This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

about:blank

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My anti-virus program recently expired June 7, Defender Pro 2011 5-in-1, I bought Defender Pro 2012 that same day down loaded and when it installed I got about:blank, I haven't been able to remove it. I appreciate any help to remove it.

ijackThis v2.0.4
Scan saved at 2:57:28 PM, on 6/11/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\HughesNet Download Manager\HDM.exe
C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
C:\Program Files (x86)\HughesNetStatusMeter\HughesNetStatusMeter\HughesNetStatusMeter.exe
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_2_202_235_ActiveX.exe
C:\Users\Steve\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: HDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\HughesNet Download Manager\iefdm2.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Dell Registration] C:\Program Files (x86)\System Registration\prodreg.exe /boot
O4 - HKLM\..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"
O4 - HKLM\..\Run: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe"
O4 - HKLM\..\Run: [CanonSolutionMenuEx] C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
O4 - HKLM\..\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"
O4 - HKCU\..\Run: [HughesNet Download Manager] "C:\Program Files (x86)\HughesNet Download Manager\HDM.exe" -autorun
O4 - HKCU\..\Run: [PC MightyMax 2011 Tray Icon] "C:\Users\Steve\AppData\Local\PC MightyMax 2012\TrayIcon.exe"
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O4 - Startup: HughesNetStatusMeter.lnk = C:\Program Files (x86)\HughesNetStatusMeter\HughesNetStatusMeter\HughesNetStatusMeter.exe
O4 - Global Startup: Secunia PSI Tray.lnk = C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
O8 - Extra context menu item: Download all with HughesNet Download Manager - file://C:\Program Files (x86)\HughesNet Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with HughesNet Download Manager - file://C:\Program Files (x86)\HughesNet Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with HughesNet Download Manager - file://C:\Program Files (x86)\HughesNet Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with HughesNet Download Manager - file://C:\Program Files (x86)\HughesNet Download Manager\dllink.htm
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {EF7ADE47-9668-42A5-A350-0945E51AB8E6} (InstallerHelper Class) - http://www.pcmightymax.net/ext/PCMMInstaller.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent\Dell Games\Dell Game Console\GameConsoleService.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel® Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Dell DataSafe Online (NOBU) - Dell, Inc. - C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: RoxMediaDB12OEM - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe
O23 - Service: Roxio Hard Drive Watcher 12 (RoxWatch12) - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Secunia PSI Agent - Secunia - C:\Program Files (x86)\Secunia\PSI\PSIA.exe
O23 - Service: Secunia Update Agent - Secunia - C:\Program Files (x86)\Secunia\PSI\sua.exe
O23 - Service: SoftThinks Agent Service (SftService) - SoftThinks SAS - C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: BitDefender Update Server v2 (Update Server) - Defender Pro - C:\Program Files\Common Files\Defender Pro\Defender Pro Arrakis Server\bin\arrakis3.exe
O23 - Service: Defender Pro Desktop Update Service (UPDATESRV) - Defender Pro - C:\Program Files\Defender Pro\Defender Pro\updatesrv.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: Defender Pro Virus Shield (VSSERV) - Defender Pro - C:\Program Files\Defender Pro\Defender Pro\vsserv.exe
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 11689 bytes
Hello ShadyGrove and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===============================================

HijackThis doesn’t really work well with Windows 7 so we’ll need a couple more scans to see if this problem is malware-related.

Download and run OTL
  • download OTL to your desktop.
  • double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • click Scan all users.
  • under Custom Scan paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    consrv.dll
    /md5stop
    %systemroot%\*. /rp /s
    DRIVES
    CREATERESTOREPOINT

  • click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long.
  • when the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • you may need two posts to fit them both in.
===================================================

Run aswMBR
  • download aswMBR.exe to your desktop.
  • double click the aswMBR.exe to run it
  • if asked, accept the AVAST virus definition download
  • click the "Scan" button to start scan
  • on completion of the scan click Save log, save it to your desktop and post in your next reply
Logs to include with next post:

OTL.txt
Extras.txt
aswMBR log


Thanks

Satchfan
OTL logfile created on: 6/12/2012 12:30:19 PM - Run 1
OTL by OldTimer - Version 3.2.48.0 Folder = C:\Users\Steve\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.97 Gb Total Physical Memory | 2.57 Gb Available Physical Memory | 64.92% Memory free
7.93 Gb Paging File | 6.25 Gb Available in Paging File | 78.77% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 684.79 Gb Total Space | 631.22 Gb Free Space | 92.18% Space Free | Partition Type: NTFS
Drive D: | 25.96 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: SHADY94GROVE | User Name: Steve | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/06/12 12:28:08 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Users\Steve\Desktop\OTL.exe
PRC - [2012/06/12 12:06:13 | 001,533,976 | —- | M] (Google Inc.) – C:\Windows\Temp\CR_E39C0.tmp\setup.exe
PRC - [2012/06/12 12:06:12 | 001,464,232 | —- | M] () – C:\Program Files (x86)\Google\Update\Install\{40C5AC13-C45D-4367-850F-7A9A78651D3D}\chrome_updater.exe
PRC - [2012/05/22 17:03:33 | 000,351,904 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_2_202_235_ActiveX.exe
PRC - [2012/03/14 16:00:12 | 000,142,336 | —- | M] () – C:\Program Files (x86)\HughesNetStatusMeter\HughesNetStatusMeter\HughesNetStatusMeter.exe
PRC - [2011/10/14 01:01:50 | 000,994,360 | —- | M] (Secunia) – C:\Program Files (x86)\Secunia\PSI\psia.exe
PRC - [2011/10/14 01:01:48 | 000,399,416 | —- | M] (Secunia) – C:\Program Files (x86)\Secunia\PSI\sua.exe
PRC - [2011/10/14 01:01:46 | 000,291,896 | —- | M] (Secunia) – C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
PRC - [2011/10/01 09:30:22 | 000,219,496 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2011/10/01 09:30:18 | 000,508,776 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2011/01/13 13:54:26 | 000,464,856 | —- | M] (SoftThinks - Dell) – C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
PRC - [2011/01/13 13:42:12 | 003,811,648 | —- | M] (SoftThinks - Dell) – C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
PRC - [2011/01/13 13:39:32 | 000,783,680 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
PRC - [2011/01/13 13:37:02 | 000,705,856 | —- | M] (SoftThinks SAS) – C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
PRC - [2010/11/17 11:35:34 | 000,514,544 | —- | M] () – C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
PRC - [2010/04/02 10:18:54 | 001,185,112 | —- | M] (CANON INC.) – C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE
PRC - [2010/03/03 21:16:06 | 000,013,336 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2010/03/03 21:16:04 | 000,284,696 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
PRC - [2009/10/26 19:10:36 | 003,563,566 | —- | M] (HughesNet.com) – C:\Program Files (x86)\HughesNet Download Manager\HDM.exe
PRC - [2009/06/09 09:11:14 | 000,155,648 | —- | M] (Stardock Corporation) – C:\Program Files\Dell\DellDock\DockLogin.exe


========== Modules (No Company Name) ==========

MOD - [2012/05/11 03:38:04 | 002,297,856 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\dfd33f59a5803a3c73cf408362e6e0b7\System.Core.ni.dll
MOD - [2012/05/11 03:37:09 | 000,452,608 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\635b3aec298ad5e8c903b2323d79cc5a\IAStorUtil.ni.dll
MOD - [2012/05/11 03:28:24 | 000,368,128 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\8e56489276063ededde74e597a121df3\PresentationFramework.Aero.ni.dll
MOD - [2012/05/11 03:28:12 | 000,771,584 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll
MOD - [2012/05/11 03:28:04 | 014,340,608 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\07f019692c382d588d3c6cb2da2a9ec5\PresentationFramework.ni.dll
MOD - [2012/05/11 03:27:53 | 012,433,408 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\90555968565afd59bce4b0974e9903bd\System.Windows.Forms.ni.dll
MOD - [2012/05/11 03:27:48 | 001,590,784 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\69f6e582cb79f107c61308b468c1a215\System.Drawing.ni.dll
MOD - [2012/05/11 03:27:46 | 012,237,824 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\2d1fd350e9bc62ce659e5cbcfd555796\PresentationCore.ni.dll
MOD - [2012/05/11 03:27:38 | 003,347,968 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll
MOD - [2012/05/11 03:27:34 | 005,452,800 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll
MOD - [2012/05/11 03:27:31 | 007,967,232 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll
MOD - [2012/05/11 03:27:31 | 000,971,264 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll
MOD - [2012/05/11 03:27:25 | 011,492,864 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll
MOD - [2012/03/14 16:00:12 | 000,142,336 | —- | M] () – C:\Program Files (x86)\HughesNetStatusMeter\HughesNetStatusMeter\HughesNetStatusMeter.exe
MOD - [2012/02/28 08:52:47 | 004,770,176 | —- | M] () – c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\WebKit.dll
MOD - [2011/01/13 13:42:02 | 000,025,920 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Local Backup\SftBRCCPiped.dll
MOD - [2011/01/13 13:39:32 | 000,783,680 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
MOD - [2011/01/13 13:37:50 | 000,079,168 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Local Backup\zlib1.dll
MOD - [2011/01/13 13:37:26 | 000,075,072 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Local Backup\STRegistry.dll
MOD - [2011/01/13 13:37:24 | 000,111,936 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Local Backup\STPE.dll
MOD - [2011/01/13 13:37:20 | 000,121,152 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Local Backup\STNLS.dll
MOD - [2011/01/13 13:37:18 | 000,128,320 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Local Backup\STLog.dll
MOD - [2011/01/13 13:37:14 | 000,234,816 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Local Backup\STFiles.dll
MOD - [2011/01/13 13:37:04 | 000,025,920 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Local Backup\STBRCCServCLR.dll
MOD - [2011/01/13 13:36:50 | 001,123,648 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Local Backup\libxml2.dll
MOD - [2010/11/24 23:44:02 | 000,375,280 | —- | M] () – c:\Program Files (x86)\Common Files\Roxio Shared\DLLShared\SQLite352.dll
MOD - [2010/11/17 11:35:34 | 000,514,544 | —- | M] () – C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
MOD - [2009/08/19 11:16:06 | 000,094,208 | —- | M] () – C:\Program Files (x86)\HughesNet Download Manager\iefdm2.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2011/08/02 13:25:14 | 001,885,576 | —- | M] (Defender Pro) [Auto | Running] – C:\Program Files\Defender Pro\Defender Pro\vsserv.exe – (VSSERV)
SRV:64bit: - [2011/08/02 13:25:08 | 000,062,512 | —- | M] (Defender Pro) [Auto | Running] – C:\Program Files\Defender Pro\Defender Pro\updatesrv.exe – (UPDATESRV)
SRV:64bit: - [2011/08/02 13:22:20 | 000,466,736 | —- | M] (Defender Pro) [On_Demand | Stopped] – C:\Program Files\Common Files\Defender Pro\Defender Pro Arrakis Server\bin\arrakis3.exe – (Update Server)
SRV:64bit: - [2010/09/22 19:10:10 | 000,057,184 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe – (wlcrasvc)
SRV:64bit: - [2009/07/13 20:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2009/06/09 09:11:14 | 000,155,648 | —- | M] (Stardock Corporation) [Auto | Running] – C:\Program Files\Dell\DellDock\DockLogin.exe – (DockLoginService)
SRV - [2012/05/22 17:03:33 | 000,257,696 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2011/10/14 01:01:50 | 000,994,360 | —- | M] (Secunia) [Auto | Running] – C:\Program Files (x86)\Secunia\PSI\psia.exe – (Secunia PSI Agent)
SRV - [2011/10/14 01:01:48 | 000,399,416 | —- | M] (Secunia) [Auto | Running] – C:\Program Files (x86)\Secunia\PSI\sua.exe – (Secunia Update Agent)
SRV - [2011/10/01 09:30:22 | 000,219,496 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe – (sftvsa)
SRV - [2011/10/01 09:30:18 | 000,508,776 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe – (sftlist)
SRV - [2011/02/22 22:19:38 | 000,016,680 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe – (GoToAssist)
SRV - [2011/01/13 13:37:02 | 000,705,856 | —- | M] (SoftThinks SAS) [Auto | Running] – C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe – (SftService)
SRV - [2010/11/25 06:34:18 | 000,219,632 | —- | M] (Sonic Solutions) [Auto | Stopped] – C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe – (RoxWatch12)
SRV - [2010/11/25 06:33:18 | 001,116,656 | —- | M] (Sonic Solutions) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe – (RoxMediaDB12OEM)
SRV - [2010/08/25 21:28:54 | 002,823,000 | —- | M] (Dell, Inc.) [Auto | Running] – C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe – (NOBU)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2010/03/03 21:16:06 | 000,013,336 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe – (IAStorDataMgrSvc) Intel®
SRV - [2009/06/10 16:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2009/06/05 19:07:28 | 000,250,616 | —- | M] (WildTangent, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\WildTangent\Dell Games\Dell Game Console\GameConsoleService.exe – (GameConsoleService)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/03/01 01:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2011/10/01 09:30:22 | 000,022,376 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Sftvollh.sys – (Sftvol)
DRV:64bit: - [2011/10/01 09:30:18 | 000,268,648 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Sftplaylh.sys – (Sftplay)
DRV:64bit: - [2011/10/01 09:30:18 | 000,025,960 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\Sftredirlh.sys – (Sftredir)
DRV:64bit: - [2011/10/01 09:30:10 | 000,764,264 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Sftfslh.sys – (Sftfs)
DRV:64bit: - [2011/07/22 20:20:05 | 000,288,600 | —- | M] (BitDefender S.R.L.) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\trufos.sys – (trufos)
DRV:64bit: - [2011/07/15 16:12:46 | 000,550,208 | —- | M] (BitDefender) [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\avckf.sys – (avckf)
DRV:64bit: - [2011/07/15 16:12:44 | 000,258,224 | —- | M] (BitDefender) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\avchv.sys – (avchv)
DRV:64bit: - [2011/07/15 16:12:42 | 000,674,904 | —- | M] (BitDefender) [File_System | Boot | Running] – C:\Windows\SysNative\drivers\avc3.sys – (avc3)
DRV:64bit: - [2011/06/17 19:54:46 | 000,079,952 | —- | M] (Windows ® Win 7 DDK provider) [File_System | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bdsandbox.sys – (bdsandbox)
DRV:64bit: - [2011/03/24 15:36:22 | 000,431,176 | —- | M] (BitDefender) [File_System | Boot | Running] – C:\Windows\SysNative\drivers\bdfsfltr.sys – (bdfsfltr)
DRV:64bit: - [2011/03/11 01:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/11 01:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2011/03/01 17:45:46 | 000,089,680 | —- | M] (BitDefender LLC) [Kernel | System | Running] – c:\Program Files\Common Files\Defender Pro\Defender Pro Firewall\bdfndisf6.sys – (BdfNdisf)
DRV:64bit: - [2011/03/01 17:45:42 | 000,102,992 | —- | M] (BitDefender LLC) [Kernel | System | Running] – C:\Program Files\Common Files\Defender Pro\Defender Pro Firewall\bdfwfpf.sys – (bdfwfpf)
DRV:64bit: - [2010/11/20 08:33:35 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/20 06:07:05 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/11/20 05:43:57 | 000,032,768 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbser.sys – (usbser)
DRV:64bit: - [2010/09/01 03:30:58 | 000,017,976 | —- | M] (Secunia) [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\psi_mf.sys – (PSI)
DRV:64bit: - [2010/03/19 04:00:00 | 000,055,856 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\PxHlpa64.sys – (PxHlpa64)
DRV:64bit: - [2010/01/19 19:32:40 | 000,103,944 | —- | M] (BitDefender) [Kernel | System | Running] – C:\Windows\SysNative\drivers\bdvedisk.sys – (BDVEDISK)
DRV:64bit: - [2009/07/30 22:58:42 | 000,236,544 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2009/07/13 20:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 20:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 20:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/07/03 12:42:08 | 007,342,432 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 15:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/06/04 21:54:36 | 000,408,600 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [2009/05/26 07:13:10 | 000,138,752 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcHdmi.sys – (IntcHdmiAddService) Intel®
DRV:64bit: - [2006/11/01 13:51:00 | 000,151,656 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysNative\drivers\WimFltr.sys – (WimFltr)
DRV - [2010/07/09 15:08:14 | 000,327,368 | —- | M] (BitDefender) [File_System | Boot | Running] – C:\Windows\SysWOW64\drivers\bdfsfltr.sys – (bdfsfltr)
DRV - [2009/07/13 20:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {49606DC7-976D-4030-A74E-9FB5C842FA68}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{49606DC7-976D-4030-A74E-9FB5C842FA68}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope = {49606DC7-976D-4030-A74E-9FB5C842FA68}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{49606DC7-976D-4030-A74E-9FB5C842FA68}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-4285281043-2332145131-3178257145-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://home.myhughesnet.com/?inc=1 [binary data]
IE - HKU\S-1-5-21-4285281043-2332145131-3178257145-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-4285281043-2332145131-3178257145-1000\..\SearchScopes,DefaultScope = {49606DC7-976D-4030-A74E-9FB5C842FA68}
IE - HKU\S-1-5-21-4285281043-2332145131-3178257145-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKU\S-1-5-21-4285281043-2332145131-3178257145-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin.dll (Amazon.com, Inc.)



========== Chrome ==========

CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\19.0.1084.52\gcswf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.230.5 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U23 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Chrome NaCl (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\19.0.1084.52\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\19.0.1084.52\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin

O1 HOSTS File: ([2009/06/10 16:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (HDMIECookiesBHO Class) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\HughesNet Download Manager\iefdm2.dll ()
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-4285281043-2332145131-3178257145-1000\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O4:64bit: - HKLM..\Run: [BDAgent] C:\Program Files\Defender Pro\Defender Pro\bdagent.exe (Defender Pro)
O4:64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [PCHealthBoost] "C:\Program Files (x86)\PC HealthBoost\PCHealthBoost.exe" /s File not found
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [CanonSolutionMenuEx] C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe (Dell, Inc.)
O4 - HKLM..\Run: [Dell Registration] C:\Program Files (x86)\System Registration\prodreg.exe (Dell, Inc.)
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe (Sonic Solutions)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-4285281043-2332145131-3178257145-1000..\Run: [HughesNet Download Manager] C:\Program Files (x86)\HughesNet Download Manager\HDM.exe (HughesNet.com)
O4 - HKU\S-1-5-21-4285281043-2332145131-3178257145-1000..\Run: [PC MightyMax 2011 Tray Icon] C:\Users\Steve\AppData\Local\PC MightyMax 2012\TrayIcon.exe ()
O4 - HKLM..\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe (Dell)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = File not found
O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = File not found
O4 - Startup: C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = File not found
O4 - Startup: C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HughesNetStatusMeter.lnk = C:\Program Files (x86)\HughesNetStatusMeter\HughesNetStatusMeter\HughesNetStatusMeter.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Download all with HughesNet Download Manager - C:\Program Files (x86)\HughesNet Download Manager\dlall.htm ()
O8:64bit: - Extra context menu item: Download selected with HughesNet Download Manager - C:\Program Files (x86)\HughesNet Download Manager\dlselected.htm ()
O8:64bit: - Extra context menu item: Download video with HughesNet Download Manager - C:\Program Files (x86)\HughesNet Download Manager\dlfvideo.htm ()
O8:64bit: - Extra context menu item: Download with HughesNet Download Manager - C:\Program Files (x86)\HughesNet Download Manager\dllink.htm ()
O8 - Extra context menu item: Download all with HughesNet Download Manager - C:\Program Files (x86)\HughesNet Download Manager\dlall.htm ()
O8 - Extra context menu item: Download selected with HughesNet Download Manager - C:\Program Files (x86)\HughesNet Download Manager\dlselected.htm ()
O8 - Extra context menu item: Download video with HughesNet Download Manager - C:\Program Files (x86)\HughesNet Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Download with HughesNet Download Manager - C:\Program Files (x86)\HughesNet Download Manager\dllink.htm ()
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {EF7ADE47-9668-42A5-A350-0945E51AB8E6} http://www.pcmightymax.net/ext/PCMMInstaller.cab (InstallerHelper Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D7D741D6-7439-4DE0-9674-5C60307684A1}: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKU\S-1-5-21-4285281043-2332145131-3178257145-1000..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
O37 - HKLM\…exe [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
O37 - HKU\S-1-5-21-4285281043-2332145131-3178257145-1000\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/06/12 12:28:08 | 000,596,480 | —- | C] (OldTimer Tools) – C:\Users\Steve\Desktop\OTL.exe
[2012/06/11 14:04:24 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Local\Secunia PSI
[2012/06/11 14:04:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\Secunia
[2012/06/11 10:20:37 | 000,000,000 | —D | C] – C:\Users\Steve\Desktop\GooredFix Backups
[2012/06/09 16:41:08 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Roaming\ApplicationData
[2012/06/09 16:17:35 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Roaming\licenses
[2012/06/09 16:17:34 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Roaming\PCMM2009
[2012/06/09 16:17:26 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Roaming\PCMM2012
[2012/06/09 16:16:46 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Local\PC MightyMax 2012
[2012/06/09 16:14:55 | 000,205,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msvcr71d.dll
[2012/06/07 16:41:52 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Defender Pro
[2012/06/07 16:41:51 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Roaming\Defender Pro
[2012/06/07 16:41:48 | 000,000,000 | —D | C] – C:\ProgramData\Defender Pro
[2012/06/07 16:38:05 | 000,000,000 | —D | C] – C:\Program Files\Defender Pro
[2012/06/07 16:37:59 | 000,288,600 | —- | C] (BitDefender S.R.L.) – C:\Windows\SysNative\drivers\trufos.sys
[2012/06/07 16:37:58 | 000,431,176 | —- | C] (BitDefender) – C:\Windows\SysNative\drivers\bdfsfltr.sys
[2012/06/07 16:37:50 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Defender Pro
[2012/05/22 17:03:33 | 000,419,488 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/05/22 17:03:31 | 000,000,000 | —D | C] – C:\Windows\SysNative\Macromed
[2012/05/21 07:00:57 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Local\{975E4E3A-50C1-4C79-9088-ADF7E71A9429}
[2012/05/21 07:00:31 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Local\{8E5F4C37-D541-4D32-8521-16ADC063DBA5}
[2012/05/21 06:55:43 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Local\{A43F423C-38EB-4445-BE24-92F16AD87CE8}
[2012/05/21 06:54:49 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Local\{72DF3A0E-D0DD-42CB-98B8-3203DC69A274}
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/06/12 12:28:08 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Users\Steve\Desktop\OTL.exe
[2012/06/12 12:21:13 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/06/12 12:21:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/06/12 12:09:52 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/12 12:09:52 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/12 12:07:43 | 000,002,346 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2012/06/12 12:03:00 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/06/12 12:02:39 | 000,065,536 | —- | M] () – C:\Windows\SysNative\Ikeext.etl
[2012/06/12 12:02:29 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/06/12 12:02:25 | 3193,688,064 | -HS- | M] () – C:\hiberfil.sys
[2012/06/11 14:04:16 | 000,001,112 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2012/06/09 16:49:26 | 000,000,275 | -H– | M] () – C:\bdr-conf
[2012/06/09 16:14:55 | 000,205,760 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msvcr71d.dll
[2012/06/09 05:35:07 | 000,003,120 | —- | M] () – C:\Windows\FDK47J7J.ocx
[2012/06/07 16:42:41 | 000,145,372 | —- | M] () – C:\ProgramData\1339105073.bdinstall.bin
[2012/06/07 16:42:14 | 000,003,120 | —- | M] () – C:\Windows\SysWow64\FEHXUQ9Q.ocx
[2012/06/07 16:41:58 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_Kernel_avchv_01009.Wdf
[2012/06/07 16:41:52 | 000,002,039 | —- | M] () – C:\Users\Public\Desktop\Defender Pro 5-in-1.lnk
[2012/06/07 14:12:59 | 000,166,358 | —- | M] () – C:\ProgramData\bdinstall.bin
[2012/06/07 13:40:08 | 000,025,040 | —- | M] () – C:\Users\Steve\Documents\dpreport.dat
[2012/06/05 14:32:00 | 000,194,496 | —- | M] () – C:\Users\Steve\AppData\Roaming\LaunchProxy.exe
[2012/05/22 17:03:33 | 000,419,488 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/05/22 17:03:33 | 000,070,304 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/06/11 14:04:16 | 000,001,112 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2012/06/11 14:04:15 | 000,001,075 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secunia PSI.lnk
[2012/06/09 16:14:58 | 000,194,496 | —- | C] () – C:\Users\Steve\AppData\Roaming\LaunchProxy.exe
[2012/06/09 05:35:07 | 000,003,120 | —- | C] () – C:\Windows\FDK47J7J.ocx
[2012/06/07 16:42:41 | 000,145,372 | —- | C] () – C:\ProgramData\1339105073.bdinstall.bin
[2012/06/07 16:42:17 | 029,123,542 | -H– | C] () – C:\bdrescue.gz
[2012/06/07 16:42:17 | 002,510,608 | -H– | C] () – C:\bdrescue.vm
[2012/06/07 16:42:17 | 000,217,769 | -H– | C] () – C:\bdrescue
[2012/06/07 16:42:17 | 000,009,216 | -H– | C] () – C:\bdrescue.mbr
[2012/06/07 16:42:17 | 000,000,275 | -H– | C] () – C:\bdr-conf
[2012/06/07 16:42:14 | 000,003,120 | —- | C] () – C:\Windows\SysWow64\FEHXUQ9Q.ocx
[2012/06/07 16:41:58 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_Kernel_avchv_01009.Wdf
[2012/06/07 16:41:52 | 000,002,039 | —- | C] () – C:\Users\Public\Desktop\Defender Pro 5-in-1.lnk
[2012/06/07 13:40:08 | 000,025,040 | —- | C] () – C:\Users\Steve\Documents\dpreport.dat
[2012/05/22 17:03:34 | 000,000,830 | —- | C] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2011/08/02 15:27:39 | 000,005,243 | —- | C] () – C:\Users\Steve\AppData\Roaming\UserTile.png
[2011/06/06 07:19:53 | 000,743,066 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/05/26 20:29:20 | 000,166,358 | —- | C] () – C:\ProgramData\bdinstall.bin
[2011/02/22 23:46:57 | 000,982,220 | —- | C] () – C:\Windows\SysWow64\igkrng500.bin
[2011/02/22 23:46:56 | 000,134,592 | —- | C] () – C:\Windows\SysWow64\igfcg500.bin
[2011/02/22 23:46:56 | 000,092,216 | —- | C] () – C:\Windows\SysWow64\igfcg500m.bin
[2011/02/22 23:46:55 | 000,439,300 | —- | C] () – C:\Windows\SysWow64\igcompkrng500.bin

========== Custom Scans ==========

< >

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2011/02/23 00:00:32 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=00B0358734CAA32C39D181FE6916B178 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20542_none_b8b0208ee0ce1889\explorer.exe
[2011/02/26 01:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/26 00:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/13 20:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/26 00:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2011/02/23 00:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/26 00:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 01:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 07:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/02/23 00:00:32 | 002,868,736 | —- | M] (Microsoft Corporation) MD5=6D4F9E4B640B413C6F73414327484C80 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16434_none_addea9f19345cd81\explorer.exe
[2011/02/23 00:00:38 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2011/02/23 00:00:51 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2011/02/23 00:00:38 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 08:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2011/02/23 00:00:51 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2011/02/23 00:00:38 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 20:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2011/02/23 00:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/02/23 00:00:32 | 002,868,736 | —- | M] (Microsoft Corporation) MD5=CA17F8620815267DC838E30B68CB5052 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20542_none_ae5b763cac6d568e\explorer.exe
[2011/02/26 01:26:45 | 002,870,784 | —- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2011/02/23 00:00:38 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
[2011/02/23 00:00:32 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=FC89FACA0473641CB625EDA9277D0885 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16434_none_b8335443c7a68f7c\explorer.exe

< MD5 for: SVCHOST.EXE >
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\SysWOW64\svchost.exe
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009/07/13 20:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Temp1234\Windows\System32\svchost.exe
[2009/07/13 20:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Temp1234\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe
[2009/07/13 20:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\SysNative\svchost.exe
[2009/07/13 20:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 07:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\SysWOW64\userinit.exe
[2010/11/20 07:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/13 20:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009/07/13 20:39:48 | 000,030,208 | —- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE – C:\Temp1234\Windows\System32\userinit.exe
[2009/07/13 20:39:48 | 000,030,208 | —- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE – C:\Temp1234\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2009/07/13 20:39:48 | 000,030,208 | —- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010/11/20 08:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\SysNative\userinit.exe
[2010/11/20 08:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010/11/20 08:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 08:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/13 20:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Temp1234\Windows\System32\winlogon.exe
[2009/07/13 20:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Temp1234\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009/07/13 20:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2011/02/23 00:00:51 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2011/02/23 00:00:51 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< %systemroot%\*. /rp /s >

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: Hitachi HDS721075CLA332
Partitions: 3
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE1 -
Interface type: USB
Media Type:
Model: Generic- SD/MMC USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE2 -
Interface type: USB
Media Type:
Model: Generic- Compact Flash USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE3 -
Interface type: USB
Media Type:
Model: Generic- SM/xD Picture USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE4 -
Interface type: USB
Media Type:
Model: Generic- MS/MS-Pro USB Device
Partitions: 0
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 0.00GB
Starting Offset: 32256
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 14.00GB
Starting Offset: 41943040
Hidden sectors: 0


DeviceID: Disk #0, Partition #2
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 685.00GB
Starting Offset: 14870904832
Hidden sectors: 0


========== Files - Unicode (All) ==========
[2012/06/07 14:13:01 | 000,000,220 | —- | M] ()(C:\Windows\SysNative\?????) – C:\Windows\SysNative\獷楬汢捯污
[2012/06/07 06:22:59 | 000,000,220 | —- | C] ()(C:\Windows\SysNative\?????) – C:\Windows\SysNative\獷楬汢捯污

========== Alternate Data Streams ==========

@Alternate Data Stream - 16 bytes -> C:\Windows\SysWow64\msvcr71d.dll:BDU
@Alternate Data Stream - 16 bytes -> C:\Users\Steve\Desktop\OTL.exe:BDU

< End of report >
OTL Extras logfile created on: 6/12/2012 12:43:09 PM - Run 1
OTL by OldTimer - Version 3.2.48.0 Folder = C:\Users\Steve\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.97 Gb Total Physical Memory | 2.32 Gb Available Physical Memory | 58.47% Memory free
7.93 Gb Paging File | 6.13 Gb Available in Paging File | 77.29% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 684.79 Gb Total Space | 631.20 Gb Free Space | 92.17% Space Free | Partition Type: NTFS
Drive D: | 25.96 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: SHADY94GROVE | User Name: Steve | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.bat [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
.chm [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
.cmd [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
.com [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
.cpl [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
.exe [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
.hlp [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
.hta [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
.html [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
.inf [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
.ini [@ = Reg Error: Key error.] – Reg Error: Key error. File not found

[HKEY_USERS\S-1-5-21-4285281043-2332145131-3178257145-1000\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
http [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{017EC9DD-E32E-4A26-A3C7-3E2E53AD85A5}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{0C6D6CB8-20C4-421C-8977-4F954A29D3D4}" = lport=10243 | protocol=6 | dir=in | app=system |
"{19BF00CC-2F69-473A-8794-7C5E4E946A52}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{2058FA43-A433-4F4E-9C14-26B725EDD8E6}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{3919C03A-4EE7-4E8B-8A66-923FB8203619}" = rport=445 | protocol=6 | dir=out | app=system |
"{3AFB8C60-A3BD-438D-A93C-BABCAAC00C64}" = rport=10243 | protocol=6 | dir=out | app=system |
"{3B56E7DA-190C-49AE-8FFD-D0D11D41735B}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{3D29763E-1722-4C0E-879B-F0BBA1C56659}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{479FF32A-982F-4B22-906F-7A6C271EAE31}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{4973097F-43BB-44B3-9A36-436EC01A68C9}" = lport=445 | protocol=6 | dir=in | app=system |
"{55EF038D-2B43-4ACC-87A0-6C5014760F46}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{6B580D3A-EF70-4055-9155-11FC99357E1B}" = rport=138 | protocol=17 | dir=out | app=system |
"{6FED21AD-4BDC-49B7-B6F7-16AAE91DF265}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{73448416-7208-409E-86A0-FB9DB4903C06}" = lport=138 | protocol=17 | dir=in | app=system |
"{75DA983C-A938-44CF-8A07-42E1B393FB8F}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{7A052466-3B31-4072-A6D8-FBA83B4B4450}" = lport=137 | protocol=17 | dir=in | app=system |
"{9228503A-ECA2-4082-BBF2-A428AE995611}" = rport=139 | protocol=6 | dir=out | app=system |
"{92CB47A6-E40E-4B98-AB0C-7F759599EFA2}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{A54F5965-217B-4EBD-A429-9F9A5C80FA21}" = rport=137 | protocol=17 | dir=out | app=system |
"{B71983CC-7210-44C3-98B9-0F0E0FEDC711}" = lport=139 | protocol=6 | dir=in | app=system |
"{B87402A2-9CF5-4576-B9ED-81B56FB9D7AA}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{C42E1F58-D877-430D-83DD-2B4B8E604C21}" = lport=2869 | protocol=6 | dir=in | app=system |
"{E3C2CA83-0E12-4AA3-9967-2EC73596FE67}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{E565A89A-F1B3-48EA-AD51-E2BD3EF4050E}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{FBF8C6EB-0E7C-48E2-994D-5C674B72A5B0}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{074E5EDE-5E99-4691-9864-F3FC532B1A02}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{0A2D3EFF-F623-416B-94D8-692F3DCE02F2}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{171908FD-DCB4-4BBC-937D-26D1BC406CBE}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{1F129F5F-CA27-4D3A-B480-A0AF790A6D24}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{2187A34B-25B9-47C1-A24C-225E38FFF0B7}" = protocol=17 | dir=in | app=c:\program files\defender pro\defender pro\antispam32\dpreg.exe |
"{2C96BCFE-1376-49EC-92C9-606BE0045B04}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{2ED0DE79-31EE-49FA-8B00-5ED5D3D777BA}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{32FA479C-EFAB-45A9-9557-A7104652F43A}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{3E9902F9-4A4B-4903-9067-CD19DC82F6DE}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{4A8A9BFC-B690-4E01-9793-7C7D2ADEC270}" = protocol=6 | dir=in | app=c:\users\steve\appdata\local\temp\rarsfx0\dpreg.exe |
"{4B0562EB-9541-44FC-853A-DDFEBE7CEAEB}" = protocol=6 | dir=in | app=c:\users\steve\appdata\local\temp\rarsfx0\dpreg.exe |
"{4B410AC7-4625-4485-9339-C787B7CC6E4E}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{5B7942AE-A9A4-483D-AB62-7C7048BCF997}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{5C8FF207-83F4-4408-BE46-58DE42A9C713}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{76C366FD-D093-4B66-B0C8-13AD44E8DBEF}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{775A6327-1E46-4BCA-85FC-4414BBA8B73D}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{792E1936-DC0F-49E0-9A8B-45489D3E883F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{7C9481AB-87BE-4EA1-9AE5-1731C57D85A6}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{87C545B3-E684-4944-BC79-3035FB07ECE4}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{8B9C92F2-A78F-4D0C-AD13-ADDD82800CCA}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{9A621333-819C-498D-A517-B4E0CC403100}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{9AB0E48C-E6F4-432F-8048-3E9F9074F37A}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{9FF36E65-2535-480F-8A5A-E5073343B547}" = protocol=6 | dir=in | app=c:\program files\defender pro\defender pro\antispam32\dpreg.exe |
"{AE68D03E-A788-4FBA-9535-57E9935798C6}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{B508D0CF-A0E1-4C78-B27B-74FF3DA2E181}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{BBCCD78B-A22B-458E-B58F-77235E94ADE5}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{C5C91E31-35E4-4768-8F05-AE30CAE0E068}" = protocol=17 | dir=in | app=c:\users\steve\appdata\local\temp\rarsfx0\dpreg.exe |
"{C5EAF8A2-46C9-422C-93C2-9396AB14C305}" = protocol=6 | dir=out | app=system |
"{F2272B71-8475-407A-AD18-A01576CA4DED}" = protocol=17 | dir=in | app=c:\users\steve\appdata\local\temp\rarsfx0\dpreg.exe |
"{FCC3D76E-A2E4-40AC-B1EA-E3E4BD28A365}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{052bac4a-6f79-46d4-a024-1ce1b4f73cd4}" = Microsoft Visual C++ 2005 Redistributable
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0ED7EE95-6A97-47AA-AD73-152C08A15B04}" = Dell DataSafe Local Backup
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{26A24AE4-039D-4CA4-87B4-2F83216023FF}" = Java™ 6 Update 23
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2A0F2CC5-3065-492C-8380-B03AA7106B1A}" = Dell Product Registration
"{3250260C-7A95-4632-893B-89657EB5545B}" = PhotoShowExpress
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5A06423A-210C-49FB-950E-CB0EB8C5CEC7}" = Roxio BackOnTrack
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{60DBEED5-6A01-44D4-86E4-1F4048DA5834}_is1" = HughesNet Download Manager 1.2
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}" = Roxio Creator Starter
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7746BFAA-2B5D-4FFD-A0E8-4558F4668105}" = Roxio Burn
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{7EC66A95-AC2D-4127-940B-0445A526AB2F}" = Dell DataSafe Online
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{820B6609-4C97-3A2B-B644-573B06A0F0CC}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90140011-0066-0409-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - English
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9A00EC4E-27E1-42C4-98DD-662F32AC8870}" = Sonic CinePlayer Decoder Pack
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A121EEDE-C68F-461D-91AA-D48BA226AF1C}" = Roxio Activation Module
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A8B88634-7F90-402F-B66A-86429755F6A5}" = eBay
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9668246-FB70-4103-A1E3-66C9BC2EFB49}" = Dell DataSafe Local Backup - Support Software
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA31EA7B-7917-4000-949B-38E91F848A25}" = Internet Explorer
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1.2
"{AF9E97C1-7431-426D-A8D5-ABE40995C0B1}" = DirectX 9 Runtime
"{C16A92EF-017B-4839-9C75-FBADB5A1FA27}" = TrustedID
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E52AAE8C-539F-1DAF-994E-7417BE45A3E8}" = HughesNet Status Meter
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EF56258E-0326-48C5-A86C-3BAC26FC15DF}" = Roxio Creator Starter
"{F06B5C4C-8D2E-4B24-9D43-7A45EEC6C878}" = Roxio Creator Starter
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F47C37A4-7189-430A-B81D-739FF8A7A554}" = Consumer In-Home Service Agreement
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"Adobe AIR" = Adobe AIR
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.15
"Canon MP495 series User Registration" = Canon MP495 series User Registration
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenuEX" = Canon Solution Menu EX
"com.hughesnet.HughesNetStatusMeter.92D257A0BA68956E9AA1D50589E83FF4134CD6A8
.1" = HughesNet Status Meter
"Dell Dock" = Dell Dock
"Easy-PhotoPrint EX" = Canon Easy-PhotoPrint EX
"Easy-WebPrint EX" = Canon Easy-WebPrint EX
"Google Chrome" = Google Chrome
"GoToAssist" = GoToAssist 8.0.0.514
"MP Navigator EX 4.0" = Canon MP Navigator EX 4.0
"Office14.Click2Run" = Microsoft Office Click-to-Run 2010
"Secunia PSI" = Secunia PSI (2.0.0.4003)
"WildTangent dell Master Uninstall" = WildTangent Games
"WinLiveSuite" = Windows Live Essentials

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 6/2/2012 11:12:37 PM | Computer Name = Shady94Grove | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 6/2/2012 11:35:44 PM | Computer Name = Shady94Grove | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 6/3/2012 3:59:38 PM | Computer Name = Shady94Grove | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 6/3/2012 4:31:52 PM | Computer Name = Shady94Grove | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 6/3/2012 5:34:41 PM | Computer Name = Shady94Grove | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 6/4/2012 2:13:48 PM | Computer Name = Shady94Grove | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 6/4/2012 2:43:06 PM | Computer Name = Shady94Grove | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 6/4/2012 3:02:57 PM | Computer Name = Shady94Grove | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 6/5/2012 7:09:37 AM | Computer Name = Shady94Grove | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 6/5/2012 11:03:16 PM | Computer Name = Shady94Grove | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

[ Dell Events ]
Error - 7/16/2011 11:30:58 AM | Computer Name = Shady94Grove | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 1/4/2012 9:00:21 PM | Computer Name = Shady94Grove | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 1/4/2012 9:00:21 PM | Computer Name = Shady94Grove | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 1/9/2012 3:53:51 PM | Computer Name = Shady94Grove | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 1/9/2012 3:53:51 PM | Computer Name = Shady94Grove | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 1/9/2012 4:10:18 PM | Computer Name = Shady94Grove | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 1/9/2012 4:10:18 PM | Computer Name = Shady94Grove | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 2/1/2012 2:16:51 PM | Computer Name = Shady94Grove | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 2/1/2012 2:16:51 PM | Computer Name = Shady94Grove | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 3/7/2012 9:11:51 AM | Computer Name = Shady94Grove | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

[ Media Center Events ]
Error - 6/25/2011 9:07:16 AM | Computer Name = Shady94Grove | Source = MCUpdate | ID = 0
Description = 8:07:13 AM - Error connecting to the internet. 8:07:13 AM - Unable
to contact server..

Error - 6/27/2011 10:38:39 AM | Computer Name = Shady94Grove | Source = MCUpdate | ID = 0
Description = 9:38:39 AM - Error connecting to the internet. 9:38:39 AM - Unable
to contact server..

Error - 6/27/2011 10:38:48 AM | Computer Name = Shady94Grove | Source = MCUpdate | ID = 0
Description = 9:38:45 AM - Error connecting to the internet. 9:38:45 AM - Unable
to contact server..

Error - 7/1/2011 12:26:36 PM | Computer Name = Shady94Grove | Source = MCUpdate | ID = 0
Description = 11:26:36 AM - Error connecting to the internet. 11:26:36 AM - Unable
to contact server..

Error - 7/1/2011 12:26:45 PM | Computer Name = Shady94Grove | Source = MCUpdate | ID = 0
Description = 11:26:42 AM - Error connecting to the internet. 11:26:42 AM - Unable
to contact server..

Error - 7/16/2011 10:16:54 PM | Computer Name = Shady94Grove | Source = MCUpdate | ID = 0
Description = 9:16:54 PM - Error connecting to the internet. 9:16:54 PM - Unable
to contact server..

Error - 7/16/2011 10:17:02 PM | Computer Name = Shady94Grove | Source = MCUpdate | ID = 0
Description = 9:16:59 PM - Error connecting to the internet. 9:16:59 PM - Unable
to contact server..

Error - 12/22/2011 1:50:31 PM | Computer Name = Shady94Grove | Source = MCUpdate | ID = 0
Description = 11:50:31 AM - Error connecting to the internet. 11:50:31 AM - Unable
to contact server..

Error - 12/22/2011 1:51:04 PM | Computer Name = Shady94Grove | Source = MCUpdate | ID = 0
Description = 11:51:00 AM - Error connecting to the internet. 11:51:00 AM - Unable
to contact server..

Error - 1/31/2012 6:41:02 AM | Computer Name = Shady94Grove | Source = MCUpdate | ID = 0
Description = 4:41:02 AM - Failed to retrieve SportsSchedule (Error: The underlying
connection was closed: Could not establish trust relationship for the SSL/TLS secure
channel.)

[ System Events ]
Error - 1/13/2012 5:44:58 AM | Computer Name = Shady94Grove | Source = Application Popup | ID = 1060
Description = \SystemRoot\SysWow64\DRIVERS\bdfsfltr.sys has been blocked from loading
due to incompatibility with this system. Please contact your software vendor for
a compatible version of the driver.

Error - 1/13/2012 5:44:58 AM | Computer Name = Shady94Grove | Source = Application Popup | ID = 1060
Description = \SystemRoot\SysWow64\DRIVERS\bdfsfltr.sys has been blocked from loading
due to incompatibility with this system. Please contact your software vendor for
a compatible version of the driver.

Error - 1/13/2012 5:44:58 AM | Computer Name = Shady94Grove | Source = Application Popup | ID = 1060
Description = \SystemRoot\SysWow64\DRIVERS\bdfsfltr.sys has been blocked from loading
due to incompatibility with this system. Please contact your software vendor for
a compatible version of the driver.

Error - 1/13/2012 5:44:58 AM | Computer Name = Shady94Grove | Source = Application Popup | ID = 1060
Description = \SystemRoot\SysWow64\DRIVERS\bdfsfltr.sys has been blocked from loading
due to incompatibility with this system. Please contact your software vendor for
a compatible version of the driver.

Error - 1/13/2012 5:44:58 AM | Computer Name = Shady94Grove | Source = Service Control Manager | ID = 7000
Description = The BDFM service failed to start due to the following error: %%2

Error - 1/13/2012 5:45:04 AM | Computer Name = Shady94Grove | Source = Application Popup | ID = 1060
Description = \SystemRoot\SysWow64\DRIVERS\bdfsfltr.sys has been blocked from loading
due to incompatibility with this system. Please contact your software vendor for
a compatible version of the driver.

Error - 1/13/2012 5:45:04 AM | Computer Name = Shady94Grove | Source = Application Popup | ID = 1060
Description = \SystemRoot\SysWow64\DRIVERS\bdfsfltr.sys has been blocked from loading
due to incompatibility with this system. Please contact your software vendor for
a compatible version of the driver.

Error - 1/13/2012 3:57:08 PM | Computer Name = Shady94Grove | Source = Application Popup | ID = 1060
Description = \SystemRoot\SysWow64\DRIVERS\bdfsfltr.sys has been blocked from loading
due to incompatibility with this system. Please contact your software vendor for
a compatible version of the driver.

Error - 1/13/2012 3:57:08 PM | Computer Name = Shady94Grove | Source = Application Popup | ID = 1060
Description = \SystemRoot\SysWow64\DRIVERS\bdfsfltr.sys has been blocked from loading
due to incompatibility with this system. Please contact your software vendor for
a compatible version of the driver.

Error - 1/13/2012 3:57:08 PM | Computer Name = Shady94Grove | Source = Application Popup | ID = 1060
Description = \SystemRoot\SysWow64\DRIVERS\bdfsfltr.sys has been blocked from loading
due to incompatibility with this system. Please contact your software vendor for
a compatible version of the driver.


< End of report >
aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-06-12 13:42:16 —————————– 13:42:16.817 OS Version: Windows x64 6.1.7601 Service Pack 1 13:42:16.817 Number of processors: 2 586 0x170A 13:42:16.818 ComputerName: SHADY94GROVE UserName: Steve 13:42:18.905 Initialize success 13:42:48.280 AVAST engine download error: 0 13:43:43.484 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 13:43:43.488 Disk 0 Vendor: Hitachi_ JP3O Size: 715404MB BusType: 3 13:43:43.508 Disk 0 MBR read successfully 13:43:43.512 Disk 0 MBR scan 13:43:43.514 Disk 0 Windows VISTA default MBR code 13:43:43.517 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63 13:43:43.524 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 14142 MB offset 81920 13:43:43.535 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 701221 MB offset 29044736 13:43:43.553 Disk 0 scanning C:\Windows\system32\drivers 13:43:48.248 Service scanning 13:44:00.004 Modules scanning 13:44:00.019 Disk 0 trace - called modules: 13:44:00.065 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 13:44:00.069 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80049ad790] 13:44:00.076 3 CLASSPNP.SYS[fffff88001b5b43f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004441050] 13:44:00.081 Scan finished successfully 13:44:13.302 Disk 0 MBR has been saved successfully to "C:\Users\Steve\Desktop\MBR.dat" 13:44:13.308 The log file has been saved successfully to "C:\Users\Steve\Desktop\aswMBR.txt" Thanks Satchfan
Hi ShadyGrove

I see nothing bad in those logs but we’ll take another look with a different scan

Run Farbar Service Scanner

Please download Farbar Service Scanner
  • make sure "Include All Files" option remains checked
  • press Scan
  • it will create a log (FSS.txt) in the same directory the tool is run
  • please copy and paste the log to your reply.
Thanks

Satchfan
Farbar Service Scanner Version: 09-06-2012 Ran by [removed] (administrator) on 13-06-2012 at 21:26:26 Running from "C:\Users\Steve\Desktop" Microsoft Windows 7 Home Premium Service Pack 1 (X64) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Google.com is accessible. Yahoo IP is accessible. Yahoo.com is accessible. File Check: ======== C:\Windows\System32\nsisvc.dll => MD5 is legit C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit C:\Windows\System32\dhcpcore.dll => MD5 is legit C:\Windows\System32\drivers\afd.sys => MD5 is legit C:\Windows\System32\drivers\tdx.sys => MD5 is legit C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit C:\Windows\System32\dnsrslvr.dll => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit I have a question, I see two about;blank files in the IE section that say main start page, what are they? Thanks again Satchfan **** End of log ****
Hi ShadyGrove

Registry cleaners

I see you are using “Registry Cleaners”, PC MightyMax 2012 and PCHealthBoost. It's not recommended to use registry cleaners/boosters.

The usefulness of cleaning the registry is highly overrated and can be dangerous. In most cases, using a cleaner to remove obsolete, invalid, and erroneous entries does not affect system performance but it can result in "unpredictable results". Unless you have a particular problem that requires a registry edit to correct it, (and you are expert in the registry), I would suggest you leave the registry alone.

I strongly advise you to get rid of PC MightyMax and any other cleaner/optimizer/booster/tuneup/tweak type utilities that you have on this or any other computer.

One of the malware experts, miekiemoes, has an excellent write-up here
Another excellent article by Bill Castner is located here

===============================================

Run OTL
  • double click on the icon to run it.
  • copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
    O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
    O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = File not found
    O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = File not found
    O4 - Startup: C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = File not found
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • click the Run Fix button at the top
  • let the program run unhindered, reboot when it is done
  • post a new OTL log (don't check the boxes beside LOP Check or Purity this time)

===============================================

Reset Internet Explorer

I don’t know if you have tried to reset your Home Page. but if not, you can try this:
  • in Internet Explorer, click on Tools, Internet Options
  • make sure the “General” tab is the current tab
  • under “Home Page”, (at the top), type in the page that you want as your home page: eg http://www.google.co.uk/
  • click OK
Restart Internet Explorer and see if your home page is now set.

Please let me know the result.

Logs to include in the next post:

OTL fix log
New OTL log


Satchfan
All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully. Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully. C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk moved successfully. File move failed. C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk scheduled to be moved on reboot. C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 56475 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public User: Steve ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 73666436 bytes ->Java cache emptied: 6484566 bytes ->Google Chrome cache emptied: 17387101 bytes ->Flash cache emptied: 59751 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 365313089 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50400 bytes RecycleBin emptied: 25040 bytes Total Files Cleaned = 442.00 mb Error: Unable to interpret <[Reboot> in the current context! OTL by OldTimer - Version 3.2.48.0 log created on 06142012_183321 Files\Folders moved on Reboot… File\Folder C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk not found! C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\QCA1CCKS\jstags[4].htm moved successfully. C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\NR6S47LN\si[1].htm moved successfully. C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87NOT8CB\header-728-90[2].htm moved successfully. C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\669N1O4K\iframe[2].htm moved successfully. C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\669N1O4K\index[3].htm moved successfully. C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully. C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully. Registry entries deleted on Reboot…
All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully. Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully. C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk moved successfully. File move failed. C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk scheduled to be moved on reboot. C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 56475 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public User: Steve ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 73666436 bytes ->Java cache emptied: 6484566 bytes ->Google Chrome cache emptied: 17387101 bytes ->Flash cache emptied: 59751 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 365313089 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50400 bytes RecycleBin emptied: 25040 bytes Total Files Cleaned = 442.00 mb Error: Unable to interpret <[Reboot> in the current context! OTL by OldTimer - Version 3.2.48.0 log created on 06142012_183321 Files\Folders moved on Reboot… File\Folder C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk not found! C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\QCA1CCKS\jstags[4].htm moved successfully. C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\NR6S47LN\si[1].htm moved successfully. C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87NOT8CB\header-728-90[2].htm moved successfully. C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\669N1O4K\iframe[2].htm moved successfully. C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\669N1O4K\index[3].htm moved successfully. C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully. C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully. Registry entries deleted on Reboot…
Satchfan In my last two visits to the internet about:blank did not show up after running the OTL custom scan and fix, hopefully its gone. As for the pc registery cleaners that was a big mistake on my part that I realized that day. I uninstalled both of them same day but am getting pop ups to fix my pc from mightymac but want let it, they both must still be somewhere if you are seeing them in my files. What to do now? How do I get rid of that Stuff. I read the two articles you posted. Good infomation.Thanks so much for the help with the About:blank and if you have a solution for this other please let me know. Steve
Hi Steve. Good news about your home page.

Let’s see what this picks up.

Download Malwarebytes-Anti-Malware

Click here
  • double-click mbam-setup.exe and follow the prompts to install the program.
  • at the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware. and Launch Malwarebytes' Anti-Malware, then click Finish..
  • if an update is found, it will download and install the latest version.
  • once the program has loaded, select Perform quick scan, then click Scan.
  • when the scan is complete, click OK, then Show Results to view the results.
  • be sure that everything is checked, and click Remove Selected.
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.
NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

================================================

Run Security Check

Download Security Check by screen317 from here or here.
  • save it to your Desktop.
  • double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • a Notepad document should open automatically called checkup.txt; please post the contents of that document.
Please also send a new OTL log.

Logs to include with the next post:

Mbam.txt
Checkup.txt
OTL.txt


Satchfan
Malwarebytes Anti-Malware (Trial) 1.61.0.1400 www.malwarebytes.org Database version: v2012.06.15.08 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 8.0.7601.17514 Steve :: SHADY94GROVE [administrator] Protection: Enabled 6/15/2012 3:29:30 PM mbam-log-2012-06-15 (15-29-30).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 205413 Time elapsed: 2 minute(s), 9 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 1 C:\Users\Steve\AppData\Local\Temp\ms0cfg32.exe (Exploit.Drop.CFG) -> Quarantined and deleted successfully. Satchfan I could not get the security check black box to come up, tried to run it numerious times. (end)
OTL logfile created on: 6/15/2012 9:08:36 PM - Run 3
OTL by OldTimer - Version 3.2.48.0 Folder = C:\Users\Steve\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.97 Gb Total Physical Memory | 2.30 Gb Available Physical Memory | 57.87% Memory free
7.93 Gb Paging File | 6.00 Gb Available in Paging File | 75.72% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 684.79 Gb Total Space | 631.02 Gb Free Space | 92.15% Space Free | Partition Type: NTFS

Computer Name: SHADY94GROVE | User Name: Steve | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/06/12 12:28:08 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Users\Steve\Desktop\OTL.exe
PRC - [2012/05/22 17:03:33 | 000,351,904 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_2_202_235_ActiveX.exe
PRC - [2012/04/04 15:56:40 | 000,654,408 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/04/04 15:56:38 | 000,462,408 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012/03/14 16:00:12 | 000,142,336 | —- | M] () – C:\Program Files (x86)\HughesNetStatusMeter\HughesNetStatusMeter\HughesNetStatusMeter.exe
PRC - [2011/10/14 01:01:50 | 000,994,360 | —- | M] (Secunia) – C:\Program Files (x86)\Secunia\PSI\psia.exe
PRC - [2011/10/14 01:01:48 | 000,399,416 | —- | M] (Secunia) – C:\Program Files (x86)\Secunia\PSI\sua.exe
PRC - [2011/10/14 01:01:46 | 000,291,896 | —- | M] (Secunia) – C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
PRC - [2011/10/01 09:30:22 | 000,219,496 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2011/10/01 09:30:18 | 000,508,776 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2011/01/13 13:54:26 | 000,464,856 | —- | M] (SoftThinks - Dell) – C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
PRC - [2011/01/13 13:42:12 | 003,811,648 | —- | M] (SoftThinks - Dell) – C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
PRC - [2011/01/13 13:39:32 | 000,783,680 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
PRC - [2011/01/13 13:37:02 | 000,705,856 | —- | M] (SoftThinks SAS) – C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
PRC - [2010/11/17 11:35:34 | 000,514,544 | —- | M] () – C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
PRC - [2010/04/02 10:18:54 | 001,185,112 | —- | M] (CANON INC.) – C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE
PRC - [2010/03/03 21:16:06 | 000,013,336 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2010/03/03 21:16:04 | 000,284,696 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
PRC - [2009/10/26 19:10:36 | 003,563,566 | —- | M] (HughesNet.com) – C:\Program Files (x86)\HughesNet Download Manager\HDM.exe
PRC - [2009/06/09 09:11:14 | 000,155,648 | —- | M] (Stardock Corporation) – C:\Program Files\Dell\DellDock\DockLogin.exe


========== Modules (No Company Name) ==========

MOD - [2012/06/14 20:57:52 | 012,436,480 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll
MOD - [2012/06/13 23:22:51 | 014,340,608 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\e717a230496832656b05b515eb9f3bc5\PresentationFramework.ni.dll
MOD - [2012/06/13 23:22:35 | 001,591,808 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll
MOD - [2012/06/13 23:22:33 | 012,237,824 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\14a87218ea49639f38097e278b98a3da\PresentationCore.ni.dll
MOD - [2012/05/11 03:38:04 | 002,297,856 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\dfd33f59a5803a3c73cf408362e6e0b7\System.Core.ni.dll
MOD - [2012/05/11 03:37:09 | 000,452,608 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\635b3aec298ad5e8c903b2323d79cc5a\IAStorUtil.ni.dll
MOD - [2012/05/11 03:28:24 | 000,368,128 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\8e56489276063ededde74e597a121df3\PresentationFramework.Aero.ni.dll
MOD - [2012/05/11 03:28:12 | 000,771,584 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll
MOD - [2012/05/11 03:27:38 | 003,347,968 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll
MOD - [2012/05/11 03:27:34 | 005,452,800 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll
MOD - [2012/05/11 03:27:31 | 007,967,232 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll
MOD - [2012/05/11 03:27:31 | 000,971,264 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll
MOD - [2012/05/11 03:27:25 | 011,492,864 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll
MOD - [2012/03/14 16:00:12 | 000,142,336 | —- | M] () – C:\Program Files (x86)\HughesNetStatusMeter\HughesNetStatusMeter\HughesNetStatusMeter.exe
MOD - [2012/02/28 08:52:47 | 004,770,176 | —- | M] () – c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\WebKit.dll
MOD - [2011/01/13 13:42:02 | 000,025,920 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Local Backup\SftBRCCPiped.dll
MOD - [2011/01/13 13:39:32 | 000,783,680 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
MOD - [2011/01/13 13:37:50 | 000,079,168 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Local Backup\zlib1.dll
MOD - [2011/01/13 13:37:26 | 000,075,072 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Local Backup\STRegistry.dll
MOD - [2011/01/13 13:37:24 | 000,111,936 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Local Backup\STPE.dll
MOD - [2011/01/13 13:37:20 | 000,121,152 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Local Backup\STNLS.dll
MOD - [2011/01/13 13:37:18 | 000,128,320 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Local Backup\STLog.dll
MOD - [2011/01/13 13:37:14 | 000,234,816 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Local Backup\STFiles.dll
MOD - [2011/01/13 13:37:04 | 000,025,920 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Local Backup\STBRCCServCLR.dll
MOD - [2011/01/13 13:36:50 | 001,123,648 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Local Backup\libxml2.dll
MOD - [2010/11/24 23:44:02 | 000,375,280 | —- | M] () – c:\Program Files (x86)\Common Files\Roxio Shared\DLLShared\SQLite352.dll
MOD - [2010/11/17 11:35:34 | 000,514,544 | —- | M] () – C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
MOD - [2009/08/19 11:16:06 | 000,094,208 | —- | M] () – C:\Program Files (x86)\HughesNet Download Manager\iefdm2.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2011/08/02 13:25:14 | 001,885,576 | —- | M] (Defender Pro) [Auto | Running] – C:\Program Files\Defender Pro\Defender Pro\vsserv.exe – (VSSERV)
SRV:64bit: - [2011/08/02 13:25:08 | 000,062,512 | —- | M] (Defender Pro) [Auto | Running] – C:\Program Files\Defender Pro\Defender Pro\updatesrv.exe – (UPDATESRV)
SRV:64bit: - [2011/08/02 13:22:20 | 000,466,736 | —- | M] (Defender Pro) [On_Demand | Stopped] – C:\Program Files\Common Files\Defender Pro\Defender Pro Arrakis Server\bin\arrakis3.exe – (Update Server)
SRV:64bit: - [2010/09/22 19:10:10 | 000,057,184 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe – (wlcrasvc)
SRV:64bit: - [2009/07/13 20:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2009/06/09 09:11:14 | 000,155,648 | —- | M] (Stardock Corporation) [Auto | Running] – C:\Program Files\Dell\DellDock\DockLogin.exe – (DockLoginService)
SRV - [2012/05/22 17:03:33 | 000,257,696 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2012/04/04 15:56:40 | 000,654,408 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2011/10/14 01:01:50 | 000,994,360 | —- | M] (Secunia) [Auto | Running] – C:\Program Files (x86)\Secunia\PSI\psia.exe – (Secunia PSI Agent)
SRV - [2011/10/14 01:01:48 | 000,399,416 | —- | M] (Secunia) [Auto | Running] – C:\Program Files (x86)\Secunia\PSI\sua.exe – (Secunia Update Agent)
SRV - [2011/10/01 09:30:22 | 000,219,496 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe – (sftvsa)
SRV - [2011/10/01 09:30:18 | 000,508,776 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe – (sftlist)
SRV - [2011/02/22 22:19:38 | 000,016,680 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe – (GoToAssist)
SRV - [2011/01/13 13:37:02 | 000,705,856 | —- | M] (SoftThinks SAS) [Auto | Running] – C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe – (SftService)
SRV - [2010/11/25 06:34:18 | 000,219,632 | —- | M] (Sonic Solutions) [Auto | Stopped] – C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe – (RoxWatch12)
SRV - [2010/11/25 06:33:18 | 001,116,656 | —- | M] (Sonic Solutions) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe – (RoxMediaDB12OEM)
SRV - [2010/08/25 21:28:54 | 002,823,000 | —- | M] (Dell, Inc.) [Auto | Running] – C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe – (NOBU)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2010/03/03 21:16:06 | 000,013,336 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe – (IAStorDataMgrSvc) Intel®
SRV - [2009/06/10 16:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2009/06/05 19:07:28 | 000,250,616 | —- | M] (WildTangent, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\WildTangent\Dell Games\Dell Game Console\GameConsoleService.exe – (GameConsoleService)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/04/04 15:56:40 | 000,024,904 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\mbam.sys – (MBAMProtector)
DRV:64bit: - [2012/03/01 01:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2011/10/01 09:30:22 | 000,022,376 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Sftvollh.sys – (Sftvol)
DRV:64bit: - [2011/10/01 09:30:18 | 000,268,648 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Sftplaylh.sys – (Sftplay)
DRV:64bit: - [2011/10/01 09:30:18 | 000,025,960 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\Sftredirlh.sys – (Sftredir)
DRV:64bit: - [2011/10/01 09:30:10 | 000,764,264 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Sftfslh.sys – (Sftfs)
DRV:64bit: - [2011/07/22 20:20:05 | 000,288,600 | —- | M] (BitDefender S.R.L.) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\trufos.sys – (trufos)
DRV:64bit: - [2011/07/15 16:12:46 | 000,550,208 | —- | M] (BitDefender) [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\avckf.sys – (avckf)
DRV:64bit: - [2011/07/15 16:12:44 | 000,258,224 | —- | M] (BitDefender) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\avchv.sys – (avchv)
DRV:64bit: - [2011/07/15 16:12:42 | 000,674,904 | —- | M] (BitDefender) [File_System | Boot | Running] – C:\Windows\SysNative\drivers\avc3.sys – (avc3)
DRV:64bit: - [2011/06/17 19:54:46 | 000,079,952 | —- | M] (Windows ® Win 7 DDK provider) [File_System | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bdsandbox.sys – (bdsandbox)
DRV:64bit: - [2011/03/24 15:36:22 | 000,431,176 | —- | M] (BitDefender) [File_System | Boot | Running] – C:\Windows\SysNative\drivers\bdfsfltr.sys – (bdfsfltr)
DRV:64bit: - [2011/03/11 01:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/11 01:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2011/03/01 17:45:46 | 000,089,680 | —- | M] (BitDefender LLC) [Kernel | System | Running] – c:\Program Files\Common Files\Defender Pro\Defender Pro Firewall\bdfndisf6.sys – (BdfNdisf)
DRV:64bit: - [2011/03/01 17:45:42 | 000,102,992 | —- | M] (BitDefender LLC) [Kernel | System | Running] – C:\Program Files\Common Files\Defender Pro\Defender Pro Firewall\bdfwfpf.sys – (bdfwfpf)
DRV:64bit: - [2010/11/20 08:33:35 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/20 06:07:05 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/11/20 05:43:57 | 000,032,768 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbser.sys – (usbser)
DRV:64bit: - [2010/09/01 03:30:58 | 000,017,976 | —- | M] (Secunia) [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\psi_mf.sys – (PSI)
DRV:64bit: - [2010/03/19 04:00:00 | 000,055,856 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\PxHlpa64.sys – (PxHlpa64)
DRV:64bit: - [2010/01/19 19:32:40 | 000,103,944 | —- | M] (BitDefender) [Kernel | System | Running] – C:\Windows\SysNative\drivers\bdvedisk.sys – (BDVEDISK)
DRV:64bit: - [2009/07/30 22:58:42 | 000,236,544 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2009/07/13 20:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 20:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 20:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/07/03 12:42:08 | 007,342,432 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 15:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/06/04 21:54:36 | 000,408,600 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [2009/05/26 07:13:10 | 000,138,752 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcHdmi.sys – (IntcHdmiAddService) Intel®
DRV:64bit: - [2006/11/01 13:51:00 | 000,151,656 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysNative\drivers\WimFltr.sys – (WimFltr)
DRV - [2010/07/09 15:08:14 | 000,327,368 | —- | M] (BitDefender) [File_System | Boot | Running] – C:\Windows\SysWOW64\drivers\bdfsfltr.sys – (bdfsfltr)
DRV - [2009/07/13 20:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {49606DC7-976D-4030-A74E-9FB5C842FA68}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{49606DC7-976D-4030-A74E-9FB5C842FA68}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope = {49606DC7-976D-4030-A74E-9FB5C842FA68}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{49606DC7-976D-4030-A74E-9FB5C842FA68}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.myhughesnet.com/
IE - HKCU\..\SearchScopes,DefaultScope = {49606DC7-976D-4030-A74E-9FB5C842FA68}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin.dll (Amazon.com, Inc.)



========== Chrome ==========

CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\19.0.1084.52\gcswf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.230.5 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U23 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Chrome NaCl (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\19.0.1084.52\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\19.0.1084.52\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin

O1 HOSTS File: ([2009/06/10 16:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (HDMIECookiesBHO Class) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\HughesNet Download Manager\iefdm2.dll ()
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKCU\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O4:64bit: - HKLM..\Run: [BDAgent] C:\Program Files\Defender Pro\Defender Pro\bdagent.exe (Defender Pro)
O4:64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [PCHealthBoost] "C:\Program Files (x86)\PC HealthBoost\PCHealthBoost.exe" /s File not found
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [CanonSolutionMenuEx] C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe (Dell, Inc.)
O4 - HKLM..\Run: [Dell Registration] C:\Program Files (x86)\System Registration\prodreg.exe (Dell, Inc.)
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe (Sonic Solutions)
O4 - HKCU..\Run: [HughesNet Download Manager] C:\Program Files (x86)\HughesNet Download Manager\HDM.exe (HughesNet.com)
O4 - HKCU..\Run: [PC MightyMax 2011 Tray Icon] C:\Users\Steve\AppData\Local\PC MightyMax 2012\TrayIcon.exe ()
O4 - HKLM..\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe (Dell)
O4 - Startup: C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HughesNetStatusMeter.lnk = C:\Program Files (x86)\HughesNetStatusMeter\HughesNetStatusMeter\HughesNetStatusMeter.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Download all with HughesNet Download Manager - C:\Program Files (x86)\HughesNet Download Manager\dlall.htm ()
O8:64bit: - Extra context menu item: Download selected with HughesNet Download Manager - C:\Program Files (x86)\HughesNet Download Manager\dlselected.htm ()
O8:64bit: - Extra context menu item: Download video with HughesNet Download Manager - C:\Program Files (x86)\HughesNet Download Manager\dlfvideo.htm ()
O8:64bit: - Extra context menu item: Download with HughesNet Download Manager - C:\Program Files (x86)\HughesNet Download Manager\dllink.htm ()
O8 - Extra context menu item: Download all with HughesNet Download Manager - C:\Program Files (x86)\HughesNet Download Manager\dlall.htm ()
O8 - Extra context menu item: Download selected with HughesNet Download Manager - C:\Program Files (x86)\HughesNet Download Manager\dlselected.htm ()
O8 - Extra context menu item: Download video with HughesNet Download Manager - C:\Program Files (x86)\HughesNet Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Download with HughesNet Download Manager - C:\Program Files (x86)\HughesNet Download Manager\dllink.htm ()
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {EF7ADE47-9668-42A5-A350-0945E51AB8E6} http://www.pcmightymax.net/ext/PCMMInstaller.cab (InstallerHelper Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D7D741D6-7439-4DE0-9674-5C60307684A1}: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
O37 - HKLM\…exe [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
O37 - HKCU\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/06/15 15:26:30 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Roaming\Malwarebytes
[2012/06/15 15:26:17 | 000,024,904 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2012/06/15 15:26:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/06/15 15:26:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/06/15 15:26:17 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/06/15 15:23:40 | 010,063,000 | —- | C] (Malwarebytes Corporation ) – C:\Users\Steve\Desktop\mbam-setup-1.61.0.1400.exe
[2012/06/14 18:33:21 | 000,000,000 | —D | C] – C:\_OTL
[2012/06/13 23:24:40 | 000,918,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/06/13 23:24:40 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/06/13 23:23:59 | 000,097,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/06/13 23:23:59 | 000,067,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/06/13 23:23:58 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/06/13 23:23:58 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/06/13 23:23:57 | 000,735,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2012/06/13 23:23:56 | 000,134,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/06/13 23:23:56 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/06/13 23:23:47 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorekmts.dll
[2012/06/13 23:23:47 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpwsx.dll
[2012/06/13 23:23:47 | 000,009,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdrmemptylst.exe
[2012/06/13 23:19:03 | 005,559,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2012/06/13 23:19:02 | 003,968,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2012/06/13 23:19:02 | 003,913,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2012/06/13 23:18:39 | 003,216,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msi.dll
[2012/06/13 23:18:05 | 001,462,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2012/06/13 23:18:05 | 000,140,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2012/06/12 13:40:32 | 004,731,392 | —- | C] (AVAST Software) – C:\Users\Steve\Desktop\aswMBR.exe
[2012/06/12 12:28:08 | 000,596,480 | —- | C] (OldTimer Tools) – C:\Users\Steve\Desktop\OTL.exe
[2012/06/11 14:04:24 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Local\Secunia PSI
[2012/06/11 14:04:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\Secunia
[2012/06/11 10:20:37 | 000,000,000 | —D | C] – C:\Users\Steve\Desktop\GooredFix Backups
[2012/06/09 16:41:08 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Roaming\ApplicationData
[2012/06/09 16:17:35 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Roaming\licenses
[2012/06/09 16:17:34 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Roaming\PCMM2009
[2012/06/09 16:17:26 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Roaming\PCMM2012
[2012/06/09 16:16:46 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Local\PC MightyMax 2012
[2012/06/09 16:14:55 | 000,205,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msvcr71d.dll
[2012/06/07 16:41:52 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Defender Pro
[2012/06/07 16:41:51 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Roaming\Defender Pro
[2012/06/07 16:41:48 | 000,000,000 | —D | C] – C:\ProgramData\Defender Pro
[2012/06/07 16:38:05 | 000,000,000 | —D | C] – C:\Program Files\Defender Pro
[2012/06/07 16:37:59 | 000,288,600 | —- | C] (BitDefender S.R.L.) – C:\Windows\SysNative\drivers\trufos.sys
[2012/06/07 16:37:58 | 000,431,176 | —- | C] (BitDefender) – C:\Windows\SysNative\drivers\bdfsfltr.sys
[2012/06/07 16:37:50 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Defender Pro
[2012/05/22 17:03:33 | 000,419,488 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/05/22 17:03:31 | 000,000,000 | —D | C] – C:\Windows\SysNative\Macromed
[2012/05/21 07:00:57 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Local\{975E4E3A-50C1-4C79-9088-ADF7E71A9429}
[2012/05/21 07:00:31 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Local\{8E5F4C37-D541-4D32-8521-16ADC063DBA5}
[2012/05/21 06:55:43 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Local\{A43F423C-38EB-4445-BE24-92F16AD87CE8}
[2012/05/21 06:54:49 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Local\{72DF3A0E-D0DD-42CB-98B8-3203DC69A274}

========== Files - Modified Within 30 Days ==========

[2012/06/15 21:03:04 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/06/15 20:57:03 | 000,853,862 | —- | M] () – C:\Users\Steve\Desktop\SecurityCheck.exe
[2012/06/15 20:56:57 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/15 20:56:57 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/15 20:49:44 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/06/15 20:49:27 | 000,065,536 | —- | M] () – C:\Windows\SysNative\Ikeext.etl
[2012/06/15 20:49:16 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/06/15 20:49:13 | 3193,688,064 | -HS- | M] () – C:\hiberfil.sys
[2012/06/15 17:21:01 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/06/15 15:26:17 | 000,001,115 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/06/15 15:23:43 | 010,063,000 | —- | M] (Malwarebytes Corporation ) – C:\Users\Steve\Desktop\mbam-setup-1.61.0.1400.exe
[2012/06/15 05:41:04 | 000,003,120 | —- | M] () – C:\Windows\FDK47J7J.ocx
[2012/06/14 20:55:16 | 000,003,120 | —- | M] () – C:\Windows\SysWow64\FEHXUQ9Q.ocx
[2012/06/14 17:16:13 | 000,319,000 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/06/13 23:27:06 | 000,740,772 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/06/13 23:27:06 | 000,624,384 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/06/13 23:27:06 | 000,106,502 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/06/13 21:20:00 | 000,338,127 | —- | M] () – C:\Users\Steve\Desktop\FSS.exe
[2012/06/12 13:44:13 | 000,000,512 | —- | M] () – C:\Users\Steve\Desktop\MBR.dat
[2012/06/12 13:40:32 | 004,731,392 | —- | M] (AVAST Software) – C:\Users\Steve\Desktop\aswMBR.exe
[2012/06/12 12:28:08 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Users\Steve\Desktop\OTL.exe
[2012/06/12 12:07:43 | 000,002,346 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2012/06/11 14:04:16 | 000,001,112 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2012/06/09 16:49:26 | 000,000,275 | -H– | M] () – C:\bdr-conf
[2012/06/09 16:14:55 | 000,205,760 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msvcr71d.dll
[2012/06/07 16:42:41 | 000,145,372 | —- | M] () – C:\ProgramData\1339105073.bdinstall.bin
[2012/06/07 16:41:58 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_Kernel_avchv_01009.Wdf
[2012/06/07 16:41:52 | 000,002,039 | —- | M] () – C:\Users\Public\Desktop\Defender Pro 5-in-1.lnk
[2012/06/07 14:12:59 | 000,166,358 | —- | M] () – C:\ProgramData\bdinstall.bin
[2012/06/05 14:32:00 | 000,194,496 | —- | M] () – C:\Users\Steve\AppData\Roaming\LaunchProxy.exe
[2012/05/22 17:03:33 | 000,419,488 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/05/22 17:03:33 | 000,070,304 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

========== Files Created - No Company Name ==========

[2012/06/15 15:36:43 | 000,853,862 | —- | C] () – C:\Users\Steve\Desktop\SecurityCheck.exe
[2012/06/15 15:26:17 | 000,001,115 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/06/15 05:41:04 | 000,003,120 | —- | C] () – C:\Windows\FDK47J7J.ocx
[2012/06/14 20:55:16 | 000,003,120 | —- | C] () – C:\Windows\SysWow64\FEHXUQ9Q.ocx
[2012/06/13 21:20:00 | 000,338,127 | —- | C] () – C:\Users\Steve\Desktop\FSS.exe
[2012/06/12 13:44:13 | 000,000,512 | —- | C] () – C:\Users\Steve\Desktop\MBR.dat
[2012/06/11 14:04:16 | 000,001,112 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2012/06/11 14:04:15 | 000,001,075 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secunia PSI.lnk
[2012/06/09 16:14:58 | 000,194,496 | —- | C] () – C:\Users\Steve\AppData\Roaming\LaunchProxy.exe
[2012/06/07 16:42:41 | 000,145,372 | —- | C] () – C:\ProgramData\1339105073.bdinstall.bin
[2012/06/07 16:42:17 | 029,123,542 | -H– | C] () – C:\bdrescue.gz
[2012/06/07 16:42:17 | 002,510,608 | -H– | C] () – C:\bdrescue.vm
[2012/06/07 16:42:17 | 000,217,769 | -H– | C] () – C:\bdrescue
[2012/06/07 16:42:17 | 000,009,216 | -H– | C] () – C:\bdrescue.mbr
[2012/06/07 16:42:17 | 000,000,275 | -H– | C] () – C:\bdr-conf
[2012/06/07 16:41:58 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_Kernel_avchv_01009.Wdf
[2012/06/07 16:41:52 | 000,002,039 | —- | C] () – C:\Users\Public\Desktop\Defender Pro 5-in-1.lnk
[2012/05/22 17:03:34 | 000,000,830 | —- | C] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2011/08/02 15:27:39 | 000,005,243 | —- | C] () – C:\Users\Steve\AppData\Roaming\UserTile.png
[2011/06/06 07:19:53 | 000,743,066 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/05/26 20:29:20 | 000,166,358 | —- | C] () – C:\ProgramData\bdinstall.bin
[2011/02/22 23:46:57 | 000,982,220 | —- | C] () – C:\Windows\SysWow64\igkrng500.bin
[2011/02/22 23:46:56 | 000,134,592 | —- | C] () – C:\Windows\SysWow64\igfcg500.bin
[2011/02/22 23:46:56 | 000,092,216 | —- | C] () – C:\Windows\SysWow64\igfcg500m.bin
[2011/02/22 23:46:55 | 000,439,300 | —- | C] () – C:\Windows\SysWow64\igcompkrng500.bin

========== Files - Unicode (All) ==========
[2012/06/07 14:13:01 | 000,000,220 | —- | M] ()(C:\Windows\SysNative\?????) – C:\Windows\SysNative\獷楬汢捯污
[2012/06/07 06:22:59 | 000,000,220 | —- | C] ()(C:\Windows\SysNative\?????) – C:\Windows\SysNative\獷楬汢捯污

========== Alternate Data Streams ==========

@Alternate Data Stream - 16 bytes -> C:\Windows\SysWow64\msvcr71d.dll:BDU
@Alternate Data Stream - 16 bytes -> C:\Users\Steve\Desktop\SecurityCheck.exe:BDU
@Alternate Data Stream - 16 bytes -> C:\Users\Steve\Desktop\OTL.exe:BDU
@Alternate Data Stream - 16 bytes -> C:\Users\Steve\Desktop\mbam-setup-1.61.0.1400.exe:BDU
@Alternate Data Stream - 16 bytes -> C:\Users\Steve\Desktop\FSS.exe:BDU
@Alternate Data Stream - 16 bytes -> C:\Users\Steve\Desktop\aswMBR.exe:BDU

< End of report >
Thanks again Satchfan, will try to run the security check again.
Your log looks clean.

Don’t worry about the SecurityCheck scan but we’ll run one more scan to be sure all is well before tidying up.

Run ESET Online Scan

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Hold down Control and click on the following link to open ESET OnlineScan in a new window.

ESET OnlineScan 1. Click the Eset online Scanner button.
2. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

• Click on esetinstaller.exe to download the ESET Smart Installer. Save it to your desktop.
• Double click on the Eset installer icon on your desktop.

3. Check Yes, I accept the Terms of Use
4. Click the Start button.
5. Accept any security warnings from your browser.
6. Check Scan archives
7. Push the Start button.
8. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
9. When the scan completes, push List of found threats
10. Push Export to Text file and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
Note - when ESET doesn't find any threats, no report will be created.
11. Push the back button.
12. Push Finish
If a log has been produced post it in your next reply.

NOTE. If Eset doesn't find any threats, it won't produce a log.

Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI