This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Possible Malware [Solved]

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Computer started acting very slow and unresponsive a couple of days ago after downloading various software tool programs (not sure which ones to be honest…) I download multiple anti-virus software packages (Kapersky, AVG, avast!, Malware-bytes) and they came up clean other than tracking cookies. Super-anti spyware however crashes during the scan no matter what set of settings I have configured in either Safe mode or normal Windows. My OS is Windows 7 Home Premium,

I followed the instructions and downloaded OTL. The .txt logs are below:
OTL.txt:

OTL logfile created on: 9/30/2012 12:12:42 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\GDuBB\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.07 Gb Available Physical Memory | 51.84% Memory free
8.00 Gb Paging File | 5.12 Gb Available in Paging File | 64.08% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 455.90 Gb Total Space | 318.64 Gb Free Space | 69.89% Space Free | Partition Type: NTFS
Drive D: | 9.76 Gb Total Space | 1.43 Gb Free Space | 14.68% Space Free | Partition Type: NTFS

Computer Name: GDUBB-PC | User Name: GDuBB | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\GDuBB\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_4_402_278.exe (Adobe Systems, Inc.)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\avp.exe (Kaspersky Lab ZAO)
PRC - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\klwtblfs.exe (Kaspersky Lab ZAO)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Windows\SysWOW64\vmnat.exe (VMware, Inc.)
PRC - C:\Windows\SysWOW64\vmnetdhcp.exe (VMware, Inc.)
PRC - C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe (VMware, Inc.)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
PRC - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files (x86)\HTC\HTC Sync\ClientInitiatedStarter\ClientInitiatedStarter.exe (Teleca)
PRC - C:\Program Files (x86)\HTC\HTC Sync\Mobile Phone Monitor\epmworker.exe (Teleca Sweden AB)
PRC - C:\Program Files (x86)\HTC\HTC Sync\Mobile Phone Monitor\FsynSrvStarter.exe (TODO: )
PRC - C:\Program Files (x86)\HTC\HTC Sync\Mobile Phone Monitor\HTCVBTServer.exe (Teleca AB)
PRC - C:\Program Files (x86)\Common Files\Teleca Shared\Generic.exe (Teleca AB)
PRC - C:\Program Files (x86)\HTC\HTC Sync\Application Launcher\Application Launcher.exe (Teleca Sweden AB)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Common Files\Teleca Shared\logger.exe (Popwire AB)
PRC - C:\Program Files (x86)\Common Files\Teleca Shared\CapabilityManager.exe (Teleca Sweden AB)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)


========== Modules (No Company Name) ==========

MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_278.dll ()
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\FFExt\[removed]\chrome\components\content_blocker_xpcom_gecko15\content_blocker_xpcom.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\QtWebKit\qmlwebkitplugin4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\dblite.dll ()
MOD - C:\Program Files (x86)\HTC\HTC Sync\Mobile Phone Monitor\fsync.dll ()
MOD - C:\Program Files (x86)\HTC\HTC Sync\ClientInitiatedStarter\fsync.dll ()
MOD - C:\Program Files (x86)\HTC\HTC Sync\Mobile Phone Monitor\tcpsock_object.dll ()
MOD - C:\Program Files (x86)\Common Files\Teleca Shared\boost_log-vc80-mt-1_33.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
SRV:64bit: - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AgereModemAudio) – C:\Program Files\LSI SoftModem\agr64svc.exe (LSI Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (AVP) – C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\avp.exe (Kaspersky Lab ZAO)
SRV - (AVGIDSAgent) – C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (VMware NAT Service) – C:\Windows\SysWOW64\vmnat.exe (VMware, Inc.)
SRV - (VMnetDHCP) – C:\Windows\SysWOW64\vmnetdhcp.exe (VMware, Inc.)
SRV - (VMAuthdService) – C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe (VMware, Inc.)
SRV - (KSS) – C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe (Kaspersky Lab ZAO)
SRV - (avgwd) – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (BBUpdate) – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (VMUSBArbService) – C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe (VMware, Inc.)
SRV - (IntuitUpdateServiceV4) – C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit Inc.)
SRV - (HPSLPSVC) – C:\Program Files (x86)\hp\Digital Imaging\bin\HPSLPSVC64.DLL (Hewlett-Packard Co.)
SRV - (IntuitUpdateService) – C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (klmouflt) – C:\Windows\SysNative\drivers\klmouflt.sys (Kaspersky Lab)
DRV:64bit: - (KLIF) – C:\Windows\SysNative\drivers\klif.sys (Kaspersky Lab)
DRV:64bit: - (klkbdflt) – C:\Windows\SysNative\drivers\klkbdflt.sys (Kaspersky Lab)
DRV:64bit: - (09517212) – C:\Windows\SysNative\drivers\09517212.sys (Kaspersky Lab ZAO)
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (Avgtdia) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (aswSnx) – C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software)
DRV:64bit: - (aswSP) – C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)
DRV:64bit: - (aswTdi) – C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software)
DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (aswRdr) – C:\Windows\SysNative\drivers\aswRdr2.sys (AVAST Software)
DRV:64bit: - (aswFsBlk) – C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)
DRV:64bit: - (kneps) – C:\Windows\SysNative\drivers\kneps.sys (Kaspersky Lab)
DRV:64bit: - (KLIM6) – C:\Windows\SysNative\drivers\klim6.sys (Kaspersky Lab ZAO)
DRV:64bit: - (Avgldx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (kl1) – C:\Windows\SysNative\drivers\kl1.sys (Kaspersky Lab ZAO)
DRV:64bit: - (vmx86) – C:\Windows\SysNative\drivers\vmx86.sys (VMware, Inc.)
DRV:64bit: - (vmkbd) – C:\Windows\SysNative\drivers\VMkbd.sys (VMware, Inc.)
DRV:64bit: - (VMnetuserif) – C:\Windows\SysNative\drivers\vmnetuserif.sys (VMware, Inc.)
DRV:64bit: - (VMnetBridge) – C:\Windows\SysNative\drivers\vmnetbridge.sys (VMware, Inc.)
DRV:64bit: - (VMnetAdapter) – C:\Windows\SysNative\drivers\vmnetadapter.sys (VMware, Inc.)
DRV:64bit: - (kltdi) – C:\Windows\SysNative\drivers\kltdi.sys (Kaspersky Lab)
DRV:64bit: - (VBoxNetAdp) – C:\Windows\SysNative\drivers\VBoxNetAdp.sys (Oracle Corporation)
DRV:64bit: - (AVGIDSHA) – C:\Windows\SysNative\drivers\avgidsha.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (dtsoftbus01) – C:\Windows\SysNative\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV:64bit: - (Avgrkx64) – C:\Windows\SysNative\drivers\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgmfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AVGIDSFilter) – C:\Windows\SysNative\drivers\avgidsfiltera.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSDriver) – C:\Windows\SysNative\drivers\avgidsdrivera.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (hcmon) – C:\Windows\SysNative\drivers\hcmon.sys (VMware, Inc.)
DRV:64bit: - (vmci) – C:\Windows\SysNative\drivers\vmci.sys (VMware, Inc.)
DRV:64bit: - (vzandnetndis) – C:\Windows\SysNative\drivers\lgvzandnetndis64.sys (LG Electronics Inc.)
DRV:64bit: - (vzandnetmodem) – C:\Windows\SysNative\drivers\lgvzandnetmdm64.sys (LG Electronics Inc.)
DRV:64bit: - (vzandnetdiag) – C:\Windows\SysNative\drivers\lgvzandnetdiag64.sys (LG Electronics Inc.)
DRV:64bit: - (vzandnetadb) – C:\Windows\SysNative\drivers\lgvzandnetadb.sys (Google Inc)
DRV:64bit: - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (UsbDiag) – C:\Windows\SysNative\drivers\lgx64diag.sys (LG Electronics Inc.)
DRV:64bit: - (USBModem) – C:\Windows\SysNative\drivers\lgx64modem.sys (LG Electronics Inc.)
DRV:64bit: - (usbbus) – C:\Windows\SysNative\drivers\lgx64bus.sys (LG Electronics Inc.)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (HTCAND64) – C:\Windows\SysNative\drivers\ANDROIDUSB.sys (HTC, Corporation)
DRV:64bit: - (OlyCamComm) – C:\Windows\SysNative\drivers\OlyCamComm.sys (OLYMPUS IMAGING CORP.)
DRV:64bit: - (AgereSoftModem) – C:\Windows\SysNative\drivers\agrsm64.sys (LSI Corporation)
DRV:64bit: - (NVNET) – C:\Windows\SysNative\drivers\nvmf6264.sys (NVIDIA Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) – C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (StillCam) – C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (RimUsb) – C:\Windows\SysNative\drivers\RimUsb_AMD64.sys (Research In Motion Limited)
DRV:64bit: - (Razerlow) – C:\Windows\SysNative\drivers\Razerlow.sys (Razer (Asia-Pacific) Pte Ltd)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/CQDSK/1
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/CQDSK/1
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {3B252D61-EB6B-4FE3-A7E0-3C8414DC7A4F}
IE:64bit: - HKLM\..\SearchScopes\{3B252D61-EB6B-4FE3-A7E0-3C8414DC7A4F}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{8BE9B8A1-C2AF-4499-AF76-B9852E2CEFC2}: "URL" = http://www.ask.com/web?q={searchTerms}&l;=dis&o;=uscqd
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/CQDSK/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/CQDSK/1
IE - HKLM\..\SearchScopes,DefaultScope = {3B252D61-EB6B-4FE3-A7E0-3C8414DC7A4F}
IE - HKLM\..\SearchScopes\{3B252D61-EB6B-4FE3-A7E0-3C8414DC7A4F}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{8BE9B8A1-C2AF-4499-AF76-B9852E2CEFC2}: "URL" = http://www.ask.com/web?q={searchTerms}&l;=dis&o;=uscqd

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/CQDSK/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\SearchScopes,DefaultScope = {3B252D61-EB6B-4FE3-A7E0-3C8414DC7A4F}
IE - HKCU\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: "URL" = http://www.daemon-search.com/search/web?q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..extensions.enabledAddons: {F53C93F1-07D5-430c-86D4-C9531B27DFAF}:12.0.0.2189
FF - prefs.js..extensions.enabledAddons: [removed]:13.0.1.4190
FF - prefs.js..extensions.enabledAddons: [removed]:13.0.1.4190
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:12.0.0.1912
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_278.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_278.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\GDuBB\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\GDuBB\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2012/07/02 18:03:50 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/07/14 22:21:59 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files (x86)\AVG\AVG2012\Firefox\DoNotTrack\ [2012/07/02 18:03:50 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012/09/26 19:35:15 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\FFExt\[removed] [2012/09/27 07:24:55 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\FFExt\[removed] [2012/09/27 07:24:57 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\FFExt\[removed] [2012/09/27 07:24:26 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/09/27 20:34:14 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/09/27 20:34:14 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/07/14 22:21:59 | 000,000,000 | —D | M]

[2010/07/25 10:48:00 | 000,000,000 | —D | M] (No name found) – C:\Users\GDuBB\AppData\Roaming\Mozilla\Extensions
[2012/06/14 07:33:36 | 000,000,000 | —D | M] (No name found) – C:\Users\GDuBB\AppData\Roaming\Mozilla\Firefox\Profiles\rghikp47.default\extensions
[2011/03/04 12:33:55 | 000,002,059 | —- | M] () – C:\Users\GDuBB\AppData\Roaming\Mozilla\Firefox\Profiles\rghikp47.default\searchplugins\daemon-search.xml
[2012/06/14 03:31:17 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/07/02 18:03:50 | 000,000,000 | —D | M] (AVG Do Not Track) – C:\PROGRAM FILES (X86)\AVG\AVG2012\FIREFOX\DONOTTRACK
[2012/09/27 07:24:26 | 000,000,000 | —D | M] (Content Blocker) – C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY ANTI-VIRUS 2013\FFEXT\[removed]
[2012/09/27 07:24:55 | 000,000,000 | —D | M] (Kaspersky URL Advisor) – C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY ANTI-VIRUS 2013\FFEXT\[removed]
[2012/09/12 07:38:01 | 000,266,720 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2010/07/25 11:40:06 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2012/09/12 07:38:00 | 000,002,465 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/09/12 07:38:00 | 000,002,253 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage:
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - homepage:
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\GDuBB\AppData\Local\Google\Chrome\Application\19.0.1084.52\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\GDuBB\AppData\Local\Google\Chrome\Application\19.0.1084.52\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\GDuBB\AppData\Local\Google\Chrome\Application\19.0.1084.52\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\GDuBB\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\GDuBB\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1901_0\plugins\/avgnpss.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.200.2 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U20 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Citrix Access Gateway (Enabled) = C:\Users\GDuBB\AppData\Roaming\Mozilla\plugins\npagee.dll
CHR - plugin: MSN\u00AE Toolbar (Enabled) = C:\Program Files (x86)\MSN Toolbar\Platform\4.0.0357.1\npwinext.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Google Update (Enabled) = C:\Users\GDuBB\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.0.61118.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\GDuBB\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\GDuBB\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: AVG Safe Search = C:\Users\GDuBB\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1901_0\
CHR - Extension: Gmail = C:\Users\GDuBB\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
O2 - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3:64bit: - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [AVP] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [BYRUA_AGENT] C:\ProgramData\LGMOBILEAX\BYR_Client\VZWUAAgent.exe (LG Electronics)
O4 - HKLM..\Run: [hpsysdrv] c:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
O4 - HKLM..\Run: [Mobile Connectivity Suite] C:\Program Files (x86)\HTC\HTC Sync\Application Launcher\Application Launcher.exe (Teleca Sweden AB)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [KSS] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe (Kaspersky Lab ZAO)
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe File not found
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9:64bit: - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O9:64bit: - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O9:64bit: - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O9 - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000011 - C:\Windows\SysNative\vsocklib.dll (VMware, Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000012 - C:\Windows\SysNative\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\SysWOW64\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\SysWOW64\vsocklib.dll (VMware, Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: atk.com ([myvpn] https in Trusted sites)
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{81040810-C827-41F2-ADDB-E06695ED4E40}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{01501fa3-41ad-11e1-b973-e0cb4e4034f0}\Shell - "" = AutoRun
O33 - MountPoints2\{01501fa3-41ad-11e1-b973-e0cb4e4034f0}\Shell\AutoRun\command - "" = G:\TL_Bootstrap.exe
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\TL_Bootstrap.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.VMnc - C:\Windows\SysWow64\vmnc.dll (VMware, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/09/30 12:10:15 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\GDuBB\Desktop\OTL.exe
[2012/09/28 08:51:20 | 000,000,000 | —D | C] – C:\Users\GDuBB\AppData\Local\MFAData
[2012/09/28 08:51:20 | 000,000,000 | —D | C] – C:\Users\GDuBB\AppData\Local\Avg2013
[2012/09/27 20:51:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ActiveState ActivePython 2.7 (64-bit)
[2012/09/27 20:50:15 | 000,000,000 | —D | C] – C:\Python27
[2012/09/27 19:11:16 | 000,000,000 | —D | C] – C:\Windows\pss
[2012/09/27 07:27:29 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Anti-Virus 2013
[2012/09/27 07:26:06 | 000,064,856 | —- | C] (Kaspersky Lab) – C:\Windows\SysNative\klfphc.dll
[2012/09/27 07:24:34 | 000,000,000 | —D | C] – C:\Windows\ELAMBKUP
[2012/09/27 07:24:08 | 000,611,160 | —- | C] (Kaspersky Lab) – C:\Windows\SysNative\drivers\klif.sys
[2012/09/27 07:24:08 | 000,089,432 | —- | C] (Kaspersky Lab) – C:\Windows\SysNative\drivers\klflt.sys
[2012/09/27 07:14:08 | 000,000,000 | —D | C] – C:\Users\GDuBB\Desktop\virus_report_files
[2012/09/27 03:39:04 | 000,000,000 | —D | C] – C:\Kaspersky Rescue Disk 10.0
[2012/09/26 23:40:42 | 000,460,888 | —- | C] (Kaspersky Lab ZAO) – C:\Windows\SysNative\drivers\09517212.sys
[2012/09/26 19:38:05 | 000,000,000 | —D | C] – C:\Users\GDuBB\AppData\Roaming\RoboForm
[2012/09/26 19:36:59 | 000,000,000 | —D | C] – C:\ProgramData\RoboForm
[2012/09/26 19:36:53 | 000,000,000 | —D | C] – C:\Users\GDuBB\Documents\My Avast EasyPass Data
[2012/09/26 19:36:26 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2012/09/26 19:36:23 | 000,025,232 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2012/09/26 19:36:20 | 000,359,464 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2012/09/26 19:36:02 | 000,054,072 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswRdr2.sys
[2012/09/26 19:35:59 | 000,059,728 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2012/09/26 19:35:54 | 000,969,200 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswSnx.sys
[2012/09/26 19:35:46 | 000,071,600 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2012/09/26 19:35:44 | 000,285,328 | —- | C] (AVAST Software) – C:\Windows\SysNative\aswBoot.exe
[2012/09/26 19:34:55 | 000,041,224 | —- | C] (AVAST Software) – C:\Windows\avastSS.scr
[2012/09/26 19:34:51 | 000,227,648 | —- | C] (AVAST Software) – C:\Windows\SysWow64\aswBoot.exe
[2012/09/26 19:34:35 | 000,000,000 | —D | C] – C:\ProgramData\AVAST Software
[2012/09/26 19:34:35 | 000,000,000 | —D | C] – C:\Program Files\AVAST Software
[2012/09/26 19:32:13 | 000,000,000 | —D | C] – C:\Users\GDuBB\AppData\Roaming\Malwarebytes
[2012/09/26 19:32:07 | 000,000,000 | —D | C] – C:\Users\GDuBB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kaspersky Security Scan
[2012/09/26 19:32:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/09/26 19:32:00 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/09/26 19:31:59 | 000,025,928 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2012/09/26 19:31:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/09/26 19:31:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\Kaspersky Lab
[2012/09/26 19:23:39 | 000,245,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\OxpsConverter.exe
[2012/09/26 18:46:55 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab
[2012/09/25 21:43:55 | 000,000,000 | —D | C] – C:\Users\GDuBB\AppData\Roaming\Python
[2012/09/22 03:02:24 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/09/22 03:02:24 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/09/22 03:02:22 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/09/22 03:02:21 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/09/22 03:02:21 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/09/22 03:02:21 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/09/22 03:02:21 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2012/09/22 03:02:21 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2012/09/22 03:02:20 | 002,312,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/09/22 03:02:20 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/09/22 03:02:20 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/09/22 03:02:19 | 000,729,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2012/09/22 03:02:17 | 000,816,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/09/22 03:02:17 | 000,717,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/09/22 03:02:17 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2012/09/18 21:23:31 | 000,000,000 | —D | C] – C:\Users\GDuBB\Dog Walking
[2012/09/14 16:22:15 | 000,000,000 | —D | C] – C:\Program Files\apache-maven-3.0.4
[2012/09/13 15:30:36 | 000,000,000 | —D | C] – C:\Users\GDuBB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Music Manager
[2012/09/13 15:30:28 | 000,000,000 | —D | C] – C:\Users\GDuBB\AppData\Local\Programs
[2012/09/11 20:01:45 | 000,574,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10level9.dll
[2012/09/11 20:01:45 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\RNDISMP.sys
[2012/09/11 20:01:43 | 000,376,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\netio.sys
[2012/09/11 20:01:43 | 000,288,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\FWPKCLNT.SYS
[2012/09/11 19:56:33 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG

========== Files - Modified Within 30 Days ==========

[2012/09/30 12:15:52 | 000,015,792 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/09/30 12:15:52 | 000,015,792 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/09/30 12:10:16 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\GDuBB\Desktop\OTL.exe
[2012/09/30 11:56:00 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1727114255-2402910526-3703745838-1000UA.job
[2012/09/30 11:53:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/09/30 10:12:54 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1727114255-2402910526-3703745838-1000Core.job
[2012/09/30 10:12:47 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/09/30 10:12:41 | 3220,676,608 | -HS- | M] () – C:\hiberfil.sys
[2012/09/30 10:11:55 | 000,454,146 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2012/09/29 10:33:19 | 096,052,554 | —- | M] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2012/09/29 10:27:39 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2012/09/28 21:22:38 | 000,696,240 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/09/28 21:22:37 | 000,073,136 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/09/28 11:46:01 | 000,346,543 | —- | M] () – C:\Users\GDuBB\Desktop\death_cab.png
[2012/09/28 07:14:40 | 000,002,495 | —- | M] () – C:\Users\GDuBB\Desktop\Google Chrome.lnk
[2012/09/27 21:16:19 | 000,000,128 | —- | M] () – C:\Users\GDuBB\Desktop\Start OAuth Proxy.bat
[2012/09/27 20:34:57 | 000,000,260 | —- | M] () – C:\Windows\SysWow64\cmdVBS.vbs
[2012/09/27 20:34:57 | 000,000,256 | —- | M] () – C:\Windows\SysWow64\MSIevent.bat
[2012/09/27 20:14:56 | 000,029,528 | —- | M] (Kaspersky Lab) – C:\Windows\SysNative\drivers\klmouflt.sys
[2012/09/27 20:14:55 | 000,611,160 | —- | M] (Kaspersky Lab) – C:\Windows\SysNative\drivers\klif.sys
[2012/09/27 20:14:55 | 000,029,016 | —- | M] (Kaspersky Lab) – C:\Windows\SysNative\drivers\klkbdflt.sys
[2012/09/27 07:14:09 | 000,096,454 | —- | M] () – C:\Users\GDuBB\Desktop\virus_report.html
[2012/09/26 19:36:27 | 000,001,928 | —- | M] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2012/09/26 19:32:02 | 000,001,079 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/09/26 19:31:45 | 000,001,043 | —- | M] () – C:\Users\GDuBB\Desktop\Kaspersky Security Scan.lnk
[2012/09/26 10:53:20 | 000,460,888 | —- | M] (Kaspersky Lab ZAO) – C:\Windows\SysNative\drivers\09517212.sys
[2012/09/22 10:13:05 | 000,002,427 | —- | M] () – C:\Windows\SysWow64\lgAxconfig.ini
[2012/09/22 03:21:12 | 000,000,408 | —- | M] () – C:\Windows\tasks\SmartDefrag.job
[2012/09/22 03:21:09 | 000,391,464 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/09/19 18:49:08 | 000,038,420 | —- | M] () – C:\Users\GDuBB\.recently-used.xbel
[2012/09/12 07:38:04 | 000,002,014 | —- | M] () – C:\Users\GDuBB\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/09/11 19:56:33 | 000,000,931 | —- | M] () – C:\Users\Public\Desktop\AVG 2012.lnk
[2012/09/09 18:15:22 | 000,001,676 | —- | M] () – C:\Users\GDuBB\AppData\Roaming\wklnhst.dat
[2012/09/07 17:04:46 | 000,025,928 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys

========== Files Created - No Company Name ==========

[2012/09/28 11:46:16 | 000,346,543 | —- | C] () – C:\Users\GDuBB\Desktop\death_cab.png
[2012/09/27 21:16:19 | 000,000,128 | —- | C] () – C:\Users\GDuBB\Desktop\Start OAuth Proxy.bat
[2012/09/27 20:09:45 | 000,000,830 | —- | C] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/09/27 07:14:08 | 000,096,454 | —- | C] () – C:\Users\GDuBB\Desktop\virus_report.html
[2012/09/26 19:36:27 | 000,001,928 | —- | C] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2012/09/26 19:35:45 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\config.nt
[2012/09/26 19:32:07 | 000,001,043 | —- | C] () – C:\Users\GDuBB\Desktop\Kaspersky Security Scan.lnk
[2012/09/26 19:32:02 | 000,001,079 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/09/19 18:49:08 | 000,038,420 | —- | C] () – C:\Users\GDuBB\.recently-used.xbel
[2012/08/11 10:43:14 | 000,027,520 | —- | C] () – C:\Users\GDuBB\AppData\Local\dt.dat
[2012/08/03 20:08:44 | 000,000,687 | —- | C] () – C:\Users\GDuBB\GDuBB - Shortcut (2).lnk
[2012/08/03 20:08:43 | 000,000,687 | —- | C] () – C:\Users\GDuBB\GDuBB - Shortcut.lnk
[2012/04/13 15:38:10 | 000,000,000 | —- | C] () – C:\Users\GDuBB\.perlcriticrc
[2012/03/02 07:55:04 | 000,000,614 | —- | C] () – C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
[2011/10/23 11:55:41 | 000,002,427 | —- | C] () – C:\Windows\SysWow64\lgAxconfig.ini
[2011/09/16 18:15:22 | 000,000,069 | —- | C] () – C:\Users\GDuBB\.wct
[2011/07/14 22:33:03 | 000,000,574 | —- | C] () – C:\Windows\hpomdl46.dat.temp
[2011/07/14 22:11:11 | 000,207,121 | —- | C] () – C:\Windows\hpoins46.dat
[2011/01/11 19:41:38 | 000,000,142 | —- | C] () – C:\ProgramData\nvUnsupRes.dat
[2010/11/28 21:06:29 | 000,007,598 | —- | C] () – C:\Users\GDuBB\AppData\Local\Resmon.ResmonCfg
[2010/10/21 19:29:38 | 000,001,676 | —- | C] () – C:\Users\GDuBB\AppData\Roaming\wklnhst.dat
[2010/09/12 14:08:17 | 000,001,105 | —- | C] () – C:\Users\GDuBB\.lmmsrc.xml

========== ZeroAccess Check ==========

[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/09 01:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/09 00:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 21:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 08:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 21:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2012/04/13 15:38:10 | 000,000,000 | —D | M] – C:\Users\GDuBB\AppData\Roaming\ActiveState
[2012/09/26 19:16:14 | 000,000,000 | —D | M] – C:\Users\GDuBB\AppData\Roaming\AVG2012
[2012/09/26 19:15:28 | 000,000,000 | —D | M] – C:\Users\GDuBB\AppData\Roaming\Corona Labs
[2012/08/04 00:32:37 | 000,000,000 | —D | M] – C:\Users\GDuBB\AppData\Roaming\DAEMON Tools Lite
[2010/09/12 17:36:46 | 000,000,000 | —D | M] – C:\Users\GDuBB\AppData\Roaming\FreeAudioPack
[2012/09/19 18:49:08 | 000,000,000 | —D | M] – C:\Users\GDuBB\AppData\Roaming\gtk-2.0
[2011/01/26 21:01:12 | 000,000,000 | —D | M] – C:\Users\GDuBB\AppData\Roaming\ICAClient
[2012/08/09 21:05:50 | 000,000,000 | —D | M] – C:\Users\GDuBB\AppData\Roaming\Icon-Robot
[2012/08/09 21:05:22 | 000,000,000 | —D | M] – C:\Users\GDuBB\AppData\Roaming\Icon-Robot-Android
[2010/07/25 12:02:22 | 000,000,000 | —D | M] – C:\Users\GDuBB\AppData\Roaming\ImTOO
[2011/10/22 10:20:33 | 000,000,000 | —D | M] – C:\Users\GDuBB\AppData\Roaming\inkscape
[2011/03/06 14:29:31 | 000,000,000 | —D | M] – C:\Users\GDuBB\AppData\Roaming\IObit
[2010/07/25 11:38:31 | 000,000,000 | —D | M] – C:\Users\GDuBB\AppData\Roaming\Notepad++
[2012/05/11 09:05:45 | 000,000,000 | —D | M] – C:\Users\GDuBB\AppData\Roaming\ObviousIdea
[2010/08/03 19:29:09 | 000,000,000 | —D | M] – C:\Users\GDuBB\AppData\Roaming\OpenOffice.org
[2012/09/26 19:15:28 | 000,000,000 | —D | M] – C:\Users\GDuBB\AppData\Roaming\Opera
[2012/09/25 21:43:55 | 000,000,000 | —D | M] – C:\Users\GDuBB\AppData\Roaming\Python
[2012/09/26 19:38:05 | 000,000,000 | —D | M] – C:\Users\GDuBB\AppData\Roaming\RoboForm
[2010/07/31 11:36:19 | 000,000,000 | —D | M] – C:\Users\GDuBB\AppData\Roaming\Subversion
[2011/12/09 15:15:22 | 000,000,000 | —D | M] – C:\Users\GDuBB\AppData\Roaming\TechWizard
[2010/08/02 18:35:19 | 000,000,000 | —D | M] – C:\Users\GDuBB\AppData\Roaming\Teleca
[2011/07/12 22:14:46 | 000,000,000 | —D | M] – C:\Users\GDuBB\AppData\Roaming\Temp
[2011/06/21 21:26:30 | 000,000,000 | —D | M] – C:\Users\GDuBB\AppData\Roaming\Template
[2010/07/26 17:58:23 | 000,000,000 | —D | M] – C:\Users\GDuBB\AppData\Roaming\Tific
[2012/08/06 21:05:31 | 000,000,000 | —D | M] – C:\Users\GDuBB\AppData\Roaming\uTorrent

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2009/07/13 22:30:02 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 16:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2009/10/06 02:06:36 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=00B0358734CAA32C39D181FE6916B178 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20542_none_b8b0208ee0ce1889\explorer.exe
[2011/02/26 02:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/26 01:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/13 21:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/26 01:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009/10/31 01:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/26 01:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 02:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 08:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009/10/06 02:35:29 | 002,868,736 | —- | M] (Microsoft Corporation) MD5=6D4F9E4B640B413C6F73414327484C80 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16434_none_addea9f19345cd81\explorer.exe
[2009/08/03 02:19:07 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009/10/31 02:34:59 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/03 01:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 09:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009/10/31 02:38:38 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/03 01:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 21:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/31 02:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2009/10/06 02:31:09 | 002,868,736 | —- | M] (Microsoft Corporation) MD5=CA17F8620815267DC838E30B68CB5052 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20542_none_ae5b763cac6d568e\explorer.exe
[2011/02/26 02:26:45 | 002,870,784 | —- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009/08/03 02:17:37 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
[2009/10/06 01:53:03 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=FC89FACA0473641CB625EDA9277D0885 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16434_none_b8335443c7a68f7c\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2009/07/13 22:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2009/07/13 22:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2009/07/13 22:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2009/07/13 22:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui

< MD5 for: EXPLORER.HTML >
[2010/07/28 20:12:57 | 000,000,200 | —- | M] () MD5=48CCC3A526A8768BD59F2FB5703B75CB – C:\Users\GDuBB\AppData\Local\Microsoft Corporation\Microsoft® Windows® Operating System\6.1.7600.16385\explorer.html

< MD5 for: EXPLORER.PY >
[2012/09/25 21:45:45 | 000,021,453 | —- | M] () MD5=07A8D21460612D43D793899D1BC17276 – C:\$Recycle.Bin\S-1-5-21-1727114255-2402910526-3703745838-1000\$RK5IL2Q\Lib\site-packages\Twisted-12.2.0-py2.7-win-amd64.egg\twisted\manhole\explorer.py
[2012/09/27 20:58:52 | 000,021,453 | —- | M] () MD5=07A8D21460612D43D793899D1BC17276 – C:\Python27\Lib\site-packages\Twisted-12.2.0-py2.7-win-amd64.egg\twisted\manhole\explorer.py

< MD5 for: EXPLORER.PYC >
[2012/09/25 21:45:56 | 000,023,469 | —- | M] () MD5=9EF90A0077954C48BE905C3B7F503A7C – C:\$Recycle.Bin\S-1-5-21-1727114255-2402910526-3703745838-1000\$RK5IL2Q\Lib\site-packages\Twisted-12.2.0-py2.7-win-amd64.egg\twisted\manhole\explorer.pyc
[2012/09/27 20:59:14 | 000,023,469 | —- | M] () MD5=CD4FCE6CAE2EDE6AF28437775A82697E – C:\Python27\Lib\site-packages\Twisted-12.2.0-py2.7-win-amd64.egg\twisted\manhole\explorer.pyc

< MD5 for: IEXPLORE.EXE >
[2012/06/02 07:47:54 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=004640AB259C1572EBD5FB0A32F63686 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20553_none_0dbfc836999db0ca\iexplore.exe
[2012/05/17 19:21:54 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=0129BB16161C2FD9A6B19111AB047198 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16446_none_1798a687b4d6030f\iexplore.exe
[2012/06/29 01:02:52 | 000,754,784 | —- | M] (Microsoft Corporation) MD5=1223ACBFC1093852DFF039E189599BBD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_0d45fcc9807373c2\iexplore.exe
[2010/09/08 00:36:39 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=14803EA3E5DD7CB37CB446C74CFDA38F – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20795_none_1a39121b8bff3c23\iexplore.exe
[2012/08/24 03:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2012/08/24 03:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_1787d4dfb4e386f6\iexplore.exe
[2012/05/17 18:59:46 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=268982F1FD671A077C6A2AF41E351436 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20551_none_181271f4ce004017\iexplore.exe
[2011/04/22 16:15:52 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=281C23EC5BCB1853A5D571F1A6E52FB1 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20949_none_101e7c5957724e1d\iexplore.exe
[2009/07/13 21:17:29 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=2C32E3E596CFE660353753EABEFB0540 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_19ba3f8a72d988f3\iexplore.exe
[2012/08/24 07:23:44 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=2D53C5F71653EF94E7829846405D4ED2 – C:\Program Files\Internet Explorer\iexplore.exe
[2012/08/24 07:23:44 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=2D53C5F71653EF94E7829846405D4ED2 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_0d332a8d8082c4fb\iexplore.exe
[2012/06/02 05:08:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=34B01BBD8F00B6B9C9248DC4F1E3CD01 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16447_none_1799a6d1b4d51c66\iexplore.exe
[2010/09/08 01:37:57 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=4879CB864E290BED38C5BDB641144B1B – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20795_none_0fe467c9579e7a28\iexplore.exe
[2010/09/08 01:49:01 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=498035ABCCF1ED47AE6791D239187587 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16671_none_0f6c69ae3e743d20\iexplore.exe
[2012/09/07 17:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2012/05/17 22:51:05 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=4E99F42504A99D5024C2EFA015001937 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16446_none_0d43fc3580754114\iexplore.exe
[2010/11/04 01:54:54 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=58CF468D3FF4CF830339FE5E45356355 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16700_none_1a0bc510729d1f54\iexplore.exe
[2012/08/24 06:49:07 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=5A150AFABB25BEA50CEDC8650A7B8A9E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_0dc3c95e999a1626\iexplore.exe
[2012/06/28 22:45:31 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=5D03518409F37D1483C98869D86E23FF – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_0dc0c880999cca21\iexplore.exe
[2012/06/02 08:52:21 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=610F6596921C4BAA8834ADBB9BE272EE – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16447_none_0d44fc7f80745a6b\iexplore.exe
[2010/09/08 00:31:24 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=61EDBCE47ADF3E52AB0B9F49EE4AEBB8 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16671_none_19c1140072d4ff1b\iexplore.exe
[2012/08/24 03:49:25 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=62188720CE27B982B4285C03163C9FB3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_181873b0cdfad821\iexplore.exe
[2011/04/22 15:29:16 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=64EFAF916C4009F1B84153D0BB491FB0 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16800_none_1a0bc6f6729d1c7b\iexplore.exe
[2010/11/04 01:54:59 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=6B2258FF6D2332073FE9E90122FA4168 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20831_none_1a75f2618bd22c48\iexplore.exe
[2010/12/18 02:17:48 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=700B40EA39DFB25517A81032F03D6D20 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16722_none_0fa37b7a3e4ac7e9\iexplore.exe
[2010/11/20 09:28:25 | 000,695,056 | —- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2010/12/18 02:11:10 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=8C6C32E4AF8A3D7155656F5897C504E0 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20861_none_1000d84b5789be20\iexplore.exe
[2011/07/16 17:40:02 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_17a944edb4ca4c7a\iexplore.exe
[2010/12/18 01:32:25 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=9321CF0D023528C71E3645F8433C86C8 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20861_none_1a55829d8bea801b\iexplore.exe
[2012/06/28 21:00:47 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=93569D46D79F9756ED077156496AFE23 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_179aa71bb4d435bd\iexplore.exe
[2010/12/18 01:33:54 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=AA08B68EF4E35EFA170CF85A44B23B70 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16722_none_19f825cc72ab89e4\iexplore.exe
[2011/02/24 01:45:11 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=AB2BB40A5FE49AD236791AC22BD08869 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20908_none_1a9d66118bb386fd\iexplore.exe
[2011/02/24 02:29:19 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=B4881B8F6EDB48CABD44BCC9FB5475C4 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20908_none_1048bbbf5752c502\iexplore.exe
[2012/06/02 04:51:58 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=BE967C74B89577B78FB57C061E12B04C – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20553_none_18147288cdfe72c5\iexplore.exe
[2010/11/20 08:22:51 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe
[2011/02/24 01:32:52 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C6697A46554E36541E81182B258A19D6 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16766_none_19d0e74472c85f04\iexplore.exe
[2011/04/22 16:16:25 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=D6F57A9ECB4606076FB9519D1698FCBA – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16800_none_0fb71ca43e3c5a80\iexplore.exe
[2010/11/04 02:37:41 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=D8E00EA671A1EFE95C69C7566C505AD4 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16700_none_0fb71abe3e3c5d59\iexplore.exe
[2011/02/24 02:32:09 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=E1BBDE0F187194D4B08335234A4B9FC7 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16766_none_0f7c3cf23e679d09\iexplore.exe
[2010/11/04 02:42:22 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=E220FB009F54AAF649C6A278A5156764 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20831_none_1021480f57716a4d\iexplore.exe
[2012/06/28 19:35:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=EB4105348272018D096FEB655CD1608C – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_181572d2cdfd8c1c\iexplore.exe
[2011/07/16 17:40:00 | 000,754,480 | —- | M] (Microsoft Corporation) MD5=F1424C1B9B1813BF825E45DF3790BC8A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_0d549a9b80698a7f\iexplore.exe
[2009/07/13 21:43:43 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=F2B0D41E1D08D0B2006DF5AA2E74C81E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_0f6595383e78c6f8\iexplore.exe
[2012/05/17 21:37:57 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=F8B2D47ED17C1D087D14EC747E5AC57A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20551_none_0dbdc7a2999f7e1c\iexplore.exe
[2011/04/22 15:11:29 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=F94877A94996B3C12BB31AD722840457 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20949_none_1a7326ab8bd31018\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2011/07/16 17:40:00 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2011/07/16 17:40:00 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2011/07/16 17:40:02 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2011/07/16 17:40:02 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui
[2009/07/13 22:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_09122aaf762607df\iexplore.exe.mui
[2009/07/13 22:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_0b433e7773148b79\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_1366d501aa86c9da\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_1597e8c9a7754d74\iexplore.exe.mui

< MD5 for: SERVICES >
[2009/06/10 17:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services

< MD5 for: SERVICES.EXE >
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2009/07/13 22:25:40 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\SysNative\en-US\services.exe.mui
[2009/07/13 22:25:40 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui

< MD5 for: SERVICES.HTML >
[2011/06/22 22:15:07 | 000,103,282 | —- | M] () MD5=5707DDF80B4791139318AFECC4BE6615 – C:\Users\GDuBB\Downloads\android-sdk_r06-windows\android-sdk-windows\docs\guide\topics\fundamentals\services.html

< MD5 for: SERVICES.JAVA >
[2012/01/20 14:57:33 | 000,006,748 | —- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 – C:\Users\GDuBB\Downloads\android-sdk_r06-windows\android-sdk-windows\sources\android-15\org\apache\harmony\security\fortress\Services.java

< MD5 for: SERVICES.LNK >
[2009/07/14 00:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 16:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2009/06/10 16:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof

< MD5 for: SERVICES.MSC >
[2009/07/13 22:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\en-US\services.msc
[2009/06/10 16:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\services.msc
[2009/07/13 22:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\en-US\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2009/07/13 22:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 16:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2009/07/13 22:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009/07/13 16:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 16:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml

< MD5 for: SERVICES.RDB >
[2010/05/21 00:34:38 | 000,262,144 | —- | M] () MD5=00D8C85E07B0D69A27816B54E56EF85B – C:\Program Files (x86)\OpenOffice.org 3\URE\misc\services.rdb
[2010/05/21 00:28:42 | 005,505,024 | —- | M] () MD5=20999743CA8D1F7132B0BFCE952F2295 – C:\Program Files (x86)\OpenOffice.org 3\Basis\program\services.rdb

< MD5 for: WINLOGON.ADML >
[2009/07/13 22:25:22 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 17:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2010/11/20 09:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 09:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/13 21:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2012/09/07 17:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/10/28 03:01:57 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009/10/28 02:24:40 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2010/11/20 09:00:25 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2010/11/20 09:00:25 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui
[2009/07/13 22:29:52 | 000,022,528 | —- | M] (Microsoft Corporation) MD5=56D03B64B8C483C1D12A8E4577B3B332 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7600.16385_en-us_26ed83321dc778e1\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2009/07/13 22:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2009/07/13 22:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 16:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2009/07/13 16:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2012/08/03 16:36:12 | 000,001,024 | —- | M] () – C:\.rnd
[2010/11/28 19:54:37 | 000,048,953 | —- | M] () – C:\ARMTestTool.apk
[2012/09/27 23:29:50 | 000,000,060 | —- | M] () – C:\gregggg.txt
[2012/09/30 10:12:41 | 3220,676,608 | -HS- | M] () – C:\hiberfil.sys
[2010/11/28 20:12:29 | 000,000,352 | —- | M] () – C:\licenseForDeveloper.omp
[2010/10/30 11:29:33 | 000,093,569 | —- | M] () – C:\MMAdView.jar
[2006/12/02 03:37:14 | 000,904,704 | —- | M] (Microsoft Corporation) – C:\msdia80.dll
[2012/09/27 23:21:40 | 000,000,060 | —- | M] () – C:\out.txt
[2012/09/30 10:12:40 | 4294,238,208 | -HS- | M] () – C:\pagefile.sys
[2008/09/20 21:03:28 | 005,778,043 | —- | M] () – C:\ring.mp3
[2010/12/15 19:12:19 | 134,217,728 | —- | M] () – C:\sdcard.iso
[2012/09/27 21:18:39 | 000,000,058 | —- | M] () – C:\text.txt

< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2012/08/21 05:12:33 | 000,041,224 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2012/03/08 18:37:20 | 000,302,448 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/07/18 22:12:30 | 000,000,221 | -HS- | M] () – C:\Users\GDuBB\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2010/11/14 14:38:19 | 003,914,176 | —- | M] (Acro Software Inc. ) – C:\Users\GDuBB\Desktop\CuteWriter.exe
[2012/06/15 22:55:21 | 110,931,834 | —- | M] () – C:\Users\GDuBB\Desktop\FreeMat-4.2.beta.exe
[2011/11/24 10:41:34 | 070,687,000 | —- | M] () – C:\Users\GDuBB\Desktop\jdk-6u29-windows-x64.exe
[2012/08/23 20:55:17 | 010,138,219 | —- | M] () – C:\Users\GDuBB\Desktop\JInstaller_1.4.8_win_x64.exe
[2010/09/12 14:06:20 | 015,431,195 | —- | M] () – C:\Users\GDuBB\Desktop\lmms-0.4.3-win32.exe
[2012/09/30 12:10:16 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\GDuBB\Desktop\OTL.exe
[2010/12/02 20:33:16 | 054,159,016 | —- | M] (Trend Micro Inc.) – C:\Users\GDuBB\Desktop\TIS_Download_SP_64bit.exe
[2012/06/15 22:24:14 | 001,287,528 | —- | M] (Microsoft Corporation) – C:\Users\GDuBB\Desktop\wlsetup-web.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >


Extras.txt:

OTL Extras logfile created on: 9/30/2012 12:12:42 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\GDuBB\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.07 Gb Available Physical Memory | 51.84% Memory free
8.00 Gb Paging File | 5.12 Gb Available in Paging File | 64.08% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 455.90 Gb Total Space | 318.64 Gb Free Space | 69.89% Space Free | Partition Type: NTFS
Drive D: | 9.76 Gb Total Space | 1.43 Gb Free Space | 14.68% Space Free | Partition Type: NTFS

Computer Name: GDUBB-PC | User Name: GDuBB | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = Opera.HTML] – C:\Program Files (x86)\Opera\Opera.exe (Opera Software)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = Opera.HTML] – C:\Program Files (x86)\Opera\Opera.exe (Opera Software)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] – "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
https [open] – "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] – "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
https [open] – "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"AutoUpdateDisableNotify" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 – ()
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 – ()

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 – ()
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 – ()


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0BFE57E3-5566-4D9F-90AC-B4302FFD28D0}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{2BAC8CB3-C032-4F61-8252-01A4CE909DDC}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{33BA4827-75CB-4CEE-AAB3-25833914EAE0}" = lport=5353 | protocol=17 | dir=in | name=bonjour port 5353 |
"{37850A42-539B-439B-9795-F7B530512932}" = lport=9322 | protocol=6 | dir=in | name=ekdiscovery |
"{3C736620-1F90-437D-AEE9-24E71435E397}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{46B0A04F-31EC-496F-9EE9-A3FE65729FD4}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{48F741B1-01DD-49A8-B7C8-6E50ADC019AF}" = lport=138 | protocol=17 | dir=in | app=system |
"{4909A79B-40A6-4520-A727-271067FA6540}" = rport=10243 | protocol=6 | dir=out | app=system |
"{490E0984-BBA6-4F83-AC3E-0369A815FA10}" = rport=427 | protocol=17 | dir=in | svc=hpslpsvc | app=c:\windows\system32\svchost.exe |
"{4CC3380C-DE53-44E5-AB99-77C780CE081A}" = rport=80 | protocol=6 | dir=out | app=c:\program files (x86)\common files\intuit\update service\intuitupdater.exe |
"{51FC3FD6-B5A3-4B83-8B7E-5C1FA1DF4B70}" = lport=2869 | protocol=6 | dir=in | app=system |
"{53FE60EE-7FCC-4F2D-94F0-41D707A0E2AC}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{560EFF76-2B51-47F6-9339-3CFA0B2EF0B4}" = rport=80 | protocol=6 | dir=out | app=c:\program files (x86)\common files\intuit\update service v4\intuitupdateservice.exe |
"{5B126E3C-1F72-4C0A-AE0F-E5B12576E1BD}" = rport=139 | protocol=6 | dir=out | app=system |
"{5BFB5B78-FDB3-4A2E-A976-7080D267E04A}" = lport=50000 | protocol=17 | dir=in | name=iha_messagecenter |
"{5F968F28-C607-470D-BF93-83A7CFDE7B5A}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{64783507-61E0-48C1-901D-5B2BD29929D0}" = lport=445 | protocol=6 | dir=in | app=system |
"{6840B6BE-1B5D-4C55-8620-4C2E160ED166}" = lport=10243 | protocol=6 | dir=in | app=system |
"{778F5948-3ADA-4FC2-A9BA-0A7302BF5FD7}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{7B479535-F2B0-4A50-845C-71FE2F87452D}" = rport=138 | protocol=17 | dir=out | app=system |
"{838D199A-EF57-4B0C-AC57-F960C7DB61BD}" = rport=445 | protocol=6 | dir=out | app=system |
"{8A62F78F-AA6D-4346-955A-DE542B8790A0}" = lport=137 | protocol=17 | dir=in | app=system |
"{8DCD6F91-498D-42FC-960C-A4A8E56A1098}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{8E0CD11B-8D6D-478D-B37C-8AB3346BEF59}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{8FA6685F-7A12-472D-8317-A2D9F8C38BA8}" = lport=50000 | protocol=17 | dir=in | name=iha_messagecenter |
"{92D9BD6D-F856-4C36-872B-82C7D90EB013}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{96D72FA3-7E69-4B72-A5FB-DBD2D4934949}" = rport=80 | protocol=6 | dir=out | app=c:\program files (x86)\common files\intuit\update service\intuitupdateservice.exe |
"{9CD15F8A-EFFC-42A3-BAC1-A1142E5DA25C}" = lport=2869 | protocol=6 | dir=in | app=system |
"{A794126F-0857-432A-A1C8-29F4B0953DAC}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{AB083C11-0851-4507-AF8C-968044C03D29}" = rport=80 | protocol=6 | dir=out | app=c:\program files (x86)\common files\intuit\update service v4\intuitupdater.exe |
"{C41ABFA3-D10D-4BFE-B892-062F31C81D27}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{D0A1FD6E-C05E-4806-BFE5-FD554DB9A129}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{DEFE281B-D9B0-4DB9-B2C0-BFC19EB95BE4}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{E9892EC8-CE9C-4D2F-A579-CC91041A3AFA}" = lport=139 | protocol=6 | dir=in | app=system |
"{E9C0B5F7-80E9-4F58-B3F4-921FAA689620}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{FEC81527-E6E6-4E0B-B81A-068F2CA55960}" = rport=137 | protocol=17 | dir=out | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{011404C4-F69F-47EA-89DA-64B8D53D76A1}" = dir=in | app=c:\program files (x86)\vmware\vmware player\vmware-authd.exe |
"{01FAA037-7B85-4294-AB05-2B2009052296}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\pluginwrapper\opera_plugin_wrapper.exe |
"{06D9C031-CC87-4C47-A009-89C77C2CC6D1}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{0A10AB63-EFF3-400C-B88F-AE0FB77832E0}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{0D0E4535-B053-4E17-90DB-7DECCD914B80}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{16C62F8D-CA59-45C5-8E5B-C8FC7F0265B0}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgpc01.exe |
"{176EE3D5-40CE-41E6-9162-2684C0D338F2}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{1998C8A5-48E7-4B2A-B0F1-D1C909477E73}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{19DAEF15-EBB3-4966-AA6E-06EACFACFDCD}" = protocol=6 | dir=in | app=c:\program files (x86)\google\google talk\googletalk.exe |
"{230B8EF9-6C0F-48B3-9B4D-16B15A9E4FDD}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{235ACA72-5492-445C-925B-06C4D9A251CD}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposid01.exe |
"{24256ACA-494E-401A-8357-8EF14FD4EA06}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{2AFFB051-5D79-44FA-8AC6-98E17EFED598}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{2B40D4CB-E0CA-4CE4-B0C0-4070346ACED7}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg10\avgmfapx.exe |
"{2C7AF577-4E9C-4396-93D5-C906104D4B8F}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{3203868E-9540-4A0D-B8D7-13A8760186A9}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqtra08.exe |
"{3467EA4A-B263-4986-928C-3F501C660195}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{368CE604-BA01-4710-A643-21D293F036D9}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{37D65655-AB37-4CAA-8BE7-2BC27E7FB935}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{416628C7-E760-4D43-9ED6-E13239E819F4}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{42545A9B-0F67-4EDD-AB91-E20C8108AA78}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{4BC6B78F-1494-4473-81F3-A0F5101E5C31}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{4F3DA7C4-5713-420D-9CFB-8AA1653E397F}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpiscnapp.exe |
"{52A25B01-E42E-4B0A-A872-1925B341B21D}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{578CAF2A-6C52-4F96-A7C9-298B00922F04}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{588AC7D9-273C-4B03-816D-AA7489B2B58B}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{5AF3C75A-0EBE-4CDA-95EE-81B6E1F4F354}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpfccopy.exe |
"{62158B30-0723-4FD4-8B15-1B0254C18B71}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgm.exe |
"{6B885F52-04B1-4210-B711-C8DC3971ED78}" = dir=in | app=c:\program files (x86)\vmware\vmware player\vmware-authd.exe |
"{6C1A824B-238D-4633-81AC-A19BDAB1E9F1}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{6C4BA20D-1454-490D-A3AE-23B46C1B24AC}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\pluginwrapper\opera_plugin_wrapper.exe |
"{6FCCEC2D-AA57-429D-B2CD-8632F8A1790F}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgmfapx.exe |
"{76D89C96-DA35-4822-926F-748B6F74D42A}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqkygrp.exe |
"{77913D5F-A996-47AC-A6E6-0546FE4C8E48}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{7AFF491A-B47E-41A0-A59D-BE284594A745}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{824C934F-3CDA-4C67-B4D1-FB5D9DD423A8}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{8C11825D-547A-447A-8D06-26ADF0B1BF1F}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\pluginwrapper\opera_plugin_wrapper.exe |
"{8E2869CD-6FE3-42F9-B0F3-379AD977EEBA}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{904D16DE-4950-4EAD-86FE-85FF1F792BA9}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{9B7A8272-3DCC-4C4D-9B28-CD755C4F1A98}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9E78C1A5-FE4D-4C2B-9212-FA713E590714}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{A07DCBCE-8BC8-4ED6-96A7-1AEFF406FB9A}" = dir=in | app=c:\program files (x86)\hp\digital imaging\smart web printing\smartwebprintexe.exe |
"{A08947CB-66E5-416C-AE73-079A1F2CEB0F}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{A09D79FA-DFD9-4A70-B92D-DD09A157A75C}" = dir=in | app=c:\program files (x86)\hp\hp software update\hpwucli.exe |
"{A2C15E3E-3464-430E-8676-B668A7F80A02}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgplgtupl.exe |
"{A55325A4-A424-4E12-8D61-69E1099D9E93}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqste08.exe |
"{B2355BA5-B3BE-46AF-AF0F-1B2058C0EC5B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{B42956C1-2F2F-4DA3-A459-1EB4E6CB5EBF}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpoews01.exe |
"{B4C58CFD-B6A7-46C3-A2F2-D38FA251B076}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{B4D223C4-1DEE-4E09-ABFE-9F232CE1F9E0}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{B78B348F-8D8E-4A26-A014-E3818F1280BE}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{B9331496-0AAD-40AD-9D51-42277B1FA914}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{C2E836C9-6DEC-42CF-BDEC-9B7F1563ABAB}" = protocol=17 | dir=in | app=c:\program files (x86)\google\google talk\googletalk.exe |
"{C459AB5C-89B4-40FC-9B95-A150899F1CA1}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{C893A2F1-3A4A-453B-9E2A-1459E261EC61}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgmfapx.exe |
"{C8E0777C-7347-4716-920C-BEC94F4F35F4}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{CAEBF0E1-DBCF-4690-8555-1C52FD79CDB4}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{CB885EFF-5B9B-41B7-80AE-6BB53DF03917}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{E05370CE-4198-42F7-9C78-AE4A935EC929}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{E2E69B0B-8D91-4818-997D-65BF159A36C1}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgh.exe |
"{E8E086B4-9C7F-44B8-ADAD-34D0CA606654}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{F03C1BF3-8950-4C27-88CA-2FE34EA1F252}" = dir=in | app=e:\setup\hpznui40.exe |
"{F5116E79-214F-455C-A1C4-E92E34B874F9}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg10\avgmfapx.exe |
"{F612FD36-969A-43CD-9CA8-6EA7B7633C6A}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{F6CB257B-A641-4447-B507-D39CA925B32E}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{F706F89C-BDE3-4574-B844-7F18F27F8E31}" = protocol=6 | dir=in | app=c:\users\gdubb\appdata\local\google\google talk plugin\googletalkplugin.exe |
"{FB44CAEF-6A92-471F-83C4-3279BFDBFE1D}" = protocol=6 | dir=out | app=system |
"{FCB95132-C974-4ECF-8651-406566A16DF5}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe |
"{FD199CD8-8B52-4AE3-8C25-2507AD73130F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{FE259589-F8CE-43AD-9A18-F4DA521F8BF8}" = protocol=17 | dir=in | app=c:\users\gdubb\appdata\local\google\google talk plugin\googletalkplugin.exe |
"{FFB1CD33-87A7-42EA-84B3-52529B3997DF}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\pluginwrapper\opera_plugin_wrapper.exe |
"TCP Query User{13F946AF-9882-4EA3-BD7E-369B1DB44329}C:\windows\system32\javaw.exe" = protocol=6 | dir=in | app=c:\windows\system32\javaw.exe |
"TCP Query User{8B2D33A1-0CE7-489F-AC15-E8AF2B6BF8DD}C:\program files (x86)\java\jdk1.6.0_20\jre\bin\java.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jdk1.6.0_20\jre\bin\java.exe |
"TCP Query User{BCD16959-5FBB-4D8C-9E46-F6AE9FE2EBFC}C:\python27\python.exe" = protocol=6 | dir=in | app=c:\python27\python.exe |
"TCP Query User{D668ED2E-D632-4273-BA73-EEB8F157F064}D:1\techwizard.exe" = protocol=6 | dir=in | app=d:1\techwizard.exe |
"UDP Query User{7ADD27F8-2791-4E3B-8E22-F8CB8841E5F3}C:\windows\system32\javaw.exe" = protocol=17 | dir=in | app=c:\windows\system32\javaw.exe |
"UDP Query User{7F7100E0-CDEE-41CC-8DFA-7A38F784F546}D:1\techwizard.exe" = protocol=17 | dir=in | app=d:1\techwizard.exe |
"UDP Query User{9C9B310C-AEFE-466E-AB91-C1EDA86CCF50}C:\program files (x86)\java\jdk1.6.0_20\jre\bin\java.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jdk1.6.0_20\jre\bin\java.exe |
"UDP Query User{E21865C8-4D48-43CC-93CE-D531019E84CA}C:\python27\python.exe" = protocol=17 | dir=in | app=c:\python27\python.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{02A5BD31-16AC-45DF-BE9F-A3167BC4AFB2}" = Windows Live Family Safety
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0D87AE67-14EB-4C10-88A5-DA6C3181EB18}" = Windows Live Family Safety
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{23170F69-40C1-2702-0928-000001000000}" = 7-Zip 9.28 (x64 edition)
"{26A24AE4-039D-4CA4-87B4-2F86416029FF}" = Java™ 6 Update 29 (64-bit)
"{344C0D46-2EF4-4BC8-AE03-3DACDA9B9485}" = AVG 2012
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{36A415C2-7181-421D-92C9-8255766E0FF3}" = TortoiseSVN 1.6.10.19898 (64 bit)
"{48C0866E-57EB-444C-8371-8E4321066BC3}" = Network64
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4EE61784-10C6-4B7C-A0B2-5BED17B05741}" = Oracle VM VirtualBox 4.1.18
"{4FC945A7-D54E-4F00-BE32-90553F80FCE8}" = ActivePerl 5.14.2 Build 1402 (64-bit)
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{64A3A4F4-B792-11D6-A78A-00B0D0160200}" = Java™ SE Development Kit 6 Update 20 (64-bit)
"{64A3A4F4-B792-11D6-A78A-00B0D0160290}" = Java™ SE Development Kit 6 Update 29 (64-bit)
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{6BFAB6C1-6D46-46DB-A538-A269907C9F2F}" = Network64
"{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{98DE7960-458C-4104-90E9-910389C81AC9}" = VmciSockets
"{99F9B5F6-C042-44C5-9BE8-36CF244480BC}" = ActiveState ActivePython [removed] (64-bit)
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{BF46C84D-1AC3-4CC3-A45C-EF6257B80984}" = AVG 2012
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DBC1DE57-B55A-4D57-9769-1DB9BE506AF7}" = HP Photosmart D110 All-In-One Driver Software 14.0 Rel. 7
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer
"2C1C2F29FADF39F533CEEE67B90F07A5306A4BDB" = Windows Driver Package - OLYMPUS IMAGING CORP. Camera Communication Driver Package (09/09/2009 1.0.0.0)
"AVG" = AVG 2012
"CutePDF Writer Installation" = CutePDF Writer 2.8
"HP Imaging Device Functions" = HP Imaging Device Functions 14.0
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"HP Solution Center & Imaging Support Tools" = HP Solution Center 14.0
"HPExtendedCapabilities" = HP Customer Participation Program 14.0
"LSI Soft Modem" = LSI PCI-SV92EX Soft Modem
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NVIDIA Drivers" = NVIDIA Drivers

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05BDC796-3451-4F81-B91D-E98F7ADA76C2}" = TurboTax 2010 WinPerTaxSupport
"{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{113AC946-0CEB-49C7-828A-230FF9EB1DBB}" = TurboTax 2010 wmdiper
"{13D55987-DB41-DD71-0047-3B3BE83EE576}" = Icon Robot
"{1458BB78-1DC5-4BC0-B9A3-2B644F5A8105}" = DeviceDiscovery
"{150B6201-E9E6-4DFB-960E-CCBD53FBDDED}" = HPProductAssistant
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{17B4760F-334B-475D-829F-1A3E94A6A4E6}" = HP Setup
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{292F0F52-B62D-4E71-921B-89A682402201}" = Toolbox
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{32A3A4F4-B792-11D6-A78A-00B0D0160200}" = Java™ SE Development Kit 6 Update 20
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3782EC09-4000-475E-8A59-9CABD6F03B4C}" = TurboTax 2010 WinPerFedFormset
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}" = HP Advisor
"{42BBA4CC-EFB6-4653-A2CC-F305D4B399C3}" = PS_AIO_07_D110_SW_Min
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E4F8163-9889-4BAB-B2E7-DBAAE248C1EB}" = LG Android Driver
"{4F2FCCCF-29F3-44B9-886F-6D16F8417522}" = TurboTax 2010 wrapper
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{56009CA3-423B-41F8-884A-E5B049534F15}" = Kaspersky Security Scan
"{560985FB-4B76-4121-9189-7A2CDC7886D6}" = Kaspersky Anti-Virus 2013
"{565E7B0E-B76B-4EAD-9753-F1E72A5CF12E}" = HPAppStudio
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5A13987D-55F4-4271-A40E-76AC9B1B38FD}" = OpenOffice.org 3.2
"{5B025634-7D5B-4B8D-BE2A-7943C1CF2D5D}" = Status
"{5C6F884D-680C-448B-B4C9-22296EE1B206}" = Logitech Harmony Remote Software 7
"{65CB4C08-C47B-4A7E-A6A4-50C06ADA5FC6}" = Adobe AIR
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6D6664A9-3342-4948-9B7E-034EFE366F0F}" = HTC Driver Installer
"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.1.0.0
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{741CFE3A-1C0B-4A7D-8E08-5D78C911C09D}" = HP Support Assistant
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{7A67AD3E-D675-2535-C2C8-83A6E37D074B}" = Icon Robot Android
"{80F19EAA-44C4-47C2-AE87-1C7628E858D6}" = Logitech Harmony Remote Software 7
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{8471021C-F529-43DE-84DF-3612E10F58C4}" = Remote Control USB Driver
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{87D4D14E-C206-4DBE-AE1A-3767B8B61379}" = Corona SDK
"{89A43E80-AC6C-4DA8-9800-F4B30ED577C0}" = OLYMPUS ib
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8EE94FD8-5F52-4463-A340-185D16328158}" = WebReg
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{91D3AD6F-09CD-4695-9FA3-8FB15429BE97}" = D110
"{9209B8AE-BA31-4FAB-9743-8E3F93DBD24E}" = LG Verizon United Drivers
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A436F67F-687E-4736-BD2B-537121A804CF}" = HP Product Detection
"{A525E00B-6609-442E-9DCD-64453C233E8D}" = TurboTax 2010 WinPerReleaseEngine
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.1
"{B4089055-D468-45A4-A6BA-5A138DD715FC}" = Bing Bar
"{B8AC1A89-FFD1-4F97-8051-E505A160F562}" = HP Odometer
"{B9A03B7B-E0FF-4FB3-BA83-762E58A1B0AA}" = HP Support Information
"{BB3447F6-9553-4AA9-960E-0DB5310C5779}" = GPBaseService2
"{BC4174D1-7970-40E6-AC57-F095F961FB08}" = HTC Sync
"{BC5DD87B-0143-4D14-AAE6-97109614DC6B}" = SolutionCenter
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C611CF88-969D-43E6-A877-D6D6439DD081}" = HP Remote Solution
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C6D442EC-14C6-4E5B-8378-305BAE7EDBBF}" = TurboTax 2011 wmdiper
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CAF5B770-082F-40C4-853D-3973BB81BDAA}" = TurboTax 2011 WinPerTaxSupport
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CD31E63D-47FD-491C-8117-CF201D0AFAB5}" = TrayApp
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D360FA88-17C8-4F14-B67F-13AAF9607B12}" = MarketResearch
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DA5BDB2A-12F0-4343-8351-21AAEB293990}" = PreReq
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E452E727-86B8-4233-8CC3-41FD817AFAFF}" = VMware Player
"{E463E171-4082-4744-A466-F7CBE8502789}" = TurboTax 2011 WinPerReleaseEngine
"{E517094C-06B6-419F-8FFD-EF4F57972130}" = QuickTransfer
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E9E34215-82EF-4909-BE2F-F581F0DC9062}" = DirectX for Managed Code Update (Summer 2004)
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{EBE030DD-D404-4D92-85E9-8C3624820808}_is1" = Light Image Resizer [removed]
"{EE556A3E-EB37-4392-9637-BAA8EC2F47FA}" = TurboTax 2011 wrapper
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FA0FF682-CC70-4C57-93CD-E276F3E7537E}" = BufferChm
"{FAD3D68B-2F9C-459B-AA79-C04B9090FD72}" = TurboTax 2011 WinPerFedFormset
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Audacity_is1" = Audacity 1.2.6
"avast" = avast! Free Antivirus
"DAEMON Tools Lite" = DAEMON Tools Lite
"DAEMON Tools Toolbar" = DAEMON Tools Toolbar
"Free Mp3 Wma Converter_is1" = Free Mp3 Wma Converter V 1.91
"FreeMat" = FreeMat
"GoldWave v5.58" = GoldWave v5.58
"HP Photo Creations" = HP Photo Creations
"HP Remote Solution" = HP Remote Solution
"Icon-Robot" = Icon Robot
"Icon-Robot-Android" = Icon Robot Android
"ImTOO Audio Encoder 6" = ImTOO Audio Encoder 6
"Inkscape" = Inkscape 0.48.2
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{89A43E80-AC6C-4DA8-9800-F4B30ED577C0}" = OLYMPUS ib
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallWIX_{56009CA3-423B-41F8-884A-E5B049534F15}" = Kaspersky Security Scan
"InstallWIX_{560985FB-4B76-4121-9189-7A2CDC7886D6}" = Kaspersky Anti-Virus 2013
"LMMS 0.4.3" = Linux MultiMedia Studio (LMMS)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.0.1400
"Mozilla Firefox 15.0.1 (x86 en-US)" = Mozilla Firefox 15.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Notepad++" = Notepad++
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Opera 12.02.1578" = Opera 12.02
"Smart Defrag_is1" = Smart Defrag
"TurboTax 2010" = TurboTax 2010
"TurboTax 2011" = TurboTax 2011
"uTorrent" = µTorrent
"VMware_Player" = VMware Player
"WinGimp-2.0_is1" = GIMP 2.6.10
"WinLiveSuite" = Windows Live Essentials

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"MusicManager" = Music Manager
"NOAA Weather and Climate Toolkit" = NOAA Weather and Climate Toolkit

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 9/25/2012 8:18:40 PM | Computer Name = GDuBB-PC | Source = Microsoft-Windows-LoadPerf | ID = 3002
Description = The performance counter explain text string value in the registry
is not formatted correctly. The malformed string is . The first DWORD in the Data
section contains the index value to the malformed string while the second and third
DWORDs in the Data section contain the last valid index values.

Error - 9/25/2012 8:20:49 PM | Computer Name = GDuBB-PC | Source = Microsoft-Windows-LoadPerf | ID = 3002
Description = The performance counter explain text string value in the registry
is not formatted correctly. The malformed string is . The first DWORD in the Data
section contains the index value to the malformed string while the second and third
DWORDs in the Data section contain the last valid index values.

Error - 9/25/2012 8:59:38 PM | Computer Name = GDuBB-PC | Source = vmauthd | ID = 1000
Description =

Error - 9/25/2012 8:59:50 PM | Computer Name = GDuBB-PC | Source = Microsoft-Windows-LoadPerf | ID = 3002
Description = The performance counter explain text string value in the registry
is not formatted correctly. The malformed string is . The first DWORD in the Data
section contains the index value to the malformed string while the second and third
DWORDs in the Data section contain the last valid index values.

Error - 9/25/2012 9:08:27 PM | Computer Name = GDuBB-PC | Source = Microsoft-Windows-LoadPerf | ID = 3002
Description = The performance counter explain text string value in the registry
is not formatted correctly. The malformed string is . The first DWORD in the Data
section contains the index value to the malformed string while the second and third
DWORDs in the Data section contain the last valid index values.

Error - 9/25/2012 11:30:22 PM | Computer Name = GDuBB-PC | Source = Microsoft-Windows-LoadPerf | ID = 3002
Description = The performance counter explain text string value in the registry
is not formatted correctly. The malformed string is . The first DWORD in the Data
section contains the index value to the malformed string while the second and third
DWORDs in the Data section contain the last valid index values.

Error - 9/26/2012 3:00:26 AM | Computer Name = GDuBB-PC | Source = Microsoft-Windows-LoadPerf | ID = 3002
Description = The performance counter explain text string value in the registry
is not formatted correctly. The malformed string is . The first DWORD in the Data
section contains the index value to the malformed string while the second and third
DWORDs in the Data section contain the last valid index values.

Error - 9/26/2012 6:25:54 PM | Computer Name = GDuBB-PC | Source = vmauthd | ID = 1000
Description =

Error - 9/26/2012 6:26:00 PM | Computer Name = GDuBB-PC | Source = Microsoft-Windows-LoadPerf | ID = 3002
Description = The performance counter explain text string value in the registry
is not formatted correctly. The malformed string is . The first DWORD in the Data
section contains the index value to the malformed string while the second and third
DWORDs in the Data section contain the last valid index values.

Error - 9/26/2012 6:28:40 PM | Computer Name = GDuBB-PC | Source = Application Error | ID = 1000
Description = Faulting application name: SUPERANTISPYWARE.EXE, version: 5.5.0.1022,
time stamp: 0x505ca474 Faulting module name: ntdll.dll, version: 6.1.7601.17725,
time stamp: 0x4ec4aa8e Exception code: 0xc0000374 Fault offset: 0x00000000000c40f2
Faulting
process id: 0xfec Faulting application start time: 0x01cd9c3607508180 Faulting application
path: C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE Faulting module path:
C:\Windows\SYSTEM32\ntdll.dll Report Id: 850ea8e0-0829-11e2-979a-005056c00008

Error - 9/26/2012 6:30:59 PM | Computer Name = GDuBB-PC | Source = Application Error | ID = 1000
Description = Faulting application name: SUPERAntiSpyware.exe, version: 5.5.0.1022,
time stamp: 0x505ca474 Faulting module name: ntdll.dll, version: 6.1.7601.17725,
time stamp: 0x4ec4aa8e Exception code: 0xc0000374 Fault offset: 0x00000000000c40f2
Faulting
process id: 0x1584 Faulting application start time: 0x01cd9c368e1d99a0 Faulting application
path: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe Faulting module path:
C:\Windows\SYSTEM32\ntdll.dll Report Id: d7b365e0-0829-11e2-979a-005056c00008

[ System Events ]
Error - 12/23/2011 2:46:24 PM | Computer Name = GDuBB-PC | Source = bowser | ID = 8003
Description =

Error - 12/23/2011 11:53:03 PM | Computer Name = GDuBB-PC | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the ShellHWDetection service.

Error - 12/26/2011 12:07:08 PM | Computer Name = GDuBB-PC | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the lmhosts service.

Error - 12/26/2011 2:25:41 PM | Computer Name = GDuBB-PC | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the ShellHWDetection service.

Error - 12/28/2011 8:13:00 AM | Computer Name = GDuBB-PC | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the ShellHWDetection service.

Error - 12/29/2011 10:52:54 AM | Computer Name = GDuBB-PC | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the ShellHWDetection service.

Error - 12/29/2011 5:24:09 PM | Computer Name = GDuBB-PC | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the Netman service.

Error - 12/29/2011 5:24:09 PM | Computer Name = GDuBB-PC | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the lmhosts service.

Error - 1/7/2012 7:13:33 PM | Computer Name = GDuBB-PC | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the Netman service.

Error - 1/10/2012 10:03:01 PM | Computer Name = GDuBB-PC | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the ShellHWDetection service.


< End of report >
Hi gdubb85, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

You have multiple antivirus programs installed. These will conflict and cause slowdowns, lockups, etc much like you are experiencing. It's ok to have an antivirus program and an antimalware program such as SUPERAntiSpyware or Malwarebytes Anti-Malware. The same goes for antimalware programs, only one running at a time. You can have 2 antimale programs installed providing only one is running in real time or they like the antivirus programs will conflict.

So to start let's get you down to the proper number of security programs.

Kaspersky is a paid for program that has a trial period. Unless you bought a subscription for it I suggest you uninstall it. This will leave you with the choice of which free antivirus program you wish to keep, Avast or AVG. The choice is yours but please uninstall one of them.

SUPERAntiSpyware or Malwarebytes Anti-Malware again the choice is yours. With this type of program you have a little more leeway. You can leave both installed but you must disable the real time scanning of one of them. I take it you have the trial copy of both of these programs? If that is the case both programs will cease to run in real time and become an on demand scanner once the trial period is up. Keep in mind since you have Windows7 you also have Windows Defender running.

Start with removing the extra antivirus programs and let me know which one you kept.
First of all thank you oldman960 for your help I have removed Kapersky + Avast! and only have AVG I have removed MalwareBytes and only have SUPERAntiSpyware I am ready for the net steps!
It's hard to tell, but I did not do anything to correct it and I want to make sure there is nothing in the logs before I feel confident I can enter passwords in, etc. on my computer.
Hi gdubb85,

Just removing the extra antivirus programs should have improved the computer.

We'll start looking.

Download aswMBR.exe ( 511KB ) to your desktop.

Right click the aswMBR.exe and click "Run as Administrator" to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]

There shall also be a file on your desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) folder. Please attach that zipped file in your next reply.
Sorry for the confusion earlier - I want to keep going with this because the many anti-virus/malware programs installed are a reaction to my computer originally acting up, not the root cause. the aswMBR tool crashed a few times and the scan took ~4.5 hours so it took me a few days to run it to completion because of the restarts….I ended up emptying 18GB of files in my recycle bin after seeing that when it crashed it was scanning items there. Attached is the compressed .dat and below is the text file: aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-10-05 07:18:41 —————————– 07:18:41.672 OS Version: Windows x64 6.1.7601 Service Pack 1 07:18:41.672 Number of processors: 2 586 0x602 07:18:41.688 ComputerName: GDUBB-PC UserName: GDuBB 07:18:46.519 Initialize success 07:19:27.183 AVAST engine defs: 12100501 07:19:33.953 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000006b 07:19:33.953 Disk 0 Vendor: WDC_WD50 05.0 Size: 476940MB BusType: 3 07:19:33.984 Disk 0 MBR read successfully 07:19:33.984 Disk 0 MBR scan 07:19:33.984 Disk 0 unknown MBR code 07:19:34.000 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 98 MB offset 2048 07:19:34.016 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 466841 MB offset 208845 07:19:34.047 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 9994 MB offset 956301312 07:19:34.109 Disk 0 scanning C:\Windows\system32\drivers 07:20:00.317 Service scanning 07:20:17.758 Modules scanning 07:20:17.758 Disk 0 trace - called modules: 07:20:17.774 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys storport.sys hal.dll nvstor64.sys 07:20:17.789 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800461c060] 07:20:17.789 3 CLASSPNP.SYS[fffff88000db943f] -> nt!IofCallDriver -> [0xfffffa8003654db0] 07:20:17.789 5 ACPI.sys[fffff88000ef87a1] -> nt!IofCallDriver -> \Device\0000006b[0xfffffa800452a630] 07:20:20.800 AVAST engine scan C:\ 11:50:20.940 Scan finished successfully 17:48:19.634 Disk 0 MBR has been saved successfully to "C:\Users\GDuBB\Desktop\MBR.dat" 17:48:19.702 The log file has been saved successfully to "C:\Users\GDuBB\Desktop\aswMBR.txt"

Attachments:

I also want to add that most scans have come up clean (including using Kapersky Rescue Disk 10 loaded after the BIOS) beside Super-Anti spyware crashing and I may have not noticed this before, but my memory in task manager is not adding up based on the listed processes. I am used to looking at this screen while managing lots of programs and right now it should be well under a gig with only a few web browers open, and it is almost maxing out my 4Gb of memory. Attached are the screen shots of my processes and my memory if it's helpful. Thanks once again for taking the time to help me out!
Hi gdubb85,

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Right click on ComboFix.exe, click Run as Administrator & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. If you recieve a message after running combofix similar to "Illegal operation attempted on a registry marked for deletion" simply reboot the computer to resolve it.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with the combofix log.

Thanks
Here is the CombFix log: ComboFix 12-10-04.02 - GDuBB 10/07/2012 10:50:09.1.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4095.2938 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\ntuser.dat C:\text.txt . . ((((((((((((((((((((((((( Files Created from 2012-09-07 to 2012-10-07 ))))))))))))))))))))))))))))))) . . 2012-10-07 14:56 . 2012-10-07 14:56 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-09-28 12:51 . 2012-09-28 12:51 ——– d—–w- c:\users\GDuBB\AppData\Local\MFAData 2012-09-28 12:51 . 2012-09-28 12:51 ——– d—–w- c:\users\GDuBB\AppData\Local\Avg2013 2012-09-28 00:50 . 2012-09-28 00:51 ——– d—–w- C:\Python27 2012-09-27 07:39 . 2012-09-27 18:08 ——– d—a-w- C:\Kaspersky Rescue Disk 10.0 2012-09-27 03:40 . 2012-09-26 14:53 460888 —-a-w- c:\windows\system32\drivers\09517212.sys 2012-09-26 23:38 . 2012-09-26 23:38 ——– d—–w- c:\users\GDuBB\AppData\Roaming\RoboForm 2012-09-26 23:36 . 2012-09-26 23:36 ——– d—–w- c:\programdata\RoboForm 2012-09-26 23:35 . 2012-08-21 09:12 285328 —-a-w- c:\windows\system32\aswBoot.exe 2012-09-26 23:34 . 2012-10-02 00:20 ——– d—–w- c:\programdata\AVAST Software 2012-09-26 23:34 . 2012-09-26 23:34 ——– d—–w- c:\program files\AVAST Software 2012-09-26 23:32 . 2012-09-26 23:32 ——– d—–w- c:\users\GDuBB\AppData\Roaming\Malwarebytes 2012-09-26 23:32 . 2012-09-26 23:32 ——– d—–w- c:\programdata\Malwarebytes 2012-09-26 23:31 . 2012-10-02 00:08 ——– d—–w- c:\program files (x86)\Kaspersky Lab 2012-09-26 23:23 . 2012-08-21 21:01 245760 —-a-w- c:\windows\system32\OxpsConverter.exe 2012-09-26 22:46 . 2012-10-02 00:20 ——– d—–w- c:\programdata\Kaspersky Lab 2012-09-26 01:43 . 2012-09-26 01:43 ——– d—–w- c:\users\GDuBB\AppData\Roaming\Python 2012-09-19 01:23 . 2012-10-01 00:59 ——– d—–w- c:\users\GDuBB\Dog Walking 2012-09-14 20:22 . 2012-09-14 20:22 ——– d—–w- c:\program files\apache-maven-3.0.4 2012-09-13 19:30 . 2012-09-26 23:15 ——– d—–w- c:\users\GDuBB\AppData\Local\Programs 2012-09-12 11:38 . 2012-09-12 11:38 73696 —-a-w- c:\program files (x86)\Mozilla Firefox\breakpadinjector.dll 2012-09-12 00:01 . 2012-08-22 18:12 950128 —-a-w- c:\windows\system32\drivers\ndis.sys 2012-09-12 00:01 . 2012-08-02 17:58 574464 —-a-w- c:\windows\system32\d3d10level9.dll 2012-09-12 00:01 . 2012-07-04 20:26 41472 —-a-w- c:\windows\system32\drivers\RNDISMP.sys 2012-09-12 00:01 . 2012-08-02 16:57 490496 —-a-w- c:\windows\SysWow64\d3d10level9.dll 2012-09-12 00:01 . 2012-08-22 18:12 1913200 —-a-w- c:\windows\system32\drivers\tcpip.sys 2012-09-12 00:01 . 2012-08-22 18:12 376688 —-a-w- c:\windows\system32\drivers\netio.sys 2012-09-12 00:01 . 2012-08-22 18:12 288624 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-09-29 01:22 . 2012-04-12 11:24 696240 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-09-29 01:22 . 2011-05-22 18:26 73136 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-09-28 00:34 . 2011-12-09 19:16 260 —-a-w- c:\windows\SysWow64\cmdVBS.vbs 2012-09-28 00:34 . 2011-12-09 19:16 256 —-a-w- c:\windows\SysWow64\MSIevent.bat 2012-09-12 07:01 . 2010-08-20 18:03 64462936 —-a-w- c:\windows\system32\MRT.exe 2012-08-24 19:43 . 2012-08-24 19:43 384352 —-a-w- c:\windows\system32\drivers\avgtdia.sys 2012-07-26 07:21 . 2012-07-26 07:21 291680 —-a-w- c:\windows\system32\drivers\avgldx64.sys 2012-07-18 18:15 . 2012-08-17 22:16 3148800 —-a-w- c:\windows\system32\win32k.sys . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-09-26 5664640] "DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-01-24 3478336] "KSS"="c:\program files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe" [2012-04-25 202296] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "hpsysdrv"="c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe" [2008-11-20 62768] "Mobile Connectivity Suite"="c:\program files (x86)\HTC\HTC Sync\Application Launcher\Application Launcher.exe" [2009-11-19 598016] "AVG_TRAY"="c:\program files (x86)\AVG\AVG2012\avgtray.exe" [2012-07-31 2596984] "BYRUA_AGENT"="c:\programdata\LGMOBILEAX\BYR_Client\VZWUAAgent.exe" [2012-09-24 380024] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files (x86)\hp\Digital Imaging\bin\hpqtra08.exe [2009-11-18 275072] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG2012\avgrsa.exe /sync /restart . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . R1 5602141drv;5602141drv;c:\windows\system32\DRIVERS\5602141drv.sys [x] R2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2012\AVGIDSAgent.exe [2012-08-13 5167736] R2 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-10-21 196176] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-29 250288] R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2009-10-26 32768] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-09-12 114144] R3 OlyCamComm;OLYMPUS USB Communication Device;c:\windows\system32\DRIVERS\OlyCamComm.sys [2009-09-09 24208] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 vzandnetadb;ADB Interface DriverNet for VZW;c:\windows\system32\Drivers\lgvzandnetadb.sys [2011-08-03 31744] R3 vzandnetdiag;LGE AndroidNet for VZW USB Serial Port;c:\windows\system32\DRIVERS\lgvzandnetdiag64.sys [2011-08-03 29696] R3 vzandnetmodem;LGE AndroidNet for VZW USB Modem;c:\windows\system32\DRIVERS\lgvzandnetmdm64.sys [2011-08-03 36864] R3 vzandnetndis;LGE AndroidNet for VZW NDIS Ethernet Adapter;c:\windows\system32\DRIVERS\lgvzandnetndis64.sys [2011-08-03 90624] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-07-25 1255736] R3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2009-07-14 23040] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184] S0 09517212;09517212;c:\windows\system32\DRIVERS\09517212.sys [2012-09-26 460888] S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys [2012-04-19 28480] S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [2012-01-31 36944] S0 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys [2011-08-08 116336] S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [2012-07-26 291680] S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [2011-12-23 47696] S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [2012-08-24 384352] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-02-12 283200] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368] S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2012-06-05 224088] S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2012-06-05 130904] S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2012-09-07 140672] S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2012\avgwdsvc.exe [2012-02-14 193288] S2 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-10-13 249648] S2 IntuitUpdateServiceV4;Intuit Update Service v4;c:\program files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe [2011-08-25 13672] S2 KSS;Kaspersky Security Scan Service;c:\program files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe [2012-04-25 202296] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2009-08-17 239648] S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2011-08-30 846448] S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys [2011-12-23 124496] S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\avgidsfiltera.sys [2011-12-23 29776] S3 Razerlow;Razer Pro|Solutions;c:\windows\system32\drivers\Razerlow.sys [2005-11-07 21120] S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2012-06-05 147288] S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [2012-06-05 166232] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder . 2012-10-07 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-12 01:22] . 2012-10-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1727114255-2402910526-3703745838-1000Core.job - c:\users\GDuBB\AppData\Local\Google\Update\GoogleUpdate.exe [2010-07-25 14:48] . 2012-10-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1727114255-2402910526-3703745838-1000UA.job - c:\users\GDuBB\AppData\Local\Google\Update\GoogleUpdate.exe [2010-07-25 14:48] . 2012-10-02 c:\windows\Tasks\SmartDefrag.job - c:\program files (x86)\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2011-03-06 23:08] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal] @="{C5994560-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}] 2010-03-21 12:55 99080 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified] @="{C5994561-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}] 2010-03-21 12:55 99080 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict] @="{C5994562-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}] 2010-03-21 12:55 99080 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked] @="{C5994563-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}] 2010-03-21 12:55 99080 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly] @="{C5994564-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}] 2010-03-21 12:55 99080 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted] @="{C5994565-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}] 2010-03-21 12:55 99080 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded] @="{C5994566-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}] 2010-03-21 12:55 99080 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored] @="{C5994567-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}] 2010-03-21 12:55 99080 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned] @="{C5994568-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}] 2010-03-21 12:55 99080 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . ——- Supplementary Scan ——- . uStart Page = hxxp://www.google.com/ uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm LSP: %SystemRoot%\system32\vsocklib.dll Trusted Zone: atk.com\myvpn Trusted Zone: intuit.com\ttlc TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\GDuBB\AppData\Roaming\Mozilla\Firefox\Profiles\rghikp47.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/ . - - - - ORPHANS REMOVED - - - - . Wow6432Node-HKCU-Run-RESTART_STICKY_NOTES - c:\windows\System32\StikyNot.exe Wow6432Node-HKLM-Run- - (no file) WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-1727114255-2402910526-3703745838-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-1727114255-2402910526-3703745838-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_278_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_278_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-10-07 10:59:18 ComboFix-quarantined-files.txt 2012-10-07 14:59 . Pre-Run: 395,746,332,672 bytes free Post-Run: 398,568,558,592 bytes free . - - End Of File - - 07989DDD771D0A6E1638035154AAB0C7
Hi gdubb85,

There isn't anything showing in the logs. I'm not sure if what you are seeing in task manager is actually acurate or the result of one of the error messages in the log. Besides what you see in task manager how is the computer running generaly?

Before I send you to the Windows forum I'd like to get a look at the computer from outside of windows.

We'll need a flashdrive and if possible your Windows7 disk. I included both sets of instructions for running FRST, with and without the disk. Some machines have the System Recovery Options installed while others don't. Either way will work though.

download

Farbar Recovery Scan Tool 64-Bit and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.

OR

To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.

Once you have entered the System Recovery Options screen:

On the System Recovery Options menu you will get the following options:
  • Startup Repair
    System Restore
    Windows Complete PC Restore
    Windows Memory Diagnostic Tool
    Command Prompt

  • Select Command Prompt
  • In the command window type in notepad and press Enter.
  • The notepad opens. Under File menu select Open.
  • Select "Computer" and find your flash drive letter and close the notepad.
  • In the command window type e:\frst64) and press Enter

    Note: Replace letter e with the drive letter of your flash drive.
  • The tool will start to run.
  • When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.
Hi oldman960 - just fyi I am still working this, will update soon. I never had a Win 7 disk and can't seem to get there from my BIOS, so am researching alternate methods…
Hi gdubb85, To enter the System Recovery Options from the Advanced Boot Options you don't need to go through the bios. Just press F8 onreboot untill the Advanced Boot Options screen appears.
Here is the log: Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 07-10-2012 Ran by [removed] at 11-10-2012 17:00:05 Running from H:\ Windows 7 Home Premium (X64) OS Language: English(US) The current controlset is ControlSet001 ==================== Registry (Whitelisted) =================== HKLM-x32\…\Run: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard) HKLM-x32\…\Run: [Mobile Connectivity Suite] "C:\Program Files (x86)\HTC\HTC Sync\Application Launcher\Application Launcher.exe" /startoptions [598016 2009-11-19] (Teleca Sweden AB) HKLM-x32\…\Run: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe" [2596984 2012-07-30] (AVG Technologies CZ, s.r.o.) HKLM-x32\…\Run: [BYRUA_AGENT] C:\ProgramData\LGMOBILEAX\BYR_Client\VZWUAAgent.exe [380024 2012-09-24] (LG Electronics) HKLM-x32\…\Run: [] [x] HKLM-x32\…\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [38872 2012-07-31] (Adobe Systems Incorporated) HKLM-x32\…\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [919008 2012-07-11] (Adobe Systems Incorporated) HKU\Default\…\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [1685048 2009-09-29] (Hewlett-Packard) HKU\Default User\…\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [1685048 2009-09-29] (Hewlett-Packard) HKU\GDuBB\…\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [5664640 2012-09-25] (SUPERAntiSpyware.com) HKU\GDuBB\…\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [3478336 2012-01-24] (DT Soft Ltd) HKU\GDuBB\…\Run: [KSS] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe" /autorun [202296 2012-04-25] (Kaspersky Lab ZAO) HKU\GDuBB\…\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe [427520 2009-07-13] (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Startup: C:\Users\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\hp\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) ==================== Services (Whitelisted) =================== 2 !SASCORE; "C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE" [140672 2012-09-07] (SUPERAntiSpyware.com) 2 Apache2.2; "C:\xampp\apache\bin\httpd.exe" -k runservice [29416 2009-12-19] (Apache Software Foundation) 2 AVGIDSAgent; "C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe" [5167736 2012-08-12] (AVG Technologies CZ, s.r.o.) 2 avgwd; "C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe" [193288 2012-02-14] (AVG Technologies CZ, s.r.o.) 2 KSS; "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe" -r [202296 2012-04-25] (Kaspersky Lab ZAO) 2 MySQL; "C:\xampp\mysql\bin\mysqld.exe" –defaults-file="C:\xampp\mysql\bin\my.ini" MySQL [5635 2012-10-07] () ==================== Drivers (Whitelisted) ===================== 0 09517212; C:\Windows\System32\Drivers\09517212.sys [460888 2012-09-26] (Kaspersky Lab ZAO) 3 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [124496 2011-12-23] (AVG Technologies CZ, s.r.o. ) 3 AVGIDSFilter; C:\Windows\System32\DRIVERS\avgidsfiltera.sys [29776 2011-12-23] (AVG Technologies CZ, s.r.o. ) 0 AVGIDSHA; C:\Windows\System32\Drivers\AVGIDSHA.sys [28480 2012-04-19] (AVG Technologies CZ, s.r.o. ) 1 Avgldx64; C:\Windows\System32\Drivers\Avgldx64.sys [291680 2012-07-25] (AVG Technologies CZ, s.r.o.) 1 Avgmfx64; C:\Windows\System32\Drivers\Avgmfx64.sys [47696 2011-12-23] (AVG Technologies CZ, s.r.o.) 0 Avgrkx64; C:\Windows\System32\Drivers\Avgrkx64.sys [36944 2012-01-31] (AVG Technologies CZ, s.r.o.) 1 Avgtdia; C:\Windows\System32\Drivers\Avgtdia.sys [384352 2012-08-24] (AVG Technologies CZ, s.r.o.) 1 dtsoftbus01; C:\Windows\System32\Drivers\dtsoftbus01.sys [283200 2012-02-12] (DT Soft Ltd) 3 Razerlow; C:\Windows\System32\Drivers\Razerlow.sys [21120 2005-11-07] (Razer (Asia-Pacific) Pte Ltd) 1 SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) 1 SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) 3 usbbus; C:\Windows\System32\DRIVERS\lgx64bus.sys [17920 2011-02-13] (LG Electronics Inc.) 3 UsbDiag; C:\Windows\System32\DRIVERS\lgx64diag.sys [28160 2011-02-13] (LG Electronics Inc.) 3 USBModem; C:\Windows\System32\DRIVERS\lgx64modem.sys [34816 2011-02-13] (LG Electronics Inc.) 3 vzandnetadb; C:\Windows\System32\Drivers\lgvzandnetadb.sys [31744 2011-08-03] (Google Inc) 3 vzandnetdiag; C:\Windows\System32\DRIVERS\lgvzandnetdiag64.sys [29696 2011-08-03] (LG Electronics Inc.) 3 vzandnetmodem; C:\Windows\System32\DRIVERS\lgvzandnetmdm64.sys [36864 2011-08-03] (LG Electronics Inc.) 3 vzandnetndis; C:\Windows\System32\DRIVERS\lgvzandnetndis64.sys [90624 2011-08-03] (LG Electronics Inc.) 1 5602141drv; C:\Windows\System32\DRIVERS\5602141drv.sys [x] 3 catchme; \??\C:\ComboFix\catchme.sys [x] ==================== NetSvcs (Whitelisted) ==================== ==================== One Month Created Files and Folders ======== 2012-10-11 16:59 - 2012-10-11 16:59 - 00000000 ____D C:\FRST 2012-10-10 03:28 - 2012-10-10 03:28 - 01456397 ____A (Farbar) C:\Users\GDuBB\Downloads\FRST64.exe 2012-10-09 15:24 - 2012-08-31 10:19 - 01659760 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ntfs.sys 2012-10-09 15:24 - 2012-08-30 10:03 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe 2012-10-09 15:24 - 2012-08-30 09:12 - 03968880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2012-10-09 15:24 - 2012-08-30 09:12 - 03914096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2012-10-09 15:23 - 2012-09-14 11:19 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\tzres.dll 2012-10-09 15:23 - 2012-09-14 10:28 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2012-10-09 15:23 - 2012-08-24 10:05 - 00220160 ____A (Microsoft Corporation) C:\Windows\System32\wintrust.dll 2012-10-09 15:23 - 2012-08-24 08:57 - 00172544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2012-10-09 15:23 - 2012-08-20 10:48 - 01162240 ____A (Microsoft Corporation) C:\Windows\System32\kernel32.dll 2012-10-09 15:23 - 2012-08-20 10:48 - 00424448 ____A (Microsoft Corporation) C:\Windows\System32\KernelBase.dll 2012-10-09 15:23 - 2012-08-20 10:48 - 00362496 ____A (Microsoft Corporation) C:\Windows\System32\wow64win.dll 2012-10-09 15:23 - 2012-08-20 10:48 - 00243200 ____A (Microsoft Corporation) C:\Windows\System32\wow64.dll 2012-10-09 15:23 - 2012-08-20 10:48 - 00215040 ____A (Microsoft Corporation) C:\Windows\System32\winsrv.dll 2012-10-09 15:23 - 2012-08-20 10:48 - 00016384 ____A (Microsoft Corporation) C:\Windows\System32\ntvdm64.dll 2012-10-09 15:23 - 2012-08-20 10:48 - 00013312 ____A (Microsoft Corporation) C:\Windows\System32\wow64cpu.dll 2012-10-09 15:23 - 2012-08-20 10:46 - 00338432 ____A (Microsoft Corporation) C:\Windows\System32\conhost.exe 2012-10-09 15:23 - 2012-08-20 10:38 - 00006144 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 10:38 - 00005120 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 10:38 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 10:38 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 10:38 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 10:38 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 10:38 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 10:38 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 10:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 10:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 10:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 10:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 10:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 10:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 10:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 10:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 10:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 10:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 10:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 10:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 10:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 10:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 10:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 10:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 10:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 10:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 10:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 10:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 09:40 - 00014336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2012-10-09 15:23 - 2012-08-20 09:38 - 00025600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2012-10-09 15:23 - 2012-08-20 09:37 - 01114112 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2012-10-09 15:23 - 2012-08-20 09:37 - 00274944 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2012-10-09 15:23 - 2012-08-20 09:37 - 00005120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2012-10-09 15:23 - 2012-08-20 09:32 - 00005120 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 09:32 - 00004608 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 09:32 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 09:32 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 09:32 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 09:32 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 09:32 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 09:32 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 09:32 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 09:32 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 09:32 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 09:32 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 09:32 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 09:32 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 09:32 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 09:32 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 09:32 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 09:32 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 09:32 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 09:32 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 09:32 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 09:32 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 09:32 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 09:32 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 07:38 - 00007680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2012-10-09 15:23 - 2012-08-20 07:38 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2012-10-09 15:23 - 2012-08-20 07:33 - 00006144 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 07:33 - 00004608 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 07:33 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2012-10-09 15:23 - 2012-08-20 07:33 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2012-10-09 15:23 - 2012-08-10 16:56 - 00715776 ____A (Microsoft Corporation) C:\Windows\System32\kerberos.dll 2012-10-09 15:23 - 2012-08-10 15:56 - 00542208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2012-10-09 15:23 - 2012-06-01 21:41 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll 2012-10-09 15:23 - 2012-06-01 21:41 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll 2012-10-09 15:23 - 2012-06-01 21:41 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll 2012-10-09 15:23 - 2012-06-01 20:36 - 01159680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2012-10-09 15:23 - 2012-06-01 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2012-10-09 15:23 - 2012-06-01 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2012-10-09 15:10 - 2012-10-09 15:10 - 00000505 ____A C:\Users\GDuBB\Downloads\MyTicketsNow.xml 2012-10-07 15:46 - 2012-10-07 15:47 - 00001454 ____A C:\Users\GDuBB\Desktop\XAMPP Control Panel.lnk 2012-10-07 15:42 - 2009-12-19 20:00 - 00000000 ___AD C:\xampp 2012-10-07 15:41 - 2012-10-07 15:41 - 53670736 ____A (Apache Friends) C:\Users\GDuBB\Downloads\xampp-win32-1.7.3.exe 2012-10-07 08:17 - 2012-10-07 08:17 - 02002153 ____A C:\Users\GDuBB\Downloads\Flurry Android SDK vAndroid 3.0.2(2).zip 2012-10-07 06:59 - 2012-10-07 06:59 - 00022154 ____A C:\ComboFix.txt 2012-10-07 06:47 - 2012-10-07 06:59 - 00000000 ____D C:\Qoobox 2012-10-07 06:47 - 2012-10-07 06:59 - 00000000 ____D C:\ComboFix 2012-10-07 06:47 - 2012-10-07 06:57 - 00000000 ____D C:\Windows\erdnt 2012-10-07 06:47 - 2011-06-25 22:45 - 00256000 ____A C:\Windows\PEV.exe 2012-10-07 06:47 - 2010-11-07 09:20 - 00208896 ____A C:\Windows\MBR.exe 2012-10-07 06:47 - 2009-04-19 20:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe 2012-10-07 06:47 - 2000-08-30 16:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe 2012-10-07 06:47 - 2000-08-30 16:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe 2012-10-07 06:47 - 2000-08-30 16:00 - 00098816 ____A C:\Windows\sed.exe 2012-10-07 06:47 - 2000-08-30 16:00 - 00080412 ____A C:\Windows\grep.exe 2012-10-07 06:47 - 2000-08-30 16:00 - 00068096 ____A C:\Windows\zip.exe 2012-10-07 06:45 - 2012-10-07 06:45 - 04762471 ____R (Swearware) C:\Users\GDuBB\Desktop\ComboFix.exe 2012-10-06 05:41 - 2012-10-06 05:41 - 02005402 ____A C:\Users\GDuBB\Downloads\Flurry Android SDK vAndroid 3.0.2(1).zip 2012-10-06 05:27 - 2012-10-06 05:27 - 02005219 ____A C:\Users\GDuBB\Downloads\Flurry Android SDK vAndroid 3.0.2.zip 2012-10-05 15:07 - 2012-10-05 15:07 - 00031364 ____A C:\Users\GDuBB\.recently-used.xbel 2012-10-05 13:48 - 2012-10-05 13:48 - 00001753 ____A C:\Users\GDuBB\Desktop\aswMBR.txt 2012-10-05 13:48 - 2012-10-05 13:48 - 00000528 ____A C:\Users\GDuBB\Desktop\MBR.zip 2012-10-05 13:48 - 2012-10-05 13:48 - 00000512 ____A C:\Users\GDuBB\Desktop\MBR.dat 2012-10-04 03:40 - 2012-10-04 03:40 - 00299112 ____A C:\Windows\Minidump\100412-32011-01.dmp 2012-10-03 17:32 - 2012-10-03 17:33 - 04731392 ____A (AVAST Software) C:\Users\GDuBB\Desktop\aswMBR.exe 2012-10-01 18:00 - 2012-10-01 18:00 - 00000000 ____D C:\Users\GDuBB\Desktop\Nicole_Sharts 2012-09-30 08:48 - 2012-09-30 08:48 - 00085490 ____A C:\Users\GDuBB\Desktop\Extras.Txt 2012-09-30 08:47 - 2012-09-30 08:47 - 00177898 ____A C:\Users\GDuBB\Desktop\OTL.Txt 2012-09-30 08:10 - 2012-09-30 08:10 - 00602112 ____A (OldTimer Tools) C:\Users\GDuBB\Desktop\OTL.exe 2012-09-28 05:12 - 2012-09-28 05:12 - 00043625 ____A C:\Users\GDuBB\Downloads\customcode-0.5.0.jar 2012-09-28 04:51 - 2012-09-28 04:51 - 00000000 ____D C:\Users\GDuBB\AppData\Local\MFAData 2012-09-28 04:51 - 2012-09-28 04:51 - 00000000 ____D C:\Users\GDuBB\AppData\Local\Avg2013 2012-09-27 19:25 - 2012-09-27 19:29 - 00000060 ____A C:\gregggg.txt 2012-09-27 19:21 - 2012-09-27 19:21 - 00000060 ____A C:\out.txt 2012-09-27 17:16 - 2012-09-27 17:16 - 00000128 ____A C:\Users\GDuBB\Desktop\Start OAuth Proxy.bat 2012-09-27 16:50 - 2012-09-27 16:51 - 00000000 ____D C:\Python27 2012-09-27 16:26 - 2012-09-27 16:28 - 45018112 ____A C:\Users\GDuBB\Downloads\ActivePython-2.7.2.5-win64-x64.msi 2012-09-27 16:09 - 2012-10-11 12:56 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2012-09-27 15:11 - 2012-09-27 15:23 - 00000000 ____D C:\Windows\pss 2012-09-27 03:19 - 2012-09-27 03:20 - 154494672 ____A (Kaspersky Lab) C:\Users\GDuBB\Downloads\kav13.0.1.4190en(1).exe 2012-09-27 03:14 - 2012-09-27 03:14 - 00096454 ____A C:\Users\GDuBB\Desktop\virus_report.html 2012-09-27 03:14 - 2012-09-27 03:14 - 00000000 ____D C:\Users\GDuBB\Desktop\virus_report_files 2012-09-26 23:39 - 2012-09-27 10:08 - 00000000 ___AD C:\Kaspersky Rescue Disk 10.0 2012-09-26 19:40 - 2012-09-26 06:53 - 00460888 ____A (Kaspersky Lab ZAO) C:\Windows\System32\Drivers\09517212.sys 2012-09-26 19:36 - 2012-09-26 19:58 - 153466374 ____A (Kaspersky Lab) C:\Users\GDuBB\Downloads\kav13.0.1.4190en.exe 2012-09-26 19:35 - 2012-09-26 19:36 - 137128792 ____A C:\Users\GDuBB\Downloads\setup_11.0.0.1245.x01_2012_09_26_10_53.exe 2012-09-26 15:38 - 2012-09-26 15:38 - 00000000 ____D C:\Users\GDuBB\AppData\Roaming\RoboForm 2012-09-26 15:36 - 2012-09-26 15:36 - 00000000 ____D C:\Users\GDuBB\Documents\My Avast EasyPass Data 2012-09-26 15:36 - 2012-09-26 15:36 - 00000000 ____D C:\Users\All Users\RoboForm 2012-09-26 15:35 - 2012-09-29 06:27 - 00000000 ____A C:\Windows\SysWOW64\config.nt 2012-09-26 15:35 - 2012-08-21 01:12 - 00285328 ____A (AVAST Software) C:\Windows\System32\aswBoot.exe 2012-09-26 15:34 - 2012-10-01 16:20 - 00000000 ____D C:\Users\All Users\AVAST Software 2012-09-26 15:34 - 2012-09-26 15:34 - 00000000 ____D C:\Program Files\AVAST Software 2012-09-26 15:32 - 2012-09-26 15:32 - 93654616 ____A C:\Users\GDuBB\Downloads\avast_free_antivirus_setup.exe 2012-09-26 15:32 - 2012-09-26 15:32 - 00000000 ____D C:\Users\GDuBB\AppData\Roaming\Malwarebytes 2012-09-26 15:32 - 2012-09-26 15:32 - 00000000 ____D C:\Users\All Users\Malwarebytes 2012-09-26 15:32 - 2012-09-26 15:31 - 00001043 ____A C:\Users\GDuBB\Desktop\Kaspersky Security Scan.lnk 2012-09-26 15:31 - 2012-10-01 16:08 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab 2012-09-26 15:31 - 2012-09-26 15:31 - 10524080 ____A (Malwarebytes Corporation ) C:\Users\GDuBB\Downloads\mbam-setup-1.65.0.1400.exe 2012-09-26 15:29 - 2012-09-26 15:29 - 00180000 ____A (Kaspersky Lab) C:\Users\GDuBB\Downloads\kss12.0.1.117EN_RU_DE_FR_2926.exe 2012-09-26 15:23 - 2012-08-21 13:01 - 00245760 ____A (Microsoft Corporation) C:\Windows\System32\OxpsConverter.exe 2012-09-26 14:46 - 2012-10-01 16:20 - 00000000 ____D C:\Users\All Users\Kaspersky Lab 2012-09-25 17:43 - 2012-09-25 17:43 - 00000000 ____D C:\Users\GDuBB\AppData\Roaming\Python 2012-09-21 23:02 - 2012-08-24 03:15 - 17810944 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-09-21 23:02 - 2012-08-24 02:39 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-09-21 23:02 - 2012-08-24 02:31 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2012-09-21 23:02 - 2012-08-24 02:22 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-09-21 23:02 - 2012-08-24 02:21 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-09-21 23:02 - 2012-08-24 02:20 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2012-09-21 23:02 - 2012-08-24 02:18 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-09-21 23:02 - 2012-08-24 02:17 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-09-21 23:02 - 2012-08-24 02:14 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-09-21 23:02 - 2012-08-24 02:14 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2012-09-21 23:02 - 2012-08-24 02:13 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2012-09-21 23:02 - 2012-08-24 02:12 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-09-21 23:02 - 2012-08-24 02:11 - 00729088 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2012-09-21 23:02 - 2012-08-24 02:10 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-09-21 23:02 - 2012-08-24 02:09 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2012-09-21 23:02 - 2012-08-24 02:04 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2012-09-21 23:02 - 2012-08-23 23:27 - 12319744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2012-09-21 23:02 - 2012-08-23 23:03 - 09738240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2012-09-21 23:02 - 2012-08-23 22:59 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2012-09-21 23:02 - 2012-08-23 22:51 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2012-09-21 23:02 - 2012-08-23 22:51 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2012-09-21 23:02 - 2012-08-23 22:51 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2012-09-21 23:02 - 2012-08-23 22:49 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2012-09-21 23:02 - 2012-08-23 22:48 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2012-09-21 23:02 - 2012-08-23 22:47 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2012-09-21 23:02 - 2012-08-23 22:47 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2012-09-21 23:02 - 2012-08-23 22:47 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2012-09-21 23:02 - 2012-08-23 22:45 - 00607744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2012-09-21 23:02 - 2012-08-23 22:44 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2012-09-21 23:02 - 2012-08-23 22:44 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2012-09-21 23:02 - 2012-08-23 22:43 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2012-09-21 23:02 - 2012-08-23 22:40 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2012-09-20 15:16 - 2012-09-20 15:16 - 03439640 ____A C:\Users\GDuBB\Downloads\httpcomponents-client-4.2.1-bin.zip 2012-09-18 17:23 - 2012-09-30 16:59 - 00000000 ____D C:\Users\GDuBB\Dog Walking 2012-09-18 17:12 - 2012-09-18 17:12 - 00048102 ____A C:\Users\GDuBB\Downloads\steelfish.zip 2012-09-18 17:11 - 2012-09-18 17:11 - 00017500 ____A C:\Users\GDuBB\Downloads\droid.zip 2012-09-18 15:50 - 2012-09-18 15:50 - 00347576 ____A C:\Users\GDuBB\Downloads\TapjoyVirtualGoodsSDK_Android_v8.3.0.zip 2012-09-18 15:50 - 2012-09-18 15:50 - 00106748 ____A C:\Users\GDuBB\Downloads\TapjoyConnectSDK_Android_v8.3.0(1).zip 2012-09-18 15:47 - 2012-09-18 15:47 - 00106748 ____A C:\Users\GDuBB\Downloads\TapjoyConnectSDK_Android_v8.3.0.zip 2012-09-18 15:26 - 2012-09-26 15:15 - 00000000 ____D C:\Users\GDuBB\Downloads\TapjoyPublisherSDK_Android_v8.3.0 2012-09-18 15:24 - 2012-09-18 15:24 - 00344248 ____A C:\Users\GDuBB\Downloads\TapjoyPublisherSDK_Android_v8.3.0.zip 2012-09-17 14:27 - 2012-09-17 14:27 - 00142558 ____A C:\Users\GDuBB\Downloads\stackmob-stackmob-java-client-sdk-stackmob-java-client-sdk-1.0.0-5-g793523f(1).zip 2012-09-17 14:05 - 2012-09-17 14:05 - 00142558 ____A C:\Users\GDuBB\Downloads\stackmob-stackmob-java-client-sdk-stackmob-java-client-sdk-1.0.0-5-g793523f.zip 2012-09-16 10:32 - 2012-09-16 10:32 - 00023737 ____A C:\Users\GDuBB\Downloads\json-simple-1.1.1.jar 2012-09-14 12:22 - 2012-09-14 12:22 - 00000000 ____D C:\Program Files\apache-maven-3.0.4 2012-09-14 12:20 - 2012-09-26 15:15 - 00000000 ____D C:\Users\GDuBB\Downloads\apache-maven-3.0.4-bin 2012-09-14 12:20 - 2012-09-14 12:20 - 04889768 ____A C:\Users\GDuBB\Downloads\apache-maven-3.0.4-bin.zip 2012-09-13 14:40 - 2012-09-13 14:40 - 00030085 ____A C:\Users\GDuBB\Downloads\commons-codec-1.2.jar 2012-09-13 14:40 - 2012-09-13 14:40 - 00030085 ____A C:\Users\GDuBB\Downloads\commons-codec-1.2(1).jar 2012-09-13 11:30 - 2012-09-13 11:30 - 00739808 ____A (Google Inc.) C:\Users\GDuBB\Downloads\musicmanagerinstaller.exe 2012-09-11 16:01 - 2012-08-22 10:12 - 01913200 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys 2012-09-11 16:01 - 2012-08-22 10:12 - 00950128 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndis.sys 2012-09-11 16:01 - 2012-08-22 10:12 - 00376688 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\netio.sys 2012-09-11 16:01 - 2012-08-22 10:12 - 00288624 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\FWPKCLNT.SYS 2012-09-11 16:01 - 2012-08-02 09:58 - 00574464 ____A (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll 2012-09-11 16:01 - 2012-08-02 08:57 - 00490496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll 2012-09-11 16:01 - 2012-07-04 12:26 - 00041472 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\RNDISMP.sys ==================== 3 Months Modified Files ================== 2012-10-11 12:57 - 2010-07-25 06:48 - 00000856 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1727114255-2402910526-3703745838-1000Core.job 2012-10-11 12:57 - 2010-07-24 16:55 - 02048469 ____A C:\Windows\WindowsUpdate.log 2012-10-11 12:56 - 2012-09-27 16:09 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2012-10-11 12:56 - 2010-07-25 06:48 - 00000908 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1727114255-2402910526-3703745838-1000UA.job 2012-10-10 15:27 - 2009-07-13 20:45 - 00015792 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2012-10-10 15:27 - 2009-07-13 20:45 - 00015792 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2012-10-10 15:20 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2012-10-10 15:20 - 2009-07-13 20:51 - 00062685 ____A C:\Windows\setupact.log 2012-10-10 14:34 - 2010-07-25 06:48 - 00002495 ____A C:\Users\GDuBB\Desktop\Google Chrome.lnk 2012-10-10 03:28 - 2012-10-10 03:28 - 01456397 ____A (Farbar) C:\Users\GDuBB\Downloads\FRST64.exe 2012-10-10 03:26 - 2012-02-12 13:13 - 00001980 ____A C:\Users\Public\Desktop\Adobe Reader 9.lnk 2012-10-09 23:27 - 2002-01-01 01:02 - 00289460 ____A C:\Windows\PFRO.log 2012-10-09 23:05 - 2010-08-20 10:03 - 65309168 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2012-10-09 15:10 - 2012-10-09 15:10 - 00000505 ____A C:\Users\GDuBB\Downloads\MyTicketsNow.xml 2012-10-08 15:53 - 2012-04-12 03:24 - 00696760 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2012-10-08 15:53 - 2011-05-22 10:26 - 00073656 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2012-10-07 15:47 - 2012-10-07 15:46 - 00001454 ____A C:\Users\GDuBB\Desktop\XAMPP Control Panel.lnk 2012-10-07 15:41 - 2012-10-07 15:41 - 53670736 ____A (Apache Friends) C:\Users\GDuBB\Downloads\xampp-win32-1.7.3.exe 2012-10-07 08:17 - 2012-10-07 08:17 - 02002153 ____A C:\Users\GDuBB\Downloads\Flurry Android SDK vAndroid 3.0.2(2).zip 2012-10-07 06:59 - 2012-10-07 06:59 - 00022154 ____A C:\ComboFix.txt 2012-10-07 06:56 - 2009-07-13 18:34 - 00000215 ____A C:\Windows\system.ini 2012-10-07 06:45 - 2012-10-07 06:45 - 04762471 ____R (Swearware) C:\Users\GDuBB\Desktop\ComboFix.exe 2012-10-06 05:41 - 2012-10-06 05:41 - 02005402 ____A C:\Users\GDuBB\Downloads\Flurry Android SDK vAndroid 3.0.2(1).zip 2012-10-06 05:27 - 2012-10-06 05:27 - 02005219 ____A C:\Users\GDuBB\Downloads\Flurry Android SDK vAndroid 3.0.2.zip 2012-10-05 15:07 - 2012-10-05 15:07 - 00031364 ____A C:\Users\GDuBB\.recently-used.xbel 2012-10-05 15:01 - 2010-11-28 17:06 - 00007603 ____A C:\Users\GDuBB\AppData\Local\Resmon.ResmonCfg 2012-10-05 13:48 - 2012-10-05 13:48 - 00001753 ____A C:\Users\GDuBB\Desktop\aswMBR.txt 2012-10-05 13:48 - 2012-10-05 13:48 - 00000528 ____A C:\Users\GDuBB\Desktop\MBR.zip 2012-10-05 13:48 - 2012-10-05 13:48 - 00000512 ____A C:\Users\GDuBB\Desktop\MBR.dat 2012-10-04 03:40 - 2012-10-04 03:40 - 00299112 ____A C:\Windows\Minidump\100412-32011-01.dmp 2012-10-04 03:40 - 2012-02-19 16:08 - 556347578 ____A C:\Windows\MEMORY.DMP 2012-10-03 17:33 - 2012-10-03 17:32 - 04731392 ____A (AVAST Software) C:\Users\GDuBB\Desktop\aswMBR.exe 2012-09-30 08:48 - 2012-09-30 08:48 - 00085490 ____A C:\Users\GDuBB\Desktop\Extras.Txt 2012-09-30 08:47 - 2012-09-30 08:47 - 00177898 ____A C:\Users\GDuBB\Desktop\OTL.Txt 2012-09-30 08:10 - 2012-09-30 08:10 - 00602112 ____A (OldTimer Tools) C:\Users\GDuBB\Desktop\OTL.exe 2012-09-29 06:27 - 2012-09-26 15:35 - 00000000 ____A C:\Windows\SysWOW64\config.nt 2012-09-28 05:12 - 2012-09-28 05:12 - 00043625 ____A C:\Users\GDuBB\Downloads\customcode-0.5.0.jar 2012-09-27 19:29 - 2012-09-27 19:25 - 00000060 ____A C:\gregggg.txt 2012-09-27 19:21 - 2012-09-27 19:21 - 00000060 ____A C:\out.txt 2012-09-27 17:16 - 2012-09-27 17:16 - 00000128 ____A C:\Users\GDuBB\Desktop\Start OAuth Proxy.bat 2012-09-27 16:34 - 2011-12-09 11:16 - 00000260 ____A C:\Windows\SysWOW64\cmdVBS.vbs 2012-09-27 16:34 - 2011-12-09 11:16 - 00000256 ____A C:\Windows\SysWOW64\MSIevent.bat 2012-09-27 16:34 - 2011-07-14 18:11 - 00004167 ____A C:\Users\All Users\hpzinstall.log 2012-09-27 16:28 - 2012-09-27 16:26 - 45018112 ____A C:\Users\GDuBB\Downloads\ActivePython-2.7.2.5-win64-x64.msi 2012-09-27 03:20 - 2012-09-27 03:19 - 154494672 ____A (Kaspersky Lab) C:\Users\GDuBB\Downloads\kav13.0.1.4190en(1).exe 2012-09-27 03:14 - 2012-09-27 03:14 - 00096454 ____A C:\Users\GDuBB\Desktop\virus_report.html 2012-09-26 19:58 - 2012-09-26 19:36 - 153466374 ____A (Kaspersky Lab) C:\Users\GDuBB\Downloads\kav13.0.1.4190en.exe 2012-09-26 19:36 - 2012-09-26 19:35 - 137128792 ____A C:\Users\GDuBB\Downloads\setup_11.0.0.1245.x01_2012_09_26_10_53.exe 2012-09-26 15:32 - 2012-09-26 15:32 - 93654616 ____A C:\Users\GDuBB\Downloads\avast_free_antivirus_setup.exe 2012-09-26 15:31 - 2012-09-26 15:32 - 00001043 ____A C:\Users\GDuBB\Desktop\Kaspersky Security Scan.lnk 2012-09-26 15:31 - 2012-09-26 15:31 - 10524080 ____A (Malwarebytes Corporation ) C:\Users\GDuBB\Downloads\mbam-setup-1.65.0.1400.exe 2012-09-26 15:29 - 2012-09-26 15:29 - 00180000 ____A (Kaspersky Lab) C:\Users\GDuBB\Downloads\kss12.0.1.117EN_RU_DE_FR_2926.exe 2012-09-26 06:53 - 2012-09-26 19:40 - 00460888 ____A (Kaspersky Lab ZAO) C:\Windows\System32\Drivers\09517212.sys 2012-09-22 06:13 - 2011-10-23 07:55 - 00002427 ____A C:\Windows\SysWOW64\lgAxconfig.ini 2012-09-21 23:21 - 2009-07-13 20:45 - 00391464 ____A C:\Windows\System32\FNTCACHE.DAT 2012-09-20 15:16 - 2012-09-20 15:16 - 03439640 ____A C:\Users\GDuBB\Downloads\httpcomponents-client-4.2.1-bin.zip 2012-09-19 16:50 - 2010-07-24 16:56 - 00100584 ____A C:\Users\GDuBB\AppData\Local\GDIPFONTCACHEV1.DAT 2012-09-18 17:12 - 2012-09-18 17:12 - 00048102 ____A C:\Users\GDuBB\Downloads\steelfish.zip 2012-09-18 17:11 - 2012-09-18 17:11 - 00017500 ____A C:\Users\GDuBB\Downloads\droid.zip 2012-09-18 15:50 - 2012-09-18 15:50 - 00347576 ____A C:\Users\GDuBB\Downloads\TapjoyVirtualGoodsSDK_Android_v8.3.0.zip 2012-09-18 15:50 - 2012-09-18 15:50 - 00106748 ____A C:\Users\GDuBB\Downloads\TapjoyConnectSDK_Android_v8.3.0(1).zip 2012-09-18 15:47 - 2012-09-18 15:47 - 00106748 ____A C:\Users\GDuBB\Downloads\TapjoyConnectSDK_Android_v8.3.0.zip 2012-09-18 15:24 - 2012-09-18 15:24 - 00344248 ____A C:\Users\GDuBB\Downloads\TapjoyPublisherSDK_Android_v8.3.0.zip 2012-09-17 14:27 - 2012-09-17 14:27 - 00142558 ____A C:\Users\GDuBB\Downloads\stackmob-stackmob-java-client-sdk-stackmob-java-client-sdk-1.0.0-5-g793523f(1).zip 2012-09-17 14:05 - 2012-09-17 14:05 - 00142558 ____A C:\Users\GDuBB\Downloads\stackmob-stackmob-java-client-sdk-stackmob-java-client-sdk-1.0.0-5-g793523f.zip 2012-09-16 10:32 - 2012-09-16 10:32 - 00023737 ____A C:\Users\GDuBB\Downloads\json-simple-1.1.1.jar 2012-09-14 12:20 - 2012-09-14 12:20 - 04889768 ____A C:\Users\GDuBB\Downloads\apache-maven-3.0.4-bin.zip 2012-09-14 11:19 - 2012-10-09 15:23 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\tzres.dll 2012-09-14 10:28 - 2012-10-09 15:23 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2012-09-13 14:40 - 2012-09-13 14:40 - 00030085 ____A C:\Users\GDuBB\Downloads\commons-codec-1.2.jar 2012-09-13 14:40 - 2012-09-13 14:40 - 00030085 ____A C:\Users\GDuBB\Downloads\commons-codec-1.2(1).jar 2012-09-13 11:30 - 2012-09-13 11:30 - 00739808 ____A (Google Inc.) C:\Users\GDuBB\Downloads\musicmanagerinstaller.exe 2012-09-11 15:56 - 2011-09-30 12:19 - 00000931 ____A C:\Users\Public\Desktop\AVG 2012.lnk 2012-09-09 14:15 - 2010-10-21 15:29 - 00001676 ____A C:\Users\GDuBB\AppData\Roaming\wklnhst.dat 2012-08-31 10:19 - 2012-10-09 15:24 - 01659760 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ntfs.sys 2012-08-30 10:03 - 2012-10-09 15:24 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe 2012-08-30 09:12 - 2012-10-09 15:24 - 03968880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2012-08-30 09:12 - 2012-10-09 15:24 - 03914096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2012-08-27 16:08 - 2012-08-27 16:08 - 00846074 ____A C:\Users\GDuBB\Downloads\AndroidSDK_MMAdview_4.6.0.zip 2012-08-27 16:04 - 2012-08-27 16:04 - 00044427 ____A C:\Users\GDuBB\Downloads\lb_android_sdk_xapp_v3.06.zip 2012-08-27 16:02 - 2012-08-27 15:15 - 00515963 ____A C:\Users\GDuBB\Downloads\com-BfavNRIT-uCgdXhYv94545.zip 2012-08-27 16:01 - 2012-08-27 16:01 - 00841023 ____A C:\Users\GDuBB\Downloads\StartApp SDK 1.0.17.zip 2012-08-26 09:15 - 2012-08-26 09:15 - 00292008 ____A C:\Users\GDuBB\Downloads\AirpushSDK_26Aug_2012.zip 2012-08-24 11:43 - 2012-08-24 11:43 - 00384352 ____A (AVG Technologies CZ, s.r.o.) C:\Windows\System32\Drivers\avgtdia.sys 2012-08-24 10:05 - 2012-10-09 15:23 - 00220160 ____A (Microsoft Corporation) C:\Windows\System32\wintrust.dll 2012-08-24 08:57 - 2012-10-09 15:23 - 00172544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2012-08-24 03:15 - 2012-09-21 23:02 - 17810944 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-08-24 02:39 - 2012-09-21 23:02 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-08-24 02:31 - 2012-09-21 23:02 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2012-08-24 02:22 - 2012-09-21 23:02 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-08-24 02:21 - 2012-09-21 23:02 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-08-24 02:20 - 2012-09-21 23:02 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2012-08-24 02:18 - 2012-09-21 23:02 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-08-24 02:17 - 2012-09-21 23:02 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-08-24 02:14 - 2012-09-21 23:02 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-08-24 02:14 - 2012-09-21 23:02 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2012-08-24 02:13 - 2012-09-21 23:02 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2012-08-24 02:12 - 2012-09-21 23:02 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-08-24 02:11 - 2012-09-21 23:02 - 00729088 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2012-08-24 02:10 - 2012-09-21 23:02 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-08-24 02:09 - 2012-09-21 23:02 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2012-08-24 02:04 - 2012-09-21 23:02 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2012-08-23 23:27 - 2012-09-21 23:02 - 12319744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2012-08-23 23:03 - 2012-09-21 23:02 - 09738240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2012-08-23 22:59 - 2012-09-21 23:02 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2012-08-23 22:51 - 2012-09-21 23:02 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2012-08-23 22:51 - 2012-09-21 23:02 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2012-08-23 22:51 - 2012-09-21 23:02 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2012-08-23 22:49 - 2012-09-21 23:02 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2012-08-23 22:48 - 2012-09-21 23:02 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2012-08-23 22:47 - 2012-09-21 23:02 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2012-08-23 22:47 - 2012-09-21 23:02 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2012-08-23 22:47 - 2012-09-21 23:02 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2012-08-23 22:45 - 2012-09-21 23:02 - 00607744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2012-08-23 22:44 - 2012-09-21 23:02 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2012-08-23 22:44 - 2012-09-21 23:02 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2012-08-23 22:43 - 2012-09-21 23:02 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2012-08-23 22:40 - 2012-09-21 23:02 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2012-08-23 16:55 - 2012-08-23 16:55 - 10138219 ____A C:\Users\GDuBB\Desktop\JInstaller_1.4.8_win_x64.exe 2012-08-22 10:12 - 2012-09-11 16:01 - 01913200 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys 2012-08-22 10:12 - 2012-09-11 16:01 - 00950128 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndis.sys 2012-08-22 10:12 - 2012-09-11 16:01 - 00376688 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\netio.sys 2012-08-22 10:12 - 2012-09-11 16:01 - 00288624 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\FWPKCLNT.SYS 2012-08-21 13:01 - 2012-09-26 15:23 - 00245760 ____A (Microsoft Corporation) C:\Windows\System32\OxpsConverter.exe 2012-08-21 01:12 - 2012-09-26 15:35 - 00285328 ____A (AVAST Software) C:\Windows\System32\aswBoot.exe 2012-08-20 10:48 - 2012-10-09 15:23 - 01162240 ____A (Microsoft Corporation) C:\Windows\System32\kernel32.dll 2012-08-20 10:48 - 2012-10-09 15:23 - 00424448 ____A (Microsoft Corporation) C:\Windows\System32\KernelBase.dll 2012-08-20 10:48 - 2012-10-09 15:23 - 00362496 ____A (Microsoft Corporation) C:\Windows\System32\wow64win.dll 2012-08-20 10:48 - 2012-10-09 15:23 - 00243200 ____A (Microsoft Corporation) C:\Windows\System32\wow64.dll 2012-08-20 10:48 - 2012-10-09 15:23 - 00215040 ____A (Microsoft Corporation) C:\Windows\System32\winsrv.dll 2012-08-20 10:48 - 2012-10-09 15:23 - 00016384 ____A (Microsoft Corporation) C:\Windows\System32\ntvdm64.dll 2012-08-20 10:48 - 2012-10-09 15:23 - 00013312 ____A (Microsoft Corporation) C:\Windows\System32\wow64cpu.dll 2012-08-20 10:46 - 2012-10-09 15:23 - 00338432 ____A (Microsoft Corporation) C:\Windows\System32\conhost.exe 2012-08-20 10:38 - 2012-10-09 15:23 - 00006144 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll 2012-08-20 10:38 - 2012-10-09 15:23 - 00005120 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll 2012-08-20 10:38 - 2012-10-09 15:23 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll 2012-08-20 10:38 - 2012-10-09 15:23 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll 2012-08-20 10:38 - 2012-10-09 15:23 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll 2012-08-20 10:38 - 2012-10-09 15:23 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll 2012-08-20 10:38 - 2012-10-09 15:23 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll 2012-08-20 10:38 - 2012-10-09 15:23 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll 2012-08-20 10:38 - 2012-10-09 15:23 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll 2012-08-20 10:38 - 2012-10-09 15:23 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll 2012-08-20 10:38 - 2012-10-09 15:23 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll 2012-08-20 10:38 - 2012-10-09 15:23 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll 2012-08-20 10:38 - 2012-10-09 15:23 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll 2012-08-20 10:38 - 2012-10-09 15:23 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll 2012-08-20 10:38 - 2012-10-09 15:23 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll 2012-08-20 10:38 - 2012-10-09 15:23 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll 2012-08-20 10:38 - 2012-10-09 15:23 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll 2012-08-20 10:38 - 2012-10-09 15:23 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll 2012-08-20 10:38 - 2012-10-09 15:23 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll 2012-08-20 10:38 - 2012-10-09 15:23 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll 2012-08-20 10:38 - 2012-10-09 15:23 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll 2012-08-20 10:38 - 2012-10-09 15:23 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll 2012-08-20 10:38 - 2012-10-09 15:23 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll 2012-08-20 10:38 - 2012-10-09 15:23 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll 2012-08-20 10:38 - 2012-10-09 15:23 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll 2012-08-20 10:38 - 2012-10-09 15:23 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll 2012-08-20 10:38 - 2012-10-09 15:23 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll 2012-08-20 10:38 - 2012-10-09 15:23 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll 2012-08-20 09:40 - 2012-10-09 15:23 - 00014336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2012-08-20 09:38 - 2012-10-09 15:23 - 00025600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2012-08-20 09:37 - 2012-10-09 15:23 - 01114112 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2012-08-20 09:37 - 2012-10-09 15:23 - 00274944 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2012-08-20 09:37 - 2012-10-09 15:23 - 00005120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2012-08-20 09:32 - 2012-10-09 15:23 - 00005120 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2012-08-20 09:32 - 2012-10-09 15:23 - 00004608 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2012-08-20 09:32 - 2012-10-09 15:23 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2012-08-20 09:32 - 2012-10-09 15:23 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2012-08-20 09:32 - 2012-10-09 15:23 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2012-08-20 09:32 - 2012-10-09 15:23 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2012-08-20 09:32 - 2012-10-09 15:23 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2012-08-20 09:32 - 2012-10-09 15:23 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2012-08-20 09:32 - 2012-10-09 15:23 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2012-08-20 09:32 - 2012-10-09 15:23 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2012-08-20 09:32 - 2012-10-09 15:23 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2012-08-20 09:32 - 2012-10-09 15:23 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2012-08-20 09:32 - 2012-10-09 15:23 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2012-08-20 09:32 - 2012-10-09 15:23 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2012-08-20 09:32 - 2012-10-09 15:23 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2012-08-20 09:32 - 2012-10-09 15:23 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2012-08-20 09:32 - 2012-10-09 15:23 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2012-08-20 09:32 - 2012-10-09 15:23 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2012-08-20 09:32 - 2012-10-09 15:23 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2012-08-20 09:32 - 2012-10-09 15:23 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2012-08-20 09:32 - 2012-10-09 15:23 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2012-08-20 09:32 - 2012-10-09 15:23 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2012-08-20 09:32 - 2012-10-09 15:23 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2012-08-20 09:32 - 2012-10-09 15:23 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2012-08-20 07:38 - 2012-10-09 15:23 - 00007680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2012-08-20 07:38 - 2012-10-09 15:23 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2012-08-20 07:33 - 2012-10-09 15:23 - 00006144 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2012-08-20 07:33 - 2012-10-09 15:23 - 00004608 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2012-08-20 07:33 - 2012-10-09 15:23 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2012-08-20 07:33 - 2012-10-09 15:23 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2012-08-19 09:53 - 2012-08-19 09:53 - 00056389 ____A C:\Users\GDuBB\Downloads\lb_android_sdk_v3.05.zip 2012-08-18 06:36 - 2012-08-18 06:36 - 00329575 ____A C:\Users\GDuBB\Downloads\TapjoyVirtualGoodsSDK_Android_v8.2.2.zip 2012-08-11 06:43 - 2012-08-11 06:43 - 00027520 ____A C:\Users\GDuBB\AppData\Local\dt.dat 2012-08-10 16:56 - 2012-10-09 15:23 - 00715776 ____A (Microsoft Corporation) C:\Windows\System32\kerberos.dll 2012-08-10 15:56 - 2012-10-09 15:23 - 00542208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2012-08-09 17:08 - 2012-08-09 17:08 - 16494710 ____A C:\Users\GDuBB\Downloads\PhysicsEditor-1.0.9-win32.exe 2012-08-09 17:05 - 2012-08-09 17:05 - 00177502 ____A C:\Users\GDuBB\Downloads\Icon-Robot.air 2012-08-09 17:05 - 2012-08-09 17:05 - 00000937 ____A C:\Users\Public\Desktop\Icon Robot Android.lnk 2012-08-09 17:05 - 2012-08-09 17:05 - 00000857 ____A C:\Users\Public\Desktop\Icon Robot.lnk 2012-08-09 17:04 - 2012-08-09 17:04 - 15201112 ____A (Adobe Systems Inc.) C:\Users\GDuBB\Downloads\AdobeAIRInstaller.exe 2012-08-09 17:04 - 2012-08-09 17:04 - 00152111 ____A C:\Users\GDuBB\Downloads\Icon-Robot-Android.air 2012-08-06 16:41 - 2012-08-05 08:15 - 00006148 ___AH C:\users\.DS_Store 2012-08-06 15:21 - 2012-08-06 15:21 - 00002707 ____A C:\Users\Public\Desktop\Corona Simulator.lnk 2012-08-05 08:19 - 2012-08-05 08:19 - 00519096 ____A C:\users\GDuBB alias 2012-08-03 15:27 - 2012-08-03 15:27 - 00001082 ____A C:\Users\Public\Desktop\Oracle VM VirtualBox.lnk 2012-08-03 15:25 - 2012-08-03 15:25 - 95228248 ____A (Oracle Corporation) C:\Users\GDuBB\Downloads\VirtualBox-4.1.18-78361-Win.exe 2012-08-03 12:48 - 2012-08-03 12:48 - 00002098 ____A C:\Users\Public\Desktop\VMware Player.lnk 2012-08-03 12:36 - 2012-08-03 12:36 - 00001024 ____A C:\.rnd 2012-08-03 10:43 - 2012-08-03 10:43 - 01409024 ____A C:\Users\GDuBB\Downloads\7z928-x64.msi 2012-08-03 09:59 - 2012-08-03 09:59 - 04270678 ____A C:\Users\GDuBB\Desktop\vmware-unlocker-mac-os-x-guest.zip 2012-08-03 09:40 - 2012-08-03 09:40 - 00023335 ____A C:\Users\GDuBB\Desktop\os-x-mountain-lion-10.8-dp-4-vmware-image.torrent 2012-08-02 09:58 - 2012-09-11 16:01 - 00574464 ____A (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll 2012-08-02 08:57 - 2012-09-11 16:01 - 00490496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll 2012-07-25 23:21 - 2012-07-25 23:21 - 00291680 ____A (AVG Technologies CZ, s.r.o.) C:\Windows\System32\Drivers\avgldx64.sys 2012-07-18 10:15 - 2012-08-17 14:16 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys ==================== Known DLLs (Whitelisted) ================= ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\…\.exe: exefile => OK HKLM\…\exefile\DefaultIcon: %1 => OK HKLM\…\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= Restore point made on: 2012-10-07 06:47:56 Restore point made on: 2012-10-09 23:01:21 ==================== Memory info =========================== Percentage of memory in use: 18% Total physical RAM: 4095.3 MB Available physical RAM: 3339.03 MB Total Pagefile: 4093.45 MB Available Pagefile: 3334.86 MB Total Virtual: 8192 MB Available Virtual: 8191.9 MB ==================== Partitions ============================= 1 Drive c: (COMPAQ) (Fixed) (Total:455.9 GB) (Free:372.65 GB) NTFS 2 Drive e: (FACTORY_IMAGE) (Fixed) (Total:9.76 GB) (Free:1.43 GB) NTFS ==>[System with boot components (obtained from reading drive)] 5 Drive h: () (Removable) (Total:3.77 GB) (Free:3.77 GB) FAT32 6 Drive x: (Boot) (Fixed) (Total:0.08 GB) (Free:0.07 GB) NTFS 7 Drive y: (SYSTEM) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)] Disk ### Status Size Free Dyn Gpt ——– ————- ——- ——- — — Disk 0 Online 465 GB 3072 KB Disk 1 No Media 0 B 0 B Disk 2 Online 3870 MB 0 B Partitions of Disk 0: =============== Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 Primary 98 MB 1024 KB Partition 2 Primary 455 GB 101 MB Partition 3 Primary 9 GB 456 GB ================================================================================ == Disk: 0 Partition 1 Type : 07 Hidden: No Active: Yes Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 1 Y SYSTEM NTFS Partition 98 MB Healthy ========================================================= Disk: 0 Partition 2 Type : 07 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 2 C COMPAQ NTFS Partition 455 GB Healthy ========================================================= Disk: 0 Partition 3 Type : 07 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 3 E FACTORY_IMA NTFS Partition 9 GB Healthy ========================================================= Partitions of Disk 2: =============== Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 Primary 3869 MB 64 KB ================================================================================ == Disk: 2 Partition 1 Type : 0B Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 5 H FAT32 Removable 3869 MB Healthy ========================================================= Last Boot: 2012-10-06 06:57 ==================== End Of Log =============================
Hi gdubb85,

I don't see anything in the logs except a couple of what looks to be Kaspersky drivers. We can remove those.

Are you experiencing any symptoms such as redirects crashes, BSODs, etc. Is SuperAntiSpyware still having problems?


Please locate the copy of combofix that you have and download a new on from Link 1



Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

File::
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe
C:\Windows\System32\DRIVERS\5602141drv.sys 
C:\Windows\System32\Drivers\09517212.sys

Driver::
5602141drv 
09517212  
KSS

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

Please post the combofix log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI