This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Possible Trojan Infection

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Following my original post at Whatthetech's Browsers Thread I was prompted to follow a guide that led to my posting here.

To summarize, I recently found out that all my browsers (Chrome, Firefox, and even IE) keep crashing unexpectedly. Chrome takes a while to crash while Firefox crashes almost 1-2 minutes after opened.

I initally ran a Microsoft Safety Scanner upon which it removed 1 Trojan and then a Bit Defender's Deep System Scan which states all system are clean.

I, then, ran another Microsoft Safety Scanner and it removed another Trojan which led to my belief that the Trojan still exists somewhere in my system.

So I followed the steps that you have kindly provided and used the OTL scanner.

Here are my OTL.txt and Extras.txt from the OTL scan:


OTL.TXT


OTL logfile created on: 3/1/2012 1:04:55 PM - Run 1
OTL by OldTimer - Version 3.2.34.0 Folder = E:\Downloads
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

5.99 Gb Total Physical Memory | 3.45 Gb Available Physical Memory | 57.59% Memory free
11.98 Gb Paging File | 8.35 Gb Available in Paging File | 69.67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 279.46 Gb Total Space | 155.62 Gb Free Space | 55.69% Space Free | Partition Type: NTFS
Drive E: | 931.51 Gb Total Space | 337.91 Gb Free Space | 36.28% Space Free | Partition Type: NTFS

Computer Name: HANSLEY-PC | User Name: sly | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - E:\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla\Mozilla Thunderbird\thunderbird.exe (Mozilla Messaging)
PRC - C:\Users\sly\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
PRC - C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
PRC - C:\Program Files\BitDefender\BitDefender 2011\Antispam32\pchooklaunch32.exe (BitDefender S.R.L.)
PRC - C:\Program Files\BitDefender\BitDefender 2011\Antispam32\bdimguiaux.exe (BitDefender S.R.L.)
PRC - C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
PRC - C:\Program Files (x86)\Logitech\Vid HD\Vid.exe (Logitech Inc.)
PRC - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files (x86)\Pidgin\pidgin.exe (The Pidgin developer community)
PRC - C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
PRC - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
PRC - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Drivers\Logitech\SetPoint\x86\SetPoint32.exe ()
PRC - C:\Program Files (x86)\Drivers\LG Soft India\forteManager\bin\Monitor.exe ()
PRC - C:\Program Files\ASUS\Six Engine\SixEngine.exe ()
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files (x86)\LaCie\Genie Backup Assistant\GBMAgent.exe (Genie-soft)
PRC - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.00\AsSysCtrlService.exe ()
PRC - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
PRC - C:\Users\sly\AppData\Roaming\Google\Google Talk\googletalk.exe (Google)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Mozilla\Mozilla Thunderbird\mozjs.dll ()
MOD - C:\Program Files (x86)\Mozilla\Mozilla Thunderbird\nsldap32v60.dll ()
MOD - C:\Program Files (x86)\Mozilla\Mozilla Thunderbird\nsldappr32v60.dll ()
MOD - C:\Users\sly\AppData\Local\Google\Chrome\Application\17.0.963.56\ppGoogleNaClPluginChrome.dll ()
MOD - C:\Users\sly\AppData\Local\Google\Chrome\Application\17.0.963.56\pdf.dll ()
MOD - C:\Users\sly\AppData\Local\Google\Chrome\Application\17.0.963.56\avutil-51.dll ()
MOD - C:\Users\sly\AppData\Local\Google\Chrome\Application\17.0.963.56\avformat-53.dll ()
MOD - C:\Users\sly\AppData\Local\Google\Chrome\Application\17.0.963.56\avcodec-53.dll ()
MOD - C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\BitDefender\BitDefender 2011\Antispam32\txmlutil.dll ()
MOD - C:\Program Files\BitDefender\BitDefender 2011\Antispam32\framework.dll ()
MOD - C:\Program Files\BitDefender\BitDefender 2011\Antispam32\connector.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\vpxmd.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\SDL.dll ()
MOD - C:\Program Files (x86)\Pidgin\Gtk\bin\libcairo-2.dll ()
MOD - C:\Program Files (x86)\Pidgin\Gtk\bin\libgio-2.0-0.dll ()
MOD - C:\Program Files (x86)\Pidgin\Gtk\bin\libfontconfig-1.dll ()
MOD - C:\Program Files (x86)\Pidgin\Gtk\bin\libpng14-14.dll ()
MOD - C:\Program Files (x86)\Pidgin\Gtk\bin\libexpat-1.dll ()
MOD - C:\Program Files (x86)\Pidgin\Gtk\bin\libpangocairo-1.0-0.dll ()
MOD - C:\Program Files (x86)\Pidgin\Gtk\lib\gtk-2.0\2.10.0\engines\libwimp.dll ()
MOD - C:\Program Files (x86)\Pidgin\Gtk\bin\zlib1.dll ()
MOD - C:\Program Files (x86)\Pidgin\Gtk\bin\freetype6.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\spellchk.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\xmppdisco.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\xmppconsole.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\ticker.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\win2ktrans.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\winprefs.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\ssl-nss.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\timestamp_format.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\timestamp.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\sendbutton.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\statenotify.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\relnot.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\ssl.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libmsn.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libqq.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libgg.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libsilc.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libmxit.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libsametime.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libmyspace.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libnovell.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libirc.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libbonjour.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libsimple.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\log_reader.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\pidginrc.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\notify.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libyahoo.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libxmpp.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libyahoojp.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\markerline.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\offlinemsg.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libicq.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\psychic.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\newline.dll ()
MOD - C:\Program Files (x86)\Pidgin\libjabber.dll ()
MOD - C:\Program Files (x86)\Pidgin\liboscar.dll ()
MOD - C:\Program Files (x86)\Pidgin\libymsg.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\convcolors.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\history.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\autoaccept.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\joinpart.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\idle.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\extplacement.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libaim.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\gtkbuddynote.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\buddynote.dll ()
MOD - C:\Program Files (x86)\Pidgin\idletrack.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\iconaway.dll ()
MOD - C:\Program Files (x86)\Pidgin\exchndl.dll ()
MOD - C:\Program Files (x86)\Pidgin\spellcheck\libgtkspell-0.dll ()
MOD - C:\Program Files (x86)\Pidgin\sqlite3.dll ()
MOD - C:\Program Files (x86)\Pidgin\libsilc-1-1-2.dll ()
MOD - C:\Program Files (x86)\Pidgin\libsilcclient-1-1-2.dll ()
MOD - C:\Program Files (x86)\Pidgin\libmeanwhile-1.dll ()
MOD - C:\Program Files (x86)\Pidgin\libxml2-2.dll ()
MOD - C:\Program Files (x86)\Yahoo!\Messenger\yui.dll ()
MOD - C:\Program Files (x86)\Logitech\LWS\Webcam Software\ImageFormats\QJpeg4.dll ()
MOD - C:\Program Files (x86)\Logitech\LWS\Webcam Software\ImageFormats\QGif4.dll ()
MOD - C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTXml4.dll ()
MOD - C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTGui4.dll ()
MOD - C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTCore4.dll ()
MOD - C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Program Files (x86)\Pidgin\libjson-glib-1.0.dll ()
MOD - C:\Program Files (x86)\Drivers\Logitech\SetPoint\x86\SetPoint32.exe ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\QtNetwork4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\QtCore4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\plugins\imageformats\qjpeg4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\plugins\imageformats\qico4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\plugins\imageformats\qgif4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\QtWebKit4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\QtXml4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\QtSql4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\QtOpenGL4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\QtGui4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\phonon4.dll ()
MOD - C:\Program Files (x86)\Drivers\LG Soft India\forteManager\bin\Monitor.exe ()
MOD - C:\Program Files (x86)\Drivers\LG Soft India\forteManager\bin\MonitorEngRes.dll ()
MOD - C:\Program Files (x86)\Drivers\LG Soft India\forteManager\bin\ApplicationManager.dll ()
MOD - C:\Program Files (x86)\Drivers\LG Soft India\forteManager\bin\ACRHook.dll ()
MOD - C:\Program Files (x86)\Drivers\LG Soft India\forteManager\bin\ProtocolEngine.dll ()
MOD - C:\Program Files (x86)\Drivers\LG Soft India\forteManager\bin\DeviceManager.dll ()
MOD - C:\Program Files (x86)\Drivers\LG Soft India\forteManager\bin\ErrorHandler.dll ()
MOD - C:\Program Files\ASUS\Six Engine\SixEngine.exe ()
MOD - C:\Program Files\ASUS\Six Engine\AsSpindownTimeout.dll ()
MOD - C:\Program Files (x86)\LaCie\Genie Backup Assistant\gs_encryption.dll ()
MOD - C:\Program Files (x86)\LaCie\Genie Backup Assistant\GSLogging.dll ()
MOD - C:\Windows\SysWOW64\AsIO.dll ()
MOD - C:\Program Files\ASUS\Six Engine\pngio.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (TabletServiceWacom) – C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe (Wacom Technology, Corp.)
SRV:64bit: - (Updatesrv) – C:\Program Files\BitDefender\BitDefender 2011\updatesrv.exe (BitDefender S.R.L.)
SRV:64bit: - (VSSERV) – C:\Program Files\BitDefender\BitDefender 2011\vsserv.exe (BitDefender S.R.L.)
SRV:64bit: - (Update Server) – C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe (BitDefender)
SRV:64bit: - (Diskeeper) – C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe (Diskeeper Corporation)
SRV:64bit: - (LBTServ) – C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (Akamai) – c:\program files (x86)\common files\akamai/netsession_win_7de0ed9.dll ()
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (UMVPFSrv) – C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SwitchBoard) – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (getPlusHelper) getPlus® – C:\Program Files (x86)\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (HPSLPSVC) – C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL (Hewlett-Packard Co.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (AsSysCtrlService) – C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.00\AsSysCtrlService.exe ()
SRV - (PSI_SVC_2) – c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (LVUVC64) Logitech HD Pro Webcam C910(UVC) – C:\Windows\SysNative\drivers\lvuvc64.sys (Logitech Inc.)
DRV:64bit: - (LVRS64) – C:\Windows\SysNative\drivers\lvrs64.sys (Logitech Inc.)
DRV:64bit: - (CompFilter64) – C:\Windows\SysNative\drivers\lvbflt64.sys (Logitech Inc.)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (bdfsfltr) – C:\Windows\SysNative\drivers\bdfsfltr.sys (BitDefender)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (RimUsb) – C:\Windows\SysNative\drivers\RimUsb_AMD64.sys (Research In Motion Limited)
DRV:64bit: - (avckf) – C:\Windows\SysNative\drivers\avckf.sys (BitDefender)
DRV:64bit: - (avc3) – C:\Windows\SysNative\drivers\avc3.sys (BitDefender)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (wacmoumonitor) – C:\Windows\SysNative\drivers\wacmoumonitor.sys (Wacom Technology)
DRV:64bit: - (bdfwfpf) – C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdfwfpf.sys (BitDefender)
DRV:64bit: - (Bdfndisf) – c:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdfndisf6.sys (BitDefender)
DRV:64bit: - (ivusb) – C:\Windows\SysNative\drivers\ivusb.sys (Initio Corporation)
DRV:64bit: - (bdfm) – C:\Windows\SysNative\drivers\bdfm.sys (BitDefender S.R.L. Bucharest, ROMANIA)
DRV:64bit: - (LVPr2Mon) – C:\Windows\SysNative\drivers\LVPr2M64.sys ()
DRV:64bit: - (LVPr2M64) – C:\Windows\SysNative\drivers\LVPr2M64.sys ()
DRV:64bit: - (adfs) – C:\Windows\SysNative\drivers\adfs.sys (Adobe Systems, Inc.)
DRV:64bit: - (Bdvedisk) – C:\Windows\SysNative\drivers\bdvedisk.sys (BitDefender)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (sptd) – C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (DKRtWrt) – C:\Windows\SysNative\drivers\DKRtWrt.sys (Diskeeper Corporation)
DRV:64bit: - (wacomvhid) – C:\Windows\SysNative\drivers\wacomvhid.sys (Wacom Technology)
DRV:64bit: - (netr28ux) – C:\Windows\SysNative\drivers\netr28ux.sys (Ralink Technology Corp.)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ROOTMODEM) – C:\Windows\SysNative\drivers\rootmdm.sys (Microsoft Corporation)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (LMouFilt) – C:\Windows\SysNative\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LHidFilt) – C:\Windows\SysNative\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (KMWDFILTER) – C:\Windows\SysNative\drivers\KMWDFILTER.sys (Windows ® Codename Longhorn DDK provider)
DRV:64bit: - (RimVSerPort) – C:\Windows\SysNative\drivers\RimSerial_AMD64.sys (Research in Motion Ltd)
DRV:64bit: - (JRAID) – C:\Windows\SysNative\drivers\jraid.sys (JMicron Technology Corp.)
DRV:64bit: - (RTL8169) – C:\Windows\SysNative\drivers\Rtlh64.sys (Realtek Corporation )
DRV:64bit: - (wacommousefilter) – C:\Windows\SysNative\drivers\wacommousefilter.sys (Wacom Technology)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (LGII2CDevice) – C:\Program Files (x86)\Drivers\LG Soft India\forteManager\bin\PII2CDriver.sys ()
DRV - (LGDDCDevice) – C:\Program Files (x86)\Drivers\LG Soft India\forteManager\bin\I2CDriver.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = FC B1 F2 F6 6B 40 CA 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {3DEA5FE7-8C23-4836-9427-C0B06DAE5DC8}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{3DEA5FE7-8C23-4836-9427-C0B06DAE5DC8}: "URL" = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={sear
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;127.0.0.1:9421;

========== FireFox ==========

FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1
FF - prefs.js..extensions.enabledItems: 6
FF - prefs.js..extensions.enabledItems: 2
FF - prefs.js..extensions.enabledItems: 48
FF - prefs.js..extensions.enabledItems: [removed]:2.0
FF - prefs.js..extensions.enabledItems: cfxHelper@Triton:1.2
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.8
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.4
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0.2
FF - prefs.js..extensions.enabledItems: [removed]:4.1.8
FF - prefs.js..extensions.enabledItems: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:[removed]
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {01A8CA0A-4C96-465b-A49B-65C46FAD54F9}:6.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:3.6.5
FF - prefs.js..extensions.enabledItems: cfxe@Triton:3.6.5


FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.102.0: C:\Program Files (x86)\Battlelog Web Plugins\1.102.0\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.10: C:\Program Files (x86)\TabletPlugins\npwacom.dll (Wacom, Inc.)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.3: C:\Program Files (x86)\TabletPlugins\npwacom.dll (Wacom, Inc.)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.5: C:\Program Files (x86)\TabletPlugins\npwacom.dll (Wacom, Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\sly\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\sly\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\PROGRAM FILES\BITDEFENDER\BITDEFENDER 2011\BDAPHFFEXT\ [2011/12/23 10:00:21 | 000,000,000 | —D | M]
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[removed]: C:\PROGRAM FILES\BITDEFENDER\BITDEFENDER 2011\BDTBEXT\ [2011/12/23 10:00:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\BitDefender\BitDefender 2011\bdaphffext\ [2011/12/23 10:00:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2009/12/20 02:24:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}: C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2012/01/09 22:56:31 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012/01/09 22:58:23 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla\Mozilla Firefox\components [2012/02/19 23:48:27 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins [2012/01/31 13:43:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla\Mozilla Thunderbird\components [2012/02/20 15:08:38 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla\Mozilla Thunderbird\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\BitDefender\BitDefender 2011\bdtbext\ [2011/12/23 10:00:21 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2009/12/20 02:24:08 | 000,000,000 | —D | M]

[2010/09/02 23:25:57 | 000,000,000 | —D | M] (No name found) – C:\Users\sly\AppData\Roaming\mozilla\Extensions
[2010/09/02 23:25:57 | 000,000,000 | —D | M] (No name found) – C:\Users\sly\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012/02/29 23:45:45 | 000,000,000 | —D | M] (No name found) – C:\Users\sly\AppData\Roaming\mozilla\Firefox\Profiles\ks3zdvup.default\extensions
[2010/05/01 15:01:32 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\sly\AppData\Roaming\mozilla\Firefox\Profiles\ks3zdvup.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/02/16 18:36:21 | 000,000,000 | —D | M] (FT SleekDark) – C:\Users\sly\AppData\Roaming\mozilla\Firefox\Profiles\ks3zdvup.default\extensions\{a21cd440-41d6-11e0-9207-0800200c9a66}
[2011/12/25 10:57:04 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\sly\AppData\Roaming\mozilla\Firefox\Profiles\ks3zdvup.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2009/10/29 16:56:48 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Users\sly\AppData\Roaming\mozilla\Firefox\Profiles\ks3zdvup.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2010/05/12 12:33:56 | 000,000,000 | —D | M] (Chromifox Extreme) – C:\Users\sly\AppData\Roaming\mozilla\Firefox\Profiles\ks3zdvup.default\extensions\cfxe@Triton
[2010/05/12 12:34:01 | 000,000,000 | —D | M] (Chromifox Companion) – C:\Users\sly\AppData\Roaming\mozilla\Firefox\Profiles\ks3zdvup.default\extensions\cfxHelper@Triton
[2010/03/09 01:49:18 | 000,000,000 | —D | M] (Chromifox Basic) – C:\Users\sly\AppData\Roaming\mozilla\Firefox\Profiles\ks3zdvup.default\extensions\[removed]
[2012/02/29 23:45:27 | 000,000,000 | —D | M] (Java Console) – C:\PROGRAM FILES (X86)\MOZILLA\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
() (No name found) – C:\USERS\SLY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KS3ZDVUP.DEFAULT\EXTENSIONS\{19503E42-CA3C-4C27-B1E2-9CDB2170EE34}.XPI
() (No name found) – C:\USERS\SLY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KS3ZDVUP.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\USERS\SLY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KS3ZDVUP.DEFAULT\EXTENSIONS\{D4DD63FA-01E4-46A7-B6B1-EDAB7D6AD389}.XPI
() (No name found) – C:\USERS\SLY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KS3ZDVUP.DEFAULT\EXTENSIONS\{DDC359D1-844A-42A7-9AA1-88A850A938A8}.XPI
() (No name found) – C:\USERS\SLY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KS3ZDVUP.DEFAULT\EXTENSIONS\[removed]

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\sly\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\sly\AppData\Local\Google\Chrome\Application\17.0.963.56\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\sly\AppData\Local\Google\Chrome\Application\17.0.963.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\sly\AppData\Local\Google\Chrome\Application\17.0.963.56\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Adobe Contribute CS5 (Enabled) = C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins\npContribute.dll
CHR - plugin: Java Deployment Toolkit 6.0.310.5 (Enabled) = C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U31 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: getPlusPlus for Adobe 16248 (Enabled) = C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins\np_gp.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: ESN Launch Mozilla Plugin (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\1.102.0\npesnlaunch.dll
CHR - plugin: ESN Sonar API (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll
CHR - plugin: RIM Handheld Application Loader (Enabled) = C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Wacom Dynamic Link Library (Enabled) = C:\Program Files (x86)\TabletPlugins\npwacom.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Google Update (Enabled) = C:\Users\sly\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\sly\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\sly\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.17_0\
CHR - Extension: Classic Blue Theme = C:\Users\sly\AppData\Local\Google\Chrome\User Data\Default\Extensions\ilkecpolncpdeefgdlnhmmdghkmonfkk\1.2_0\
CHR - Extension: Evernote Web Clipper = C:\Users\sly\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc\5.1.22.1457_0\
CHR - Extension: Gmail = C:\Users\sly\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2011/01/28 12:08:32 | 000,007,354 | R— | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com #192.150.22.22
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com #192.150.14.21
O1 - Hosts: 127.0.0.1 3dns-4.adobe.com #192.150.18.247
O1 - Hosts: 127.0.0.1 3dns-5.adobe.com #192.150.22.46
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com #192.150.11.30
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com #192.150.11.247
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com #192.150.22.30
O1 - Hosts: 127.0.0.1 adobe.activate.com #69.175.22.26
O1 - Hosts: 127.0.0.1 activate.adobe.com #192.150.22.40
O1 - Hosts: 109 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (Bitdefender Toolbar) - {381FFDE8-2394-4F90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2011\ietoolbar.dll (BitDefender S.R.L.)
O3 - HKLM\..\Toolbar: (Bitdefender Toolbar) - {381FFDE8-2394-4F90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2011\Antispam32\ietoolbar.dll (BitDefender S.R.L.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [BDAgent] C:\Program Files\BitDefender\BitDefender 2011\bdagent.exe (BitDefender S.R.L.)
O4:64bit: - HKLM..\Run: [BitDefender Antiphishing Helper] C:\Program Files\BitDefender\BitDefender 2011\ieshow.exe (BitDefender S.R.L.)
O4:64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BitDefender Antiphishing Helper] C:\Program Files\BitDefender\BitDefender 2011\Antispam32\ieshow.exe (BitDefender S.R.L.)
O4 - HKLM..\Run: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKLM..\Run: [RIMBBLaunchAgent.exe] C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\sly\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [GBMLite8AgentLaCie] C:\Program Files (x86)\LaCie\Genie Backup Assistant\GBMAgent.exe (Genie-soft)
O4 - HKCU..\Run: [googletalk] C:\Users\sly\AppData\Roaming\Google\Google Talk\googletalk.exe (Google)
O4 - HKCU..\Run: [Logitech Vid] C:\Program Files (x86)\Logitech\Vid HD\Vid.exe (Logitech Inc.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [taskhost.exe] C:\Users\sly\AppData\Roaming\System\taskhost.exe (Microsoft Corporation)
O4 - HKCU..\Run: [UpgradeChecker] C:\Users\sly\AppData\Roaming\Google Inc.\{87A61807-CF46-4468-8401-E0986FCB271A}\UpgradeChecker.exe (Promise Technology, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000 File not found
O8:64bit: - Extra context menu item: Se&nd; to OneNote - res://C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Se&nd; to OneNote - res://C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105 File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} http://support.asus.com/select/asusTek_sys_ctrl3.cab (asusTek_sysctrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0AB410A2-FBE6-46EC-89B2-BFFB78C867CC}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{113C7E6C-950E-4621-B4EB-E2A87D3B157C}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8503626F-D908-4BC5-9C21-AF42A88C37CF}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F8C1AF6C-2D63-4D3D-A20D-4A000031F19A}: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O24 - Desktop WallPaper: C:\Users\sly\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\sly\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{2c0b70e2-8142-11df-acab-002618360274}\Shell - "" = AutoRun
O33 - MountPoints2\{2c0b70e2-8142-11df-acab-002618360274}\Shell\AutoRun\command - "" = K:\INSTALL.EXE
O33 - MountPoints2\{5604181f-80bf-11e0-9db8-002618360274}\Shell - "" = AutoRun
O33 - MountPoints2\{5604181f-80bf-11e0-9db8-002618360274}\Shell\AutoRun\command - "" = M:\LaunchU3.exe -a
O33 - MountPoints2\{cdf6e30e-d4df-11de-b542-002618360274}\Shell - "" = AutoRun
O33 - MountPoints2\{cdf6e30e-d4df-11de-b542-002618360274}\Shell\AutoRun\command - "" = "K:\Adobe CS5\Set-up.exe"
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.FFDS - ff_vfw.dll ()
Drivers32:64bit: vidc.i420 - lvcod64.dll (Logitech Inc.)
Drivers32: msacm.ac3acm - C:\Windows\SysWow64\ac3acm.acm (fccHandler)
Drivers32: msacm.divxa32 - C:\Windows\SysWow64\divxa32.acm (Kristal StudioDFileDescription)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3fhg - C:\Windows\SysWow64\mp3fhg.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\SysWow64\lameACM.acm (http://www.mp3dev.org/)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.dvsd - C:\Windows\SysWow64\pdvcodec.dll (Matsushita Electric Industrial Co., Ltd.)
Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
Drivers32: VIDC.HFYU - C:\Windows\SysWow64\huffyuv.dll (Disappearing Inc.)
Drivers32: vidc.i263 - C:\Windows\SysWow64\I263_32.drv (Intel Corporation)
Drivers32: vidc.i420 - C:\Windows\SysWow64\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iv41 - C:\Windows\SysWow64\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\Windows\SysWow64\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.VP60 - C:\Windows\SysWow64\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP61 - C:\Windows\SysWow64\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP62 - C:\Windows\SysWow64\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP70 - C:\Windows\SysWow64\vp7vfw.dll (On2.com)
Drivers32: VIDC.X264 - C:\Windows\SysWow64\x264vfw.dll ()
Drivers32: VIDC.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\SysWow64\yv12vfw.dll (www.helixcommunity.org)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/03/01 11:52:11 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Roaming\Google Inc
[2012/03/01 11:34:41 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{CAE59414-BCFE-4144-9E78-33CE034893A7}
[2012/03/01 11:34:30 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{AB2401EA-190B-4FDE-8963-F9138560F1F8}
[2012/03/01 00:46:50 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012/03/01 00:46:46 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2012/02/29 23:45:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2012/02/29 23:45:25 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2012/02/29 23:45:25 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2012/02/29 23:45:25 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2012/02/29 23:33:54 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{971A30D9-E284-410E-98AA-C3DDDAA0DE46}
[2012/02/29 23:33:38 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{BC2319CF-2001-4E36-9B37-2A2E4A3D1420}
[2012/02/29 08:31:31 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{C7536067-4350-40E3-AC5C-81A216DB2FFA}
[2012/02/29 08:31:19 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{C9713318-97F1-4C79-A467-EB79FB5B0F67}
[2012/02/28 22:08:32 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Roaming\Help
[2012/02/28 22:04:23 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Roaming\TeamViewer
[2012/02/28 20:30:53 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{33D234F2-5FD3-4040-8189-72F81207340A}
[2012/02/28 20:30:22 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{A1319534-0AF0-4699-81A7-94518F100241}
[2012/02/27 20:41:35 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{C4CBAA1B-0E22-4914-A960-7D44D282A4AD}
[2012/02/27 20:41:21 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{065F7C43-7000-4074-9CF7-856B757E169F}
[2012/02/27 07:41:49 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{84E60DF3-7B51-417C-AC78-DF4977A5B71E}
[2012/02/27 07:41:30 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{2E090832-0305-434D-8579-47155F6B3E0F}
[2012/02/26 12:26:48 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{4A57A52A-5AC2-4E5F-B9A9-168DE991909B}
[2012/02/26 12:26:19 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{C87F948A-E3E8-44C9-9B06-5C0F88D30CCA}
[2012/02/25 15:37:29 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{175684E2-2717-44FB-A152-5594B342912A}
[2012/02/25 15:37:15 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{0A194CEE-97ED-4EF2-B2E3-B82299768885}
[2012/02/25 00:48:38 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{4E61713D-A907-4BED-B2A3-2C9E797361A1}
[2012/02/25 00:48:24 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{79825E15-DC9C-4E50-8FC3-76F6EED7F96C}
[2012/02/24 07:05:45 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{BDD89A75-1DCE-414A-A2F5-0C30ACB86281}
[2012/02/24 07:05:33 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{398718C1-44A3-40FC-A0D4-94C0E5E9FF3C}
[2012/02/23 18:57:28 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{E0CE8F97-B0C2-4399-A893-F1E8A2C58736}
[2012/02/23 18:57:10 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{045F5F5F-E9D5-4A01-9F81-DC5F1B4EBB66}
[2012/02/22 23:05:30 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{859BE391-7D6D-4ABC-945C-A4A57AE07F82}
[2012/02/22 23:05:16 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{5D118682-2527-43C7-A424-313B3B3A3122}
[2012/02/21 17:45:38 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{01A96671-7D41-4A2F-9680-BA30E1A84093}
[2012/02/21 17:45:24 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{214F46B1-8B65-4CA2-A2BF-06CC2DEE0F74}
[2012/02/20 20:25:08 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{2CBD94CD-B65F-4652-ACD2-7D06FFED2426}
[2012/02/20 08:24:31 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{BEBAC18E-1B2C-461F-81DA-20C0471B4D7B}
[2012/02/20 08:24:15 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{1F5962F4-D7D2-488E-861B-D1205BC337C8}
[2012/02/19 19:55:32 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{ECBB22B8-9AE4-4D60-9054-6C9AF43CEBB4}
[2012/02/19 19:55:21 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{4FEC0536-7B23-469C-9ACF-93ADDBB526C7}
[2012/02/19 07:54:48 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{1C7BF400-4F65-4DEE-BAF9-E215B32B8B6A}
[2012/02/19 07:54:32 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{889E9461-A852-4392-84CB-2E8667D47CEC}
[2012/02/18 13:33:28 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{5245A670-6AE0-4044-8B6A-AC191CA82227}
[2012/02/18 13:33:17 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{0C6A03D5-CC76-401C-ABC3-B660A38A06FB}
[2012/02/18 01:01:24 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{1D50AF74-7F68-471F-A3B8-3090C18789FE}
[2012/02/18 01:01:07 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{20F161F3-DB0C-4041-9C99-D8943410985C}
[2012/02/17 08:48:59 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{70EF22B7-D3B8-443D-BC25-97C0CEA306D9}
[2012/02/17 08:48:26 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{987B3918-5D78-4B32-9463-2A8897359B84}
[2012/02/16 18:04:03 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{6F64E2F2-7262-4CD0-B12B-64B65CEBCD1C}
[2012/02/16 18:03:14 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{89E6E963-5F34-4396-8582-7C4302039F31}
[2012/02/15 18:09:30 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{E330D309-9A52-4D48-AA56-BB6DC8BBCAC4}
[2012/02/15 18:09:12 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{57C1C50D-C7D8-4F2E-8857-CFE58965C4EB}
[2012/02/14 19:54:22 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/02/14 19:54:22 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/02/14 19:54:21 | 002,308,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/02/14 19:54:21 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/02/14 19:54:21 | 000,818,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/02/14 19:54:21 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/02/14 19:54:21 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/02/14 19:54:21 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/02/14 19:54:21 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/02/14 19:54:21 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/02/14 19:54:20 | 001,493,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/02/14 18:08:43 | 000,509,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntshrui.dll
[2012/02/14 18:08:42 | 000,515,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\timedate.cpl
[2012/02/14 18:08:42 | 000,478,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\timedate.cpl
[2012/02/14 18:08:39 | 000,634,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msvcrt.dll
[2012/02/14 18:03:25 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{9A0538DD-4003-45E3-A1CD-E6591E129DE2}
[2012/02/14 18:03:06 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{DABD846F-EEFF-4B36-83A0-7D2ADCBDA58A}
[2012/02/13 22:21:06 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{57FECE42-E21B-47D2-B314-BDDA336CAEFB}
[2012/02/13 22:20:43 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{26C75DBB-ABE1-4B21-B2EE-E145C21FD632}
[2012/02/13 09:15:19 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{A86E0609-FAF2-4962-ACB1-9B19D352D48E}
[2012/02/13 09:15:05 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{14A0188D-9F66-4A64-89BB-0167711D5ECA}
[2012/02/12 10:40:12 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{4EA270CD-DE24-41F0-AE3E-917543D814D9}
[2012/02/12 10:40:00 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{200E6656-7B16-47DF-B555-72DBF0CA1D26}
[2012/02/11 22:39:36 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{589A6C85-52FF-4A79-BF17-0FD6B460BFA2}
[2012/02/11 22:39:19 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{4AAF2A38-51C5-4D0F-86E4-373F46E2A3BB}
[2012/02/11 07:33:27 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{72AC5326-466C-46C8-A7EF-C24633283E27}
[2012/02/11 07:33:11 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{846A1738-02F9-4DD5-A89D-5B5633A5CBDD}
[2012/02/10 15:03:26 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{8E5129DC-CFC1-4B50-BE9B-061E836A1AA9}
[2012/02/10 15:03:05 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{9926D961-4888-4A1A-8E51-18AC522A6D4E}
[2012/02/10 00:14:44 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{D5F5A715-4A3D-4A22-B468-4DB6897A2DA3}
[2012/02/10 00:14:27 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{4C4228D5-BD62-4E0D-B89B-BF9B965F2EE1}
[2012/02/09 07:14:07 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{F80D8C4A-0E44-4775-8896-E7E7083987B8}
[2012/02/09 07:13:35 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{DFABECFC-3F79-42DC-B26F-BD7F4A20B800}
[2012/02/08 17:39:44 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{BE1B4DA1-503E-40B3-B809-4F8A5850B4D3}
[2012/02/08 17:39:26 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{1F98B7A1-94F3-4C98-B48B-500A8A054504}
[2012/02/07 17:48:36 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{22F7537F-383A-4CC0-A15D-B08AD0A8B67F}
[2012/02/07 17:48:21 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{2253ECFB-E112-4F98-AA63-1DF681AFD71D}
[2012/02/06 21:58:43 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{701A4F6E-BD9F-45B9-88E1-EA0E8E67A05E}
[2012/02/06 21:58:21 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{8A633E12-7965-4132-8173-989B89D77F04}
[2012/02/06 21:52:22 | 000,000,000 | —D | C] – C:\ProgramData\bdch
[2012/02/06 20:14:54 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{0A92AB1C-02B3-4FFB-B69B-F645580EDEFE}
[2012/02/06 08:14:28 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{85F1C51F-9DC3-4EED-8E8A-7D568A85D204}
[2012/02/06 08:14:15 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{F588E6B7-6849-48F1-A970-2639BB6C9AF7}
[2012/02/05 12:12:50 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{39176875-37F2-4CE9-8CF1-5A08D7BEBECE}
[2012/02/05 12:12:38 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{69D93C8C-46E1-4307-8C97-48E283A1699A}
[2012/02/05 00:12:13 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{0CD7477B-DD62-497D-B94F-675772293E6A}
[2012/02/05 00:12:01 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{15EF6C68-D7B0-4A68-8AE7-9A3CAFA5C46C}
[2012/02/04 12:11:36 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{5737E8C5-B87E-4218-9EA9-F42886CDEEAE}
[2012/02/04 12:11:24 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{8ED08EDF-6E0F-4081-8910-B4BCEF00FD98}
[2012/02/04 00:10:44 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{088ED07F-6F18-40D9-ABCC-8542CC6DE598}
[2012/02/04 00:10:24 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{52171174-8C5B-4195-9CA9-6C882E5B3FC3}
[2012/02/03 07:19:26 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{86E4D813-4C3D-4EFF-91B0-EE066EDAC3B5}
[2012/02/03 07:19:11 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{114E7C52-8843-4367-A385-8401DBAD1BD1}
[2012/02/02 11:25:03 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{EE8BB213-621F-4C7F-A866-19CCFA43301F}
[2012/02/02 11:24:50 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{4A979982-EDCB-4587-9177-6FCC5CFB6218}
[2012/02/01 22:54:19 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{8638BE4E-8419-4C77-9FEC-19E0F1D172B1}
[2012/02/01 22:53:58 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{3A6C1013-00E5-48AD-91BD-F71290CE419D}
[2012/02/01 07:44:10 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{F39178BB-C6E0-476E-A21E-8725D286F28F}
[2012/02/01 07:43:53 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{741C4826-DDFE-491B-A60D-3C5285B1C3F6}
[2012/01/31 13:18:50 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{9B84A0E4-A949-4F45-B8DA-F8F194D94DC0}
[2012/01/31 13:18:39 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{DF4EF07A-A10E-4DA8-8EB7-9095E6B6F9DE}
[43 E:\*.tmp files -> E:\*.tmp -> ]
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/03/01 12:57:52 | 000,000,000 | -HS- | M] () – C:\DkHyperbootSync
[2012/03/01 12:54:18 | 000,011,136 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/03/01 12:54:18 | 000,011,136 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/03/01 12:46:13 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/03/01 12:46:05 | 529,096,703 | -HS- | M] () – C:\hiberfil.sys
[2012/03/01 12:05:30 | 000,003,304 | —- | M] () – C:\bootsqm.dat
[2012/03/01 11:29:00 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2825036124-2352061616-2705343857-1000UA.job
[2012/03/01 08:28:36 | 000,753,670 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/03/01 08:28:36 | 000,632,930 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/03/01 08:28:36 | 000,110,564 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/03/01 00:56:31 | 001,124,574 | —- | M] () – C:\cc_20120301_005612.reg
[2012/03/01 00:46:50 | 000,000,822 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/02/29 23:45:22 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\deployJava1.dll
[2012/02/29 23:45:22 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2012/02/29 23:45:22 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2012/02/29 23:45:22 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2012/02/28 23:35:59 | 000,000,448 | —- | M] () – C:\Windows\tasks\GBM - Easy Layout Backup Job-Full.job
[2012/02/20 15:08:38 | 000,002,095 | —- | M] () – C:\Users\sly\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk
[2012/02/18 14:29:00 | 000,000,848 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2825036124-2352061616-2705343857-1000Core.job
[2012/02/17 08:49:14 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/02/14 21:28:06 | 006,656,208 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/02/10 11:06:57 | 000,002,029 | —- | M] () – C:\Users\sly\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/01/31 13:43:51 | 000,001,979 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[43 E:\*.tmp files -> E:\*.tmp -> ]
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/03/01 12:57:52 | 000,000,000 | -HS- | C] () – C:\DkHyperbootSync
[2012/03/01 12:05:30 | 000,003,304 | —- | C] () – C:\bootsqm.dat
[2012/03/01 00:56:23 | 001,124,574 | —- | C] () – C:\cc_20120301_005612.reg
[2012/03/01 00:46:50 | 000,000,822 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/01/31 13:43:51 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2012/01/31 13:43:51 | 000,001,979 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011/10/25 10:03:18 | 000,280,904 | —- | C] () – C:\Windows\SysWow64\PnkBstrB.exe
[2011/10/25 10:03:15 | 000,075,136 | —- | C] () – C:\Windows\SysWow64\PnkBstrA.exe
[2011/10/14 23:54:52 | 000,321,856 | —- | C] () – C:\Windows\SysWow64\nvStreaming.exe
[2011/08/19 01:26:20 | 010,898,456 | —- | C] () – C:\Windows\SysWow64\LogiDPP.dll
[2011/08/19 01:26:20 | 000,336,408 | —- | C] () – C:\Windows\SysWow64\DevManagerCore.dll
[2011/08/19 01:26:20 | 000,104,472 | —- | C] () – C:\Windows\SysWow64\LogiDPPApp.exe
[2011/05/23 07:39:24 | 000,542,363 | —- | C] () – C:\ProgramData\bdinstall.bin
[2010/12/14 20:05:42 | 000,001,456 | —- | C] () – C:\Users\sly\AppData\Local\Adobe Save for Web 12.0 Prefs
[2010/11/08 09:27:13 | 000,000,132 | —- | C] () – C:\Users\sly\AppData\Roaming\Adobe IllExport Filter CS5 Prefs
[2010/10/05 14:31:42 | 000,175,104 | —- | C] () – C:\Users\sly\AppData\Roaming\sly3SQLite3.dll
[2010/09/30 20:58:57 | 000,000,132 | —- | C] () – C:\Users\sly\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2010/09/28 07:45:09 | 000,165,376 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2010/09/28 07:45:09 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2010/09/28 07:45:08 | 002,931,712 | —- | C] () – C:\Windows\SysWow64\x264vfw.dll
[2010/09/28 07:45:08 | 000,790,528 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2010/09/28 07:45:08 | 000,134,144 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2010/09/28 07:45:08 | 000,108,032 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2010/07/08 09:37:14 | 000,101,544 | —- | C] () – C:\Program Files\Common Files\LinkInstaller.exe
[2010/04/17 22:28:25 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/04/16 10:13:00 | 000,003,140 | -HS- | C] () – C:\ProgramData\KGyGaAvL.sys
[2010/04/16 10:13:00 | 000,000,008 | RHS- | C] () – C:\ProgramData\A145BC7D98.sys
[2010/04/15 23:09:07 | 000,000,037 | —- | C] () – C:\Windows\SWFConverter.INI
[2010/04/15 23:04:06 | 000,000,091 | —- | C] () – C:\Users\sly\AppData\Local\fusioncache.dat
[2010/04/15 22:11:31 | 000,000,025 | —- | C] () – C:\Users\sly\AppData\Roaming\bdfvconp.ini
[2010/04/08 14:55:10 | 000,034,308 | —- | C] () – C:\Windows\SysWow64\BASSMOD.dll

========== LOP Check ==========

[2012/03/01 13:12:26 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\.purple
[2010/01/11 14:38:24 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Activision
[2009/08/10 23:32:15 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Amazon
[2011/05/23 08:12:44 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\BitDefender
[2010/06/29 13:15:30 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/12/22 10:34:38 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2009/12/16 14:39:06 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\cYo
[2012/03/01 00:57:24 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\DAEMON Tools Lite
[2012/01/04 17:08:04 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Eclipsit
[2012/03/01 00:49:25 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\FileZilla
[2010/06/09 09:47:32 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Genie-Soft
[2011/07/16 15:46:10 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\go
[2010/11/20 18:40:50 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\gtk-2.0
[2009/11/30 17:01:37 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\HDRsoft
[2009/10/29 16:56:37 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Image Zone Express
[2009/10/29 16:56:37 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Leadertech
[2010/10/15 23:33:57 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\LightZone
[2010/07/17 00:14:24 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\LolClient
[2011/10/25 09:33:06 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Origin
[2010/10/15 23:34:37 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\PACE Anti-Piracy
[2011/07/27 13:44:47 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\PandoraRecovery
[2009/10/29 16:56:49 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Printer Info Cache
[2010/04/08 14:56:55 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Publish Providers
[2011/05/23 08:03:34 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\QuickScan
[2010/10/16 13:35:35 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Research In Motion
[2010/04/08 14:55:32 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Sony
[2010/07/14 10:39:06 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2005/12/23 22:12:24 | 000,000,000 | RHSD | M] – C:\Users\sly\AppData\Roaming\System
[2012/03/01 08:07:16 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\TeamViewer
[2010/09/02 23:25:57 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Thunderbird
[2012/03/01 00:57:23 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\uTorrent
[2012/02/28 23:35:59 | 000,000,448 | —- | M] () – C:\Windows\Tasks\GBM - Easy Layout Backup Job-Full.job
[2012/01/19 07:28:05 | 000,032,640 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2012/03/01 12:11:54 | 000,702,773 | —- | M] () – C:\bdlog.txt
[2011/04/20 08:29:01 | 012,054,781 | —- | M] () – C:\BdUninstallTool2011.04.20-09.28.18.log
[2011/04/20 08:29:01 | 000,133,272 | —- | M] () – C:\BdUninstallTool2011.04.20-09.28.18.reg
[2010/11/20 04:40:07 | 000,383,786 | RHS- | M] () – C:\bootmgr
[2009/10/29 17:32:21 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2012/03/01 12:05:30 | 000,003,304 | —- | M] () – C:\bootsqm.dat
[2012/03/01 00:56:31 | 001,124,574 | —- | M] () – C:\cc_20120301_005612.reg
[2012/03/01 12:57:52 | 000,000,000 | -HS- | M] () – C:\DkHyperbootSync
[2012/03/01 12:46:05 | 529,096,703 | -HS- | M] () – C:\hiberfil.sys
[2007/02/01 00:31:12 | 000,338,944 | —- | M] (Hewlett-Packard) – C:\hpzids40.dll
[2012/03/01 12:46:08 | 2137,120,767 | -HS- | M] () – C:\pagefile.sys
[2011/05/13 21:48:23 | 000,000,000 | —- | M] () – C:\pcversion.txt
[2009/08/08 01:38:25 | 000,000,473 | —- | M] () – C:\RHDSetup.log
[2011/10/25 10:31:35 | 000,019,518 | —- | M] () – C:\shared.log
[2009/08/08 01:50:13 | 000,000,057 | —- | M] () – C:\splash.idx
[2008/11/18 09:25:20 | 000,005,632 | -H– | M] () – C:\version

< %systemroot%\Fonts\*.com >
[2009/07/13 21:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 21:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 21:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 21:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 12:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 20:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/08/10 15:20:50 | 000,000,221 | -HS- | M] () – C:\Users\sly\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop (1).ini
[2011/04/20 10:56:10 | 000,000,221 | -HS- | M] () – C:\Users\sly\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 1243 bytes -> C:\Users\sly\AppData\Local\Temp:kvGL6aJIXvCIAINCN9lmuG3

< End of report >


EXTRAS.TXT


OTL Extras logfile created on: 3/1/2012 1:04:55 PM - Run 1
OTL by OldTimer - Version 3.2.34.0 Folder = E:\Downloads
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

5.99 Gb Total Physical Memory | 3.45 Gb Available Physical Memory | 57.59% Memory free
11.98 Gb Paging File | 8.35 Gb Available in Paging File | 69.67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 279.46 Gb Total Space | 155.62 Gb Free Space | 55.69% Space Free | Partition Type: NTFS
Drive E: | 931.51 Gb Total Space | 337.91 Gb Free Space | 36.28% Space Free | Partition Type: NTFS

Computer Name: HANSLEY-PC | User Name: sly | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
.js[@ = jsfile] – Reg Error: Key error. File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.js [@ = jsfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\system32\rundll32.exe" "C:\Windows\system32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile [open] – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
jsfile [open] – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05EFBF37-0E52-4579-875C-7EEF0DFB4FCB}" = Network64
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
"{138A4072-9E64-46BD-B5F9-DB2BB395391F}" = LWS VideoEffects
"{17016DA1-F040-4032-BD36-34DD317BC9D5}" = HP Photosmart All-In-One Driver Software 13.0 Rel. A
"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{4E82E2E9-668B-4F8A-814A-78E163FCDBCD}" = IconHandler 64 bit
"{55D55008-E5F6-47D6-B16F-B2A40D4D145F}" = 64 Bit HP CIO Components Installer
"{5E11C972-1E76-45FE-8F92-14E0D1140B1B}" = iTunes
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{75104836-CAC7-444E-A39E-3F54151942F5}" = Apple Mobile Device Support
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{858CCC22-7029-4426-B4D5-58C38742EBD3}" = Diskeeper 2010 Pro Premier
"{8BBA6F77-4A79-4E90-BD82-E24669ACF221}" = Adobe Photoshop Lightroom 3.4.1 64-bit
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{90BF0360-A1DB-4599-A643-95AB90A52C1E}" = Microsoft_VC90_MFCLOC_x86_x64
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.11.0621
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.5.20
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B6CA7A3C-35FD-401F-9335-FFFD2BCD5FF3}" = BitDefender Total Security 2011
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F3F18612-7B5D-4C05-86C9-AB50F6F71727}" = KhalInstallWrapper
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"6af12c54-643b-4752-87d0-8335503010de_is1" = Nexus Mod Manager
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit
"BitDefender" = BitDefender Total Security 2011
"CCleaner" = CCleaner
"ComicRack" = ComicRack v0.9.111
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Photosmart Essential" = HP Photosmart Essential 3.5
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"HPOCR" = OCR Software by I.R.I.S. 13.0
"KLiteCodecPack64_is1" = K-Lite Codec Pack (64-bit) v2.6.0
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"Shop for HP Supplies" = Shop for HP Supplies
"Wacom Tablet Driver" = Wacom Tablet
"WinRAR archiver" = WinRAR archiver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{5B51BB5F-4E7C-4275-A653-E98534E9C1D2}" = Corel Painter 11
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{024521CF-C07E-4F8E-8481-0D75695E03AF}" = PxMergeModule
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0DEF8C02-2EAB-4BFE-A7E0-7990665DF1A9}" = C6100
"{0EF5BEA9-B9D3-46d7-8958-FB69A0BAEACC}" = Status
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi
"{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main
"{174A3B31-4C43-43DD-866F-73C9DB887B48}" = LWS Twitter
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{1AED4ABF-0852-4B3F-9F87-00CF88F25CE0}" = IconHandler 32 bit
"{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}" = TrayApp
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin
"{23C12370-3A82-4558-B727-F345B473AD87}" = BlackBerry Device Software Updater
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java™ 6 Update 31
"{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1" = ConvertHelper 2.2
"{28F8F8F0-C278-454A-9507-46B344AAD188}" = Corel Painter 11
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2A7EF808-14F3-4E93-BE3A-1675EE5332A4}" = AIO_CDA_ProductContext
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2FF8C687-DB7D-4adc-A5DC-57983EC25046}" = DeviceDiscovery
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{3521BDBD-D453-5D9F-AA55-44B75D214629}" = Adobe Community Help
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = JMicron JMB36X Driver
"{3C92B2E6-380D-4fef-B4DF-4A3B4B669771}" = Copy
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = erLT
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4BD5B5D2-406D-4bc5-BB10-2F0D1D367C95}" = c6100_Help
"{4E33D05D-76CF-5D3C-4D5D-7727530FA161}" = Adobe Content Viewer
"{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport
"{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}" = Photo Story 3 for Windows
"{56B83336-FBC1-4C46-8613-90A9E3B440D6}" = EPU-6 Engine
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5B51BB5F-4E7C-4275-A653-E98534E9C1D2}" = Corel Painter 11 - ICA
"{5D9B17E4-5C34-45B2-9C95-8B9DB4CF7AF3}" = HP_Network_UserGuide
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6842DCCB-2840-4E46-8AF3-BEA9CFF3455B}" = Sony Sound Forge 9.0
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection
"{75157F34-02C6-4831-BD66-3BC49E7A8394}" = BlackBerry Desktop Software 6.1
"{76285C16-411A-488A-BCE3-C83CB933D8CF}" = Battlefield 3™
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7EC69F77-5494-4E1F-8BC6-956DAA5A91F2}" = Corel Painter 11 - IPM
"{7F6D7FD9-648D-4DD9-BB6E-3990C675ECA4}" = NVIDIA PhysX
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher
"{840BF2FE-033D-437C-89D1-AAA206BA13B6}" = Langauge
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin
"{A0494B41-EBD7-4C0D-91B7-DC39741B27BB}" = Express Gate
"{A31951C5-DCD8-4DFE-A525-CFC701F54792}" = TurboV
"{A498D9EB-927B-459B-85D6-DD6EF8C2C564}" = erLT
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A7AEE29F-839E-46B5-B347-6D430618129F}" = AIO_CDA_Software
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AC76BA86-1033-F400-7760-000000000005}" = Adobe Acrobat X Pro - English, Français, Deutsch
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.2)
"{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR
"{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update
"{B369483E-0728-405C-8F8C-3427B263B01F}" = Content
"{B3DAF54F-DB25-4586-9EF1-96D24BB14088}" = Windows Movie Maker 2.6
"{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86
"{B9CA59A0-3B70-48F8-9054-67595DE6E72B}" = League of Legends
"{BCB4C18A-ACA6-4383-8688-E19933A705DD}" = Microsoft SOAP Toolkit 3.0
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{BDE646E8-86E0-50E1-37BC-0AEBB2185D76}" = Adobe Widget Browser
"{C28DD992-5B7B-D195-6841-4EC57DF512BD}" = Adobe Story
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C86E7C99-E4AD-79C7-375B-1AEF9A91EC2B}" = Acrobat.com
"{C9A162C1-031F-4EBF-A3E6-C45F7FCCBB9E}_is1" = Genie Backup Assistant
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech Webcam Software
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D533C9D4-ED96-4191-B9C3-279C0DD6BABA}" = Sony Noise Reduction Plug-In 2.0e
"{D57FC112-312E-4D70-860F-2DB8FB6858F0}" = Adobe Creative Suite 5.5 Master Collection
"{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential
"{D86B0E2E-DF9A-441C-AF77-8D1A0FF00FA6}" = AIO_Scan
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DA6FAB8D-E87A-4E8E-A3D3-B7B9F479C725}" = forteManager
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E1845F1C-068C-F8F4-D31D-D3540D47C453}" = Adobe Download Assistant
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{EED027B7-0DB6-404B-8F45-6DFEE34A0441}" = LWS Video Mask Maker
"{EF6E783C-339A-49EB-9872-DE0F131DE5DA}" = BlackBerry Device Software v5.0.0 for the BlackBerry 9000 smartphone
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint
"{FA54AFB1-5745-4389-B8C1-9F7509672ED1}" = iPhone Configuration Utility
"{FB9DD41D-533E-42C6-8C27-B67086C04EC0}" = 11N Wireless USB Adapter
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Akamai" = Akamai NetSession Interface Service
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.5
"ASF-AVI-RM-WMV Repair_is1" = ASF-AVI-RM-WMV Repair 1.83
"AVS Screen Capture_is1" = AVS Screen Capture version 1.1.2
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS Video Editor_is1" = AVS Video Editor 5
"AVS Video Recorder_is1" = AVS Video Recorder 2.4
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.4
"BlackBerry_Desktop" = BlackBerry Desktop Software 6.1
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.AdobeStory.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Story
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.dmp.contentviewer" = Adobe Content Viewer
"com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"com.adobe.WidgetBrowser.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1" = Adobe Widget Browser
"ESN Sonar-0.70.4" = ESN Sonar
"FileZilla Client" = FileZilla Client 3.5.2
"Free 3GP Video Converter_is1" = Free 3GP Video Converter version 3.2
"Free Video to MP3 Converter_is1" = Free Video to MP3 Converter version 3.2
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 6.4.0
"LaCie Device Updater" = LaCie Device Updater
"Logitech Vid" = Logitech Vid HD
"Microangelo Creation" = Microangelo Creation
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox 10.0.2 (x86 en-US)" = Mozilla Firefox 10.0.2 (x86 en-US)
"Mozilla Thunderbird 10.0.2 (x86 en-US)" = Mozilla Thunderbird 10.0.2 (x86 en-US)
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"Origin" = Origin
"PandoraRecovery" = PandoraRecovery (Remove Only)
"Picasa 3" = Picasa 3
"Pidgin" = Pidgin
"PunkBusterSvc" = PunkBuster Services
"Uninstall_is1" = Uninstall 1.0.0.1
"uTorrent" = µTorrent
"Wacom WebTabletPlugin for IE" = WebTablet IE Plugin
"Wacom WebTabletPlugin for Netscape" = WebTablet Netscape Plugin
"WinLiveSuite" = Windows Live Essentials
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)
"Akamai" = Akamai NetSession Interface
"Game Organizer" = EasyBits GO
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/1/2012 4:03:12 AM | Computer Name = hansley-pc | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: unknown, version: 0.0.0.0, time stamp:
0x00000000 Exception code: 0xc0000005 Fault offset: 0xf39b4bb2 Faulting process id:
0x2380 Faulting application start time: 0x01ccf781b84f0653 Faulting application path:
C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path: unknown
Report
Id: fd1ef90e-6374-11e1-be9d-002618360274

Error - 3/1/2012 4:19:12 AM | Computer Name = hansley-pc | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: unknown, version: 0.0.0.0, time stamp:
0x00000000 Exception code: 0xc0000005 Fault offset: 0xf7354bb2 Faulting process id:
0x138 Faulting application start time: 0x01ccf783f49675db Faulting application path:
C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path: unknown
Report
Id: 395d19a3-6377-11e1-be9d-002618360274

Error - 3/1/2012 4:35:02 AM | Computer Name = hansley-pc | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: unknown, version: 0.0.0.0, time stamp:
0x00000000 Exception code: 0xc0000005 Fault offset: 0xf6404bb2 Faulting process id:
0x590 Faulting application start time: 0x01ccf78631036f50 Faulting application path:
C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path: unknown
Report
Id: 6f9256da-6379-11e1-be9d-002618360274

Error - 3/1/2012 4:35:10 AM | Computer Name = hansley-pc | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: unknown, version: 0.0.0.0, time stamp:
0x00000000 Exception code: 0xc0000005 Fault offset: 0xf64f4bb2 Faulting process id:
0x1478 Faulting application start time: 0x01ccf78630ed75fe Faulting application path:
C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path: unknown
Report
Id: 749908b1-6379-11e1-be9d-002618360274

Error - 3/1/2012 4:38:56 AM | Computer Name = hansley-pc | Source = Application Error | ID = 1000
Description = Faulting application name: firefox.exe, version: 10.0.2.4428, time
stamp: 0x4f3cdb2a Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0xf34518a7 Faulting process id: 0x3c8 Faulting application
start time: 0x01ccf786bbb4170f Faulting application path: C:\Program Files (x86)\Mozilla\Mozilla
Firefox\firefox.exe Faulting module path: unknown Report Id: fb09ace2-6379-11e1-be9d-002618360274

Error - 3/1/2012 4:41:34 AM | Computer Name = hansley-pc | Source = Application Error | ID = 1000
Description = Faulting application name: firefox.exe, version: 10.0.2.4428, time
stamp: 0x4f3cdb2a Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0xf32818a7 Faulting process id: 0x2258 Faulting application
start time: 0x01ccf7871a929adc Faulting application path: C:\Program Files (x86)\Mozilla\Mozilla
Firefox\firefox.exe Faulting module path: unknown Report Id: 59370686-637a-11e1-be9d-002618360274

Error - 3/1/2012 4:59:59 AM | Computer Name = hansley-pc | Source = Application Error | ID = 1000
Description = Faulting application name: firefox.exe, version: 10.0.2.4428, time
stamp: 0x4f3cdb2a Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0xf1bc18a7 Faulting process id: 0x2328 Faulting application
start time: 0x01ccf789ad4786a3 Faulting application path: C:\Program Files (x86)\Mozilla\Mozilla
Firefox\firefox.exe Faulting module path: unknown Report Id: ebf28216-637c-11e1-9873-002618360274

Error - 3/1/2012 10:02:57 AM | Computer Name = hansley-pc | Source = Application Error | ID = 1000
Description = Faulting application name: firefox.exe, version: 10.0.2.4428, time
stamp: 0x4f3cdb2a Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0xf9a84b44 Faulting process id: 0x964 Faulting application
start time: 0x01ccf7b3f8741d44 Faulting application path: C:\Program Files (x86)\Mozilla\Mozilla
Firefox\firefox.exe Faulting module path: unknown Report Id: 3f04b251-63a7-11e1-9873-002618360274

Error - 3/1/2012 12:27:44 PM | Computer Name = hansley-pc | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddWin32ServiceFiles: Unable to back up image
of service ASP.NET State Service since QueryServiceConfig API failed System Error:
The
system cannot find the file specified. .

Error - 3/1/2012 12:36:54 PM | Computer Name = hansley-pc | Source = Application Error | ID = 1000
Description = Faulting application name: bdtkexec.exe, version: 14.0.28.143, time
stamp: 0x4dcd1deb Faulting module name: ole32.dll, version: 6.1.7601.17514, time
stamp: 0x4ce7c92c Exception code: 0xc0000005 Fault offset: 0x0000000000029fa6 Faulting
process id: 0x1f78 Faulting application start time: 0x01ccf7c803d52445 Faulting application
path: C:\Program Files\BitDefender\BitDefender 2011\bdtkexec.exe Faulting module
path: C:\Windows\system32\ole32.dll Report Id: c09b7086-63bc-11e1-9873-002618360274

[ System Events ]
Error - 2/28/2012 12:52:14 AM | Computer Name = hansley-pc | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
storage could not grow due to a user imposed limit.

Error - 2/28/2012 1:55:07 AM | Computer Name = hansley-pc | Source = BROWSER | ID = 8032
Description =

Error - 2/29/2012 12:29:43 AM | Computer Name = hansley-pc | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Windows
Font Cache Service service to connect.

Error - 2/29/2012 12:29:44 AM | Computer Name = hansley-pc | Source = Service Control Manager | ID = 7000
Description = The Windows Font Cache Service service failed to start due to the
following error: %%1053

Error - 2/29/2012 12:11:17 PM | Computer Name = hansley-pc | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Windows
Font Cache Service service to connect.

Error - 2/29/2012 12:11:18 PM | Computer Name = hansley-pc | Source = Service Control Manager | ID = 7000
Description = The Windows Font Cache Service service failed to start due to the
following error: %%1053

Error - 2/29/2012 8:23:38 PM | Computer Name = hansley-pc | Source = WMPNetworkSvc | ID = 866300
Description =

Error - 3/1/2012 4:43:37 AM | Computer Name = hansley-pc | Source = VDS Basic Provider | ID = 33554433
Description =

Error - 3/1/2012 4:54:04 AM | Computer Name = hansley-pc | Source = EventLog | ID = 6008
Description = The previous system shutdown at 12:51:13 AM on ?3/?1/?2012 was unexpected.

Error - 3/1/2012 8:34:17 AM | Computer Name = hansley-pc | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
storage could not grow due to a user imposed limit.


< End of report >
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post





Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)













Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
Thank you for replying, I really need the assistance.

I don't know if this helps but the problem started after I received a notice to update Java and I updated it.

Anyway, please find the two logs pasted below.


TDSSKiller Log


10:08:24.0726 1972 TDSS rootkit removing tool 2.7.18.0 Mar 2 2012 09:40:07
10:08:25.0634 1972 ============================================================
10:08:25.0634 1972 Current date / time: 2012/03/03 10:08:25.0634
10:08:25.0634 1972 SystemInfo:
10:08:25.0635 1972
10:08:25.0635 1972 OS Version: 6.1.7601 ServicePack: 1.0
10:08:25.0635 1972 Product type: Workstation
10:08:25.0635 1972 ComputerName: HANSLEY-PC
10:08:25.0635 1972 UserName: sly
10:08:25.0635 1972 Windows directory: C:\Windows
10:08:25.0635 1972 System windows directory: C:\Windows
10:08:25.0635 1972 Running under WOW64
10:08:25.0635 1972 Processor architecture: Intel x64
10:08:25.0635 1972 Number of processors: 8
10:08:25.0635 1972 Page size: 0x1000
10:08:25.0635 1972 Boot type: Normal boot
10:08:25.0635 1972 ============================================================
10:08:26.0365 1972 Drive \Device\Harddisk0\DR0 - Size: 0x45DD826000 (279.46 Gb), SectorSize: 0x200, Cylinders: 0x8E81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
10:08:26.0365 1972 Drive \Device\Harddisk1\DR1 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
10:08:26.0386 1972 \Device\Harddisk0\DR0:
10:08:26.0386 1972 MBR used
10:08:26.0386 1972 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x22EEB000
10:08:26.0386 1972 \Device\Harddisk1\DR1:
10:08:26.0386 1972 MBR used
10:08:26.0386 1972 \Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x74705800
10:08:26.0400 1972 Initialize success
10:08:26.0400 1972 ============================================================
10:08:27.0437 1300 ============================================================
10:08:27.0437 1300 Scan started
10:08:27.0437 1300 Mode: Manual;
10:08:27.0437 1300 ============================================================
10:08:28.0026 1300 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
10:08:28.0029 1300 1394ohci - ok
10:08:28.0051 1300 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
10:08:28.0054 1300 ACPI - ok
10:08:28.0074 1300 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
10:08:28.0075 1300 AcpiPmi - ok
10:08:28.0122 1300 adfs (d44bcaf639e4e45307c2bc80715273d5) C:\Windows\system32\drivers\adfs.sys
10:08:28.0123 1300 adfs - ok
10:08:28.0179 1300 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
10:08:28.0182 1300 adp94xx - ok
10:08:28.0211 1300 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
10:08:28.0214 1300 adpahci - ok
10:08:28.0226 1300 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
10:08:28.0228 1300 adpu320 - ok
10:08:28.0270 1300 AFD (1c7857b62de5994a75b054a9fd4c3825) C:\Windows\system32\drivers\afd.sys
10:08:28.0273 1300 AFD - ok
10:08:28.0290 1300 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
10:08:28.0290 1300 agp440 - ok
10:08:28.0324 1300 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
10:08:28.0325 1300 aliide - ok
10:08:28.0341 1300 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
10:08:28.0341 1300 amdide - ok
10:08:28.0389 1300 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
10:08:28.0390 1300 AmdK8 - ok
10:08:28.0402 1300 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
10:08:28.0403 1300 AmdPPM - ok
10:08:28.0435 1300 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
10:08:28.0436 1300 amdsata - ok
10:08:28.0457 1300 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
10:08:28.0459 1300 amdsbs - ok
10:08:28.0477 1300 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
10:08:28.0478 1300 amdxata - ok
10:08:28.0509 1300 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
10:08:28.0510 1300 AppID - ok
10:08:28.0554 1300 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
10:08:28.0555 1300 arc - ok
10:08:28.0564 1300 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
10:08:28.0565 1300 arcsas - ok
10:08:28.0588 1300 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
10:08:28.0589 1300 AsyncMac - ok
10:08:28.0604 1300 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
10:08:28.0605 1300 atapi - ok
10:08:28.0669 1300 avc3 (34fc546a5c13dae1aa07defd579effe7) C:\Windows\system32\DRIVERS\avc3.sys
10:08:28.0673 1300 avc3 - ok
10:08:28.0742 1300 avckf (8a1fafe409b3d24d55be62bfc8ecec8e) C:\Windows\system32\DRIVERS\avckf.sys
10:08:28.0750 1300 avckf - ok
10:08:28.0779 1300 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
10:08:28.0783 1300 b06bdrv - ok
10:08:28.0804 1300 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
10:08:28.0806 1300 b57nd60a - ok
10:08:28.0829 1300 bdfm (57a812537b752e2b0409576120183e4f) C:\Windows\system32\DRIVERS\bdfm.sys
10:08:28.0831 1300 bdfm - ok
10:08:28.0877 1300 Bdfndisf (7afb43894a9bcea183ebca27d2baa48c) c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys
10:08:28.0879 1300 Bdfndisf - ok
10:08:28.0915 1300 bdfsfltr (66116e0a4da8407ff7f2aaace52b8b54) C:\Windows\system32\DRIVERS\bdfsfltr.sys
10:08:28.0919 1300 bdfsfltr - ok
10:08:28.0936 1300 bdfwfpf (37e7491ca07ab737e68d655d658e1e94) C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdfwfpf.sys
10:08:28.0937 1300 bdfwfpf - ok
10:08:28.0963 1300 Bdvedisk (b89deff4817b4cc6fc2bcd8f83b4e75d) C:\Windows\system32\DRIVERS\bdvedisk.sys
10:08:28.0964 1300 Bdvedisk - ok
10:08:28.0998 1300 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
10:08:28.0999 1300 Beep - ok
10:08:29.0068 1300 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
10:08:29.0070 1300 blbdrive - ok
10:08:29.0112 1300 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
10:08:29.0113 1300 bowser - ok
10:08:29.0125 1300 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
10:08:29.0125 1300 BrFiltLo - ok
10:08:29.0135 1300 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
10:08:29.0136 1300 BrFiltUp - ok
10:08:29.0158 1300 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
10:08:29.0159 1300 Brserid - ok
10:08:29.0175 1300 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
10:08:29.0176 1300 BrSerWdm - ok
10:08:29.0190 1300 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
10:08:29.0191 1300 BrUsbMdm - ok
10:08:29.0201 1300 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
10:08:29.0202 1300 BrUsbSer - ok
10:08:29.0216 1300 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
10:08:29.0217 1300 BTHMODEM - ok
10:08:29.0234 1300 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
10:08:29.0235 1300 cdfs - ok
10:08:29.0257 1300 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys
10:08:29.0258 1300 cdrom - ok
10:08:29.0275 1300 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
10:08:29.0276 1300 circlass - ok
10:08:29.0298 1300 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
10:08:29.0300 1300 CLFS - ok
10:08:29.0336 1300 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
10:08:29.0337 1300 CmBatt - ok
10:08:29.0401 1300 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
10:08:29.0401 1300 cmdide - ok
10:08:29.0430 1300 CNG (c4943b6c962e4b82197542447ad599f4) C:\Windows\system32\Drivers\cng.sys
10:08:29.0434 1300 CNG - ok
10:08:29.0452 1300 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
10:08:29.0453 1300 Compbatt - ok
10:08:29.0494 1300 CompFilter64 (403433d758c2d8908937265c1fb34f34) C:\Windows\system32\DRIVERS\lvbflt64.sys
10:08:29.0494 1300 CompFilter64 - ok
10:08:29.0516 1300 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys
10:08:29.0516 1300 CompositeBus - ok
10:08:29.0544 1300 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
10:08:29.0545 1300 crcdisk - ok
10:08:29.0583 1300 CSC (54da3dfd29ed9f1619b6f53f3ce55e49) C:\Windows\system32\drivers\csc.sys
10:08:29.0588 1300 CSC - ok
10:08:29.0655 1300 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
10:08:29.0656 1300 DfsC - ok
10:08:29.0676 1300 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
10:08:29.0677 1300 discache - ok
10:08:29.0687 1300 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
10:08:29.0688 1300 Disk - ok
10:08:29.0770 1300 DKRtWrt (7297cde753955f45070d38fec52c9705) C:\Windows\system32\DRIVERS\DKRtWrt.sys
10:08:29.0771 1300 DKRtWrt - ok
10:08:29.0816 1300 Dot4 (b42ed0320c6e41102fde0005154849bb) C:\Windows\system32\DRIVERS\Dot4.sys
10:08:29.0817 1300 Dot4 - ok
10:08:29.0846 1300 Dot4Print (e9f5969233c5d89f3c35e3a66a52a361) C:\Windows\system32\drivers\Dot4Prt.sys
10:08:29.0847 1300 Dot4Print - ok
10:08:29.0864 1300 dot4usb (fd05a02b0370bc3000f402e543ca5814) C:\Windows\system32\DRIVERS\dot4usb.sys
10:08:29.0865 1300 dot4usb - ok
10:08:29.0897 1300 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
10:08:29.0898 1300 drmkaud - ok
10:08:29.0930 1300 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
10:08:29.0937 1300 DXGKrnl - ok
10:08:30.0005 1300 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
10:08:30.0025 1300 ebdrv - ok
10:08:30.0050 1300 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
10:08:30.0053 1300 elxstor - ok
10:08:30.0068 1300 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
10:08:30.0069 1300 ErrDev - ok
10:08:30.0087 1300 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
10:08:30.0089 1300 exfat - ok
10:08:30.0101 1300 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
10:08:30.0103 1300 fastfat - ok
10:08:30.0165 1300 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
10:08:30.0166 1300 fdc - ok
10:08:30.0195 1300 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
10:08:30.0196 1300 FileInfo - ok
10:08:30.0212 1300 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
10:08:30.0213 1300 Filetrace - ok
10:08:30.0226 1300 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
10:08:30.0226 1300 flpydisk - ok
10:08:30.0251 1300 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
10:08:30.0253 1300 FltMgr - ok
10:08:30.0272 1300 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
10:08:30.0273 1300 FsDepends - ok
10:08:30.0284 1300 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
10:08:30.0284 1300 Fs_Rec - ok
10:08:30.0321 1300 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
10:08:30.0323 1300 fvevol - ok
10:08:30.0339 1300 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
10:08:30.0340 1300 gagp30kx - ok
10:08:30.0361 1300 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
10:08:30.0362 1300 GEARAspiWDM - ok
10:08:30.0390 1300 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
10:08:30.0391 1300 hcw85cir - ok
10:08:30.0422 1300 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys
10:08:30.0422 1300 HDAudBus - ok
10:08:30.0437 1300 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
10:08:30.0438 1300 HidBatt - ok
10:08:30.0450 1300 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
10:08:30.0451 1300 HidBth - ok
10:08:30.0458 1300 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
10:08:30.0458 1300 HidIr - ok
10:08:30.0526 1300 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys
10:08:30.0527 1300 HidUsb - ok
10:08:30.0556 1300 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
10:08:30.0557 1300 HpSAMD - ok
10:08:30.0593 1300 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
10:08:30.0596 1300 HTTP - ok
10:08:30.0614 1300 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
10:08:30.0614 1300 hwpolicy - ok
10:08:30.0642 1300 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
10:08:30.0643 1300 i8042prt - ok
10:08:30.0674 1300 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
10:08:30.0676 1300 iaStorV - ok
10:08:30.0710 1300 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
10:08:30.0711 1300 iirsp - ok
10:08:30.0761 1300 IntcAzAudAddService (46cb3abe8150e7b181e86d4906de17e8) C:\Windows\system32\drivers\RTKVHD64.sys
10:08:30.0767 1300 IntcAzAudAddService - ok
10:08:30.0780 1300 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
10:08:30.0781 1300 intelide - ok
10:08:30.0805 1300 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
10:08:30.0805 1300 intelppm - ok
10:08:30.0827 1300 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
10:08:30.0828 1300 IpFilterDriver - ok
10:08:30.0922 1300 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
10:08:30.0923 1300 IPMIDRV - ok
10:08:30.0993 1300 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
10:08:30.0994 1300 IPNAT - ok
10:08:31.0055 1300 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
10:08:31.0055 1300 IRENUM - ok
10:08:31.0068 1300 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
10:08:31.0076 1300 isapnp - ok
10:08:31.0100 1300 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
10:08:31.0102 1300 iScsiPrt - ok
10:08:31.0121 1300 ivusb (bd5bf20ec242e003a2f570b8754a56d1) C:\Windows\system32\DRIVERS\ivusb.sys
10:08:31.0121 1300 ivusb - ok
10:08:31.0141 1300 JRAID (db85fe8d6cbaa2047cb4da1b2c193d76) C:\Windows\system32\DRIVERS\jraid.sys
10:08:31.0142 1300 JRAID - ok
10:08:31.0164 1300 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\drivers\kbdclass.sys
10:08:31.0165 1300 kbdclass - ok
10:08:31.0185 1300 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\drivers\kbdhid.sys
10:08:31.0186 1300 kbdhid - ok
10:08:31.0209 1300 KMWDFILTER (07071c1e3cd8f0f9114aac8b072ca1e5) C:\Windows\system32\DRIVERS\KMWDFILTER.sys
10:08:31.0210 1300 KMWDFILTER - ok
10:08:31.0230 1300 KSecDD (da1e991a61cfdd755a589e206b97644b) C:\Windows\system32\Drivers\ksecdd.sys
10:08:31.0231 1300 KSecDD - ok
10:08:31.0283 1300 KSecPkg (7e33198d956943a4f11a5474c1e9106f) C:\Windows\system32\Drivers\ksecpkg.sys
10:08:31.0284 1300 KSecPkg - ok
10:08:31.0304 1300 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
10:08:31.0305 1300 ksthunk - ok
10:08:31.0367 1300 LGDDCDevice (9dcb9d9bdb7e3c0f66f86ee09a392cbb) C:\Program Files (x86)\Drivers\LG Soft India\forteManager\bin\I2CDriver.sys
10:08:31.0367 1300 LGDDCDevice - ok
10:08:31.0377 1300 LGII2CDevice (21a62a7a95b1905634e7c12e5158ec32) C:\Program Files (x86)\Drivers\LG Soft India\forteManager\bin\PII2CDriver.sys
10:08:31.0377 1300 LGII2CDevice - ok
10:08:31.0401 1300 LHidFilt (b6552d382ff070b4ed34cbd6737277c0) C:\Windows\system32\DRIVERS\LHidFilt.Sys
10:08:31.0401 1300 LHidFilt - ok
10:08:31.0429 1300 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
10:08:31.0430 1300 lltdio - ok
10:08:31.0464 1300 LMouFilt (73c1f563ab73d459dffe682d66476558) C:\Windows\system32\DRIVERS\LMouFilt.Sys
10:08:31.0465 1300 LMouFilt - ok
10:08:31.0486 1300 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
10:08:31.0486 1300 LSI_FC - ok
10:08:31.0494 1300 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
10:08:31.0495 1300 LSI_SAS - ok
10:08:31.0507 1300 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
10:08:31.0508 1300 LSI_SAS2 - ok
10:08:31.0516 1300 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
10:08:31.0517 1300 LSI_SCSI - ok
10:08:31.0578 1300 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
10:08:31.0579 1300 luafv - ok
10:08:31.0612 1300 LVPr2M64 (b3944d06eb4b64d57bd7e5fe89415f58) C:\Windows\system32\DRIVERS\LVPr2M64.sys
10:08:31.0613 1300 LVPr2M64 - ok
10:08:31.0617 1300 LVPr2Mon (b3944d06eb4b64d57bd7e5fe89415f58) C:\Windows\system32\DRIVERS\LVPr2M64.sys
10:08:31.0618 1300 LVPr2Mon - ok
10:08:31.0650 1300 LVRS64 (ef2be2f45d4f06410a3bd2a3467325b0) C:\Windows\system32\DRIVERS\lvrs64.sys
10:08:31.0652 1300 LVRS64 - ok
10:08:31.0728 1300 LVUVC64 (ac22f92c6078640fe8a70d662a2f3ad5) C:\Windows\system32\DRIVERS\lvuvc64.sys
10:08:31.0748 1300 LVUVC64 - ok
10:08:31.0760 1300 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
10:08:31.0761 1300 megasas - ok
10:08:31.0780 1300 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
10:08:31.0782 1300 MegaSR - ok
10:08:31.0808 1300 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
10:08:31.0809 1300 Modem - ok
10:08:31.0834 1300 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
10:08:31.0834 1300 monitor - ok
10:08:31.0861 1300 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
10:08:31.0861 1300 mouclass - ok
10:08:31.0885 1300 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
10:08:31.0885 1300 mouhid - ok
10:08:31.0904 1300 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
10:08:31.0905 1300 mountmgr - ok
10:08:31.0965 1300 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
10:08:31.0966 1300 mpio - ok
10:08:31.0984 1300 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
10:08:31.0985 1300 mpsdrv - ok
10:08:32.0003 1300 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
10:08:32.0004 1300 MRxDAV - ok
10:08:32.0021 1300 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
10:08:32.0022 1300 mrxsmb - ok
10:08:32.0048 1300 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
10:08:32.0050 1300 mrxsmb10 - ok
10:08:32.0062 1300 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
10:08:32.0063 1300 mrxsmb20 - ok
10:08:32.0075 1300 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
10:08:32.0075 1300 msahci - ok
10:08:32.0099 1300 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
10:08:32.0100 1300 msdsm - ok
10:08:32.0114 1300 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
10:08:32.0115 1300 Msfs - ok
10:08:32.0124 1300 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
10:08:32.0125 1300 mshidkmdf - ok
10:08:32.0140 1300 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
10:08:32.0141 1300 msisadrv - ok
10:08:32.0176 1300 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
10:08:32.0177 1300 MSKSSRV - ok
10:08:32.0202 1300 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
10:08:32.0203 1300 MSPCLOCK - ok
10:08:32.0221 1300 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
10:08:32.0222 1300 MSPQM - ok
10:08:32.0246 1300 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
10:08:32.0249 1300 MsRPC - ok
10:08:32.0307 1300 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys
10:08:32.0308 1300 mssmbios - ok
10:08:32.0331 1300 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
10:08:32.0332 1300 MSTEE - ok
10:08:32.0343 1300 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
10:08:32.0344 1300 MTConfig - ok
10:08:32.0364 1300 MTsensor (6936198f2cc25b39cf5262436c80df46) C:\Windows\system32\DRIVERS\ASACPI.sys
10:08:32.0365 1300 MTsensor - ok
10:08:32.0382 1300 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
10:08:32.0383 1300 Mup - ok
10:08:32.0402 1300 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
10:08:32.0405 1300 NativeWifiP - ok
10:08:32.0442 1300 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
10:08:32.0449 1300 NDIS - ok
10:08:32.0465 1300 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
10:08:32.0466 1300 NdisCap - ok
10:08:32.0485 1300 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
10:08:32.0486 1300 NdisTapi - ok
10:08:32.0515 1300 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
10:08:32.0516 1300 Ndisuio - ok
10:08:32.0538 1300 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
10:08:32.0540 1300 NdisWan - ok
10:08:32.0563 1300 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
10:08:32.0565 1300 NDProxy - ok
10:08:32.0584 1300 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
10:08:32.0585 1300 NetBIOS - ok
10:08:32.0613 1300 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
10:08:32.0615 1300 NetBT - ok
10:08:32.0703 1300 netr28ux (eed1fbde98cf5f6d5c0c5b27ab1f68ec) C:\Windows\system32\DRIVERS\netr28ux.sys
10:08:32.0711 1300 netr28ux - ok
10:08:32.0734 1300 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
10:08:32.0735 1300 nfrd960 - ok
10:08:32.0751 1300 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
10:08:32.0752 1300 Npfs - ok
10:08:32.0765 1300 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
10:08:32.0765 1300 nsiproxy - ok
10:08:32.0806 1300 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
10:08:32.0814 1300 Ntfs - ok
10:08:32.0827 1300 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
10:08:32.0828 1300 Null - ok
10:08:33.0020 1300 nvlddmkm (b15258b1f45f9571758ac6bb2f043b01) C:\Windows\system32\DRIVERS\nvlddmkm.sys
10:08:33.0073 1300 nvlddmkm - ok
10:08:33.0119 1300 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
10:08:33.0120 1300 nvraid - ok
10:08:33.0142 1300 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
10:08:33.0144 1300 nvstor - ok
10:08:33.0190 1300 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
10:08:33.0192 1300 nv_agp - ok
10:08:33.0216 1300 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
10:08:33.0217 1300 ohci1394 - ok
10:08:33.0296 1300 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
10:08:33.0297 1300 Parport - ok
10:08:33.0318 1300 partmgr (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys
10:08:33.0319 1300 partmgr - ok
10:08:33.0334 1300 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
10:08:33.0335 1300 pci - ok
10:08:33.0345 1300 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
10:08:33.0346 1300 pciide - ok
10:08:33.0360 1300 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
10:08:33.0361 1300 pcmcia - ok
10:08:33.0375 1300 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
10:08:33.0376 1300 pcw - ok
10:08:33.0395 1300 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
10:08:33.0398 1300 PEAUTH - ok
10:08:33.0450 1300 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
10:08:33.0451 1300 PptpMiniport - ok
10:08:33.0466 1300 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
10:08:33.0467 1300 Processor - ok
10:08:33.0501 1300 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
10:08:33.0502 1300 Psched - ok
10:08:33.0541 1300 PxHlpa64 (4712cc14e720ecccc0aa16949d18aaf1) C:\Windows\system32\Drivers\PxHlpa64.sys
10:08:33.0542 1300 PxHlpa64 - ok
10:08:33.0574 1300 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
10:08:33.0583 1300 ql2300 - ok
10:08:33.0596 1300 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
10:08:33.0597 1300 ql40xx - ok
10:08:33.0607 1300 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
10:08:33.0608 1300 QWAVEdrv - ok
10:08:33.0619 1300 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
10:08:33.0620 1300 RasAcd - ok
10:08:33.0670 1300 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
10:08:33.0671 1300 RasAgileVpn - ok
10:08:33.0692 1300 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
10:08:33.0694 1300 Rasl2tp - ok
10:08:33.0720 1300 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
10:08:33.0721 1300 RasPppoe - ok
10:08:33.0735 1300 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
10:08:33.0736 1300 RasSstp - ok
10:08:33.0755 1300 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
10:08:33.0757 1300 rdbss - ok
10:08:33.0765 1300 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
10:08:33.0766 1300 rdpbus - ok
10:08:33.0779 1300 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
10:08:33.0780 1300 RDPCDD - ok
10:08:33.0800 1300 RDPDR (1b6163c503398b23ff8b939c67747683) C:\Windows\system32\drivers\rdpdr.sys
10:08:33.0802 1300 RDPDR - ok
10:08:33.0825 1300 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
10:08:33.0826 1300 RDPENCDD - ok
10:08:33.0835 1300 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
10:08:33.0836 1300 RDPREFMP - ok
10:08:33.0851 1300 RDPWD (15b66c206b5cb095bab980553f38ed23) C:\Windows\system32\drivers\RDPWD.sys
10:08:33.0853 1300 RDPWD - ok
10:08:33.0887 1300 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
10:08:33.0889 1300 rdyboost - ok
10:08:33.0915 1300 RimUsb (71b48ddaf5e9c2b40e64de5c405f5aac) C:\Windows\system32\Drivers\RimUsb_AMD64.sys
10:08:33.0916 1300 RimUsb - ok
10:08:33.0962 1300 RimVSerPort (c903d49655b4aae46673f0aaa6be0f58) C:\Windows\system32\DRIVERS\RimSerial_AMD64.sys
10:08:33.0963 1300 RimVSerPort - ok
10:08:34.0021 1300 ROOTMODEM (388d3dd1a6457280f3badba9f3acd6b1) C:\Windows\system32\Drivers\RootMdm.sys
10:08:34.0022 1300 ROOTMODEM - ok
10:08:34.0050 1300 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
10:08:34.0051 1300 rspndr - ok
10:08:34.0088 1300 RTL8167 (fd978b2bf8a9b2390dcbef435e9c1f9f) C:\Windows\system32\DRIVERS\Rt64win7.sys
10:08:34.0091 1300 RTL8167 - ok
10:08:34.0111 1300 RTL8169 (9f248ef4d204ade0b18dd50e26095cd5) C:\Windows\system32\DRIVERS\Rtlh64.sys
10:08:34.0113 1300 RTL8169 - ok
10:08:34.0129 1300 s3cap (e60c0a09f997826c7627b244195ab581) C:\Windows\system32\drivers\vms3cap.sys
10:08:34.0130 1300 s3cap - ok
10:08:34.0155 1300 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
10:08:34.0156 1300 sbp2port - ok
10:08:34.0177 1300 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
10:08:34.0178 1300 scfilter - ok
10:08:34.0215 1300 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
10:08:34.0216 1300 secdrv - ok
10:08:34.0237 1300 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
10:08:34.0237 1300 Serenum - ok
10:08:34.0246 1300 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
10:08:34.0247 1300 Serial - ok
10:08:34.0260 1300 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
10:08:34.0261 1300 sermouse - ok
10:08:34.0292 1300 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
10:08:34.0293 1300 sffdisk - ok
10:08:34.0305 1300 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
10:08:34.0305 1300 sffp_mmc - ok
10:08:34.0321 1300 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
10:08:34.0322 1300 sffp_sd - ok
10:08:34.0338 1300 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
10:08:34.0339 1300 sfloppy - ok
10:08:34.0355 1300 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
10:08:34.0356 1300 SiSRaid2 - ok
10:08:34.0407 1300 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
10:08:34.0409 1300 SiSRaid4 - ok
10:08:34.0428 1300 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
10:08:34.0430 1300 Smb - ok
10:08:34.0454 1300 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
10:08:34.0454 1300 spldr - ok
10:08:34.0511 1300 sptd (602884696850c86434530790b110e8eb) C:\Windows\system32\Drivers\sptd.sys
10:08:34.0511 1300 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: 602884696850c86434530790b110e8eb
10:08:34.0514 1300 sptd ( LockedFile.Multi.Generic ) - warning
10:08:34.0514 1300 sptd - detected LockedFile.Multi.Generic (1)
10:08:34.0542 1300 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
10:08:34.0545 1300 srv - ok
10:08:34.0566 1300 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
10:08:34.0569 1300 srv2 - ok
10:08:34.0579 1300 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
10:08:34.0581 1300 srvnet - ok
10:08:34.0617 1300 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
10:08:34.0618 1300 stexstor - ok
10:08:34.0652 1300 storflt (7785dc213270d2fc066538daf94087e7) C:\Windows\system32\drivers\vmstorfl.sys
10:08:34.0653 1300 storflt - ok
10:08:34.0677 1300 storvsc (d34e4943d5ac096c8edeebfd80d76e23) C:\Windows\system32\drivers\storvsc.sys
10:08:34.0678 1300 storvsc - ok
10:08:34.0691 1300 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys
10:08:34.0692 1300 swenum - ok
10:08:34.0819 1300 Tcpip (fc62769e7bff2896035aeed399108162) C:\Windows\system32\drivers\tcpip.sys
10:08:34.0833 1300 Tcpip - ok
10:08:34.0879 1300 TCPIP6 (fc62769e7bff2896035aeed399108162) C:\Windows\system32\DRIVERS\tcpip.sys
10:08:34.0892 1300 TCPIP6 - ok
10:08:34.0916 1300 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
10:08:34.0918 1300 tcpipreg - ok
10:08:34.0934 1300 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
10:08:34.0935 1300 TDPIPE - ok
10:08:34.0948 1300 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
10:08:34.0949 1300 TDTCP - ok
10:08:34.0972 1300 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
10:08:34.0973 1300 tdx - ok
10:08:34.0987 1300 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys
10:08:34.0989 1300 TermDD - ok
10:08:35.0030 1300 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
10:08:35.0031 1300 tssecsrv - ok
10:08:35.0066 1300 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
10:08:35.0073 1300 TsUsbFlt - ok
10:08:35.0106 1300 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
10:08:35.0108 1300 tunnel - ok
10:08:35.0160 1300 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
10:08:35.0161 1300 uagp35 - ok
10:08:35.0185 1300 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
10:08:35.0188 1300 udfs - ok
10:08:35.0216 1300 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
10:08:35.0218 1300 uliagpkx - ok
10:08:35.0246 1300 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\drivers\umbus.sys
10:08:35.0248 1300 umbus - ok
10:08:35.0263 1300 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
10:08:35.0264 1300 UmPass - ok
10:08:35.0335 1300 USBAAPL64 (aa33fc47ed58c34e6e9261e4f850b7eb) C:\Windows\system32\Drivers\usbaapl64.sys
10:08:35.0336 1300 USBAAPL64 - ok
10:08:35.0365 1300 usbaudio (82e8f44688e6fac57b5b7c6fc7adbc2a) C:\Windows\system32\drivers\usbaudio.sys
10:08:35.0367 1300 usbaudio - ok
10:08:35.0387 1300 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
10:08:35.0389 1300 usbccgp - ok
10:08:35.0444 1300 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
10:08:35.0446 1300 usbcir - ok
10:08:35.0470 1300 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\drivers\usbehci.sys
10:08:35.0471 1300 usbehci - ok
10:08:35.0492 1300 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
10:08:35.0494 1300 usbhub - ok
10:08:35.0524 1300 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys
10:08:35.0525 1300 usbohci - ok
10:08:35.0551 1300 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
10:08:35.0552 1300 usbprint - ok
10:08:35.0573 1300 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
10:08:35.0574 1300 usbscan - ok
10:08:35.0591 1300 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
10:08:35.0593 1300 USBSTOR - ok
10:08:35.0611 1300 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\drivers\usbuhci.sys
10:08:35.0612 1300 usbuhci - ok
10:08:35.0652 1300 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
10:08:35.0654 1300 vdrvroot - ok
10:08:35.0671 1300 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
10:08:35.0672 1300 vga - ok
10:08:35.0688 1300 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
10:08:35.0689 1300 VgaSave - ok
10:08:35.0706 1300 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
10:08:35.0708 1300 vhdmp - ok
10:08:35.0722 1300 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
10:08:35.0723 1300 viaide - ok
10:08:35.0733 1300 vmbus (86ea3e79ae350fea5331a1303054005f) C:\Windows\system32\drivers\vmbus.sys
10:08:35.0735 1300 vmbus - ok
10:08:35.0748 1300 VMBusHID (7de90b48f210d29649380545db45a187) C:\Windows\system32\drivers\VMBusHID.sys
10:08:35.0749 1300 VMBusHID - ok
10:08:35.0769 1300 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
10:08:35.0770 1300 volmgr - ok
10:08:35.0833 1300 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
10:08:35.0836 1300 volmgrx - ok
10:08:35.0860 1300 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
10:08:35.0863 1300 volsnap - ok
10:08:35.0887 1300 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
10:08:35.0888 1300 vsmraid - ok
10:08:35.0932 1300 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
10:08:35.0933 1300 vwifibus - ok
10:08:35.0950 1300 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
10:08:35.0952 1300 vwififlt - ok
10:08:35.0973 1300 vwifimp (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys
10:08:35.0974 1300 vwifimp - ok
10:08:35.0999 1300 wacmoumonitor (fe75777289278a4941fe6139e82b3bd9) C:\Windows\system32\DRIVERS\wacmoumonitor.sys
10:08:35.0999 1300 wacmoumonitor - ok
10:08:36.0020 1300 wacommousefilter (e04d43c7d1641e95d35cae6086c7e350) C:\Windows\system32\DRIVERS\wacommousefilter.sys
10:08:36.0021 1300 wacommousefilter - ok
10:08:36.0075 1300 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
10:08:36.0076 1300 WacomPen - ok
10:08:36.0128 1300 wacomvhid (ec1ceb237e365330c1fcfc4876aa0ac0) C:\Windows\system32\DRIVERS\wacomvhid.sys
10:08:36.0129 1300 wacomvhid - ok
10:08:36.0154 1300 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
10:08:36.0155 1300 WANARP - ok
10:08:36.0160 1300 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
10:08:36.0161 1300 Wanarpv6 - ok
10:08:36.0207 1300 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
10:08:36.0208 1300 Wd - ok
10:08:36.0262 1300 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
10:08:36.0267 1300 Wdf01000 - ok
10:08:36.0321 1300 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
10:08:36.0322 1300 WfpLwf - ok
10:08:36.0335 1300 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
10:08:36.0336 1300 WIMMount - ok
10:08:36.0384 1300 WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys
10:08:36.0385 1300 WinUsb - ok
10:08:36.0405 1300 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
10:08:36.0405 1300 WmiAcpi - ok
10:08:36.0426 1300 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
10:08:36.0427 1300 ws2ifsl - ok
10:08:36.0455 1300 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
10:08:36.0456 1300 WudfPf - ok
10:08:36.0470 1300 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
10:08:36.0471 1300 WUDFRd - ok
10:08:36.0505 1300 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
10:08:36.0525 1300 \Device\Harddisk0\DR0 - ok
10:08:36.0527 1300 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk1\DR1
10:08:36.0528 1300 \Device\Harddisk1\DR1 - ok
10:08:36.0530 1300 Boot (0x1200) (fe92993095c2ce132df4a8e36b4e24da) \Device\Harddisk0\DR0\Partition0
10:08:36.0531 1300 \Device\Harddisk0\DR0\Partition0 - ok
10:08:36.0533 1300 Boot (0x1200) (c7a93779290510805c8d1b220a7f9771) \Device\Harddisk1\DR1\Partition0
10:08:36.0534 1300 \Device\Harddisk1\DR1\Partition0 - ok
10:08:36.0534 1300 ============================================================
10:08:36.0534 1300 Scan finished
10:08:36.0534 1300 ============================================================
10:08:36.0540 7380 Detected object count: 1
10:08:36.0540 7380 Actual detected object count: 1
10:08:42.0245 7380 sptd ( LockedFile.Multi.Generic ) - skipped by user
10:08:42.0245 7380 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
10:08:54.0552 3040 Deinitialize success


ComboFix Log


ComboFix 12-03-02.01 - sly 03/03/2012 10:43:50.1.8 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.6134.3842 [GMT -8:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\sly\AppData\Roaming\Help\coredb\storage
c:\users\sly\AppData\Roaming\Identities\{9EBCF0DF-4D36-42BB-8EFE-BE9500FCE19E}\LicenseValidator.exe
c:\users\sly\AppData\Roaming\sly3SQLite3.dll
c:\users\sly\AppData\Roaming\slylog.dat
E:\1136_8282935_MVM_0.tmp
E:\1136_8282935_MVM_1.tmp
E:\1136_8282935_MVM_2.tmp
E:\1136_8282935_MVM_3.tmp
E:\1136_8282935_MVM_4.tmp
E:\1136_8282935_MVM_5.tmp
E:\1136_8282935_MVM_6.tmp
E:\1136_8282935_MVM_9.tmp
E:\1720_12348321_MVM_0.tmp
E:\1720_12348321_MVM_1.tmp
E:\1720_12348321_MVM_11.tmp
E:\1720_12348321_MVM_2.tmp
E:\1720_12348321_MVM_3.tmp
E:\1720_12348321_MVM_4.tmp
E:\1720_12348321_MVM_5.tmp
E:\1720_12348321_MVM_6.tmp
E:\1720_12348321_MVM_7.tmp
E:\4380_10581984_MVM_0.tmp
E:\4380_10581984_MVM_1.tmp
E:\4380_10581984_MVM_2.tmp
E:\4380_10581984_MVM_3.tmp
E:\4380_10581984_MVM_4.tmp
E:\4380_10581984_MVM_5.tmp
E:\4380_10581984_MVM_6.tmp
E:\4380_10581984_MVM_9.tmp
E:\6156_11811163_MVM_0.tmp
E:\6156_11811163_MVM_1.tmp
E:\6156_11811163_MVM_2.tmp
E:\6156_11811163_MVM_3.tmp
E:\6156_11811163_MVM_4.tmp
E:\6156_11811163_MVM_5.tmp
E:\6156_11811163_MVM_6.tmp
E:\6156_11811163_MVM_9.tmp
E:\7264_15165605_MVM_0.tmp
E:\7264_15165605_MVM_1.tmp
E:\7264_15165605_MVM_10.tmp
E:\7264_15165605_MVM_2.tmp
E:\7264_15165605_MVM_3.tmp
E:\7264_15165605_MVM_4.tmp
E:\7264_15165605_MVM_5.tmp
E:\7264_15165605_MVM_6.tmp
E:\7264_15165605_MVM_7.tmp
E:\install.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-02-03 to 2012-03-03 )))))))))))))))))))))))))))))))
.
.
2012-03-02 08:56 . 2012-03-02 08:56 ——– d—–w- c:\program files (x86)\Common Files\Java
2012-03-01 19:52 . 2012-03-01 19:52 ——– d—–w- c:\users\sly\AppData\Roaming\Google Inc
2012-03-01 08:56 . 2012-03-01 08:56 1124574 —-a-w- C:\cc_20120301_005612.reg
2012-03-01 08:46 . 2012-03-01 08:46 ——– d—–w- c:\program files\CCleaner
2012-02-29 06:04 . 2012-03-02 09:10 ——– d—–w- c:\users\sly\AppData\Roaming\TeamViewer
2012-02-15 02:08 . 2012-01-04 10:44 509952 —-a-w- c:\windows\system32\ntshrui.dll
2012-02-15 02:08 . 2012-01-04 08:58 442880 —-a-w- c:\windows\SysWow64\ntshrui.dll
2012-02-15 02:08 . 2012-01-14 04:06 3145728 —-a-w- c:\windows\system32\win32k.sys
2012-02-15 02:08 . 2011-12-30 06:26 515584 —-a-w- c:\windows\system32\timedate.cpl
2012-02-15 02:08 . 2011-12-30 05:27 478720 —-a-w- c:\windows\SysWow64\timedate.cpl
2012-02-15 02:08 . 2011-12-28 03:59 498688 —-a-w- c:\windows\system32\drivers\afd.sys
2012-02-15 02:08 . 2011-12-16 08:46 634880 —-a-w- c:\windows\system32\msvcrt.dll
2012-02-15 02:08 . 2011-12-16 07:52 690688 —-a-w- c:\windows\SysWow64\msvcrt.dll
2012-02-07 05:52 . 2012-02-07 05:52 ——– d—–w- c:\programdata\bdch
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-03-03 19:04 . 2011-05-23 15:39 557511 —-a-w- c:\programdata\bdinstall.bin
2012-03-02 08:55 . 2010-04-19 01:04 472808 —-a-w- c:\windows\SysWow64\deployJava1.dll
2012-02-17 16:49 . 2011-05-14 22:21 414368 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-01-23 17:27 . 2012-01-23 17:27 53248 —-a-r- c:\users\sly\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2010-07-08 18:37 . 2010-07-08 18:37 101544 —-a-w- c:\program files\Common Files\LinkInstaller.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\progra~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608]
"Messenger (Yahoo!)"="c:\progra~2\Yahoo!\MESSEN~1\YahooMessenger.exe" [2010-06-01 5252408]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"GBMLite8AgentLaCie"="c:\program files (x86)\LaCie\Genie Backup Assistant\GBMAgent.exe" [2008-09-18 189056]
"taskhost.exe"="c:\users\sly\AppData\Roaming\System\taskhost.exe" [2005-04-19 1169224]
"googletalk"="c:\users\sly\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-10-13 17351304]
"Akamai NetSession Interface"="c:\users\sly\AppData\Local\Akamai\netsession_win.exe" [2012-02-02 3329824]
"Logitech Vid"="c:\program files (x86)\Logitech\Vid HD\Vid.exe" [2010-10-29 5915480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-23 150528]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [2010-10-25 36760]
"Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [2010-10-25 821144]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-01-22 91520]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2011\Antispam32\ieshow.exe" [2011-01-11 71216]
"RIMBBLaunchAgent.exe"="c:\program files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe" [2011-02-18 79192]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-02 59240]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360]
"LWS"="c:\program files (x86)\Logitech\LWS\Webcam Software\LWS.exe" [2011-08-12 205336]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-01-17 421736]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
forteManager.lnk - c:\program files (x86)\Drivers\LG Soft India\forteManager\bin\Monitor.exe [2009-8-8 1687552]
HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336]
Logitech SetPoint.lnk - c:\program files (x86)\Drivers\Logitech\SetPoint\SetPoint.exe [2009-8-8 1207312]
Pidgin.lnk - c:\program files (x86)\Pidgin\pidgin.exe [2010-8-10 49321]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 avc3;avc3;c:\windows\system32\DRIVERS\avc3.sys [x]
R3 avckf;avckf;c:\windows\system32\DRIVERS\avckf.sys [x]
R3 CompFilter64;UVCCompositeFilter;c:\windows\system32\DRIVERS\lvbflt64.sys [x]
R3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\DRIVERS\ivusb.sys [x]
R3 LGDDCDevice;LGDDCDevice;c:\program files (x86)\Drivers\LG Soft India\forteManager\bin\I2CDriver.sys [2008-12-12 14336]
R3 LGII2CDevice;LGII2CDevice;c:\program files (x86)\Drivers\LG Soft India\forteManager\bin\PII2CDriver.sys [2008-12-12 18432]
R3 LVPr2M64;Logitech LVPr2M64 Driver;c:\windows\system32\DRIVERS\LVPr2M64.sys [x]
R3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys [x]
R3 LVUVC64;Logitech HD Pro Webcam C910(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys [x]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-01-22 30963576]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]
R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 Update Server;BitDefender Update Server v2;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe [2010-11-30 467248]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 Bdfndisf;BitDefender Firewall NDIS 6 Filter Driver;c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [2010-08-20 88144]
S1 bdfwfpf;bdfwfpf;c:\program files\Common Files\BitDefender\BitDefender Firewall\bdfwfpf.sys [2010-08-21 99408]
S1 Bdvedisk;Bdvedisk;c:\windows\system32\DRIVERS\bdvedisk.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136]
S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.00\AsSysCtrlService.exe [2008-08-15 86016]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-15 2253120]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-15 381248]
S2 TabletServiceWacom;TabletServiceWacom;c:\program files\Tablet\Wacom\Wacom_Tablet.exe [2011-06-06 6438264]
S2 UMVPFSrv;UMVPFSrv;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2011-08-19 450848]
S2 UPDATESRV;BitDefender Desktop Update Service;c:\program files\BitDefender\BitDefender 2011\updatesrv.exe [2011-03-25 53224]
S3 bdfm;bdfm;c:\windows\system32\DRIVERS\bdfm.sys [x]
S3 DKRtWrt;DKRtWrt;c:\windows\system32\DRIVERS\DKRtWrt.sys [x]
S3 netr28ux;RT2870 USB Extensible Wireless LAN Card Driver;c:\windows\system32\DRIVERS\netr28ux.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder
.
2012-03-03 c:\windows\Tasks\GBM - Easy Layout Backup Job-Full.job
- c:\program files (x86)\LaCie\Genie Backup Assistant\GBM8.exe [2010-07-28 10:57]
.
2012-03-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2825036124-2352061616-2705343857-1000Core.job
- c:\users\sly\AppData\Local\Google\Update\GoogleUpdate.exe [2009-08-09 15:27]
.
2012-03-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2825036124-2352061616-2705343857-1000UA.job
- c:\users\sly\AppData\Local\Google\Update\GoogleUpdate.exe [2009-08-09 15:27]
.
.
——— x86-64 ———–
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RAVCpl64.exe" [2008-07-03 6430208]
"Skytel"="Skytel.exe" [2008-06-25 1826816]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 130576]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-30 499608]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2011\ieshow.exe" [2011-01-11 76360]
"BDAgent"="c:\program files\BitDefender\BitDefender 2011\bdagent.exe" [2011-03-31 2011224]
"combofix"="c:\combofix\CF9820.3XE" [2010-11-20 345088]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
——- Supplementary Scan ——-
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local;127.0.0.1:9421;
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Append Link Target to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~2\Office14\ONBttnIE.dll/105
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\sly\AppData\Roaming\Mozilla\Firefox\Profiles\ks3zdvup.default\
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKCU-Run-LicenseValidator - c:\users\sly\AppData\Roaming\Identities\{9EBCF0DF-4D36-42BB-8EFE-BE9500FCE19E}\LicenseValidator.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Akamai]
"ServiceDll"="c:\program files (x86)\common files\akamai/netsession_win_7de0ed9.dll"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10x_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10x_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10x.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10x.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10x.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10x.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
———————— Other Running Processes ————————
.
c:\program files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
c:\program files\BitDefender\BitDefender 2011\Antispam32\pchooklaunch32.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\ASUS\Six Engine\SixEngine.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
.
**************************************************************************
.
Completion time: 2012-03-03 11:17:20 - machine was rebooted
ComboFix-quarantined-files.txt 2012-03-03 19:17
.
Pre-Run: 198,459,990,016 bytes free
Post-Run: 187,794,243,584 bytes free
.
- - End Of File - - 80DB26432B1CA23A46794FFB3C4404DC
COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    DDS::
    uInternet Settings,ProxyOverride = *.local;127.0.0.1:9421;
    
    DirLook::
    c:\programdata\bdch
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.






Next


Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the log please











Next

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is checked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the Back button.
  • Push Finish
http://www.eset.com/onlinescan/





Also tell me how the computer is running now.
When I dragged the CFScript.txt to the ComboFix Cat Icon, it opens the initial window and then closed. Then, nothing happened. I had expected that it will pop up a Blue window like the first time I used ComboFix to scan the computer but alas, nothing so far. Should I wait or retry?
I've ran both Malwarebytes and ESET, the ComboFix window has not appeared so far.

The system has been running smoothly after the very first ComboFix run and did not show any sign of the crash problems so far.

Attached are the two logs from Malwarebytes and Eset.

Please let me know if I should retry running the ComboFix-Script again.


Malwarebytes Log


Malwarebytes Anti-Malware (Trial) 1.60.1.1000
www.malwarebytes.org

Database version: v2012.03.04.01

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
sly :: HANSLEY-PC [administrator]

Protection: Enabled

3/3/2012 5:21:31 PM
mbam-log-2012-03-03 (17-21-31).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 217390
Time elapsed: 2 minute(s), 38 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 1
HKCU\SOFTWARE\CYBER (Backdoor.Trace) -> Quarantined and deleted successfully.

Registry Values Detected: 1
HKCU\Software\Cyber|FirstExecution (Backdoor.Trace) -> Data: 05/10/2010 – 15:31 -> Quarantined and deleted successfully.

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)


Eset Log


C:\Qoobox\Quarantine\C\Users\sly\AppData\Roaming\Identities\{9EBCF0DF-4D36-42BB-8EFE-BE9500FCE19E}\LicenseValidator.exe.vir a variant of Win32/Kryptik.ABPE trojan cleaned by deleting - quarantined
We will do the script with OTL instead.



Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :Otl
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;127.0.0.1:9421;
    O4 - HKLM..\Run: [] File not found
    @Alternate Data Stream - 1243 bytes -> C:\Users\sly\AppData\Local\Temp:kvGL6aJIXvCIAINCN9lmuG3
    
    
    :Commands
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
OTL Log


All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ not found.
ADS C:\Users\sly\AppData\Local\Temp:kvGL6aJIXvCIAINCN9lmuG3 deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 56466 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

User: sly
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 4822197 bytes
->Java cache emptied: 20824038 bytes
->FireFox cache emptied: 53411717 bytes
->Google Chrome cache emptied: 368383751 bytes
->Flash cache emptied: 59561 bytes

User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 56466 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 84410 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 52854 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 427.00 mb


OTL by OldTimer - Version 3.2.34.0 log created on 03042012_080247

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…
You appear clean of infections,please do the following.

Delete TDSSKiller and ESET.



ComboFix - Cleanup
Time for some housekeeping
  • Click Start…select Run from the menu.
  • Copy and paste the following into the text entry box:
    Combofix /Uninstall
  • Click the OK button. (See image below as reference.)
🖼Click to load external image (Posted Image)









Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.









Here are some recommendations to help you stay clean.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Visit Microsoft often to get the latest updates for your computer.
http://www.update.microsoft.com/



Make sure you are running a FIREWALL.The windows firewall is not sufficient to protect your system. It doesn't monitor outgoing traffic and this is a must.
Please read this article 'Safe Computing Practices'.
So how did I get infected in the first place.

please take a moment to read quietman7's excellent prevention tips in post 3 here
Click >>>> Tips to protect yourself against malware and reduce the potential for re-infection:

Preventing Infections in the Future

Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

  • Avoid gaming sites, underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users. The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications. Read P2P Software User Advisories and Risks of File-Sharing Technology.

Update Non-Microsoft Programs

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.


Thats it you are good to go.Safe surfing
I have removed all the .exes and now my system is running smoothly. Thank you so much for the assistance. You may close this thread, if the problem reoccur, I'll post a new thread. THANK YOU!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI