize.job
[2011/10/18 16:30:41 | 000,000,727 | —- | M] () – C:\Users\Public\Desktop\WinUtilities.lnk
[2011/10/18 08:15:37 | 000,000,193 | —- | M] () – C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2011/10/17 08:42:42 | 000,000,380 | —- | M] () – C:\Windows\tasks\SmartDefrag.job
[2011/10/17 08:39:22 | 000,339,584 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/10/15 11:53:10 | 000,012,036 | —- | M] () – C:\Users\Jim\Documents\111115 McClintock ltr.odt
[2011/10/11 16:33:24 | 000,051,144 | —- | M] (Soluto LTD.) – C:\Windows\System32\drivers\Soluto.sys
[2011/10/07 21:18:42 | 000,018,737 | —- | M] () – C:\Users\Jim\Desktop\FINRA CASE LOG.ods
[2011/10/05 16:43:53 | 005,356,304 | —- | M] (PC Cleaners) – C:\Windows\uninst.exe
[2011/10/05 11:08:30 | 000,000,849 | —- | M] () – C:\Users\Jim\Application Data\Microsoft\Internet Explorer\Quick Launch\Glary Utilities.lnk
[2011/10/04 23:28:24 | 000,000,881 | —- | M] () – C:\Users\Jim\Application Data\Microsoft\Internet Explorer\Quick Launch\Holdem Indicator.lnk
[2011/10/04 23:28:24 | 000,000,857 | —- | M] () – C:\Users\Jim\Desktop\Holdem Indicator.lnk
[2011/10/04 10:02:04 | 000,001,996 | —- | M] () – C:\Users\Jim\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/10/04 00:12:03 | 000,010,853 | —- | M] () – C:\Users\Jim\Desktop\ENVELOPE.odt
[2011/10/02 00:38:19 | 000,000,058 | —- | M] () – C:\Users\Jim\Desktop\SF Giants and Football.URL
[2011/09/29 00:30:35 | 001,359,824 | —- | M] () – C:\Users\Jim\Desktop\pc-decrapifier-2.2.8.exe
[2011/09/27 23:26:56 | 000,000,750 | —- | M] () – C:\Users\Jim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FreeClip.lnk
[2011/09/27 10:29:36 | 000,006,796 | —- | M] () – C:\Users\Jim\Documents\ALLO CATION 1012.ods

========== Files Created - No Company Name ==========

[2011/10/25 11:48:26 | 000,014,678 | —- | C] () – C:\Users\Jim\Desktop\help
[2011/10/25 11:44:16 | 000,022,276 | —- | C] () – C:\Users\Jim\Desktop\online-scanner
[2011/10/25 11:16:06 | 000,000,868 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/10/25 09:51:10 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2011/10/25 09:51:10 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2011/10/25 09:51:10 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/10/25 09:51:10 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/10/25 09:51:10 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/10/25 09:32:41 | 001,545,338 | —- | C] () – C:\Users\Jim\Desktop\tdsskiller.zip
[2011/10/24 22:07:30 | 000,038,765 | —- | C] () – C:\Users\Jim\Desktop\tdsskiller.exe
[2011/10/24 09:36:50 | 000,000,065 | —- | C] () – C:\Users\Jim\Desktop\After Battery.URL
[2011/10/23 00:00:43 | 000,000,083 | —- | C] () – C:\Users\Jim\Desktop\WHAT THE TECH.URL
[2011/10/21 23:37:34 | 000,002,035 | —- | C] () – C:\Users\Public\Desktop\Google Earth.lnk
[2011/10/19 20:52:28 | 000,000,085 | —- | C] () – C:\Users\Jim\Desktop\USAA.URL
[2011/10/19 11:14:52 | 000,000,933 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ninite Updater.lnk
[2011/10/16 20:15:07 | 3084,042,240 | -HS- | C] () – C:\hiberfil.sys
[2011/10/15 11:19:55 | 000,012,036 | —- | C] () – C:\Users\Jim\Documents\111115 McClintock ltr.odt
[2011/10/05 11:08:30 | 000,000,849 | —- | C] () – C:\Users\Jim\Application Data\Microsoft\Internet Explorer\Quick Launch\Glary Utilities.lnk
[2011/10/03 00:19:33 | 000,000,881 | —- | C] () – C:\Users\Jim\Application Data\Microsoft\Internet Explorer\Quick Launch\Holdem Indicator.lnk
[2011/10/03 00:19:33 | 000,000,857 | —- | C] () – C:\Users\Jim\Desktop\Holdem Indicator.lnk
[2011/10/02 00:38:19 | 000,000,058 | —- | C] () – C:\Users\Jim\Desktop\SF Giants and Football.URL
[2011/09/29 00:30:27 | 001,359,824 | —- | C] () – C:\Users\Jim\Desktop\pc-decrapifier-2.2.8.exe
[2011/09/27 23:26:56 | 000,000,726 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeClip.lnk
[2011/09/27 10:29:36 | 000,006,796 | —- | C] () – C:\Users\Jim\Documents\ALLO CATION 1012.ods
[2011/09/08 11:31:11 | 000,000,193 | —- | C] () – C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2011/09/06 00:40:21 | 000,000,064 | —- | C] () – C:\Windows\System32\rp_stats.dat
[2011/09/06 00:40:21 | 000,000,044 | —- | C] () – C:\Windows\System32\rp_rules.dat
[2011/07/08 15:54:15 | 000,102,912 | —- | C] () – C:\Windows\System32\EasyHook64.dll
[2011/07/08 15:54:15 | 000,084,480 | —- | C] () – C:\Windows\System32\EasyHook32.dll
[2011/05/21 08:12:34 | 000,004,984 | —- | C] () – C:\Windows\System32\drivers\nvphy.bin
[2011/05/11 01:34:36 | 000,101,230 | —- | C] () – C:\Program Files\frname.xml
[2011/05/04 19:05:08 | 000,000,207 | —- | C] () – C:\Program Files\pokerclient.ini
[2011/04/01 00:40:18 | 000,029,520 | —- | C] () – C:\Windows\System32\SmartDefragBootTime.exe
[2011/04/01 00:40:18 | 000,016,184 | —- | C] () – C:\Windows\System32\drivers\SmartDefragDriver.sys
[2011/01/01 01:59:39 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/10/09 21:50:52 | 000,000,272 | —- | C] () – C:\Windows\SysMech.INI
[2010/08/27 22:15:59 | 000,000,109 | —- | C] () – C:\ProgramData\avalon2.2.ini
[2010/06/30 21:53:49 | 000,074,703 | —- | C] () – C:\Windows\System32\mfc45.dll
[2010/06/18 01:47:05 | 000,002,560 | —- | C] () – C:\Windows\_MSRSTRT.EXE
[2010/06/04 20:26:08 | 000,413,696 | —- | C] () – C:\Windows\System32\lxbkutil.dll
[2010/06/04 20:26:08 | 000,274,432 | —- | C] () – C:\Windows\System32\LXBKinst.dll
[2010/06/04 00:22:33 | 000,115,369 | —- | C] () – C:\Windows\System32\drivers\klin.dat
[2010/06/04 00:22:33 | 000,097,961 | —- | C] () – C:\Windows\System32\drivers\klick.dat
[2010/05/21 22:31:03 | 000,000,197 | —- | C] () – C:\Windows\ODBCINST.INI
[2010/04/17 22:19:23 | 000,219,136 | —- | C] () – C:\Windows\System32\sqlite3_engine.dll
[2010/02/13 21:48:21 | 000,000,046 | —- | C] () – C:\Windows\System32\DonationCoder_findrunrobot_InstallInfo.dat
[2010/02/13 21:48:21 | 000,000,046 | —- | C] () – C:\Users\Jim\AppData\Local\DonationCoder_findrunrobot_InstallInfo.dat
[2009/11/26 13:47:52 | 000,000,032 | —- | C] () – C:\Windows\wwwbatch.ini
[2009/10/08 23:14:56 | 000,000,060 | —- | C] () – C:\Windows\mhses.dat
[2009/09/09 18:01:40 | 000,027,675 | —- | C] () – C:\Windows\System32\drivers\klopp.dat
[2009/08/26 00:14:28 | 000,000,063 | —- | C] () – C:\Windows\wininit.ini
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\Windows\System32\OGAEXEC.exe
[2009/07/17 22:04:25 | 000,016,432 | —- | C] () – C:\Windows\System32\lsdelete.exe
[2009/07/03 22:08:37 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2009/06/07 15:42:59 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/06/07 15:42:31 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/05/03 16:13:28 | 000,000,120 | —- | C] () – C:\Windows\QUICKEN.INI
[2009/04/24 23:04:14 | 000,107,547 | —- | C] () – C:\Windows\System32\drivers\klin(730).dat
[2009/04/24 23:04:14 | 000,095,259 | —- | C] () – C:\Windows\System32\drivers\klick(729).dat
[2009/04/24 23:03:14 | 001,794,080 | -HS- | C] () – C:\Windows\System32\drivers\fidbox2.dat
[2009/04/24 23:03:14 | 001,679,392 | -HS- | C] () – C:\Windows\System32\drivers\fidbox2(28).dat
[2009/04/24 23:03:14 | 001,581,088 | -HS- | C] () – C:\Windows\System32\drivers\fidbox2(369).dat
[2009/04/24 23:03:14 | 001,482,784 | -HS- | C] () – C:\Windows\System32\drivers\fidbox2(161).dat
[2009/04/24 23:03:14 | 001,466,400 | -HS- | C] () – C:\Windows\System32\drivers\fidbox2(77).dat
[2009/04/24 23:03:14 | 001,433,632 | -HS- | C] () – C:\Windows\System32\drivers\fidbox2(335).dat
[2009/04/24 23:03:14 | 001,376,288 | -HS- | C] () – C:\Windows\System32\drivers\fidbox2(157).dat
[2009/04/24 23:03:14 | 001,359,904 | -HS- | C] () – C:\Windows\System32\drivers\fidbox2(108).dat
[2009/04/24 23:03:14 | 001,171,488 | -HS- | C] () – C:\Windows\System32\drivers\fidbox2(727).dat
[2009/04/24 23:03:14 | 001,146,912 | -HS- | C] () – C:\Windows\System32\drivers\fidbox2(156).dat
[2009/04/24 23:03:14 | 000,802,848 | -HS- | C] () – C:\Windows\System32\drivers\fidbox2(26).dat
[2009/04/24 23:03:14 | 000,753,696 | -HS- | C] () – C:\Windows\System32\drivers\fidbox2(184).dat
[2009/04/24 23:03:14 | 000,409,632 | -HS- | C] () – C:\Windows\System32\drivers\fidbox2(56).dat
[2009/04/22 16:23:24 | 000,007,168 | —- | C] () – C:\Users\Jim\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/21 23:56:18 | 000,219,136 | —- | C] () – C:\Windows\sqlite3_engine.dll
[2009/04/20 08:43:00 | 026,553,888 | —- | C] () – C:\Windows\System32\drivers\fidbox.dat
[2009/04/20 08:43:00 | 026,353,184 | —- | C] () – C:\Windows\System32\drivers\fidbox(367).dat
[2009/04/20 08:43:00 | 026,353,184 | —- | C] () – C:\Windows\System32\drivers\fidbox(27).dat
[2009/04/20 08:43:00 | 025,844,256 | —- | C] () – C:\Windows\System32\drivers\fidbox(159).dat
[2009/04/20 08:43:00 | 025,833,504 | —- | C] () – C:\Windows\System32\drivers\fidbox(75).dat
[2009/04/20 08:43:00 | 022,267,424 | —- | C] () – C:\Windows\System32\drivers\fidbox(333).dat
[2009/04/20 08:43:00 | 022,263,840 | —- | C] () – C:\Windows\System32\drivers\fidbox(155).dat
[2009/04/20 08:43:00 | 022,235,168 | —- | C] () – C:\Windows\System32\drivers\fidbox(107).dat
[2009/04/20 08:43:00 | 014,343,200 | —- | C] () – C:\Windows\System32\drivers\fidbox(725).dat
[2009/04/20 08:43:00 | 014,307,360 | —- | C] () – C:\Windows\System32\drivers\fidbox(154).dat
[2009/04/20 08:43:00 | 013,522,464 | —- | C] () – C:\Windows\System32\drivers\fidbox(25).dat
[2009/04/20 08:43:00 | 013,515,296 | —- | C] () – C:\Windows\System32\drivers\fidbox(182).dat
[2009/04/20 08:43:00 | 012,400,672 | -HS- | C] () – C:\Windows\System32\drivers\fidbox(55).dat
[2009/04/19 23:28:56 | 000,003,580 | —- | C] () – C:\Users\Jim\AppData\Roaming\wklnhst.dat
[2009/04/19 18:37:17 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2009/04/19 15:38:11 | 000,001,356 | —- | C] () – C:\Users\Jim\AppData\Local\d3d9caps.dat
[2009/04/19 15:23:02 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/04/19 15:08:17 | 000,000,400 | —- | C] () – C:\Windows\Lexstat.ini
[2008/11/06 17:42:45 | 000,107,357 | —- | C] () – C:\Windows\hpqins13.dat
[2008/11/06 17:21:21 | 000,327,680 | —- | C] () – C:\Windows\System32\pythoncom25.dll
[2008/11/06 17:21:21 | 000,102,400 | —- | C] () – C:\Windows\System32\pywintypes25.dll
[2007/02/07 18:57:50 | 000,039,899 | —- | C] () – C:\Windows\System32\rtsicis.ini
[2007/01/22 08:49:34 | 000,344,064 | —- | C] () – C:\Windows\System32\lxbkcoin.dll
[2006/11/02 05:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 05:47:37 | 000,339,584 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 05:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:33:01 | 000,600,122 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 03:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 03:33:01 | 000,102,020 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 03:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 03:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 01:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 01:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 00:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 00:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2005/10/05 12:19:32 | 000,040,960 | —- | C] () – C:\Windows\System32\lxbkvs.dll
[2005/09/13 17:27:10 | 000,061,440 | —- | C] () – C:\Windows\System32\lxbkcnv5.dll
[2005/09/13 16:27:10 | 000,061,440 | —- | C] () – C:\Windows\System32\lxbkcnv4.dll

========== Files - Unicode (All) ==========
[2010/07/28 10:24:30 | 000,000,177 | —- | M] ()(C:\Users\Jim\Desktop\FINRA Education ? Sites ? Catalog ? Search Results.URL) – C:\Users\Jim\Desktop\FINRA Education → Sites → Catalog → Search Results.URL
[2010/07/28 10:24:30 | 000,000,177 | —- | C] ()(C:\Users\Jim\Desktop\FINRA Education ? Sites ? Catalog ? Search Results.URL) – C:\Users\Jim\Desktop\FINRA Education → Sites → Catalog → Search Results.URL

========== Alternate Data Streams ==========

@Alternate Data Stream - 81 bytes -> C:\Program Files\Cake Poker 2.0:MID
@Alternate Data Stream - 8 bytes -> C:\WINDOWS:
@Alternate Data Stream - 378 bytes -> C:\Windows\System32\drivers\brnewddh.sys:changelist
@Alternate Data Stream - 260 bytes -> C:\ProgramData\TEMP:010ADD2C
@Alternate Data Stream - 256 bytes -> C:\ProgramData\TEMP:2B11E0DF
@Alternate Data Stream - 252 bytes -> C:\ProgramData\TEMP:553CA6CA
@Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:E138854D
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:56E2E879

< End of report >
You could ask in our windows forum about the genuine windows message.

http://forums.whatthetech.com/index.php?showforum=119


You appear clean of infections,please do the following.



ComboFix - Cleanup
Time for some housekeeping
  • Click Start…select Run from the menu.
  • Copy and paste the following into the text entry box:
    Combofix /Uninstall
  • Click the OK button. (See image below as reference.)
🖼Click to load external image (Posted Image)









Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.











Download TFC to your desktop

Close any open windows.
Double click the TFC icon to run the program
TFC will close all open programs itself in order to run,
Click the Start button to begin the process.
Allow TFC to run uninterrupted.
The program should not take long to finish it's job
Once its finished it should automatically reboot your machine,
if it doesn't, manually reboot to ensure a complete clean







Here are some recommendations to help you stay clean.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Visit Microsoft often to get the latest updates for your computer.
http://www.update.microsoft.com/



Make sure you are running a FIREWALL.The windows firewall is not sufficient to protect your system. It doesn't monitor outgoing traffic and this is a must.
Please read this article 'Safe Computing Practices'.
So how did I get infected in the first place.

please take a moment to read quietman7's excellent prevention tips in post 3 here
Click >>>> Tips to protect yourself against malware and reduce the potential for re-infection:

Preventing Infections in the Future

Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

  • Avoid gaming sites, underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users. The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications. Read P2P Software User Advisories and Risks of File-Sharing Technology.

Update Non-Microsoft Programs

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.


Thats it you are good to go.Safe surfing
OK, I got the final cleanup done. Thanks for all your help and for the added advice. I'll pursue the verification process separately, as you suggested.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI