This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Sifrefef.AB and Sirefef.P - HELP! [Closed]

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

A few days ago I noticed my MSE was not working properly. SOmehow it had been disabled. I uninstalled it and reinstalled it and ran a scan. It immediately popped up with these 2 viruses. I tried to clean the files, which threw me into a reboot loop every minute the machine was powered on. I managed to stop the loop and ran a few "fixes" I had found n the internet which seemed to have removed the viruses, but Yesterday when I reinstalled and ran MSE again, the viruses are still there.

Here are my logs:
OTL.txt


OTL logfile created on: 7/11/2012 4:26:52 PM - Run 1
OTL by OldTimer - Version 3.2.54.0 Folder = C:\Users\MommaCass\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.80 Gb Total Physical Memory | 2.16 Gb Available Physical Memory | 56.81% Memory free
7.60 Gb Paging File | 5.45 Gb Available in Paging File | 71.72% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 452.70 Gb Total Space | 103.98 Gb Free Space | 22.97% Space Free | Partition Type: NTFS
Drive E: | 7.39 Gb Total Space | 7.14 Gb Free Space | 96.58% Space Free | Partition Type: FAT32

Computer Name: MOMMACASS-PC | User Name: MommaCass | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/07/11 16:24:02 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Users\MommaCass\Desktop\OTL.exe
PRC - [2012/06/20 19:02:30 | 012,163,848 | —- | M] (Google) – C:\Program Files (x86)\Google\Drive\googledrivesync.exe
PRC - [2012/05/26 12:04:52 | 000,913,792 | —- | M] (IObit) – C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe
PRC - [2012/05/16 11:12:45 | 000,932,528 | —- | M] () – C:\Users\MommaCass\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
PRC - [2011/09/11 17:52:57 | 000,273,528 | —- | M] (RealNetworks, Inc.) – C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
PRC - [2011/07/28 16:08:12 | 001,259,376 | —- | M] () – C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
PRC - [2011/06/05 18:41:34 | 000,222,496 | —- | M] (Acresso Corporation) – C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
PRC - [2010/11/30 13:11:16 | 002,745,648 | —- | M] (LanSchool Technologies, llc) – C:\Program Files (x86)\LanSchool\teacher.exe
PRC - [2010/11/30 12:29:12 | 003,508,528 | —- | M] (LanSchool) – C:\Program Files (x86)\LanSchool\lsproxy\LskProxy.exe
PRC - [2010/03/03 14:42:02 | 002,320,920 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2010/03/03 14:41:58 | 000,268,824 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2009/12/25 15:21:16 | 000,034,160 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe
PRC - [2009/12/03 10:12:12 | 000,976,320 | —- | M] (SEIKO EPSON CORPORATION) – C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
PRC - [2009/12/03 00:00:00 | 000,847,872 | —- | M] (SEIKO EPSON CORPORATION) – C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe
PRC - [2006/12/19 18:23:20 | 000,094,208 | —- | M] (SEIKO EPSON CORPORATION) – C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSvc.exe


========== Modules (No Company Name) ==========

MOD - [2012/07/11 15:13:54 | 000,571,392 | —- | M] () – C:\Users\MommaCass\AppData\Local\Temp\_MEI51122\pysqlite2._sqlite.pyd
MOD - [2012/07/11 15:13:54 | 000,263,168 | —- | M] () – C:\Users\MommaCass\AppData\Local\Temp\_MEI51122\win32com.shell.shell.pyd
MOD - [2012/07/11 15:13:54 | 000,096,256 | —- | M] () – C:\Users\MommaCass\AppData\Local\Temp\_MEI51122\win32api.pyd
MOD - [2012/07/11 15:13:54 | 000,086,016 | —- | M] () – C:\Users\MommaCass\AppData\Local\Temp\_MEI51122\_elementtree.pyd
MOD - [2012/07/11 15:13:54 | 000,040,448 | —- | M] () – C:\Users\MommaCass\AppData\Local\Temp\_MEI51122\_socket.pyd
MOD - [2012/07/11 15:13:53 | 001,169,408 | —- | M] () – C:\Users\MommaCass\AppData\Local\Temp\_MEI51122\wx._core_.pyd
MOD - [2012/07/11 15:13:53 | 001,056,256 | —- | M] () – C:\Users\MommaCass\AppData\Local\Temp\_MEI51122\wx._controls_.pyd
MOD - [2012/07/11 15:13:53 | 001,018,368 | —- | M] () – C:\Users\MommaCass\AppData\Local\Temp\_MEI51122\windows._cacheinvalidation.pyd
MOD - [2012/07/11 15:13:53 | 000,807,424 | —- | M] () – C:\Users\MommaCass\AppData\Local\Temp\_MEI51122\wx._windows_.pyd
MOD - [2012/07/11 15:13:53 | 000,792,576 | —- | M] () – C:\Users\MommaCass\AppData\Local\Temp\_MEI51122\wx._gdi_.pyd
MOD - [2012/07/11 15:13:53 | 000,731,136 | —- | M] () – C:\Users\MommaCass\AppData\Local\Temp\_MEI51122\wx._misc_.pyd
MOD - [2012/07/11 15:13:53 | 000,645,120 | —- | M] () – C:\Users\MommaCass\AppData\Local\Temp\_MEI51122\_ssl.pyd
MOD - [2012/07/11 15:13:53 | 000,354,304 | —- | M] () – C:\Users\MommaCass\AppData\Local\Temp\_MEI51122\pythoncom26.dll
MOD - [2012/07/11 15:13:53 | 000,311,808 | —- | M] () – C:\Users\MommaCass\AppData\Local\Temp\_MEI51122\_hashlib.pyd
MOD - [2012/07/11 15:13:53 | 000,153,088 | —- | M] () – C:\Users\MommaCass\AppData\Local\Temp\_MEI51122\pyexpat.pyd
MOD - [2012/07/11 15:13:53 | 000,121,856 | —- | M] () – C:\Users\MommaCass\AppData\Local\Temp\_MEI51122\wx._wizard.pyd
MOD - [2012/07/11 15:13:53 | 000,111,104 | —- | M] () – C:\Users\MommaCass\AppData\Local\Temp\_MEI51122\win32file.pyd
MOD - [2012/07/11 15:13:53 | 000,110,592 | —- | M] () – C:\Users\MommaCass\AppData\Local\Temp\_MEI51122\PyWinTypes26.dll
MOD - [2012/07/11 15:13:53 | 000,073,728 | —- | M] () – C:\Users\MommaCass\AppData\Local\Temp\_MEI51122\_ctypes.pyd
MOD - [2012/07/11 15:13:53 | 000,070,656 | —- | M] () – C:\Users\MommaCass\AppData\Local\Temp\_MEI51122\wx._html2.pyd
MOD - [2012/07/11 15:13:53 | 000,039,424 | —- | M] () – C:\Users\MommaCass\AppData\Local\Temp\_MEI51122\win32inet.pyd
MOD - [2012/07/11 15:13:53 | 000,036,352 | —- | M] () – C:\Users\MommaCass\AppData\Local\Temp\_MEI51122\win32process.pyd
MOD - [2012/07/11 15:13:53 | 000,022,528 | —- | M] () – C:\Users\MommaCass\AppData\Local\Temp\_MEI51122\win32pdh.pyd
MOD - [2012/07/11 15:13:53 | 000,017,920 | —- | M] () – C:\Users\MommaCass\AppData\Local\Temp\_MEI51122\win32event.pyd
MOD - [2012/07/11 15:13:53 | 000,011,776 | —- | M] () – C:\Users\MommaCass\AppData\Local\Temp\_MEI51122\win32crypt.pyd
MOD - [2012/07/11 15:13:52 | 000,585,728 | —- | M] () – C:\Users\MommaCass\AppData\Local\Temp\_MEI51122\unicodedata.pyd
MOD - [2012/07/11 15:13:52 | 000,011,776 | —- | M] () – C:\Users\MommaCass\AppData\Local\Temp\_MEI51122\select.pyd
MOD - [2012/06/28 03:28:56 | 000,438,296 | —- | M] () – C:\Users\MommaCass\AppData\Local\Google\Chrome\Application\20.0.1132.47\ppgooglenaclpluginchrome.dll
MOD - [2012/06/28 03:28:54 | 003,972,120 | —- | M] () – C:\Users\MommaCass\AppData\Local\Google\Chrome\Application\20.0.1132.47\pdf.dll
MOD - [2012/06/28 03:27:40 | 000,554,520 | —- | M] () – C:\Users\MommaCass\AppData\Local\Google\Chrome\Application\20.0.1132.47\libglesv2.dll
MOD - [2012/06/28 03:27:38 | 000,117,784 | —- | M] () – C:\Users\MommaCass\AppData\Local\Google\Chrome\Application\20.0.1132.47\libegl.dll
MOD - [2012/06/28 03:27:29 | 000,140,328 | —- | M] () – C:\Users\MommaCass\AppData\Local\Google\Chrome\Application\20.0.1132.47\avutil-51.dll
MOD - [2012/06/28 03:27:28 | 000,262,184 | —- | M] () – C:\Users\MommaCass\AppData\Local\Google\Chrome\Application\20.0.1132.47\avformat-54.dll
MOD - [2012/06/28 03:27:26 | 002,386,984 | —- | M] () – C:\Users\MommaCass\AppData\Local\Google\Chrome\Application\20.0.1132.47\avcodec-54.dll
MOD - [2012/06/28 01:27:26 | 009,252,040 | —- | M] () – C:\Users\MommaCass\AppData\Local\Google\Chrome\Application\20.0.1132.47\gcswf32.dll
MOD - [2012/05/16 11:12:45 | 000,932,528 | —- | M] () – C:\Users\MommaCass\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
MOD - [2011/07/28 16:09:42 | 000,096,112 | —- | M] () – C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2011/07/28 16:08:12 | 001,259,376 | —- | M] () – C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
MOD - [2010/11/30 12:29:30 | 000,075,056 | —- | M] () – C:\Windows\SysWOW64\lskhook.dll
MOD - [2010/11/17 11:16:56 | 000,067,872 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2012/03/26 18:49:56 | 000,291,696 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – c:\Program Files\Microsoft Security Client\NisSrv.exe – (NisSrv)
SRV:64bit: - [2012/03/26 18:49:56 | 000,012,600 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\MsMpEng.exe – (MsMpSvc)
SRV:64bit: - [2011/11/01 13:37:56 | 001,518,352 | —- | M] (Intel® Corporation) [Auto | Running] – C:\Program Files\Intel\WiFi\bin\EvtEng.exe – (EvtEng) Intel®
SRV:64bit: - [2011/11/01 13:25:42 | 000,340,240 | —- | M] () [On_Demand | Stopped] – C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe – (MyWiFiDHCPDNS)
SRV:64bit: - [2011/11/01 13:22:28 | 000,844,560 | —- | M] (Intel® Corporation) [Auto | Running] – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe – (RegSrvc) Intel®
SRV:64bit: - [2011/10/20 18:33:22 | 000,135,440 | —- | M] (Intel® Corporation) [On_Demand | Stopped] – C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe – (BTHSSecurityMgr) Intel® Centrino® Wireless Bluetooth®
SRV:64bit: - [2011/10/19 14:25:00 | 000,661,504 | —- | M] (Intel Corporation) [On_Demand | Stopped] – C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe – (AMPPALR3)
SRV:64bit: - [2010/07/28 10:27:16 | 000,267,192 | —- | M] (TOSHIBA Corporation) [On_Demand | Stopped] – C:\Program Files\TOSHIBA\TECO\TecoService.exe – (TOSHIBA eco Utility Service)
SRV:64bit: - [2010/07/22 16:36:16 | 000,822,192 | —- | M] (TOSHIBA Corporation) [On_Demand | Running] – C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe – (TPCHSrv)
SRV:64bit: - [2010/06/29 11:05:02 | 000,489,384 | —- | M] (TOSHIBA Corporation) [Auto | Running] – C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe – (TosCoSrv)
SRV:64bit: - [2010/06/07 15:39:40 | 000,911,872 | —- | M] (Intel® Corporation) [Auto | Running] – C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe – (WiMAXAppSrv)
SRV:64bit: - [2010/06/07 15:34:20 | 000,408,576 | —- | M] (Red Bend Ltd.) [On_Demand | Stopped] – C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe – (DMAgent)
SRV:64bit: - [2010/02/05 17:44:48 | 000,137,560 | —- | M] (TOSHIBA Corporation) [On_Demand | Running] – C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe – (TOSHIBA HDD SSD Alert Service)
SRV:64bit: - [2009/10/21 09:30:36 | 000,531,520 | —- | M] (TOSHIBA Corporation) [Auto | Running] – C:\Windows\SysNative\ThpSrv.exe – (Thpsrv)
SRV:64bit: - [2009/07/28 15:48:06 | 000,140,632 | —- | M] (TOSHIBA Corporation) [Auto | Running] – C:\Windows\SysNative\TODDSrv.exe – (TODDSrv)
SRV:64bit: - [2009/07/13 18:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2009/06/03 16:38:36 | 000,277,032 | —- | M] (ActivIdentity) [On_Demand | Stopped] – C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe – (ac.sharedstore)
SRV - [2012/07/08 21:56:39 | 000,257,224 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2012/06/24 14:09:16 | 000,113,120 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/06/07 19:12:14 | 000,160,944 | R— | M] (Skype Technologies) [Auto | Stopped] – C:\Program Files (x86)\Skype\Updater\Updater.exe – (SkypeUpdate)
SRV - [2012/05/26 12:04:52 | 000,913,792 | —- | M] (IObit) [Auto | Running] – C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe – (AdvancedSystemCareService5)
SRV - [2012/01/03 06:10:42 | 000,063,928 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2011/08/24 10:59:58 | 000,102,912 | —- | M] () [Auto | Running] – C:\Windows\agent_x64.exe – (Agent)
SRV - [2011/06/05 21:12:44 | 000,296,808 | —- | M] (Nuance Communications, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe – (DragonSvc)
SRV - [2010/11/30 12:29:12 | 003,508,528 | —- | M] (LanSchool) [On_Demand | Running] – C:\Program Files (x86)\LanSchool\lsproxy\LskProxy.exe – (LskProxy)
SRV - [2010/03/03 14:42:02 | 002,320,920 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe – (UNS) Intel®
SRV - [2010/03/03 14:41:58 | 000,268,824 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe – (LMS) Intel®
SRV - [2009/10/06 09:21:50 | 000,051,512 | —- | M] (TOSHIBA Corporation) [On_Demand | Running] – C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe – (TMachInfo)
SRV - [2009/06/10 14:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2006/12/19 18:23:20 | 000,094,208 | —- | M] (SEIKO EPSON CORPORATION) [Auto | Running] – C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSvc.exe – (EpsonBidirectionalService)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/03/20 20:44:12 | 000,098,688 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\NisDrvWFP.sys – (NisDrv)
DRV:64bit: - [2012/02/29 23:54:38 | 000,022,896 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2011/11/28 19:28:28 | 000,055,856 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\PxHlpa64.sys – (PxHlpa64)
DRV:64bit: - [2011/10/31 15:57:50 | 008,615,936 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\NETwNs64.sys – (NETwNs64) ___ Intel®
DRV:64bit: - [2011/10/19 14:19:08 | 000,195,072 | —- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\AmpPal.sys – (AMPPALP)
DRV:64bit: - [2011/10/19 14:19:08 | 000,195,072 | —- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\AmpPal.sys – (AMPPAL)
DRV:64bit: - [2011/08/01 16:59:06 | 000,045,416 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\point64.sys – (Point64)
DRV:64bit: - [2011/07/28 19:37:10 | 000,052,584 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\dc3d.sys – (dc3d) MS Hardware Device Detection Driver (USB)
DRV:64bit: - [2011/05/26 08:21:28 | 000,174,680 | —- | M] (JMicron Technology Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\jmcr.sys – (JMCR)
DRV:64bit: - [2011/05/10 08:06:08 | 000,051,712 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbaapl64.sys – (USBAAPL64)
DRV:64bit: - [2011/03/10 23:22:41 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/10 23:22:40 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2010/06/18 10:38:06 | 000,039,832 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WDKMD.sys – (wdkmd)
DRV:64bit: - [2010/05/31 12:05:06 | 007,689,216 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\NETw5s64.sys – (NETw5s64) Intel®
DRV:64bit: - [2010/05/16 17:28:38 | 000,175,104 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\bpmp.sys – (bpmp) Intel® Centrino®
DRV:64bit: - [2010/05/16 17:28:30 | 000,081,920 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\bpusb.sys – (bpusb)
DRV:64bit: - [2010/05/16 17:28:28 | 000,071,168 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\bpenum.sys – (bpenum)
DRV:64bit: - [2010/05/08 18:38:56 | 000,482,384 | —- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\tos_sps64.sys – (tos_sps64)
DRV:64bit: - [2010/05/03 14:44:02 | 000,331,880 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2010/04/21 11:18:44 | 010,326,784 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2010/03/10 18:51:32 | 000,316,464 | —- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SynTP.sys – (SynTP)
DRV:64bit: - [2010/02/26 16:32:12 | 000,158,976 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Impcd.sys – (Impcd)
DRV:64bit: - [2010/02/03 06:38:30 | 000,271,872 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcDAud.sys – (IntcDAud) Intel®
DRV:64bit: - [2010/01/29 11:39:10 | 000,125,344 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\ssadbus.sys – (ssadbus) SAMSUNG Android USB Composite Device driver (WDM)
DRV:64bit: - [2010/01/15 12:22:08 | 000,538,136 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [2009/10/09 19:41:20 | 000,109,056 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\sdbus.sys – (sdbus)
DRV:64bit: - [2009/09/17 12:54:54 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (HECIx64) Intel®
DRV:64bit: - [2009/07/30 21:02:36 | 000,044,912 | —- | M] (COMPAL ELECTRONIC INC.) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\LPCFilter.sys – (LPCFilter)
DRV:64bit: - [2009/07/30 20:22:04 | 000,027,784 | —- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\tdcmdpst.sys – (tdcmdpst)
DRV:64bit: - [2009/07/14 15:31:18 | 000,026,840 | —- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\TVALZ_O.SYS – (TVALZ)
DRV:64bit: - [2009/07/13 18:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 18:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 18:47:48 | 000,077,888 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2009/07/13 18:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/07/13 17:10:47 | 000,011,264 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\rootmdm.sys – (ROOTMODEM)
DRV:64bit: - [2009/07/13 17:00:24 | 000,009,728 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\acpials.sys – (acpials)
DRV:64bit: - [2009/06/29 16:16:20 | 000,014,784 | —- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\Thpevm.sys – (Thpevm)
DRV:64bit: - [2009/06/29 10:25:22 | 000,034,880 | —- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\thpdrv.sys – (Thpdrv)
DRV:64bit: - [2009/06/22 17:06:38 | 000,035,008 | —- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\PGEffect.sys – (PGEffect)
DRV:64bit: - [2009/06/19 19:15:22 | 000,014,472 | —- | M] (TOSHIBA Corporation) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\TVALZFL.sys – (TVALZFL)
DRV:64bit: - [2009/06/10 13:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 13:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 13:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 13:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/05/18 13:17:08 | 000,034,152 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2007/03/07 10:13:20 | 000,017,920 | —- | M] (June Fabrics Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\pnetmdm64.sys – (pnetmdm)
DRV - [2009/07/13 18:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)
DRV - [2003/11/21 16:15:14 | 000,029,156 | —- | M] (Apple Computer, Inc.) [Kernel | Auto | Stopped] – C:\Windows\SysWOW64\drivers\DVDAccss.sys – (DVDAccss)
DRV - [2002/02/11 14:15:50 | 000,014,572 | —- | M] (Padus, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\PFC.SYS – (pfc)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {2B6F1E47-294C-447A-AC11-EE624293C76F}
IE:64bit: - HKLM\..\SearchScopes\{2B6F1E47-294C-447A-AC11-EE624293C76F}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7TSND
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain?br…D&bmod;=TSND
IE - HKLM\..\SearchScopes,DefaultScope = {D72E3EFB-7D28-4B58-A781-6633524EABA1}
IE - HKLM\..\SearchScopes\{D72E3EFB-7D28-4B58-A781-6633524EABA1}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7TSND

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}…00064d4da14d889
IE - HKCU\..\SearchScopes\{9DF056D1-DA53-4B4B-A6E9-C467CE0C00E6}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7TSND
IE - HKCU\..\SearchScopes\{D72E3EFB-7D28-4B58-A781-6633524EABA1}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7TSND
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 192.168.*.*;

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.selectedEngine: "Search the web (Babylon)"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com"
FF - prefs.js..extensions.enabledItems: [removed]:1.4.3
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6906
FF - prefs.js..extensions.enabledItems: feedly@devhd:5.5
FF - prefs.js..extensions.enabledItems: [removed]:7
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {6E19037A-12E3-4295-8915-ED48BC341614}:1.3.328.4
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {7000b6ca-4388-4d95-893d-6659c2d4d1ce}:3.5
FF - prefs.js..keyword.URL: "http://search.babylon.com/?affID=109937&tt;=100512_3_&babsrc;=KW_ss&mntrId;=c25c4e8800000000000064d4da14d889&q;="


FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_3_300_262.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.666: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.666: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.666: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.666: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.666: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@doubletwist.com/NPPodcast: File not found
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Users\MommaCass\AppData\Roaming\Move Networks\plugins\npqmp071706000001.dll (Move Networks)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\MommaCass\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\MommaCass\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\MommaCass\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\MommaCass\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\MommaCass\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\MommaCass\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin.dll (Amazon.com, Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/07/09 18:29:41 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012/06/20 20:40:39 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/06/24 14:09:17 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/05/08 11:22:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/06/24 14:09:17 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/05/08 11:22:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/06/24 14:09:17 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/05/08 11:22:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/06/24 14:09:17 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/05/08 11:22:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/06/24 14:09:17 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/05/08 11:22:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/06/24 14:09:17 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/05/08 11:22:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/06/24 14:09:17 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/05/08 11:22:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/06/24 14:09:17 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/05/08 11:22:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 5.0\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2011/09/11 17:53:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 5.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins [2012/05/08 11:12:38 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Users\MommaCass\AppData\Roaming\Move Networks [2011/01/11 19:27:29 | 000,000,000 | —D | M]

[2010/12/29 17:33:00 | 000,000,000 | —D | M] (No name found) – C:\Users\MommaCass\AppData\Roaming\Mozilla\Extensions
[2012/07/10 07:52:34 | 000,000,000 | —D | M] (No name found) – C:\Users\MommaCass\AppData\Roaming\Mozilla\Firefox\Profiles\gy74lx5u.default\extensions
[2012/06/07 22:49:18 | 000,000,000 | —D | M] (Diigo Toolbar) – C:\Users\MommaCass\AppData\Roaming\Mozilla\Firefox\Profiles\gy74lx5u.default\extensions\{fc2b8f80-d9a5-4f51-8076-7c7ce3c67ee3}
[2012/06/01 19:33:27 | 000,000,000 | —D | M] (Roomy Bookmarks Toolbar) – C:\Users\MommaCass\AppData\Roaming\Mozilla\Firefox\Profiles\gy74lx5u.default\extensions\[removed]
[2010/12/29 22:42:39 | 000,000,000 | —D | M] (Smart Bookmarks Bar) – C:\Users\MommaCass\AppData\Roaming\Mozilla\Firefox\Profiles\gy74lx5u.default\extensions\[removed]
[2012/07/10 07:52:34 | 000,000,000 | —D | M] (Zotero) – C:\Users\MommaCass\AppData\Roaming\Mozilla\Firefox\Profiles\gy74lx5u.default\extensions\[removed]
[2012/01/28 00:08:24 | 000,002,434 | —- | M] () – C:\Users\MommaCass\AppData\Roaming\Mozilla\Firefox\Profiles\gy74lx5u.default\searchplugins\google-scholar.xml
[2012/03/23 14:28:59 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/12/31 21:10:47 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/10/14 22:40:57 | 000,000,000 | —D | M] ("Ginger") – C:\Program Files (x86)\Mozilla Firefox\extensions\[removed]
[2012/03/05 14:03:54 | 000,325,600 | —- | M] () (No name found) – C:\USERS\MOMMACASS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GY74LX5U.DEFAULT\EXTENSIONS\[removed]
[2012/06/24 14:09:17 | 000,085,472 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2010/11/30 12:29:42 | 000,095,536 | —- | M] (LanSchool Technologies, llc) – C:\Program Files (x86)\mozilla firefox\components\Lsk_fBlk.dll
[2012/05/08 11:12:37 | 000,466,944 | —- | M] (Catalina Marketing Corporation) – C:\Program Files (x86)\mozilla firefox\plugins\NPcol400.dll
[2011/03/18 11:32:12 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npCouponPrinter.dll
[2012/03/15 21:15:29 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/03/18 11:32:14 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npMozCouponPrinter.dll
[2012/05/18 11:30:57 | 000,002,352 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2012/06/24 14:09:14 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/06/24 14:09:14 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
[2010/10/06 07:51:30 | 000,003,277 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\xfinitylcsearch.xml

========== Chrome ==========

CHR - homepage: http://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms},
CHR - homepage: http://www.google.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\MommaCass\AppData\Local\Google\Chrome\Application\20.0.1132.47\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\MommaCass\AppData\Local\Google\Chrome\Application\20.0.1132.47\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\MommaCass\AppData\Local\Google\Chrome\Application\20.0.1132.47\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\MommaCass\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll
CHR - plugin: Skype Toolbars (Enabled) = C:\Users\MommaCass\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.8.0.8855_0\npSkypeChromePlugin.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.310.5 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U31 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: CouponNetwork Coupon Activator Netscape Plugin v. 5.0.0.0 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPcol400.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\MommaCass\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\MommaCass\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: AmazonMP3DownloaderPlugin (Enabled) = C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Plus Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: RealNetworks™ Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\MommaCass\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Facebook Desktop (Enabled) = C:\Users\MommaCass\AppData\Local\Facebook\Messenger\2.1.4554.0\npFbDesktopPlugin.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Users\MommaCass\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: Move Streaming Media Player (Enabled) = C:\Users\MommaCass\AppData\Roaming\Move Networks\plugins\npqmp071706000001.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: Add to Amazon Wish List = C:\Users\MommaCass\AppData\Local\Google\Chrome\User Data\Default\Extensions\ciagpekplgpbepdgggflgmahnjgiaced\1.0.0.8_1\
CHR - Extension: Read Later Fast = C:\Users\MommaCass\AppData\Local\Google\Chrome\User Data\Default\Extensions\decdfngdidijkdjgbknlnepdljfaepji\1.5.0_0\
CHR - Extension: Codecv = C:\Users\MommaCass\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpgkoeinjnkgcieloaioiohencfcjjjc\1.0_0\
CHR - Extension: feedly = C:\Users\MommaCass\AppData\Local\Google\Chrome\User Data\Default\Extensions\hipbfijinpcgfogaopmgehiegacbhmob\10.2.437_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\MommaCass\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: Skype Click to Call = C:\Users\MommaCass\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.8.0.8855_0\
CHR - Extension: Incredible StartPage - Productive Start Page for Chrome! = C:\Users\MommaCass\AppData\Local\Google\Chrome\User Data\Default\Extensions\ncdfeghkpohnalmpblddmnppfooljekh\1.5.2_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\MommaCass\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
CHR - Extension: Shine Bright Aero Skin (by Skarv) = C:\Users\MommaCass\AppData\Local\Google\Chrome\User Data\Default\Extensions\opbmkhidakljakionlcfcnimhmgdpgll\0.0.9_0\
CHR - Extension: Bitdefender QuickScan = C:\Users\MommaCass\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdnkcidphdcakpkheohlhocaicfamjie\0.9.9.118_0\

O1 HOSTS File: ([2012/07/09 18:17:53 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2:64bit: - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O2 - BHO: (lsk_WebBlk Class) - {1935E690-1AC1-4AA5-BA23-3D9D0CEB3A00} - C:\Windows\SysWOW64\lsk_iblk.dll (LanSchool Technologies, llc)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll ()
O3:64bit: - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [accrdsub] C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe (ActivIdentity)
O4:64bit: - HKLM..\Run: [acevents] C:\Program Files\ActivIdentity\ActivClient\acevents.exe (ActivIdentity)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [HSON] C:\Program Files\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelliPoint] c:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [IntelPAN] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
O4:64bit: - HKLM..\Run: [IntelWirelessWiMAX] C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe (Intel® Corporation)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [SmartFaceVWatcher] C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatcher.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosNC] C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosReelTimeMonitor] C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosWaitSrv] C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [DNS7reminder] C:\Program Files (x86)\Nuance\NaturallySpeaking11\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [EEventManager] C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [FUFAXSTM] C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe (TOSHIBA Electronics, Inc.)
O4 - HKLM..\Run: [KeNotify] C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [LTCM Client] C:\Program Files (x86)\LTCM Client\ltcmClient.exe (Leader Technologies Inc.)
O4 - HKLM..\Run: [Qwest Personal Digital Vault] C:\Program Files (x86)\Qwest Personal Digital Vault\QwestPersonalDigitalVault.exe ()
O4 - HKLM..\Run: [SVPWUTIL] C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [Teacher] C:\Program Files (x86)\LanSchool\teacher.exe (LanSchool Technologies, llc)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TWebCamera] C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
O4 - HKCU..\Run: [Advanced SystemCare 5] C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCTray.exe (IObit)
O4 - HKCU..\Run: [Facebook Update] C:\Users\MommaCass\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [GoogleDriveSync] C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Google)
O4 - HKCU..\Run: [googletalk] C:\Users\MommaCass\AppData\Roaming\Google\Google Talk\googletalk.exe (Google)
O4 - HKCU..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
O4 - HKCU..\Run: [Spotify Web Helper] C:\Users\MommaCass\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe ()
O4 - HKCU..\Run: [WorkForce 630(Network)] C:\windows\system32\spool\DRIVERS\x64\3\E_IATIGBA.EXE /FU "C:\Users\MOMMAC~1\AppData\Local\Temp\E_S399A.tmp" /EF "HKCU" File not found
O4 - HKCU..\Run: [Xvid] C:\Program Files (x86)\Xvid\CheckUpdate.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\windows\SysNative\lskproxy64.dll (LanSchool)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\windows\SysNative\lskproxy64.dll (LanSchool)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\windows\SysNative\lskproxy64.dll (LanSchool)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\windows\SysNative\lskproxy64.dll (LanSchool)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000015 - C:\windows\SysNative\lskproxy64.dll (LanSchool)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\windows\SysWow64\lskproxy.dll (LanSchool)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\windows\SysWow64\lskproxy.dll (LanSchool)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\windows\SysWow64\lskproxy.dll (LanSchool)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\windows\SysWow64\lskproxy.dll (LanSchool)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\windows\SysWow64\lskproxy.dll (LanSchool)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 10.5.1)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 10.5.1)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2BAD4BCE-D7CE-4394-898A-0C77EF3C2827}: DhcpNameServer = 192.168.0.1 [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4BB98771-22DC-433C-82D7-7143110C531E}: DhcpNameServer = 192.168.0.1 [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{932B78C0-0CA6-41F1-A3B1-923BCDCACD1A}: NameServer = 0.0.0.0
O18:64bit: - Protocol\Handler\lbxfile - No CLSID value found
O18:64bit: - Protocol\Handler\lbxres - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\lbxfile {56831180-F115-11d2-B6AA-00104B2B9943} - C:\Program Files (x86)\Libronix DLS\System\FileProt.dll (Libronix Corporation)
O18 - Protocol\Handler\lbxres {24508F1B-9E94-40EE-9759-9AF5795ADF52} - C:\Program Files (x86)\Libronix DLS\System\ResProt.dll (Libronix Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: vidc.tscc - C:\windows\SysWOW64\tsccvid64.dll (TechSmith Corporation)
Drivers32:64bit: vidc.XVID - xvidvfw.dll ()
Drivers32: msacm.ac3filter - ac3filter.acm File not found
Drivers32: msacm.l3acm - C:\windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.pspgru - C:\windows\SysWow64\PSPGRU.acm (Philips Austria GmbH - Speech Processing)
Drivers32: vidc.cvid - C:\windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\windows\SysWow64\ff_vfw.dll ()
Drivers32: vidc.tscc - C:\Windows\SysWOW64\tsccvid.dll (TechSmith Corporation)
Drivers32: vidc.VP60 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
Drivers32: vidc.XVID - C:\windows\SysWow64\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\windows\SysWow64\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/07/11 16:24:21 | 000,596,480 | —- | C] (OldTimer Tools) – C:\Users\MommaCass\Desktop\OTL.exe
[2012/07/11 14:29:22 | 000,000,000 | —D | C] – C:\_OTM
[2012/07/11 14:26:41 | 000,522,240 | —- | C] (OldTimer Tools) – C:\Users\MommaCass\Desktop\OTM.exe
[2012/07/11 14:12:55 | 000,000,000 | —D | C] – C:\Users\MommaCass\AppData\Roaming\SpeedyPC Software
[2012/07/11 14:12:55 | 000,000,000 | —D | C] – C:\Users\MommaCass\AppData\Roaming\DriverCure
[2012/07/11 14:12:50 | 000,000,000 | —D | C] – C:\Users\MommaCass\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedyPC Software
[2012/07/11 14:12:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\SpeedyPC Software
[2012/07/11 14:12:47 | 000,000,000 | —D | C] – C:\ProgramData\SpeedyPC Software
[2012/07/11 14:12:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\SpeedyPC Software
[2012/07/10 14:21:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Security Client
[2012/07/10 14:21:08 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2012/07/10 13:48:03 | 000,307,200 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ncrypt.dll
[2012/07/10 13:45:21 | 002,311,680 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\jscript9.dll
[2012/07/10 13:45:21 | 000,818,688 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\jscript.dll
[2012/07/10 13:45:21 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\jscript.dll
[2012/07/10 13:45:21 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ieui.dll
[2012/07/10 13:45:21 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ieui.dll
[2012/07/10 13:45:21 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ieUnatt.exe
[2012/07/10 13:45:21 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ieUnatt.exe
[2012/07/10 13:45:21 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\mshtmled.dll
[2012/07/10 13:45:21 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\mshtmled.dll
[2012/07/10 13:45:20 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\inetcpl.cpl
[2012/07/10 13:45:20 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\inetcpl.cpl
[2012/07/10 13:45:20 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\url.dll
[2012/07/10 13:45:20 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\url.dll
[2012/07/10 13:31:13 | 000,000,000 | —D | C] – C:\Users\MommaCass\AppData\Roaming\QuickScan
[2012/07/09 21:46:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2012/07/09 21:45:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Oracle
[2012/07/09 21:45:20 | 000,772,504 | —- | C] (Oracle Corporation) – C:\windows\SysWow64\npDeployJava1.dll
[2012/07/09 21:45:20 | 000,227,720 | —- | C] (Oracle Corporation) – C:\windows\SysWow64\javaws.exe
[2012/07/09 21:40:20 | 000,000,000 | —D | C] – C:\ProgramData\McAfee
[2012/07/09 18:35:28 | 000,000,000 | —D | C] – C:\Users\MommaCass\AppData\Roaming\Malwarebytes
[2012/07/09 18:35:03 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/07/09 18:23:49 | 000,000,000 | —D | C] – C:\windows\temp
[2012/07/09 18:17:55 | 000,000,000 | —D | C] – C:\$RECYCLE.BIN
[2012/07/09 17:38:40 | 000,000,000 | —D | C] – C:\Qoobox
[2012/07/09 17:38:37 | 000,000,000 | —D | C] – C:\windows\erdnt
[2012/07/08 14:58:19 | 002,622,464 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wucltux.dll
[2012/07/08 14:58:19 | 000,057,880 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wuauclt.exe
[2012/07/08 14:58:19 | 000,044,056 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wups2.dll
[2012/07/08 14:58:11 | 000,701,976 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wuapi.dll
[2012/07/08 14:58:11 | 000,099,840 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wudriver.dll
[2012/07/08 14:58:11 | 000,038,424 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wups.dll
[2012/07/08 14:57:54 | 000,186,752 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wuwebv.dll
[2012/07/08 14:57:54 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wuapp.exe
[2012/06/29 02:03:13 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xvid
[2012/06/29 02:03:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\Xvid
[2012/06/28 01:58:23 | 000,000,000 | —D | C] – C:\Users\MommaCass\Desktop\Personal
[2012/06/25 15:57:25 | 028,903,296 | —- | C] (Amazon.com) – C:\Users\MommaCass\Desktop\temp_%1%2
[2012/06/25 15:53:31 | 000,000,000 | —D | C] – C:\Users\MommaCass\Desktop\KindleGen
[2012/06/24 13:16:07 | 003,213,824 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\msi.dll
[2012/06/24 13:15:38 | 001,460,224 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\crypt32.dll
[2012/06/24 13:15:38 | 000,140,288 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\cryptnet.dll
[2012/06/23 15:23:02 | 000,000,000 | —D | C] – C:\Users\MommaCass\AppData\Local\Macromedia
[2012/06/23 12:51:17 | 000,000,000 | -HSD | C] – C:\windows\SysWow64\%APPDATA%
[2012/06/21 00:36:35 | 000,527,192 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\XAudio2_7.dll
[2012/06/21 00:36:35 | 000,518,488 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\XAudio2_7.dll
[2012/06/21 00:36:35 | 000,077,656 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\XAPOFX1_5.dll
[2012/06/21 00:36:35 | 000,074,072 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\XAPOFX1_5.dll
[2012/06/21 00:36:34 | 000,239,960 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\xactengine3_7.dll
[2012/06/21 00:36:34 | 000,176,984 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\xactengine3_7.dll
[2012/06/21 00:36:33 | 002,526,056 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\D3DCompiler_43.dll
[2012/06/21 00:36:33 | 002,106,216 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\D3DCompiler_43.dll
[2012/06/21 00:36:33 | 001,907,552 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\d3dcsx_43.dll
[2012/06/21 00:36:33 | 001,868,128 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\d3dcsx_43.dll
[2012/06/21 00:36:32 | 000,276,832 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\d3dx11_43.dll
[2012/06/21 00:36:32 | 000,248,672 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\d3dx11_43.dll
[2012/06/21 00:36:31 | 002,401,112 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\D3DX9_43.dll
[2012/06/21 00:36:31 | 001,998,168 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\D3DX9_43.dll
[2012/06/21 00:36:31 | 000,511,328 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\d3dx10_43.dll
[2012/06/21 00:36:31 | 000,470,880 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\d3dx10_43.dll
[2012/06/21 00:36:30 | 000,530,776 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\XAudio2_6.dll
[2012/06/21 00:36:30 | 000,528,216 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\XAudio2_6.dll
[2012/06/21 00:36:30 | 000,078,680 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\XAPOFX1_4.dll
[2012/06/21 00:36:30 | 000,074,072 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\XAPOFX1_4.dll
[2012/06/21 00:36:28 | 000,238,936 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\xactengine3_6.dll
[2012/06/21 00:36:28 | 000,176,984 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\xactengine3_6.dll
[2012/06/21 00:36:28 | 000,024,920 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\X3DAudio1_7.dll
[2012/06/21 00:36:28 | 000,022,360 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\X3DAudio1_7.dll
[2012/06/21 00:36:27 | 000,517,960 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\XAudio2_5.dll
[2012/06/21 00:36:26 | 002,582,888 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\D3DCompiler_42.dll
[2012/06/21 00:36:26 | 001,974,616 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\D3DCompiler_42.dll
[2012/06/21 00:36:26 | 000,238,936 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\xactengine3_5.dll
[2012/06/21 00:36:26 | 000,176,968 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\xactengine3_5.dll
[2012/06/21 00:36:25 | 005,554,512 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\d3dcsx_42.dll
[2012/06/21 00:36:25 | 005,501,792 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\d3dcsx_42.dll
[2012/06/21 00:36:24 | 002,475,352 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\D3DX9_42.dll
[2012/06/21 00:36:24 | 002,430,312 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\D3DCompiler_41.dll
[2012/06/21 00:36:24 | 001,892,184 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\D3DX9_42.dll
[2012/06/21 00:36:24 | 000,520,544 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\d3dx10_41.dll
[2012/06/21 00:36:24 | 000,285,024 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\d3dx11_42.dll
[2012/06/21 00:36:24 | 000,235,344 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\d3dx11_42.dll
[2012/06/21 00:36:23 | 005,425,496 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\D3DX9_41.dll
[2012/06/21 00:36:22 | 000,521,560 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\XAudio2_4.dll
[2012/06/21 00:36:22 | 000,517,448 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\XAudio2_4.dll
[2012/06/21 00:36:22 | 000,235,352 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\xactengine3_4.dll
[2012/06/21 00:36:22 | 000,174,936 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\xactengine3_4.dll
[2012/06/21 00:36:22 | 000,073,544 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\XAPOFX1_3.dll
[2012/06/21 00:36:21 | 002,605,920 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\D3DCompiler_40.dll
[2012/06/21 00:36:21 | 002,036,576 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\D3DCompiler_40.dll
[2012/06/21 00:36:21 | 000,519,000 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\d3dx10_40.dll
[2012/06/21 00:36:21 | 000,452,440 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\d3dx10_40.dll
[2012/06/21 00:36:21 | 000,024,920 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\X3DAudio1_6.dll
[2012/06/21 00:36:21 | 000,022,360 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\X3DAudio1_6.dll
[2012/06/21 00:36:20 | 005,631,312 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\D3DX9_40.dll
[2012/06/21 00:36:20 | 004,379,984 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\D3DX9_40.dll
[2012/06/21 00:36:20 | 000,518,480 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\XAudio2_3.dll
[2012/06/21 00:36:20 | 000,514,384 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\XAudio2_3.dll
[2012/06/21 00:36:20 | 000,074,576 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\XAPOFX1_2.dll
[2012/06/21 00:36:20 | 000,070,992 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\XAPOFX1_2.dll
[2012/06/21 00:36:19 | 000,235,856 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\xactengine3_3.dll
[2012/06/21 00:36:19 | 000,175,440 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\xactengine3_3.dll
[2012/06/21 00:36:19 | 000,025,936 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\X3DAudio1_5.dll
[2012/06/21 00:36:19 | 000,023,376 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\X3DAudio1_5.dll
[2012/06/21 00:36:18 | 000,513,544 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\XAudio2_2.dll
[2012/06/21 00:36:18 | 000,509,448 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\XAudio2_2.dll
[2012/06/21 00:36:18 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\xactengine3_2.dll
[2012/06/21 00:36:18 | 000,177,672 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\xactengine3_2.dll
[2012/06/21 00:36:18 | 000,072,200 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\XAPOFX1_1.dll
[2012/06/21 00:36:18 | 000,068,616 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\XAPOFX1_1.dll
[2012/06/21 00:36:17 | 001,942,552 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\D3DCompiler_39.dll
[2012/06/21 00:36:17 | 001,493,528 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\D3DCompiler_39.dll
[2012/06/21 00:36:17 | 000,540,688 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\d3dx10_39.dll
[2012/06/21 00:36:17 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\d3dx10_39.dll
[2012/06/21 00:36:16 | 004,992,520 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\D3DX9_39.dll
[2012/06/21 00:36:16 | 003,851,784 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\D3DX9_39.dll
[2012/06/21 00:36:15 | 000,068,104 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\XAPOFX1_0.dll
[2012/06/21 00:36:15 | 000,065,032 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\XAPOFX1_0.dll
[2012/06/21 00:36:14 | 000,511,496 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\XAudio2_1.dll
[2012/06/21 00:36:14 | 000,507,400 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\XAudio2_1.dll
[2012/06/21 00:36:13 | 001,941,528 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\D3DCompiler_38.dll
[2012/06/21 00:36:13 | 001,491,992 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\D3DCompiler_38.dll
[2012/06/21 00:36:13 | 000,540,688 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\d3dx10_38.dll
[2012/06/21 00:36:13 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\d3dx10_38.dll
[2012/06/21 00:36:13 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\xactengine3_1.dll
[2012/06/21 00:36:13 | 000,177,672 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\xactengine3_1.dll
[2012/06/21 00:36:13 | 000,028,168 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\X3DAudio1_4.dll
[2012/06/21 00:36:13 | 000,025,608 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\X3DAudio1_4.dll
[2012/06/21 00:36:12 | 004,991,496 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\D3DX9_38.dll
[2012/06/21 00:36:12 | 003,850,760 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\D3DX9_38.dll
[2012/06/21 00:36:12 | 000,489,480 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\XAudio2_0.dll
[2012/06/21 00:36:12 | 000,479,752 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\XAudio2_0.dll
[2012/06/21 00:36:11 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\xactengine3_0.dll
[2012/06/21 00:36:11 | 000,177,672 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\xactengine3_0.dll
[2012/06/21 00:36:11 | 000,028,168 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\X3DAudio1_3.dll
[2012/06/21 00:36:11 | 000,025,608 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\X3DAudio1_3.dll
[2012/06/21 00:36:10 | 004,910,088 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\D3DX9_37.dll
[2012/06/21 00:36:10 | 003,786,760 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\D3DX9_37.dll
[2012/06/21 00:36:10 | 001,860,120 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\D3DCompiler_37.dll
[2012/06/21 00:36:10 | 001,420,824 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\D3DCompiler_37.dll
[2012/06/21 00:36:10 | 000,529,424 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\d3dx10_37.dll
[2012/06/21 00:36:10 | 000,462,864 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\d3dx10_37.dll
[2012/06/21 00:36:10 | 000,411,656 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\xactengine2_10.dll
[2012/06/21 00:36:10 | 000,267,272 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\xactengine2_10.dll
[2012/06/21 00:36:09 | 002,006,552 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\D3DCompiler_36.dll
[2012/06/21 00:36:09 | 001,374,232 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\D3DCompiler_36.dll
[2012/06/21 00:36:09 | 000,508,264 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\d3dx10_36.dll
[2012/06/21 00:36:09 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\d3dx10_36.dll
[2012/06/21 00:36:08 | 005,081,608 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\d3dx9_36.dll
[2012/06/21 00:36:08 | 003,734,536 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\d3dx9_36.dll
[2012/06/21 00:36:07 | 001,985,904 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\D3DCompiler_35.dll
[2012/06/21 00:36:07 | 001,358,192 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\D3DCompiler_35.dll
[2012/06/21 00:36:07 | 000,508,264 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\d3dx10_35.dll
[2012/06/21 00:36:07 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\d3dx10_35.dll
[2012/06/21 00:36:07 | 000,411,496 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\xactengine2_9.dll
[2012/06/21 00:36:07 | 000,267,112 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\xactengine2_9.dll
[2012/06/21 00:36:06 | 005,073,256 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\d3dx9_35.dll
[2012/06/21 00:36:06 | 003,727,720 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\d3dx9_35.dll
[2012/06/21 00:36:04 | 004,496,232 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\d3dx9_34.dll
[2012/06/21 00:36:04 | 003,497,832 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\d3dx9_34.dll
[2012/06/21 00:36:04 | 001,401,200 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\D3DCompiler_34.dll
[2012/06/21 00:36:04 | 001,124,720 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\D3DCompiler_34.dll
[2012/06/21 00:36:04 | 000,506,728 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\d3dx10_34.dll
[2012/06/21 00:36:04 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\d3dx10_34.dll
[2012/06/21 00:36:04 | 000,409,960 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\xactengine2_8.dll
[2012/06/21 00:36:04 | 000,266,088 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\xactengine2_8.dll
[2012/06/21 00:36:04 | 000,021,000 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\X3DAudio1_2.dll
[2012/06/21 00:36:04 | 000,017,928 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\X3DAudio1_2.dll
[2012/06/21 00:36:03 | 000,107,368 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\xinput1_3.dll
[2012/06/21 00:36:03 | 000,081,768 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\xinput1_3.dll
[2012/06/21 00:36:01 | 000,403,304 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\xactengine2_7.dll
[2012/06/21 00:36:01 | 000,261,480 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\xactengine2_7.dll
[2012/06/21 00:36:00 | 004,494,184 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\d3dx9_33.dll
[2012/06/21 00:36:00 | 003,495,784 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\d3dx9_33.dll
[2012/06/21 00:36:00 | 001,400,176 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\D3DCompiler_33.dll
[2012/06/21 00:36:00 | 001,123,696 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\D3DCompiler_33.dll
[2012/06/21 00:36:00 | 000,506,728 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\d3dx10_33.dll
[2012/06/21 00:36:00 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\d3dx10_33.dll
[2012/06/21 00:35:59 | 000,393,576 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\xactengine2_6.dll
[2012/06/21 00:35:59 | 000,255,848 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\xactengine2_6.dll
[2012/06/21 00:35:58 | 003,977,496 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\d3dx9_31.dll
[2012/06/21 00:35:58 | 002,414,360 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\d3dx9_31.dll
[2012/06/21 00:35:58 | 000,469,264 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\d3dx10.dll
[2012/06/21 00:35:58 | 000,440,080 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\d3dx10.dll
[2012/06/21 00:35:58 | 000,390,424 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\xactengine2_5.dll
[2012/06/21 00:35:58 | 000,364,824 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\xactengine2_4.dll
[2012/06/21 00:35:58 | 000,251,672 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\xactengine2_5.dll
[2012/06/21 00:35:58 | 000,237,848 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\xactengine2_4.dll
[2012/06/21 00:35:58 | 000,017,688 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\x3daudio1_1.dll
[2012/06/21 00:35:58 | 000,015,128 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\x3daudio1_1.dll
[2012/06/21 00:35:57 | 000,363,288 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\xactengine2_3.dll
[2012/06/21 00:35:57 | 000,236,824 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\xactengine2_3.dll
[2012/06/21 00:35:57 | 000,083,736 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\xinput1_2.dll
[2012/06/21 00:35:57 | 000,062,744 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\xinput1_2.dll
[2012/06/21 00:35:56 | 000,354,072 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\xactengine2_2.dll
[2012/06/21 00:35:56 | 000,230,168 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\xactengine2_2.dll
[2012/06/21 00:35:56 | 000,083,664 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\xinput1_1.dll
[2012/06/21 00:35:56 | 000,062,672 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\xinput1_1.dll
[2012/06/21 00:35:54 | 000,352,464 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\xactengine2_1.dll
[2012/06/21 00:35:54 | 000,229,584 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\xactengine2_1.dll
[2012/06/21 00:35:49 | 003,927,248 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\d3dx9_30.dll
[2012/06/21 00:35:49 | 002,388,176 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\d3dx9_30.dll
[2012/06/21 00:35:48 | 003,830,992 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\d3dx9_29.dll
[2012/06/21 00:35:48 | 002,332,368 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\d3dx9_29.dll
[2012/06/21 00:35:48 | 000,355,536 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\xactengine2_0.dll
[2012/06/21 00:35:48 | 000,230,096 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\xactengine2_0.dll
[2012/06/21 00:35:48 | 000,016,592 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\x3daudio1_0.dll
[2012/06/21 00:35:48 | 000,014,032 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\x3daudio1_0.dll
[2012/06/21 00:35:47 | 003,815,120 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\d3dx9_28.dll
[2012/06/21 00:35:47 | 002,323,664 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\d3dx9_28.dll
[2012/06/21 00:35:46 | 003,807,440 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\d3dx9_27.dll
[2012/06/21 00:35:46 | 002,319,568 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\d3dx9_27.dll
[2012/06/21 00:35:45 | 003,823,312 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\d3dx9_25.dll
[2012/06/21 00:35:45 | 003,767,504 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\d3dx9_26.dll
[2012/06/21 00:35:45 | 002,337,488 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\d3dx9_25.dll
[2012/06/21 00:35:45 | 002,297,552 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\d3dx9_26.dll
[2012/06/21 00:35:44 | 003,544,272 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\d3dx9_24.dll
[2012/06/21 00:35:44 | 002,222,800 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\d3dx9_24.dll
[2012/06/21 00:22:06 | 000,000,000 | —D | C] – C:\Users\MommaCass\AppData\Roaming\Media Player Classic
[2012/06/21 00:11:29 | 000,000,000 | —D | C] – C:\windows\SysWow64\directx
[2012/06/21 00:10:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC-HC x64
[2012/06/21 00:10:39 | 000,000,000 | —D | C] – C:\Program Files\MPC-HC
[2012/06/21 00:05:31 | 000,000,000 | —D | C] – C:\Users\MommaCass\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mega Codec Pack
[2012/06/21 00:05:29 | 000,000,000 | —D | C] – C:\ProgramData\Windows Codecs
[2012/06/21 00:05:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mega Codec Pack
[2012/06/20 20:42:40 | 000,000,000 | —D | C] – C:\Users\MommaCass\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AC3Filter
[2012/06/20 20:42:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AC3Filter
[2012/06/20 20:42:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\AC3Filter
[2012/06/20 20:41:23 | 000,000,000 | —D | C] – C:\Users\MommaCass\AppData\Local\DDMSettings
[2012/06/20 19:06:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\uTorrent
[2012/06/20 19:06:05 | 000,000,000 | —D | C] – C:\Users\MommaCass\AppData\Roaming\uTorrent
[2012/06/13 20:48:08 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\rdpcorekmts.dll
[2012/06/13 20:48:08 | 000,076,288 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\rdpwsx.dll
[2012/06/13 20:48:08 | 000,009,216 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\rdrmemptylst.exe
[2012/06/13 20:48:05 | 005,505,392 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ntoskrnl.exe
[2012/06/13 20:48:04 | 003,958,128 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ntkrnlpa.exe
[2012/06/13 20:48:04 | 003,902,320 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ntoskrnl.exe
[2012/06/12 18:25:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Codecv
[2012/06/12 18:25:41 | 000,000,000 | —D | C] – C:\ProgramData\Codecv
[1 C:\Users\MommaCass\Desktop\*.tmp files -> C:\Users\MommaCass\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/07/11 16:25:00 | 000,000,830 | —- | M] () – C:\windows\tasks\Adobe Flash Player Updater.job
[2012/07/11 16:24:02 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Users\MommaCass\Desktop\OTL.exe
[2012/07/11 16:19:00 | 000,000,904 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/07/11 16:13:00 | 000,000,924 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1607321905-2529273621-3586155247-1000UA.job
[2012/07/11 15:20:58 | 000,016,304 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/11 15:20:58 | 000,016,304 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/11 15:17:52 | 000,787,136 | —- | M] () – C:\windows\SysNative\PerfStringBackup.INI
[2012/07/11 15:17:52 | 000,667,072 | —- | M] () – C:\windows\SysNative\perfh009.dat
[2012/07/11 15:17:52 | 000,123,188 | —- | M] () – C:\windows\SysNative\perfc009.dat
[2012/07/11 15:13:31 | 000,000,410 | —- | M] () – C:\windows\tasks\FreeFileViewerUpdateChecker.job
[2012/07/11 15:13:30 | 000,000,900 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/07/11 15:13:05 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2012/07/11 15:12:58 | 3059,748,864 | -HS- | M] () – C:\hiberfil.sys
[2012/07/11 14:33:15 | 000,000,500 | —- | M] () – C:\windows\tasks\SpeedyPC Registration3.job
[2012/07/11 14:33:15 | 000,000,472 | —- | M] () – C:\windows\tasks\SpeedyPC Update Version3.job
[2012/07/11 14:33:15 | 000,000,428 | —- | M] () – C:\windows\tasks\SpeedyPC Pro.job
[2012/07/11 14:26:44 | 000,522,240 | —- | M] (OldTimer Tools) – C:\Users\MommaCass\Desktop\OTM.exe
[2012/07/11 14:12:50 | 000,001,170 | —- | M] () – C:\Users\MommaCass\Desktop\SpeedyPC Pro.lnk
[2012/07/11 14:07:00 | 000,000,944 | —- | M] () – C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-1607321905-2529273621-3586155247-1000UA.job
[2012/07/11 14:07:00 | 000,000,922 | —- | M] () – C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-1607321905-2529273621-3586155247-1000Core.job
[2012/07/10 20:13:00 | 000,000,872 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1607321905-2529273621-3586155247-1000Core.job
[2012/07/10 14:21:41 | 000,001,945 | —- | M] () – C:\windows\epplauncher.mif
[2012/07/10 14:21:26 | 000,800,918 | —- | M] () – C:\windows\SysWow64\PerfStringBackup.INI
[2012/07/10 14:00:28 | 000,935,648 | —- | M] () – C:\windows\SysNative\FNTCACHE.DAT
[2012/07/10 13:48:03 | 000,307,200 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\ncrypt.dll
[2012/07/10 13:45:21 | 002,311,680 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\jscript9.dll
[2012/07/10 13:45:21 | 000,818,688 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\jscript.dll
[2012/07/10 13:45:21 | 000,716,800 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\jscript.dll
[2012/07/10 13:45:21 | 000,248,320 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\ieui.dll
[2012/07/10 13:45:21 | 000,176,640 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\ieui.dll
[2012/07/10 13:45:21 | 000,173,056 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\ieUnatt.exe
[2012/07/10 13:45:21 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\ieUnatt.exe
[2012/07/10 13:45:21 | 000,096,768 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\mshtmled.dll
[2012/07/10 13:45:21 | 000,073,216 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\mshtmled.dll
[2012/07/10 13:45:20 | 001,494,528 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\inetcpl.cpl
[2012/07/10 13:45:20 | 001,427,968 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\inetcpl.cpl
[2012/07/10 13:45:20 | 000,237,056 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\url.dll
[2012/07/10 13:45:20 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\url.dll
[2012/07/09 21:45:00 | 000,174,064 | —- | M] (Oracle Corporation) – C:\windows\SysWow64\javaw.exe
[2012/07/09 21:45:00 | 000,174,064 | —- | M] (Oracle Corporation) – C:\windows\SysWow64\java.exe
[2012/07/09 18:17:53 | 000,000,027 | —- | M] () – C:\windows\SysNative\drivers\etc\hosts
[2012/07/08 21:56:38 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\windows\SysWow64\FlashPlayerApp.exe
[2012/07/08 21:56:38 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/06/25 16:01:13 | 028,903,296 | —- | M] (Amazon.com) – C:\Users\MommaCass\Desktop\temp_%1%2
[2012/06/25 15:52:02 | 001,228,422 | —- | M] () – C:\Users\MommaCass\Desktop\Fifty Shades of Grey - E L James.mobi
[2012/06/25 09:44:00 | 000,001,577 | —- | M] () – C:\Users\Public\Desktop\Launch PERRLA.lnk
[2012/06/24 13:16:07 | 003,213,824 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\msi.dll
[2012/06/24 13:15:38 | 001,460,224 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\crypt32.dll
[2012/06/24 13:15:38 | 000,140,288 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\cryptnet.dll
[2012/06/22 21:26:13 | 009,815,752 | —- | M] (Adobe Systems Incorporated) – C:\windows\SysWow64\FlashPlayerInstaller.exe
[2012/06/21 00:10:41 | 000,001,723 | —- | M] () – C:\Users\MommaCass\Desktop\MPC-HC x64.lnk
[2012/06/20 20:40:43 | 000,002,091 | —- | M] () – C:\Users\Public\Desktop\DivX Plus Converter.lnk
[2012/06/20 20:40:43 | 000,001,633 | —- | M] () – C:\Users\MommaCass\Desktop\DivX Movies.lnk
[2012/06/20 20:40:34 | 000,001,087 | —- | M] () – C:\Users\Public\Desktop\DivX Plus Player.lnk
[2012/06/20 19:06:59 | 000,000,918 | —- | M] () – C:\Users\Public\Desktop\µTorrent.lnk
[1 C:\Users\MommaCass\Desktop\*.tmp files -> C:\Users\MommaCass\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/07/11 14:12:58 | 000,000,500 | —- | C] () – C:\windows\tasks\SpeedyPC Registration3.job
[2012/07/11 14:12:50 | 000,001,170 | —- | C] () – C:\Users\MommaCass\Desktop\SpeedyPC Pro.lnk
[2012/07/11 14:12:49 | 000,000,472 | —- | C] () – C:\windows\tasks\SpeedyPC Update Version3.job
[2012/07/11 14:12:49 | 000,000,428 | —- | C] () – C:\windows\tasks\SpeedyPC Pro.job
[2012/07/10 14:21:34 | 000,001,926 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/06/29 02:03:12 | 000,696,832 | —- | C] () – C:\windows\SysNative\xvidcore.dll
[2012/06/29 02:03:12 | 000,645,632 | —- | C] () – C:\windows\SysWow64\xvidcore.dll
[2012/06/29 02:03:12 | 000,255,488 | —- | C] () – C:\windows\SysNative\xvidvfw.dll
[2012/06/29 02:03:12 | 000,240,640 | —- | C] () – C:\windows\SysWow64\xvidvfw.dll
[2012/06/29 02:03:12 | 000,173,568 | —- | C] () – C:\windows\SysNative\xvid.ax
[2012/06/29 02:03:12 | 000,153,088 | —- | C] () – C:\windows\SysWow64\xvid.ax
[2012/06/25 15:52:04 | 001,228,422 | —- | C] () – C:\Users\MommaCass\Desktop\Fifty Shades of Grey - E L James.mobi
[2012/06/21 00:10:41 | 000,204,800 | —- | C] () – C:\windows\SysNative\unrar64.dll
[2012/06/21 00:10:41 | 000,001,723 | —- | C] () – C:\Users\MommaCass\Desktop\MPC-HC x64.lnk
[2012/06/20 20:42:40 | 000,421,888 | —- | C] () – C:\windows\SysNative\ac3filter.acm
[2012/06/20 20:40:43 | 000,001,633 | —- | C] () – C:\Users\MommaCass\Desktop\DivX Movies.lnk
[2012/06/20 20:40:34 | 000,001,087 | —- | C] () – C:\Users\Public\Desktop\DivX Plus Player.lnk
[2012/06/20 20:40:10 | 000,002,091 | —- | C] () – C:\Users\Public\Desktop\DivX Plus Converter.lnk
[2012/06/20 19:06:59 | 000,000,918 | —- | C] () – C:\Users\Public\Desktop\µTorrent.lnk
[2012/06/03 11:39:32 | 000,004,608 | —- | C] () – C:\Users\MommaCass\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/03/26 20:19:09 | 000,102,912 | —- | C] () – C:\windows\agent_x64.exe
[2012/02/03 01:47:32 | 000,002,035 | —- | C] () – C:\Users\MommaCass\AppData\Roaming\SAS7_000.DAT
[2012/01/09 16:49:38 | 000,000,028 | —- | C] () – C:\windows\pdf995.ini
[2011/12/31 18:46:53 | 000,000,000 | —- | C] () – C:\windows\EEventManager.INI
[2011/11/05 11:56:01 | 000,000,079 | —- | C] () – C:\windows\EWF630.ini
[2011/06/23 14:22:54 | 000,057,344 | —- | C] () – C:\windows\SysWow64\ff_vfw.dll
[2011/03/03 15:23:02 | 000,000,122 | —- | C] () – C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2011/01/16 09:50:03 | 000,047,616 | —- | C] () – C:\windows\SysWow64\pdf995mon64.dll
[2011/01/16 09:50:03 | 000,000,060 | —- | C] () – C:\windows\wpd99.drv
[2010/12/30 11:15:15 | 000,073,220 | —- | C] () – C:\windows\SysWow64\EPPICPrinterDB.dat
[2010/12/30 11:15:15 | 000,031,053 | —- | C] () – C:\windows\SysWow64\EPPICPattern131.dat
[2010/12/30 11:15:15 | 000,029,114 | —- | C] () – C:\windows\SysWow64\EPPICPattern1.dat
[2010/12/30 11:15:15 | 000,027,417 | —- | C] () – C:\windows\SysWow64\EPPICPattern121.dat
[2010/12/30 11:15:15 | 000,021,021 | —- | C] () – C:\windows\SysWow64\EPPICPattern3.dat
[2010/12/30 11:15:15 | 000,015,670 | —- | C] () – C:\windows\SysWow64\EPPICPattern5.dat
[2010/12/30 11:15:15 | 000,013,280 | —- | C] () – C:\windows\SysWow64\EPPICPattern2.dat
[2010/12/30 11:15:15 | 000,010,673 | —- | C] () – C:\windows\SysWow64\EPPICPattern4.dat
[2010/12/30 11:15:15 | 000,004,943 | —- | C] () – C:\windows\SysWow64\EPPICPattern6.dat
[2010/12/30 11:15:15 | 000,001,140 | —- | C] () – C:\windows\SysWow64\EPPICPresetData_PT.dat
[2010/12/30 11:15:15 | 000,001,140 | —- | C] () – C:\windows\SysWow64\EPPICPresetData_BP.dat
[2010/12/30 11:15:15 | 000,001,137 | —- | C] () – C:\windows\SysWow64\EPPICPresetData_ES.dat
[2010/12/30 11:15:15 | 000,001,130 | —- | C] () – C:\windows\SysWow64\EPPICPresetData_FR.dat
[2010/12/30 11:15:15 | 000,001,130 | —- | C] () – C:\windows\SysWow64\EPPICPresetData_CF.dat
[2010/12/30 11:15:15 | 000,001,104 | —- | C] () – C:\windows\SysWow64\EPPICPresetData_EN.dat
[2010/12/30 11:15:15 | 000,000,097 | —- | C] () – C:\windows\SysWow64\PICSDK.ini
[2010/12/30 01:17:40 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/12/30 00:01:24 | 000,002,992 | —- | C] () – C:\windows\SysWow64\LskProxy.ini
[2010/12/30 00:01:24 | 000,001,776 | —- | C] () – C:\windows\SysWow64\LSKProxyOff.ini
[2010/12/29 17:38:11 | 000,800,918 | —- | C] () – C:\windows\SysWow64\PerfStringBackup.INI
[2010/11/30 12:29:32 | 000,061,232 | —- | C] () – C:\windows\SysWow64\lskhook64.dll
[2010/11/30 12:29:30 | 000,075,056 | —- | C] () – C:\windows\SysWow64\lskhook.dll

========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2009/07/13 18:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2010/08/30 13:44:47 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2011/11/15 17:12:39 | 000,000,066 | —- | M] () – C:\Err.log
[2011/11/01 22:49:42 | 000,000,485 | —- | M] () – C:\GingerSetup.log
[2012/07/11 15:12:58 | 3059,748,864 | -HS- | M] () – C:\hiberfil.sys
[2011/11/26 01:02:20 | 000,001,650 | —- | M] () – C:\InstallHelper.log
[2011/04/27 18:39:06 | 001,356,905 | —- | M] () – C:\lskproxy-aln.dmp
[2005/09/23 00:39:38 | 000,894,976 | —- | M] (Microsoft Corporation) – C:\msdia80.dll
[2012/07/11 15:13:03 | 4079,665,152 | -HS- | M] () – C:\pagefile.sys
[2012/03/15 08:12:44 | 000,000,510 | —- | M] () – C:\settings.ini
[2012/05/18 11:31:09 | 000,000,487 | —- | M] () – C:\user.js
[2012/03/15 21:39:23 | 000,007,717 | —- | M] () – C:\WirelessDiagLog.csv

< %systemroot%\Fonts\*.com >
[2009/07/13 22:32:31 | 000,026,040 | —- | M] () – C:\windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 22:32:31 | 000,026,489 | —- | M] () – C:\windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 22:32:31 | 000,029,779 | —- | M] () – C:\windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 22:32:31 | 000,043,318 | —- | M] () – C:\windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 13:49:50 | 000,000,065 | —- | M] () – C:\windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/09/23 00:32:56 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 21:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/06/21 15:45:22 | 000,000,221 | -HS- | M] () – C:\Users\MommaCass\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2012/06/08 22:17:31 | 143,878,616 | —- | M] (Smith Micro Software, Inc.) – C:\Users\MommaCass\Desktop\Grocery University.exe
[2012/07/11 16:24:02 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Users\MommaCass\Desktop\OTL.exe
[2012/07/11 14:26:44 | 000,522,240 | —- | M] (OldTimer Tools) – C:\Users\MommaCass\Desktop\OTM.exe
[1 C:\Users\MommaCass\Desktop\*.tmp files -> C:\Users\MommaCass\Desktop\*.tmp -> ]

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >
[2010/10/20 21:23:26 | 000,000,698 | —- | M] () – C:\windows\AppPatch\Custom\{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 235 bytes -> C:\ProgramData\TEMP:0FF263E8

< End of report >

Extras.txt


OTL Extras logfile created on: 7/11/2012 4:26:53 PM - Run 1
OTL by OldTimer - Version 3.2.54.0 Folder = C:\Users\MommaCass\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.80 Gb Total Physical Memory | 2.16 Gb Available Physical Memory | 56.81% Memory free
7.60 Gb Paging File | 5.45 Gb Available in Paging File | 71.72% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 452.70 Gb Total Space | 103.98 Gb Free Space | 22.97% Space Free | Partition Type: NTFS
Drive E: | 7.39 Gb Total Space | 7.14 Gb Free Space | 96.58% Space Free | Partition Type: FAT32

Computer Name: MOMMACASS-PC | User Name: MommaCass | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [print] – rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0294BB2F-6178-459D-8C46-8D1C40D6AD6B}" = rport=445 | protocol=6 | dir=out | app=system |
"{057550CC-1C7E-4C7B-A2F8-3A8DDC978C8C}" = lport=138 | protocol=17 | dir=in | app=system |
"{08E024BB-596A-4DFF-A430-159062EB67CE}" = lport=10243 | protocol=6 | dir=in | app=system |
"{19A5737B-0BEE-43C8-BCD3-3CC714AA4FD3}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{25B9D31D-64EC-44F5-900B-17177C3E5D3C}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{295EF879-34FC-4A05-A484-51AA1443280E}" = lport=445 | protocol=6 | dir=in | app=system |
"{2FA65B31-3A9D-4C20-AFC6-469495F0EF44}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{4084E937-EAAA-47EE-9520-7BE7CE434C09}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{4BF5EB07-06A2-40E2-B5B6-244EF5C49A0F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{5456EA1E-AF45-48BD-9C96-AB99A6CCF1D9}" = lport=139 | protocol=6 | dir=in | app=system |
"{6364B77A-8796-4078-B3CC-5963A3E70B4F}" = rport=139 | protocol=6 | dir=out | app=system |
"{6EFD3216-D4DB-448C-81DA-E8838C66FFD2}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{7C7BD74E-D59D-40F9-8481-A74C4729E9DD}" = rport=138 | protocol=17 | dir=out | app=system |
"{86444BB3-291D-4D31-A046-BB4AA3243C28}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{AF8150A9-8B4A-4262-900E-D368942052B3}" = lport=2869 | protocol=6 | dir=in | app=system |
"{BE10AB93-C4A6-464B-BE93-069E778BFF99}" = rport=10243 | protocol=6 | dir=out | app=system |
"{C232D951-55E7-4D04-9346-F88A07FC0B22}" = lport=137 | protocol=17 | dir=in | app=system |
"{C428A183-FD79-40B5-990D-895328F43AC8}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{CF0676E6-E2EC-438A-9741-7029DEBD00CE}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F534D21D-02A4-4E48-A237-A3745ED5E6D3}" = rport=137 | protocol=17 | dir=out | app=system |
"{F9C1EEE5-72B7-40C6-BC7C-64E9DF7DEB39}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{003C7A18-60D9-4C89-94D8-DE42C1AA1D76}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{02A4D600-582A-4C14-ADFE-C125CF0CB18F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{1473D86F-6F04-46A3-9153-CD04272511DC}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{4849799C-D8E9-4360-8F9A-6B5F2BCC7EA4}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{56E808A1-BFD0-4B79-B567-B9FA848D697F}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{61FB8AD2-C831-45AB-9DFB-D685C3A8300D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{62F27534-2769-4D2F-B42F-E96E62F64F44}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{65901CFC-D156-4C8F-90EA-C26D256CA195}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{68F6992D-6E9D-4F14-88EC-3E0B8BEC7EFF}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{8642AF85-31DC-4BB3-8E9D-1E478C224084}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A22901B5-83AE-4FED-A219-99B09BDA50D0}" = protocol=17 | dir=in | app=c:\users\mommacass\appdata\local\google\google talk plugin\googletalkplugin.exe |
"{A5589677-56C4-46C1-A86B-1F0B5425786F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{AB3FBA72-52C3-4476-9A38-230DBE05659B}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{BC7833D1-AE4B-4CAB-BDD5-6EA587E5C763}" = protocol=6 | dir=out | app=system |
"{CE504808-152F-4073-8BB9-0F8E7C4D30C6}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{D3648D1D-2BA3-4973-9B7E-EDC907B6E342}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{E323C2D1-E806-4BC8-934B-477355C6C824}" = protocol=6 | dir=in | app=c:\users\mommacass\appdata\local\google\google talk plugin\googletalkplugin.exe |
"{E8715BB0-E132-4617-B344-62E03BFE2C1C}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{E926E57D-011D-4F63-BCC5-FFCFDC28D091}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{EFA98652-B437-42AA-B7D3-EFFD71ED4ECD}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F7DCF881-DB9D-4779-8D1C-CCCBAC7C73FF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"TCP Query User{5E37A16C-AB5A-4550-9468-5976F26E3E62}C:\program files (x86)\lanschool\teacher.exe" = protocol=6 | dir=in | app=c:\program files (x86)\lanschool\teacher.exe |
"TCP Query User{A3ED0524-64AB-4BC2-85A3-E7F081249829}C:\program files (x86)\lanschool\teacher.exe" = protocol=6 | dir=in | app=c:\program files (x86)\lanschool\teacher.exe |
"TCP Query User{C78FDDC4-9A0D-494F-B156-2A23C0C9FE36}C:\program files (x86)\epson software\event manager\eeventmanager.exe" = protocol=6 | dir=in | app=c:\program files (x86)\epson software\event manager\eeventmanager.exe |
"UDP Query User{29018440-50C4-4FEE-AFC6-915D21520589}C:\program files (x86)\lanschool\teacher.exe" = protocol=17 | dir=in | app=c:\program files (x86)\lanschool\teacher.exe |
"UDP Query User{63DB3519-199E-40F9-B142-4048A3ADAB10}C:\program files (x86)\lanschool\teacher.exe" = protocol=17 | dir=in | app=c:\program files (x86)\lanschool\teacher.exe |
"UDP Query User{E040B48C-0C88-451A-8C43-8EC318C60B32}C:\program files (x86)\epson software\event manager\eeventmanager.exe" = protocol=17 | dir=in | app=c:\program files (x86)\epson software\event manager\eeventmanager.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{237E305C-B625-466A-88CE-1E121BF4FDB1}" = Send To Neat
"{24811C12-F4A9-4D0F-8494-A7B8FE46123C}" = TOSHIBA ReelTime
"{26A24AE4-039D-4CA4-87B4-2F86416031FF}" = Java™ 6 Update 31 (64-bit)
"{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1" = MPC-HC 1.6.2.4902 (64-bit)
"{439760BC-7737-4386-9B1D-A90A3E8A22EA}" = Apple Mobile Device Support
"{4A5A427F-BA39-4BF0-7777-9A47FBE60C9F}" = Visual C++ 9.0 Runtime for Dragon NaturallySpeaking 64bit (x64)
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}" = Windows Live Language Selector
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{624C7F0A-89B2-4C49-9CAB-9D69613EC95A}" = Microsoft IntelliPoint 8.2
"{6548B189-BEA4-4041-80E0-AEB60548E046}" = Intel® PROSet/Wireless WiMAX Software
"{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{7EA2D88A-C8B7-4102-8644-0A437B6FC143}" = Neat Mobile Scanner Driver
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{86E45973-5352-439F-A115-2E8EE4D40140}" = ActivClient CAC x64
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A2BC7D4-A7D3-45D5-B3D2-394718C53C41}" = Neat ADF Scanner 2008 Driver
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{94A90C69-71C1-470A-88F5-AA47ECC96B40}" = TOSHIBA HDD Protection
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9ACF3FDB-C8E6-444C-8C64-13A221F7BFFD}" = Microsoft SQL Server Native Client
"{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}" = Microsoft Security Client
"{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}" = TOSHIBA PC Health Monitor
"{A55F1206-BFA7-4027-92B8-CE4EFDBC3CF2}" = Neat ADF Scanner Driver
"{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb" = Internet Explorer (Enable DEP)
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}" = TOSHIBA eco Utility
"{B636C9B9-A3F2-4DCE-ADCC-72E095018385}" = Microsoft SQL Server VSS Writer
"{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Media Creator
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{BCF07271-A853-4D3A-B668-4B752174CAA8}" = iTunes
"{C14518AF-1A0F-4D39-8011-69BAA01CD380}" = TOSHIBA Bulletin Board
"{C298FF86-AB23-4B58-AC53-A23383C07B3A}" = Intel® Wireless Display
"{D1108D4B-72F8-419F-88C5-ABB8DC09B3C7}" = Neat Mobile Scanner (Silver) Driver
"{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}" = Microsoft SQL Server Compact 3.5 SP2 x64 ENU
"{D61E4101-9E15-4D0E-ABD1-1ABD36B43330}" = Intel® PROSet/Wireless WiFi Software
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DDE25FC9-892D-4D24-9325-3BAA5C15ACA9}" = Neat Mobile Scanner 2008 Driver
"{F67FA545-D8E5-4209-86B1-AEE045D1003F}" = TOSHIBA Face Recognition
"{FBBC4667-2521-4E78-B1BD-8706F774549B}" = Best Buy pc app
"CutePDF Writer Installation" = CutePDF Writer 2.8
"EPSON WorkForce 630 Series" = EPSON WorkForce 630 Series Printer Uninstall
"Microsoft IntelliPoint 8.2" = Microsoft IntelliPoint 8.2
"Microsoft Security Client" = Microsoft Security Essentials
"ProInst" = Intel PROSet Wireless
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02418C87-F90C-4E47-8BA6-16226B35D9C3}" = Serif MoviePlus X3
"{03B8AA32-F23C-4178-B8E6-09ECD07EAA47}" = Epson Event Manager
"{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}" = Epson FAX Utility
"{1101AD13-F7A9-4B65-83C6-48344E8F88C2}" = Switched-On Schoolhouse 2011 - Home Edition Tutorials
"{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1
"{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}" = Utility Common Driver
"{13A5E785-5197-4EAD-8EE3-D660271E49BC}" = Feedback Tool
"{19991EAD-C273-47EB-87E8-0D274925230B}" = OEB Resource Driver
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1B87C40B-A60B-4EF3-9A68-706CF4B69978}" = TOSHIBA Assist
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6A1825-474F-4124-9016-1168471D847B}" = Google Drive
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron Flash Media Controller Driver
"{26A24AE4-039D-4CA4-87B4-2F83216020F0}" = Java™ 6 Update 20
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java™ 6 Update 31
"{26A24AE4-039D-4CA4-87B4-2F83217005FF}" = Java™ 7 Update 5
"{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}" = Microsoft SQL Server 2005 Tools Express Edition
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{28E82311-8616-11E1-BEB0-B8AC6F97B88E}" = Google Earth
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (SOSHOME309)
"{2B34414C-14FB-11D6-A329-0050045C24B2}" = DVD@ccess 2.0.3
"{2EA870FA-585F-4187-903D-CB9FFD21E2E0}" = DHTML Editing Component
"{2EF17083-57D4-4D64-AE4F-55F32A2C4571}" = Codecv
"{316B3C3F-6B5A-DBC3-1398-FBE614ECCAA7}" = TweetDeck
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{342126E1-173C-4585-BFBE-3EBDD20E3E9E}" = Mobipocket Reader 6.2
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{3A9FC03D-C685-4831-94CF-4EDFD3749497}" = Microsoft SQL Server Compact 3.5 SP2 ENU
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{3E31400D-274E-4647-916C-2CACC3741799}" = EpsonNet Print
"{47FA2C44-D148-4DBC-AF60-B91934AA4842}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Supervisor Password
"{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{596DA8A2-C576-46F5-A92E-8C9CCECE4E9D}" = Serif PagePlus X3
"{5AF550B4-BB67-4E7E-82F1-2C4300279050}" = ToshibaRegistration
"{5E6F6CF3-BACC-4144-868C-E14622C658F3}" = TOSHIBA Web Camera Application
"{5F81DD84-6A2F-11D4-903E-00E0293397B7}" = Bible Data Type System Files
"{5F81DD89-6A2F-11D4-903E-00E0293397B7}" = Common System Files
"{5F81DD92-6A2F-11D4-903E-00E0293397B7}" = Libronix Digital Library System
"{5F81DD97-6A2F-11D4-903E-00E0293397B7}" = Libronix DLS Application
"{5F81DD9B-6A2F-11D4-903E-00E0293397B7}" = LibronixUpdate
"{5F81DD9F-6A2F-11D4-903E-00E0293397B7}" = LLS Resource Driver
"{5F81DDA3-6A2F-11D4-903E-00E0293397B7}" = PDF Resource Driver
"{604CD5A1-4520-4844-B064-A3D884B77E91}" = SpeedyPC Pro
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support Utility
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{654F7484-88C5-46DC-AB32-C66BCB0E2102}" = TOSHIBA Sleep Utility
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6ABB06AA-5E94-4250-9BD9-4AE81FE4EBAC}" = LanSchool Home Teacher
"{6AF4A721-280D-40FA-8AD6-A2EC4314F16F}" = Switched-On Schoolhouse 2011 - Home Edition
"{6B9C32DB-DBCD-45A8-B901-3A92A99A2474}" = InstallVC90Support
"{6C5F3BDC-0A1B-4436-A696-5939629D5C31}" = TOSHIBA DVD PLAYER
"{6FED7B0F-E870-4606-B87D-444514E4A891}" = Twitter Plugin for Windows Live Writer
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{72CB5335-6D2A-4207-B811-6CB6C6925039}" = Batch Update
"{746FB02B-1D03-43B7-917A-E1341AB69A00}" = Qwest Personal Digital Vault™
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{787CBAF8-0325-448D-9B99-D1A8BD8A5010}" = PERRLA
"{7B3577F5-1D82-4C9B-008B-69D026FD8BCA}" = The Sims 2 Open For Business
"{7B7044AE-6D1F-456D-B2BA-28BFFFAF3F71}" = Epson Easy Photo Print Plug-in for Windows Live Photo Gallery Setup
"{7CAC6A44-C3DE-4153-ACA6-7524602C789E}" = Facebook Video Calling 1.2.0.159
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7
"{8AB8D458-939E-403F-0097-9BA1C1F013D5}" = The Sims 2
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8FD3F4BA-A4A6-4380-00A6-CC6853AB2DC2}" = The Sims 2 University
"{8FFB3051-70DC-49B6-879E-E1DA1551C4CC}" = LanSchool Home Teacher
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_PROPLUS_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0409-1000-0000000FF1CE}_PROPLUS_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROPLUS_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0116-0409-1000-0000000FF1CE}_PROPLUS_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{94CAC2F1-C856-47F4-AF24-65A1E75AEDB9}" = MotoHelper MergeModules
"{94D3E3CE-CE56-428B-A92D-F06B7723CF9E}" = Typing Instructor for Kids
"{970472D0-F5F9-4158-A6E3-1AE49EFEF2D3}" = TOSHIBA Application Installer
"{975C3A93-2491-3D44-A071-F6CBF153E46D}" = Google Talk Plugin
"{983CD6FE-8320-4B80-A8F6-0D0366E0AA22}" = TOSHIBA Media Controller
"{99432E4C-1189-4887-9D75-DAA796015FFD}" = Neat Core Files
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0EFB06D-0C7C-4A85-B1D3-65AF82536A7B}" = Sentence Diagramming
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A8DE5E50-DF5B-4E8C-881A-9019914B0EF9}" = Homeschool Tracker Plus
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{ABD25A5D-9379-D392-40B6-B3529659BBE9}" = Zoodles
"{AC6569FA-6919-442A-8552-073BE69E247A}" = TOSHIBA Service Station
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.3)
"{AFE499B5-FCC4-45E6-A1A5-3C51AE0E539B}" = Mobipocket Creator 4.2
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B2D55EB8-32C5-4B43-9006-9E97DECBA178}" = Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser)
"{B3575D00-27EF-49C2-B9E0-14B3D954E992}" = Apple Application Support
"{B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}" = TOSHIBA eco Utility
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{BB51B753-9A0C-4D1D-B3EF-A1B936F55796}" = Toshiba Book Place
"{BC489586-33E9-412D-BA70-485F3EA92DBE}" = DaisyTrail DigiKit Collection 1
"{C1A0A3F9-C302-4A18-A2E0-71C927D24652}" = Epson Easy Photo Print 2
"{C6579A65-9CAE-4B31-8B6B-3306E0630A66}" = Apple Software Update
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C9D8A041-2963-4B31-8FFC-1500F3DB9293}" = EpsonNet Setup 3.3
"{CA0AF735-4583-413E-897F-E91A237EE2E1}" = Libronix DLS Shortcuts
"{CC351B44-5610-43C5-81E6-A2C760CB0A20}" = Graphical Query Editor
"{CE26F10F-C80F-4377-908B-1B7882AE2CE3}" = Crystal Reports Basic Runtime for Visual Studio 2008
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D0CE0D3A-6F06-43B7-93B2-46EED1E00B1D}" = Clause Visualizer
"{D303CDE8-D1DB-4DBA-A15A-C7EE3D775726}" = Serif Digital Scrapbook Artist
"{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E20B2BBD-28B8-4378-97AD-C30F40ED13D2}" = Motorola Software Update
"{E3C0A1C8-F588-4A5B-87A0-08090B61DD42}" = Switched-On Schoolhouse 2011 - Home Edition Database
"{E53A24DC-F90E-4372-937C-77E23DE0932B}" = Z 39.50 Library
"{E69992ED-A7F6-406C-9280-1C156417BC49}" = TOSHIBA Quality Application
"{E6C82F8F-2031-4825-8CC3-98C5960875C1}" = Epson CreativeZone
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{EFFA53BC-8C04-2E21-3D90-A13B1697B0CA}" = Dragon NaturallySpeaking 11
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Graphics Media Accelerator Driver
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F26FDF57-483E-42C8-A9C9-EEE1EDB256E0}" = TOSHIBA Media Controller Plug-in
"{F7529650-B9DB-481B-0089-A2AC3C2821C1}" = The Sims 2 Nightlife
"{F97272B4-82C4-46B2-BCF1-C4D6E8CAB3E6}" = Avery Wizard 4.0
"{FB1FF87F-CBB0-470B-8025-5729827BEFD1}" = Ginger
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"AC3Filter" = AC3Filter (remove only)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Advanced SystemCare 5_is1" = Advanced SystemCare 5
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.15
"BrainWare Safari 2.5" = BrainWare Safari 2.5
"com.zoodles.3B7D4B2F97D0C2BDB13554D0687ECC70A3734EDD.1" = Zoodles
"Coupon Printer for Windows5.0.0.1" = Coupon Printer for Windows
"Digital Editions" = Adobe Digital Editions
"DivX Setup" = DivX Setup
"EEPPPlugIn" = Epson Easy Photo Print Plug-in for Windows Live Photo Gallery
"EPSON PC-FAX Driver 2" = Epson PC-FAX Driver
"EPSON Scanner" = EPSON Scan
"ffdshow_is1" = ffdshow [rev 2527] [2008-12-19]
"FreeFileViewer_is1" = Free File Viewer 2011
"InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"InstallShield_{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}" = Utility Common Driver
"InstallShield_{24811C12-F4A9-4D0F-8494-A7B8FE46123C}" = TOSHIBA ReelTime
"InstallShield_{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Supervisor Password
"InstallShield_{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup
"InstallShield_{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support Utility
"InstallShield_{B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}" = TOSHIBA eco Utility
"InstallShield_{C14518AF-1A0F-4D39-8011-69BAA01CD380}" = TOSHIBA Bulletin Board
"InstallShield_{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"InstallShield_{F67FA545-D8E5-4209-86B1-AEE045D1003F}" = TOSHIBA Face Recognition
"InstallShield_{FB1FF87F-CBB0-470B-8025-5729827BEFD1}" = Ginger
"Libronix DLS" = Libronix Digital Library System
"Lizard Safeguard - PDF Viewer_is1" = Lizard Safeguard - PDF Viewer 2.5.152
"LTCM Client" = LTCM Client
"Math Facts Now" = Math Facts Now!
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime
"Mozilla Firefox 13.0.1 (x86 en-US)" = Mozilla Firefox 13.0.1 (x86 en-US)
"Mozilla Thunderbird (5.0)" = Mozilla Thunderbird (5.0)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Neat" = Neat
"Pdf995" = Pdf995
"PdfEdit995" = PdfEdit995
"ProInst" = Intel PROSet Wireless
"PROPLUS" = Microsoft Office Professional Plus 2007
"RealPlayer 12.0" = RealPlayer
"Signature995" = Signature995
"Startwrite" = Startwrite Startwrite 5.0 b209 Demo
"TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1" = TweetDeck
"uTorrent" = µTorrent
"Virtual Magnifying Glass_is1" = Virtual Magnifying Glass v3.4
"WinLiveSuite" = Windows Live Essentials
"World of Warcraft" = World of Warcraft
"Writing Aids" = Writing Aids
"Xvid Video Codec 1.3.2" = Xvid Video Codec
"Year 1 Curriculum" = Year 1 Curriculum
"Year 1 Evaluations" = Year 1 Evaluations
"Year 1 Interface" = Year 1 Interface
"Year 1 Lapbooks" = Year 1 Lapbooks
"Year 1 MapAids" = Year 1 MapAids

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)
"Amazon Kindle" = Amazon Kindle
"Google Chrome" = Google Chrome
"GoToMeeting" = GoToMeeting 5.1.0.880
"KindlePreviewer" = Kindle Previewer
"Move Media Player" = Move Media Player
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player
"Spotify" = Spotify
"UnityWebPlayer" = Unity Web Player

========== Last 20 Event Log Errors ==========

[ ActivIdentity Events ]
Error - 3/14/2012 2:07:38 AM | Computer Name = MommaCass-PC | Source = ActivClient | ID = 769
Description = No exchange account

Error - 3/14/2012 2:10:13 AM | Computer Name = MommaCass-PC | Source = ActivClient | ID = 769
Description = No exchange account

Error - 3/14/2012 2:20:55 AM | Computer Name = MommaCass-PC | Source = ActivClient | ID = 769
Description = No exchange account

Error - 3/14/2012 2:46:49 AM | Computer Name = MommaCass-PC | Source = ActivClient | ID = 769
Description = No exchange account

Error - 3/14/2012 2:56:09 AM | Computer Name = MommaCass-PC | Source = ActivClient | ID = 769
Description = No exchange account

Error - 3/14/2012 11:23:14 AM | Computer Name = MommaCass-PC | Source = ActivClient | ID = 769
Description = No exchange account

Error - 4/2/2012 10:37:59 PM | Computer Name = MommaCass-PC | Source = ActivClient | ID = 769
Description = No exchange account

Error - 5/24/2012 12:08:09 AM | Computer Name = MommaCass-PC | Source = ActivClient | ID = 769
Description = No exchange account

Error - 7/9/2012 12:31:13 AM | Computer Name = MommaCass-PC | Source = ActivClient | ID = 769
Description = No exchange account

[ Application Events ]
Error - 7/9/2012 8:33:24 PM | Computer Name = MommaCass-PC | Source = Application Error | ID = 1000
Description = Faulting application name: FUFAXSTM.exe, version: 2.0.0.10, time stamp:
0x4b172edc Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0x6d617267 Faulting process id: 0x10f4 Faulting application
start time: 0x01cd5e338c853bee Faulting application path: C:\Program Files (x86)\Epson
Software\FAX Utility\FUFAXSTM.exe Faulting module path: unknown Report Id: db0cc95d-ca26-11e1-921b-88ae1df30b14

Error - 7/10/2012 10:42:27 AM | Computer Name = MommaCass-PC | Source = Google Update | ID = 20
Description =

Error - 7/10/2012 3:55:45 PM | Computer Name = MommaCass-PC | Source = Google Update | ID = 20
Description =

Error - 7/10/2012 5:00:56 PM | Computer Name = MommaCass-PC | Source = Windows Search Service | ID = 3038
Description =

Error - 7/10/2012 5:00:56 PM | Computer Name = MommaCass-PC | Source = Windows Search Service | ID = 7040
Description =

Error - 7/10/2012 5:00:56 PM | Computer Name = MommaCass-PC | Source = Windows Search Service | ID = 7042
Description =

Error - 7/10/2012 5:01:08 PM | Computer Name = MommaCass-PC | Source = Windows Search Service | ID = 3028
Description =

Error - 7/10/2012 5:01:08 PM | Computer Name = MommaCass-PC | Source = Windows Search Service | ID = 3058
Description =

Error - 7/10/2012 5:01:08 PM | Computer Name = MommaCass-PC | Source = Windows Search Service | ID = 7010
Description =

Error - 7/11/2012 2:41:41 PM | Computer Name = MommaCass-PC | Source = Google Update | ID = 20
Description =

[ OSession Events ]
Error - 5/18/2011 1:42:45 AM | Computer Name = MommaCass-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 745
seconds with 720 seconds of active time. This session ended with a crash.

Error - 8/14/2011 1:11:05 AM | Computer Name = MommaCass-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 28
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 7/11/2012 5:45:51 PM | Computer Name = MommaCass-PC | Source = Microsoft Antimalware | ID = 1119
Description = %%860 has encountered a critical error when taking action on malware
or other potentially unwanted software. For more information please see the following:
http://go.microsoft.com/fwlink/?linkid=370…atid=2147654467

Name:
Trojan:Win32/Sirefef.AB ID: 2147654467 Severity: Severe Category: Trojan Path: file:_C:\windows\assembly\GAC_32\Desktop.ini

Detection
Origin: %%845 Detection Type: %%822 Detection Source: %%820 User: NT AUTHORITY\SYSTEM

Process
Name: Unknown Action: %%809 Action Status: No additional actions required Error Code:
0x8007001e Error description: The system cannot read from the specified device.
Signature Version: AV: 1.129.1379.0, AS: 1.129.1379.0, NIS: 11.159.0.0 Engine Version:
AM: 1.1.8502.0, NIS: 2.0.8001.0

Error - 7/11/2012 5:47:54 PM | Computer Name = MommaCass-PC | Source = Service Control Manager | ID = 7034
Description = The Advanced SystemCare Service 5 service terminated unexpectedly.
It has done this 1 time(s).

Error - 7/11/2012 5:48:16 PM | Computer Name = MommaCass-PC | Source = Service Control Manager | ID = 7034
Description = The EpsonBidirectionalService service terminated unexpectedly. It
has done this 1 time(s).

Error - 7/11/2012 5:50:17 PM | Computer Name = MommaCass-PC | Source = Application Popup | ID = 1060
Description = \SystemRoot\SysWow64\drivers\DVDAccss.sys has been blocked from loading
due to incompatibility with this system. Please contact your software vendor for
a compatible version of the driver.

Error - 7/11/2012 5:50:17 PM | Computer Name = MommaCass-PC | Source = Service Control Manager | ID = 7000
Description = The DVDAccss service failed to start due to the following error: %%1275

Error - 7/11/2012 5:51:43 PM | Computer Name = MommaCass-PC | Source = Microsoft Antimalware | ID = 1119
Description = %%860 has encountered a critical error when taking action on malware
or other potentially unwanted software. For more information please see the following:
http://go.microsoft.com/fwlink/?linkid=370…atid=2147654467

Name:
Trojan:Win32/Sirefef.AB ID: 2147654467 Severity: Severe Category: Trojan Path: file:_C:\windows\assembly\GAC_32\Desktop.ini

Detection
Origin: %%845 Detection Type: %%822 Detection Source: %%820 User: NT AUTHORITY\SYSTEM

Process
Name: Unknown Action: %%809 Action Status: No additional actions required Error Code:
0x8007001e Error description: The system cannot read from the specified device.
Signature Version: AV: 1.129.1379.0, AS: 1.129.1379.0, NIS: 11.159.0.0 Engine Version:
AM: 1.1.8502.0, NIS: 2.0.8001.0

Error - 7/11/2012 5:52:46 PM | Computer Name = MommaCass-PC | Source = Service Control Manager | ID = 7001
Description = The HomeGroup Provider service depends on the Function Discovery Provider
Host service which failed to start because of the following error: %%1058

Error - 7/11/2012 6:13:14 PM | Computer Name = MommaCass-PC | Source = Application Popup | ID = 1060
Description = \SystemRoot\SysWow64\drivers\DVDAccss.sys has been blocked from loading
due to incompatibility with this system. Please contact your software vendor for
a compatible version of the driver.

Error - 7/11/2012 6:13:14 PM | Computer Name = MommaCass-PC | Source = Service Control Manager | ID = 7000
Description = The DVDAccss service failed to start due to the following error: %%1275

Error - 7/11/2012 6:13:45 PM | Computer Name = MommaCass-PC | Source = Service Control Manager | ID = 7001
Description = The HomeGroup Provider service depends on the Function Discovery Provider
Host service which failed to start because of the following error: %%1058


< End of report >
Hi hsmommaof4,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

As we work through your logs. Please remember to run any tools by Right-clicking on the icon and selecting Run As Administrator….

Download ComboFix:

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.


When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI