This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

searchnu infection [Closed]

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi - please can anybody help? Have searchnu virus and don't know how to get rid of it. Really grateful to anybody who can help Kind regards, Mark Here are the two logs . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_11-03-05.01) . Microsoft Windows 7 Home Premium Boot Device: \Device\HarddiskVolume1 Install Date: 07/01/2011 18:43:16 System Uptime: 25/10/2012 07:05:58 (5 hours ago) . Motherboard: Dell Inc. | | 0H670P Processor: Intel® Core™2 Duo CPU P7550 @ 2.26GHz | U2E1 | 793/266mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 298 GiB total, 247.561 GiB free. D: is CDROM () F: is FIXED (NTFS) - 298 GiB total, 297.987 GiB free. . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP182: 21/10/2012 20:21:58 - Windows Update RP183: 23/10/2012 08:54:46 - Installed MySQL Installer . ==== Installed Programs ====================== . Accelerometer Adobe AIR Adobe Flash Player 10 ActiveX Adobe Reader X (10.1.4) Adobe Shockwave Player 11.6 Advanced Audio FX Engine Amazon MP3 Downloader 1.0.9 Apple Application Support Apple Software Update Ask Toolbar Ask Toolbar Updater AVerMedia A335/A338 Hybrid TV Tuner 2.2.64.33 BlackBerry Desktop Software 4.5 Catalyst Control Center - Branding Catalyst Control Center Core Implementation Catalyst Control Center Graphics Full Existing Catalyst Control Center Graphics Full New Catalyst Control Center Graphics Light Catalyst Control Center Graphics Previews Common Catalyst Control Center Graphics Previews Vista Catalyst Control Center InstallProxy Catalyst Control Center Localization All ccc-core-static CCC Help Chinese Standard CCC Help Chinese Traditional CCC Help Danish CCC Help Dutch CCC Help English CCC Help Finnish CCC Help French CCC Help German CCC Help Italian CCC Help Japanese CCC Help Korean CCC Help Norwegian CCC Help Portuguese CCC Help Russian CCC Help Spanish CCC Help Swedish Cisco EAP-FAST Module Cisco LEAP Module Cisco PEAP Module ClueFinders Years 5 & 6 Adventures Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition Dell Resource CD Dell Support Center Dell Webcam Central Dropbox Express Burn Disc Burning Software Express Zip FileZilla Client 3.5.3 FLV Runner Toolbar Google Chrome Google Toolbar for Internet Explorer Google Update Helper IDT Audio Live! Cam Avatar Creator Malwarebytes Anti-Malware version 1.65.1.1000 McAfee Security Scan Plus Microsoft Office 2010 Language Pack Service Pack 1 (SP1) Microsoft Office 2010 Service Pack 1 (SP1) Microsoft Office Access MUI (Chinese (Simplified)) 2010 Microsoft Office Access MUI (English) 2010 Microsoft Office Access Setup Metadata MUI (English) 2010 Microsoft Office Excel MUI (Chinese (Simplified)) 2010 Microsoft Office Excel MUI (English) 2010 Microsoft Office Groove MUI (Chinese (Simplified)) 2010 Microsoft Office IME (Chinese (Simplified)) 2010 Microsoft Office InfoPath MUI (Chinese (Simplified)) 2010 Microsoft Office Language Pack 2010 - Chinese (PRC)/??(??) Microsoft Office O MUI (Chinese (Simplified)) 2010 Microsoft Office OneNote MUI (Chinese (Simplified)) 2010 Microsoft Office OneNote MUI (English) 2010 Microsoft Office Outlook MUI (Chinese (Simplified)) 2010 Microsoft Office Outlook MUI (English) 2010 Microsoft Office PowerPoint MUI (Chinese (Simplified)) 2010 Microsoft Office PowerPoint MUI (English) 2010 Microsoft Office Professional 2010 Microsoft Office Proof (Chinese (Simplified)) 2010 Microsoft Office Proof (English) 2010 Microsoft Office Proof (French) 2010 Microsoft Office Proof (Spanish) 2010 Microsoft Office Proofing (Chinese (Simplified)) 2010 Microsoft Office Proofing (English) 2010 Microsoft Office Publisher MUI (Chinese (Simplified)) 2010 Microsoft Office Publisher MUI (English) 2010 Microsoft Office Shared MUI (Chinese (Simplified)) 2010 Microsoft Office Shared MUI (English) 2010 Microsoft Office Shared Setup Metadata MUI (English) 2010 Microsoft Office SharePoint Designer MUI (Chinese (Simplified)) 2010 Microsoft Office Single Image 2010 Microsoft Office Word MUI (Chinese (Simplified)) 2010 Microsoft Office Word MUI (English) 2010 Microsoft Office X MUI (Chinese (Simplified)) 2010 Microsoft SharePoint Designer 2010 Service Pack 1 (SP1) Microsoft Silverlight Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 MySQL Connector J MySQL Connector Net 6.5.4 MySQL Documents 5.5 MySQL Examples and Samples 5.5 MySQL For Excel 1.1.0 MySQL Installer MySQL Notifier 1.0.3 MySQL Workbench 5.2 CE Norton Internet Security O2Micro Flash Memory Card Windows Driver Pixillion Image Converter PowerDVD DX Prism Video File Converter QuickTime Safari Scratch Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841) Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft Excel 2010 (KB2597166) 32-Bit Edition Security Update for Microsoft InfoPath 2010 (KB2687417) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2553091) Security Update for Microsoft Office 2010 (KB2553096) Security Update for Microsoft Office 2010 (KB2553260) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2553447) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2589322) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2597986) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2598243) 32-Bit Edition Security Update for Microsoft PowerPoint 2010 (KB2553185) 32-Bit Edition Security Update for Microsoft SharePoint Workspace 2010 (KB2566445) Security Update for Microsoft Visio Viewer 2010 (KB2598287) 32-Bit Edition Security Update for Microsoft Word 2010 (KB2553488) 32-Bit Edition Skype Click to Call Skype™ 5.10 Spotify Switch Sound File Converter swMSM Total Immersion D'Fusion @Home Web Plug-In Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2473228) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Update for Microsoft Office 2010 (KB2494150) Update for Microsoft Office 2010 (KB2553065) Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition Update for Microsoft Office 2010 (KB2553272) 32-Bit Edition Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition Update for Microsoft Office 2010 (KB2566458) Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition Update for Microsoft Office 2010 (KB2598241) 32-Bit Edition Update for Microsoft Office 2010 (KB2598289) 32-Bit Edition Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition Update for Microsoft OneNote 2010 (KB2589345) 32-Bit Edition Update for Microsoft Outlook 2010 (KB2553248) 32-Bit Edition Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition WavePad Sound Editor . ==== Event Viewer Messages From Past Week ======== . 25/10/2012 07:51:21, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk2\DR2. 25/10/2012 07:07:50, Error: Microsoft-Windows-WMPNSS-Service [14332] - Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80004005'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly. 24/10/2012 19:59:37, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the AC Auto-update system service to connect. 24/10/2012 19:59:37, Error: Service Control Manager [7000] - The AC Auto-update system service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 24/10/2012 19:18:10, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Bandoo Coordinator service to connect. 24/10/2012 19:18:10, Error: Service Control Manager [7000] - The Bandoo Coordinator service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. . ==== End Of File =========================== . DDS (Ver_11-03-05.01) - NTFS_AMD64 Run by [removed] at 11:56:25.96 on 25/10/2012 Internet Explorer: 9.0.8112.16421 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.4091.1261 [GMT 1:00] . AV: Norton Internet Security *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} FW: Norton Internet Security *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\atieclxx.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE C:\Windows\system32\WLANExt.exe C:\Windows\system32\conhost.exe C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwltry.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\AxiomCoders\ACProtector\ACProtector.exe C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskhost.exe C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\AESTSr64.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Program Files\IDT\WDM\sttray64.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE C:\Program Files (x86)\STMicroelectronics\Accelerometer\FF_Protection.exe C:\Program Files (x86)\Skype\Phone\Skype.exe C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE C:\Users\Honor\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe C:\Windows\system32\conhost.exe C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe C:\Users\Honor\AppData\Roaming\Dropbox\bin\Dropbox.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE C:\Program Files\MySQL\MySQL Server 5.5\bin\mysqld.exe C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\ccSvcHst.exe C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Windows\system32\DRIVERS\o2flash.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files (x86)\Ask.com\Updater\Updater.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\ccSvcHst.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\iPod\bin\iPodService.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\taskeng.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE C:\Windows\splwow64.exe C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Windows\system32\taskhost.exe C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10m_ActiveX.exe C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Users\Honor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2LMYWF26\dds.scr C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.searchnu.com uInternet Settings,ProxyOverride = *.local uURLSearchHooks: UrlSearchHook Class: {00000000-6e41-4fd3-8538-502f5495e5fc} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll uURLSearchHooks: FLV Runner Toolbar: {3bbd3c14-4c16-4989-8366-95bc9179779d} - C:\Program Files (x86)\FLV_Runner\prxtbFLV_.dll mURLSearchHooks: FLV Runner Toolbar: {3bbd3c14-4c16-4989-8366-95bc9179779d} - C:\Program Files (x86)\FLV_Runner\prxtbFLV_.dll mWinlogon: Userinit=userinit.exe BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: FLV Runner Toolbar: {3bbd3c14-4c16-4989-8366-95bc9179779d} - C:\Program Files (x86)\FLV_Runner\prxtbFLV_.dll BHO: Norton Identity Protection: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\coIEPlg.dll BHO: Norton Vulnerability Protection: {6d53ec84-6aae-4787-aeee-f4628f01010c} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\IPS\IPSBHO.DLL BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\coIEPlg.dll TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll TB: FLV Runner Toolbar: {3bbd3c14-4c16-4989-8366-95bc9179779d} - C:\Program Files (x86)\FLV_Runner\prxtbFLV_.dll uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun uRun: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe uRun: [OfficeSyncProcess] "C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE" uRun: [Spotify] "C:\Users\Honor\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart uRun: [Spotify Web Helper] "C:\Users\Honor\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe" mRun: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2 mRun: [dscactivate] "C:\Program Files (x86)\Dell Support Center\gs_agent\custom\dsca.exe" mRun: [IME14 CHS Setup] C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /CHS /Log mRun: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun: [] mRun: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe" mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRunOnce: [removeSearchqudatamngr] cmd.exe /c RD /S /Q "C:\Program Files (x86)\SRToolbar" mRunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent StartupFolder: C:\Users\Honor\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Honor\AppData\Roaming\Dropbox\bin\Dropbox.exe StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MCAFEE~1.LNK - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll LSP: %systemroot%\AxiomLsp.dll DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.3.0/GarminAxControl.CAB DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {FAB2BB9D-91E9-457E-9D42-75A7FCCBBC00} - hxxp://wondla.com/plugin/DFusionHomeWebPlugIn.Installer.exe Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL BHO-X64: URLRedirectionBHO - No File TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll TB-X64: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File TB-X64: {3BBD3C14-4C16-4989-8366-95BC9179779D} - No File mRun-x64: [QuickSet] C:\Program Files\Dell\QuickSet\QuickSet.exe mRun-x64: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe mRun-x64: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe mRun-x64: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe mRun-x64: [FreeFallProtection] C:\Program Files (x86)\STMicroelectronics\Accelerometer\FF_Protection.exe mRun-x64: [IME14 CHS Setup] C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /CHS /Log AppInit_DLLs-X64: . ============= SERVICES / DRIVERS =============== . R0 stdflt;Disk Filter Driver for Accelerometer;C:\Windows\System32\drivers\stdflt.sys [2010-7-26 17256] R0 SymDS;Symantec Data Store;C:\Windows\System32\drivers\NISx64\1309000.009\symds64.sys [2012-10-2 451192] R0 SymEFA;Symantec Extended File Attributes;C:\Windows\System32\drivers\NISx64\1309000.009\symefa64.sys [2012-10-2 1129120] R1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\BASHDefs\20121005.002\BHDrvx64.sys [2012-10-5 1385632] R1 ccSet_NIS;Norton Internet Security Settings Manager;C:\Windows\System32\drivers\NISx64\1309000.009\ccsetx64.sys [2012-10-2 167072] R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\IPSDefs\20121024.001\IDSviA64.sys [2012-10-25 513184] R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368] R1 SymIRON;Symantec Iron Driver;C:\Windows\System32\drivers\NISx64\1309000.009\ironx64.sys [2012-10-2 190072] R1 SymNetS;Symantec Network Security WFP Driver;C:\Windows\System32\drivers\NISx64\1309000.009\symnets.sys [2012-10-2 405624] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-14 59904] R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2012-7-11 140672] R2 ACProtector;AC Auto-update system;C:\Program Files\AxiomCoders\ACProtector\ACProtector.exe [2012-7-2 142808] R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-7-27 63960] R2 AESTFilters;Andrea ST Filters Service;C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\AESTSr64.exe [2010-7-26 89600] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2010-7-26 203264] R2 ImeDictUpdateService;Microsoft IME Dictionary Update;C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE [2010-10-20 83312] R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-10-25 399432] R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-10-25 676936] R2 MySQL55;MySQL55;"C:\Program Files\MySQL\MySQL Server 5.5\bin\mysqld" –defaults-file="C:\ProgramData\MySQL\MySQL Server 5.5\my.ini" MySQL55 –> C:\Program Files\MySQL\MySQL Server 5.5\bin\mysqld [?] R2 NIS;Norton Internet Security;C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\ccsvchst.exe [2012-10-2 138272] R3 Acceler;Accelerometer Service;C:\Windows\System32\drivers\Acceler.sys [2010-7-26 23912] R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\System32\drivers\CtClsFlt.sys [2010-7-26 172032] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-8-9 138912] R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2012-10-25 25928] R3 O2MDGRDR;O2MDGRDR;C:\Windows\System32\drivers\o2mdgx64.sys [2009-5-23 69152] R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2009-6-10 187392] R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\System32\drivers\vwifimp.sys [2009-7-14 17920] S1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-1-7 136176] S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-13 160944] S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-1-7 136176] S3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-1-15 227232] S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-6-14 59392] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-7-9 52736] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-1-8 1255736] . =============== Created Last 30 ================ . 2012-10-25 09:26:09 ——– d—–w- C:\Users\Honor\AppData\Roaming\SUPERAntiSpyware.com 2012-10-25 09:25:30 ——– d—–w- C:\Program Files\SUPERAntiSpyware 2012-10-25 09:25:30 ——– d—–w- C:\PROGRA~3\SUPERAntiSpyware.com 2012-10-25 06:58:07 ——– d—–w- C:\Users\Honor\AppData\Roaming\Malwarebytes 2012-10-25 06:57:54 ——– d—–w- C:\PROGRA~3\Malwarebytes 2012-10-25 06:57:50 25928 —-a-w- C:\Windows\System32\drivers\mbam.sys 2012-10-25 06:57:50 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2012-10-24 14:21:35 ——– d—–w- C:\Users\Honor\AppData\Roaming\Bandoo 2012-10-24 14:21:28 ——– d—–w- C:\PROGRA~3\boost_interprocess 2012-10-24 14:21:25 ——– d—–w- C:\Program Files (x86)\SRToolbar 2012-10-24 12:44:36 ——– d—–w- C:\Users\Honor\AppData\Local\assembly 2012-10-23 11:52:10 ——– d—–r- C:\Users\Honor\Dropbox 2012-10-23 11:49:48 ——– d—–w- C:\Users\Honor\AppData\Roaming\Dropbox 2012-10-23 09:40:41 ——– d—–w- C:\Program Files (x86)\Conduit 2012-10-23 09:40:36 ——– d—–w- C:\Users\Honor\AppData\Local\Conduit 2012-10-23 09:40:31 ——– d—–w- C:\Program Files (x86)\FLV_Runner 2012-10-23 08:04:06 ——– d—–w- C:\MyBB 2012-10-23 08:01:43 ——– d—–w- C:\Users\Honor\AppData\Roaming\MySQL 2012-10-23 07:57:41 ——– d—–w- C:\Program Files\MySQL 2012-10-23 07:55:29 ——– d—–w- C:\Program Files (x86)\MySQL 2012-10-23 07:55:27 ——– d—–w- C:\PROGRA~3\MySQL 2012-10-14 15:09:56 ——– d—–w- C:\Users\Honor\AppData\Local\Spotify 2012-10-14 15:08:46 ——– d—–w- C:\Users\Honor\AppData\Roaming\Spotify 2012-10-14 15:08:21 ——– d—–w- C:\Users\Honor\AppData\Local\Deployment 2012-10-14 15:08:21 ——– d—–w- C:\Users\Honor\AppData\Local\Apps 2012-10-10 06:19:56 3968880 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe 2012-10-10 06:19:56 3914096 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe 2012-10-10 06:19:52 1659760 —-a-w- C:\Windows\System32\drivers\ntfs.sys 2012-10-10 06:19:49 220160 —-a-w- C:\Windows\System32\wintrust.dll 2012-10-10 06:19:49 172544 —-a-w- C:\Windows\SysWow64\wintrust.dll 2012-10-10 06:19:33 2048 —-a-w- C:\Windows\SysWow64\tzres.dll 2012-10-10 06:19:33 2048 —-a-w- C:\Windows\System32\tzres.dll 2012-10-10 06:19:14 715776 —-a-w- C:\Windows\System32\kerberos.dll 2012-10-10 06:19:14 542208 —-a-w- C:\Windows\SysWow64\kerberos.dll 2012-10-10 06:19:00 1464320 —-a-w- C:\Windows\System32\crypt32.dll 2012-10-10 06:18:59 1159680 —-a-w- C:\Windows\SysWow64\crypt32.dll 2012-10-10 06:18:58 184320 —-a-w- C:\Windows\System32\cryptsvc.dll 2012-10-10 06:18:58 140288 —-a-w- C:\Windows\SysWow64\cryptsvc.dll 2012-10-10 06:18:58 140288 —-a-w- C:\Windows\System32\cryptnet.dll 2012-10-10 06:18:58 103936 —-a-w- C:\Windows\SysWow64\cryptnet.dll 2012-10-02 06:24:26 737952 —-a-w- C:\Windows\System32\drivers\NISx64\1309000.009\srtsp64.sys 2012-10-02 06:24:26 451192 —-a-r- C:\Windows\System32\drivers\NISx64\1309000.009\symds64.sys 2012-10-02 06:24:26 405624 —-a-w- C:\Windows\System32\drivers\NISx64\1309000.009\symnets.sys 2012-10-02 06:24:26 37536 —-a-w- C:\Windows\System32\drivers\NISx64\1309000.009\srtspx64.sys 2012-10-02 06:24:26 1129120 —-a-w- C:\Windows\System32\drivers\NISx64\1309000.009\symefa64.sys 2012-10-02 06:24:25 190072 —-a-w- C:\Windows\System32\drivers\NISx64\1309000.009\ironx64.sys 2012-10-02 06:24:25 167072 —-a-w- C:\Windows\System32\drivers\NISx64\1309000.009\ccsetx64.sys 2012-10-02 06:24:04 ——– d—–w- C:\Windows\System32\drivers\NISx64\1309000.009 2012-09-26 15:30:44 245760 —-a-w- C:\Windows\System32\OxpsConverter.exe . ==================== Find3M ==================== . 2012-08-30 18:03:45 5559664 —-a-w- C:\Windows\System32\ntoskrnl.exe 2012-08-24 10:31:32 2312704 —-a-w- C:\Windows\System32\jscript9.dll 2012-08-24 10:21:18 1392128 —-a-w- C:\Windows\System32\wininet.dll 2012-08-24 10:20:11 1494528 —-a-w- C:\Windows\System32\inetcpl.cpl 2012-08-24 10:14:45 173056 —-a-w- C:\Windows\System32\ieUnatt.exe 2012-08-24 10:13:29 599040 —-a-w- C:\Windows\System32\vbscript.dll 2012-08-24 10:09:42 2382848 —-a-w- C:\Windows\System32\mshtml.tlb 2012-08-24 06:59:17 1800704 —-a-w- C:\Windows\SysWow64\jscript9.dll 2012-08-24 06:51:27 1129472 —-a-w- C:\Windows\SysWow64\wininet.dll 2012-08-24 06:51:02 1427968 —-a-w- C:\Windows\SysWow64\inetcpl.cpl 2012-08-24 06:47:26 142848 —-a-w- C:\Windows\SysWow64\ieUnatt.exe 2012-08-24 06:47:12 420864 —-a-w- C:\Windows\SysWow64\vbscript.dll 2012-08-24 06:43:58 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2012-08-22 18:12:50 1913200 —-a-w- C:\Windows\System32\drivers\tcpip.sys 2012-08-22 18:12:40 950128 —-a-w- C:\Windows\System32\drivers\ndis.sys 2012-08-22 18:12:40 376688 —-a-w- C:\Windows\System32\drivers\netio.sys 2012-08-22 18:12:33 288624 —-a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS 2012-08-21 12:01:20 33240 —-a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys 2012-08-21 12:01:20 125872 —-a-w- C:\Windows\System32\GEARAspi64.dll 2012-08-21 12:01:20 106928 —-a-w- C:\Windows\SysWow64\GEARAspi.dll 2012-08-20 18:48:44 362496 —-a-w- C:\Windows\System32\wow64win.dll 2012-08-20 18:48:44 243200 —-a-w- C:\Windows\System32\wow64.dll 2012-08-20 18:48:44 13312 —-a-w- C:\Windows\System32\wow64cpu.dll 2012-08-20 18:48:43 215040 —-a-w- C:\Windows\System32\winsrv.dll 2012-08-20 18:48:37 16384 —-a-w- C:\Windows\System32\ntvdm64.dll 2012-08-20 18:48:35 424448 —-a-w- C:\Windows\System32\KernelBase.dll 2012-08-20 18:46:22 338432 —-a-w- C:\Windows\System32\conhost.exe 2012-08-20 17:40:21 14336 —-a-w- C:\Windows\SysWow64\ntvdm64.dll 2012-08-20 17:38:44 44032 —-a-w- C:\Windows\apppatch\acwow64.dll 2012-08-20 17:38:26 25600 —-a-w- C:\Windows\SysWow64\setup16.exe 2012-08-20 17:37:19 5120 —-a-w- C:\Windows\SysWow64\wow32.dll 2012-08-20 17:37:18 274944 —-a-w- C:\Windows\SysWow64\KernelBase.dll 2012-08-20 15:38:21 7680 —-a-w- C:\Windows\SysWow64\instnm.exe 2012-08-20 15:38:20 2048 —-a-w- C:\Windows\SysWow64\user.exe 2012-08-20 15:33:28 6144 —ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll 2012-08-20 15:33:28 4608 —ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll 2012-08-20 15:33:28 3584 —ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll 2012-08-20 15:33:28 3072 —ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll 2012-08-02 17:58:52 574464 —-a-w- C:\Windows\System32\d3d10level9.dll 2012-08-02 16:57:20 490496 —-a-w- C:\Windows\SysWow64\d3d10level9.dll . ============= FINISH: 12:02:32.51 ===============
Hello markshelton,

My name is OCD. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise, this will be a team effort. This may cause a delay, but I will do my best to keep it as short as possible. Please bear with me, I will post back to you as soon as I can.
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Important Note for Vista and Windows 7 users:

These tools MUST be run from the executable.(.exe) every time you run them with Admin Rights (Right click, choose "Run as Administrator")

Please stay with this topic until I let you know that your system appears to be "All Clear"
Hi markshelton,

Sorry for the delay.

Download AdwCleaner from here and save it to your desktop.

Windows Vista and Windows 7 users Right Click and select "Run as Administrator"
  • Run AdwCleaner and select Delete
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply
Next

Please download aswMBR to your desktop.
  • Right click the aswMBR icon and select "Run as Administrator". to run it.
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the log file to your desktop.
[external image: Posted Image]
Click the image to enlarge it

Next

  • Download OTL to your desktop.
  • Right click and select "Run as Administrator". Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    services.exe
    /md5stop
    %systemroot%\*. /rp /s
    %systemdrive%\$Recycle.Bin|@;true;true;true
    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s >
    DRIVES
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

In your next post please provide the following:
  • AdwCleaner log
  • aswMBR log
  • OTL.txt
  • Extras.txt
Dear OCD

Many thanks for your response.

Here is the adwcleaner log

# AdwCleaner v2.005 - Logfile created 10/27/2012 at 10:47:32
# Updated 14/10/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Honor - HONOR-PC
# Boot Mode : Normal
# Running from : C:\Users\Honor\Downloads\AdwCleaner.exe
# Option [Search]


***** [Services] *****




***** [Files / Folders] *****

File Found : C:\Users\Honor\AppData\Local\Temp\Searchqu.ini
File Found : C:\Users\Honor\AppData\Local\Temp\SetupDataMngr_Searchqu.exe
Folder Found : C:\Program Files (x86)\Ask.com
Folder Found : C:\Program Files (x86)\Conduit
Folder Found : C:\Program Files (x86)\FLV_Runner
Folder Found : C:\ProgramData\boost_interprocess
Folder Found : C:\Users\Honor\AppData\Local\Conduit
Folder Found : C:\Users\Honor\AppData\LocalLow\AskToolbar
Folder Found : C:\Users\Honor\AppData\LocalLow\Bandoo
Folder Found : C:\Users\Honor\AppData\LocalLow\Conduit
Folder Found : C:\Users\Honor\AppData\LocalLow\FLV_Runner
Folder Found : C:\Users\Honor\AppData\LocalLow\PriceGong
Folder Found : C:\Users\Honor\AppData\Roaming\Bandoo
Folder Found : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}

***** [Registry] *****

Key Found : HKCU\Software\APN
Key Found : HKCU\Software\AppDataLow\Software\AskToolbar
Key Found : HKCU\Software\AppDataLow\Software\Conduit
Key Found : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Found : HKCU\Software\AppDataLow\Software\FLV_Runner
Key Found : HKCU\Software\AppDataLow\Software\PriceGong
Key Found : HKCU\Software\AppDataLow\Software\SmartBar
Key Found : HKCU\Software\AppDataLow\Toolbar
Key Found : HKCU\Software\Ask.com
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\DataMngr
Key Found : HKCU\Software\DataMngr_Toolbar
Key Found : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3BBD3C14-4C16-4989-8366-95BC9179779D}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07CEA379-7178-4758-9C80-969876E32395}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3BBD3C14-4C16-4989-8366-95BC9179779D}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Key Found : HKLM\Software\APN
Key Found : HKLM\Software\AskToolbar
Key Found : HKLM\Software\Bandoo
Key Found : HKLM\SOFTWARE\Classes\AppID\{1301A8A5-3DFB-4731-A162-B357D00C9644}
Key Found : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Found : HKLM\SOFTWARE\Classes\AppID\BandooCore.EXE
Key Found : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Found : HKLM\SOFTWARE\Classes\BandooCore.BandooCore
Key Found : HKLM\SOFTWARE\Classes\BandooCore.BandooCore.1
Key Found : HKLM\SOFTWARE\Classes\BandooCore.ResourcesMngr
Key Found : HKLM\SOFTWARE\Classes\BandooCore.ResourcesMngr.1
Key Found : HKLM\SOFTWARE\Classes\BandooCore.SettingsMngr
Key Found : HKLM\SOFTWARE\Classes\BandooCore.SettingsMngr.1
Key Found : HKLM\SOFTWARE\Classes\BandooCore.StatisticMngr
Key Found : HKLM\SOFTWARE\Classes\BandooCore.StatisticMngr.1
Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Key Found : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
Key Found : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3201318
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{8F5F1CB6-EA9E-40AF-A5CA-C7FD63CC1971}
Key Found : HKLM\Software\Conduit
Key Found : HKLM\Software\FLV_Runner
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07CEA379-7178-4758-9C80-969876E32395}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6087829B-114F-42A1-A72B-B4AEDCEA4E5B}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{07CEA379-7178-4758-9C80-969876E32395}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{27F69C85-64E1-43CE-98B5-3C9F22FB408E}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3BBD3C14-4C16-4989-8366-95BC9179779D}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B543EF05-9758-464E-9F37-4C28525B4A4C}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{BB76A90B-2B4C-4378-8506-9A2B6E16943C}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{C3AB94A4-BFD0-4BBA-A331-DE504F07D2DB}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{06DE5702-44CF-4B79-B4EF-3DDF653358F5}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{477F210A-2A86-4666-9C4B-1189634D2C84}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{FF871E51-2655-4D06-AED5-745962A96B32}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{031D8696-CA11-4123-A04A-C7CA3981BF00}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{424624F4-C5DD-4E1D-BDD0-1E9C9B7799CC}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F000001-DB8E-F89C-2FEC-49BF726F8C12}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9C8A3CA5-889E-4554-BEEC-EC0876E4E96A}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9189560-573A-4FDE-B055-AE7B0F4CF080}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FB3B9BB7-FD71-438C-B4C6-53B496EE826C}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3BBD3C14-4C16-4989-8366-95BC9179779D}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\FLV_Runner Toolbar
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Searchqu Toolbar
Key Found : HKLM\SOFTWARE\Classes\Interface\{06DE5702-44CF-4B79-B4EF-3DDF653358F5}
Key Found : HKLM\SOFTWARE\Classes\Interface\{477F210A-2A86-4666-9C4B-1189634D2C84}
Key Found : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Found : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Found : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Found : HKLM\SOFTWARE\Classes\Interface\{FF871E51-2655-4D06-AED5-745962A96B32}
Key Found : HKLM\SOFTWARE\DataMngr
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{424624F4-C5DD-4E1D-BDD0-1E9C9B7799CC}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F000001-DB8E-F89C-2FEC-49BF726F8C12}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9C8A3CA5-889E-4554-BEEC-EC0876E4E96A}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9189560-573A-4FDE-B055-AE7B0F4CF080}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Found : HKU\S-1-5-21-2263837816-1314234786-3601107990-1001\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{3BBD3C14-4C16-4989-8366-95BC9179779D}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{00000000-6E41-4FD3-8538-502F5495E5FC}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{3BBD3C14-4C16-4989-8366-95BC9179779D}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{3BBD3C14-4C16-4989-8366-95BC9179779D}]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater]
Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{3BBD3C14-4C16-4989-8366-95BC9179779D}]
Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://www.searchnu.com

-\\ Google Chrome v [Unable to get version]

File : C:\Users\Honor\AppData\Local\Google\Chrome\User Data\Default\Preferences

Found [l.8] : homepage = "hxxp://www.searchnu.com",
Found [l.12] : urls_to_restore_on_startup = [ "hxxp://www.searchnu.com", "hxxp://www.google.com" ]
Found [l.1421] : homepage = "hxxp://www.searchnu.com",
Found [l.1652] : urls_to_restore_on_startup = [ "hxxp://www.searchnu.com", "hxxp://www.google.com" ]

*************************

AdwCleaner[R1].txt - [10471 octets] - [27/10/2012 10:42:03]
AdwCleaner[R2].txt - [10361 octets] - [27/10/2012 10:47:32]

########## EOF - C:\AdwCleaner[R2].txt - [10422 octets] ##########

Here is the OTL log file

OTL logfile created on: 10/27/2012 10:58:35 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Honor\Documents
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

4.00 Gb Total Physical Memory | 1.73 Gb Available Physical Memory | 43.31% Memory free
7.99 Gb Paging File | 5.02 Gb Available in Paging File | 62.87% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 297.81 Gb Total Space | 249.35 Gb Free Space | 83.73% Space Free | Partition Type: NTFS
Drive F: | 298.09 Gb Total Space | 297.99 Gb Free Space | 99.97% Space Free | Partition Type: NTFS

Computer Name: HONOR-PC | User Name: Honor | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Honor\My Documents\OTL.exe File not found
PRC - File not found
PRC - C:\Users\Honor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UZPGGBP6\aswMBR.exe (AVAST Software)
PRC - C:\Users\Honor\Downloads\AdwCleaner.exe ()
PRC - C:\Users\Honor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CZNT8W8I\AdwCleaner.exe ()
PRC - C:\Users\Honor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P8KGCI0F\AdwCleaner.exe ()
PRC - C:\Users\Honor\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Users\Honor\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe ()
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
PRC - C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10m_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\STMicroelectronics\Accelerometer\FF_Protection.exe ()
PRC - C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)


========== Modules (No Company Name) ==========

MOD - C:\Users\Honor\Downloads\AdwCleaner.exe ()
MOD - C:\Users\Honor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CZNT8W8I\AdwCleaner.exe ()
MOD - C:\Users\Honor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P8KGCI0F\AdwCleaner.exe ()
MOD - C:\Users\Honor\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Program Files (x86)\Microsoft Office\Office14\ADDINS\UmOutlookAddin.dll ()
MOD - C:\Program Files (x86)\STMicroelectronics\Accelerometer\FF_Protection.exe ()


========== Services (SafeList) ==========

SRV:64bit: - (MySQL55) – C:\Program Files\MySQL\MySQL Server 5.5\bin\mysqld.exe ()
SRV:64bit: - (ACProtector) – C:\Program Files\AxiomCoders\ACProtector\ACProtector.exe (AxiomCoders)
SRV:64bit: - (wltrysvc) – C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE ()
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (STacSV) – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (AESTFilters) – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\AESTSr64.exe (Andrea Electronics Corporation)
SRV:64bit: - (O2FLASH) – C:\Windows\SysNative\drivers\o2flash.exe (O2Micro International)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (NIS) – C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\ccSvcHst.exe (Symantec Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (McComponentHostService) – C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe (IDT, Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (AESTFilters) – C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\AESTSr64.exe (Andrea Electronics Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (SRTSPX) – C:\Windows\SysNative\drivers\NISx64\1309000.009\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\drivers\NISx64\1309000.009\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (ccSet_NIS) – C:\Windows\SysNative\drivers\NISx64\1309000.009\ccsetx64.sys (Symantec Corporation)
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\drivers\NISx64\1309000.009\symefa64.sys (Symantec Corporation)
DRV:64bit: - (SymNetS) – C:\Windows\SysNative\drivers\NISx64\1309000.009\symnets.sys (Symantec Corporation)
DRV:64bit: - (SymIRON) – C:\Windows\SysNative\drivers\NISx64\1309000.009\ironx64.sys (Symantec Corporation)
DRV:64bit: - (SymEvent) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (SymDS) – C:\Windows\SysNative\drivers\NISx64\1309000.009\symds64.sys (Symantec Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (BCM42RLY) – C:\Windows\SysNative\drivers\bcm42rly.sys (Broadcom Corporation)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ROOTMODEM) – C:\Windows\SysNative\drivers\rootmdm.sys (Microsoft Corporation)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation )
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (AtiHdmiService) – C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Research Inc.)
DRV:64bit: - (Acceler) – C:\Windows\SysNative\drivers\Acceler.sys (ST Microelectronics)
DRV:64bit: - (stdflt) – C:\Windows\SysNative\drivers\stdflt.sys (ST Microelectronics)
DRV:64bit: - (O2MDGRDR) – C:\Windows\SysNative\drivers\o2mdgx64.sys (O2Micro )
DRV:64bit: - (CtClsFlt) – C:\Windows\SysNative\drivers\CtClsFlt.sys (Creative Technology Ltd.)
DRV:64bit: - (RimUsb) – C:\Windows\SysNative\drivers\RimUsb_AMD64.sys (Research In Motion Limited)
DRV:64bit: - (RimVSerPort) – C:\Windows\SysNative\drivers\RimSerial_AMD64.sys (Research in Motion Ltd)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\VirusDefs\20121026.032\ex64.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\VirusDefs\20121026.032\eng64.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\BASHDefs\20121005.002\BHDrvx64.sys (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\IPSDefs\20121027.001\IDSviA64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2101}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2101}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {3bbd3c14-4c16-4989-8366-95bc9179779d} - C:\Program Files (x86)\FLV_Runner\prxtbFLV_.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2101}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2101}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.co.uk/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchnu.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 4B EA 37 EB 9A AE CB 01 [binary data]
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\URLSearchHook: {3bbd3c14-4c16-4989-8366-95bc9179779d} - C:\Program Files (x86)\FLV_Runner\prxtbFLV_.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2101}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…1I7ADFA_enGB413
IE - HKCU\..\SearchScopes\{8A7AEC63-66A8-41C9-815D-7B1772ACFAF7}: "URL" = http://websearch.ask.com/redirect?client=i…54-3DAB971485DA
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2101}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKCU\..\SearchScopes\{A3F56741-C55C-4800-959D-F01AA909298F}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT3201318
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://uk.ask.com/web?q={SEARCHTERMS}&…o=GB&ver=18
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@t-immersion.com/DFusionHomeWebPlugIn: C:\Program Files (x86)\Total Immersion\DFusionHomeWebPlugIn\NPDFusionWebFirefox.dll (Total Immersion)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\IPSFFPlgn\ [2012/01/31 18:02:38 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\coFFPlgn\ [2012/10/27 10:33:49 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - homepage: http://www.searchnu.com
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://www.searchnu.com
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.79\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.94\pdf.dll
CHR - plugin: Skype Click to Call (Enabled) = C:\Users\Honor\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.10.0.9560_0\npSkypeChromePlugin.dll
CHR - plugin: Norton Confidential (Enabled) = C:\Users\Honor\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.5.6.10_0\npcoplgn.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: D'Fusion @Home Web Plug-In (2.30.11285.AR23) (Enabled) = C:\Program Files (x86)\Total Immersion\DFusionHomeWebPlugIn\NPDFusionWebFirefox.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
CHR - Extension: YouTube = C:\Users\Honor\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\Honor\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Skype Click to Call = C:\Users\Honor\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.10.0.9560_0\
CHR - Extension: Norton Identity Protection = C:\Users\Honor\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.5.6.10_0\
CHR - Extension: Gmail = C:\Users\Honor\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009/06/10 22:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (FLV Runner Toolbar) - {3bbd3c14-4c16-4989-8366-95bc9179779d} - C:\Program Files (x86)\FLV_Runner\prxtbFLV_.dll (Conduit Ltd.)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (FLV Runner Toolbar) - {3bbd3c14-4c16-4989-8366-95bc9179779d} - C:\Program Files (x86)\FLV_Runner\prxtbFLV_.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (FLV Runner Toolbar) - {3BBD3C14-4C16-4989-8366-95BC9179779D} - C:\Program Files (x86)\FLV_Runner\prxtbFLV_.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\coieplg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE (Dell Inc.)
O4:64bit: - HKLM..\Run: [FreeFallProtection] C:\Program Files (x86)\STMicroelectronics\Accelerometer\FF_Protection.exe ()
O4:64bit: - HKLM..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [dscactivate] C:\Program Files (x86)\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.)
O4 - HKCU..\Run: [Spotify] C:\Users\Honor\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd)
O4 - HKCU..\Run: [Spotify Web Helper] C:\Users\Honor\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe ()
O4 - Startup: C:\Users\Honor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Honor\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\AxiomLSPx64.dll (AxiomCoders)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\AxiomLSPx64.dll (AxiomCoders)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\AxiomLSPx64.dll (AxiomCoders)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\AxiomLSPx64.dll (AxiomCoders)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000015 - C:\Windows\AxiomLSPx64.dll (AxiomCoders)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\AxiomLSP.dll (AxiomCoders)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\AxiomLSP.dll (AxiomCoders)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\AxiomLSP.dll (AxiomCoders)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\AxiomLSP.dll (AxiomCoders)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Windows\AxiomLSP.dll (AxiomCoders)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FAB2BB9D-91E9-457E-9D42-75A7FCCBBC00} http://wondla.com/plugin/DFusionHomeWebPlugIn.Installer.exe (CDFusionActiveXCtl Object)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/2.9.3.0…inAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{83065E13-A9E6-4C79-B19A-99C9780E8BD0}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B090AE88-5745-4A13-B2CE-92B435EB45A7}: DhcpNameServer = 0.0.0.0
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/10/27 10:56:38 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Honor\Documents\OTL.exe
[2012/10/27 10:49:29 | 000,000,000 | —D | C] – C:\New folder
[2012/10/25 07:58:07 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Roaming\Malwarebytes
[2012/10/25 07:57:56 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/10/25 07:57:54 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/10/25 07:57:50 | 000,025,928 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2012/10/25 07:57:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/10/24 15:21:35 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Roaming\Bandoo
[2012/10/24 15:21:28 | 000,000,000 | —D | C] – C:\ProgramData\boost_interprocess
[2012/10/24 15:13:49 | 000,000,000 | —D | C] – C:\Users\Honor\Documents\3148-1320190820-FaceBook-v1_Theme
[2012/10/24 13:44:39 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Roaming\Oracle
[2012/10/24 13:44:36 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Local\assembly
[2012/10/24 10:37:38 | 000,000,000 | —D | C] – C:\Users\Honor\Documents\2207-1281768339-thecure
[2012/10/24 10:25:04 | 000,000,000 | —D | C] – C:\Users\Honor\Documents\1830-1302322512-DarkFusion
[2012/10/24 07:40:03 | 000,000,000 | —D | C] – C:\Users\Honor\Documents\3120-1317633656-2.0 Inspired
[2012/10/23 17:46:04 | 000,000,000 | —D | C] – C:\Users\Honor\Documents\1407-1328561066-Google-SEO-1.6.3
[2012/10/23 16:21:06 | 000,000,000 | —D | C] – C:\Users\Honor\Documents\2283-1284663245-Archivio
[2012/10/23 15:41:30 | 000,000,000 | —D | C] – C:\Users\Honor\Documents\2125-1281218688-Apart 1
[2012/10/23 15:24:43 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Graphics Related Programs
[2012/10/23 15:24:43 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Audio Related Programs
[2012/10/23 15:24:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Video Related Programs
[2012/10/23 15:23:39 | 000,000,000 | —D | C] – C:\Users\Honor\Documents\2098-1281619591-BlueVision-ACP-12
[2012/10/23 12:55:06 | 000,000,000 | —D | C] – C:\Users\Honor\Documents\Install MyBB
[2012/10/23 12:52:10 | 000,000,000 | R–D | C] – C:\Users\Honor\Dropbox
[2012/10/23 12:50:38 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2012/10/23 12:49:48 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Roaming\Dropbox
[2012/10/23 10:49:03 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Roaming\FileZilla
[2012/10/23 10:48:52 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
[2012/10/23 10:48:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\FileZilla FTP Client
[2012/10/23 10:40:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Conduit
[2012/10/23 10:40:36 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Local\Conduit
[2012/10/23 10:40:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\FLV_Runner
[2012/10/23 09:05:16 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
[2012/10/23 09:05:12 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Utilities
[2012/10/23 09:04:06 | 000,000,000 | —D | C] – C:\MyBB
[2012/10/23 09:01:43 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Roaming\MySQL
[2012/10/23 08:57:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MySQL
[2012/10/23 08:57:41 | 000,000,000 | —D | C] – C:\Program Files\MySQL
[2012/10/23 08:55:34 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MySQL
[2012/10/23 08:55:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\MySQL
[2012/10/23 08:55:27 | 000,000,000 | —D | C] – C:\ProgramData\MySQL
[2012/10/14 16:09:56 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Local\Spotify
[2012/10/14 16:08:46 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Roaming\Spotify
[2012/10/14 16:08:21 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Local\Deployment
[2012/10/14 16:08:21 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Local\Apps
[2012/10/10 07:20:33 | 001,162,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2012/10/10 07:20:33 | 000,424,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\KernelBase.dll
[2012/10/10 07:20:32 | 000,338,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\conhost.exe
[2012/10/10 07:20:32 | 000,215,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2012/10/10 07:20:30 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2012/10/10 07:20:30 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2012/10/10 07:20:29 | 000,362,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64win.dll
[2012/10/10 07:20:29 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntvdm64.dll
[2012/10/10 07:20:29 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2012/10/10 07:20:29 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64cpu.dll
[2012/10/10 07:20:29 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2012/10/10 07:20:29 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2012/10/10 07:20:29 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2012/10/10 07:20:29 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2012/10/10 07:20:29 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2012/10/10 07:20:29 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2012/10/10 07:20:29 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2012/10/10 07:20:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2012/10/10 07:20:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012/10/10 07:20:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2012/10/10 07:20:28 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2012/10/10 07:20:28 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2012/10/10 07:20:28 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2012/10/10 07:20:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2012/10/10 07:20:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2012/10/10 07:20:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2012/10/10 07:20:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2012/10/10 07:20:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/10/10 07:20:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2012/10/10 07:20:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2012/10/10 07:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2012/10/10 07:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2012/10/10 07:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2012/10/10 07:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2012/10/10 07:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2012/10/10 07:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2012/10/10 07:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2012/10/10 07:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2012/10/10 07:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2012/10/10 07:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2012/10/10 07:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2012/10/10 07:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2012/10/10 07:20:27 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2012/10/10 07:20:27 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2012/10/10 07:20:27 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2012/10/10 07:20:27 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2012/10/10 07:20:26 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2012/10/10 07:20:26 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2012/10/10 07:20:26 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2012/10/10 07:20:26 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2012/10/10 07:20:26 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2012/10/10 07:20:26 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2012/10/10 07:20:26 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2012/10/10 07:20:26 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012/10/10 07:20:26 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2012/10/10 07:20:26 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2012/10/10 07:20:26 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/10/10 07:20:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2012/10/10 07:20:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2012/10/10 07:20:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2012/10/10 07:20:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2012/10/10 07:20:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2012/10/10 07:20:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2012/10/10 07:20:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2012/10/10 07:20:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2012/10/10 07:20:25 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2012/10/10 07:20:25 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2012/10/10 07:20:25 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2012/10/10 07:20:24 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2012/10/10 07:20:00 | 005,559,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2012/10/10 07:19:56 | 003,968,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2012/10/10 07:19:56 | 003,914,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2012/10/10 07:19:49 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wintrust.dll
[2012/10/10 07:19:00 | 001,464,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2012/10/10 07:18:58 | 000,140,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2012/10/09 07:14:17 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2 C:\Users\Honor\Documents\*.tmp files -> C:\Users\Honor\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/10/27 10:56:39 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Honor\Documents\OTL.exe
[2012/10/27 10:52:02 | 000,000,512 | —- | M] () – C:\Users\Honor\Documents\MBR.dat
[2012/10/27 10:41:01 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/10/27 10:41:01 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/10/27 10:33:23 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/10/27 10:33:09 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/10/27 10:33:01 | 3217,244,160 | -HS- | M] () – C:\hiberfil.sys
[2012/10/26 20:29:03 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/10/26 13:33:37 | 000,281,088 | —- | M] () – C:\Users\Honor\Documents\ark critical study.pub
[2012/10/26 08:46:18 | 000,736,614 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/10/26 08:46:18 | 000,632,284 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/10/26 08:46:18 | 000,112,086 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/10/25 13:25:37 | 000,058,642 | —- | M] () – C:\Users\Honor\Documents\Craigton Limited.pdf
[2012/10/25 07:57:57 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/10/25 07:53:41 | 000,727,332 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/10/24 15:27:19 | 000,005,857 | —- | M] () – C:\Users\Honor\Documents\picaso_guernica.jpg
[2012/10/24 15:24:31 | 000,016,800 | —- | M] () – C:\Users\Honor\Documents\arnolfini_portrait.jpg
[2012/10/24 15:21:19 | 000,001,138 | —- | M] () – C:\Users\Public\Desktop\Upgrade Facebook Chat Experience with fTalk.lnk
[2012/10/24 15:13:31 | 000,294,326 | —- | M] () – C:\Users\Honor\Documents\3148-1320190820-FaceBook-v1_Theme.zip
[2012/10/24 12:14:56 | 000,240,625 | —- | M] () – C:\Users\Honor\Documents\oxford summer evening.png
[2012/10/24 10:52:01 | 000,024,281 | —- | M] () – C:\Users\Honor\Documents\oxford summer evening.jpg
[2012/10/23 17:22:18 | 000,454,472 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/10/23 15:24:39 | 000,001,156 | —- | M] () – C:\Users\Public\Desktop\Pixillion Image Converter.lnk
[2012/10/23 15:24:34 | 000,001,126 | —- | M] () – C:\Users\Public\Desktop\Switch Sound File Converter.lnk
[2012/10/23 15:24:14 | 000,001,110 | —- | M] () – C:\Users\Public\Desktop\Prism Video File Converter.lnk
[2012/10/23 13:14:41 | 000,536,329 | —- | M] () – C:\Users\Honor\Documents\MyBB set-up guide.pdf
[2012/10/23 12:54:43 | 000,502,499 | —- | M] () – C:\Users\Honor\Documents\Install MyBB.zip
[2012/10/23 12:52:11 | 000,001,039 | —- | M] () – C:\Users\Honor\Desktop\Dropbox.lnk
[2012/10/23 12:50:57 | 000,001,049 | —- | M] () – C:\Users\Honor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2012/10/23 12:07:50 | 000,007,225 | —- | M] () – C:\Users\Honor\Documents\Upload.xml
[2012/10/23 12:06:12 | 000,007,229 | —- | M] () – C:\Users\Honor\Documents\FileZilla.xml
[2012/10/23 09:05:12 | 000,001,138 | —- | M] () – C:\Users\Public\Desktop\Express Zip.lnk
[2012/10/23 08:58:39 | 000,000,238 | —- | M] () – C:\Windows\ODBCINST.INI
[2012/10/22 14:51:35 | 000,052,252 | —- | M] () – C:\Users\Honor\Documents\flowchart i.jpg
[2012/10/22 14:50:59 | 000,099,599 | —- | M] () – C:\Users\Honor\Documents\flowchart h.jpg
[2012/10/22 14:50:22 | 000,008,503 | —- | M] () – C:\Users\Honor\Documents\flowchart g.gif
[2012/10/22 14:49:31 | 000,090,344 | —- | M] () – C:\Users\Honor\Documents\flowchart e.png
[2012/10/22 14:47:25 | 000,036,694 | —- | M] () – C:\Users\Honor\Documents\flowchart d.gif
[2012/10/22 14:45:53 | 000,009,263 | —- | M] () – C:\Users\Honor\Documents\flowchart c.gif
[2012/10/22 14:42:01 | 000,220,340 | —- | M] () – C:\Users\Honor\Documents\flowchart b.png
[2012/10/22 14:41:29 | 000,040,892 | —- | M] () – C:\Users\Honor\Documents\flowchart a.jpg
[2012/10/22 12:19:26 | 000,076,627 | —- | M] () – C:\Users\Honor\Documents\Blinc.pdf
[2012/10/18 17:01:10 | 000,108,032 | —- | M] () – C:\Users\Honor\Documents\gordon diagram.pub
[2012/10/16 19:38:14 | 000,172,032 | —- | M] () – C:\Users\Honor\Documents\battle of hastings.pub
[2012/10/16 07:28:35 | 000,010,074 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1309000.009\VT20121008.022
[2012/10/15 18:35:14 | 000,190,464 | —- | M] () – C:\Users\Honor\Documents\beekman.pub
[2012/10/14 17:45:43 | 001,497,088 | —- | M] () – C:\Users\Honor\Documents\charlie gordon 2.pub
[2012/10/14 16:09:54 | 000,001,805 | —- | M] () – C:\Users\Honor\Desktop\Spotify.lnk
[2012/10/13 12:31:45 | 000,002,378 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2012/10/10 08:33:09 | 002,011,827 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1309000.009\Cat.DB
[2012/10/08 20:41:18 | 000,195,584 | —- | M] () – C:\Users\Honor\Documents\biology plan.pub
[2012/10/07 15:18:52 | 001,647,104 | —- | M] () – C:\Users\Honor\Documents\mandarin.pub
[2012/10/06 13:33:49 | 001,584,640 | —- | M] () – C:\Users\Honor\Documents\textiles diagrams.pub
[2012/10/06 11:54:26 | 002,502,656 | —- | M] () – C:\Users\Honor\Documents\textilers diagrams.pub
[2012/10/03 17:10:07 | 000,387,072 | —- | M] () – C:\Users\Honor\Documents\birthday calendar.pub
[2012/10/02 07:40:18 | 000,002,492 | —- | M] () – C:\Users\Public\Desktop\Norton Internet Security.lnk
[2012/09/30 13:15:06 | 000,269,824 | —- | M] () – C:\Users\Honor\Documents\geography revision 2.pub
[2012/09/29 19:54:26 | 000,025,928 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2 C:\Users\Honor\Documents\*.tmp files -> C:\Users\Honor\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/10/27 10:52:02 | 000,000,512 | —- | C] () – C:\Users\Honor\Documents\MBR.dat
[2012/10/26 13:33:36 | 000,281,088 | —- | C] () – C:\Users\Honor\Documents\ark critical study.pub
[2012/10/25 13:25:37 | 000,058,642 | —- | C] () – C:\Users\Honor\Documents\Craigton Limited.pdf
[2012/10/25 07:57:57 | 000,001,113 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/10/24 15:27:28 | 000,005,857 | —- | C] () – C:\Users\Honor\Documents\picaso_guernica.jpg
[2012/10/24 15:25:00 | 000,016,800 | —- | C] () – C:\Users\Honor\Documents\arnolfini_portrait.jpg
[2012/10/24 15:21:19 | 000,001,138 | —- | C] () – C:\Users\Public\Desktop\Upgrade Facebook Chat Experience with fTalk.lnk
[2012/10/24 15:13:30 | 000,294,326 | —- | C] () – C:\Users\Honor\Documents\3148-1320190820-FaceBook-v1_Theme.zip
[2012/10/24 12:14:56 | 000,240,625 | —- | C] () – C:\Users\Honor\Documents\oxford summer evening.png
[2012/10/24 10:52:18 | 000,024,281 | —- | C] () – C:\Users\Honor\Documents\oxford summer evening.jpg
[2012/10/23 15:24:38 | 000,001,168 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pixillion Image Converter.lnk
[2012/10/23 15:24:38 | 000,001,156 | —- | C] () – C:\Users\Public\Desktop\Pixillion Image Converter.lnk
[2012/10/23 15:24:33 | 000,001,126 | —- | C] () – C:\Users\Public\Desktop\Switch Sound File Converter.lnk
[2012/10/23 15:24:29 | 000,001,138 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Switch Sound File Converter.lnk
[2012/10/23 15:24:13 | 000,001,110 | —- | C] () – C:\Users\Public\Desktop\Prism Video File Converter.lnk
[2012/10/23 15:24:12 | 000,001,122 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Prism Video File Converter.lnk
[2012/10/23 13:14:41 | 000,536,329 | —- | C] () – C:\Users\Honor\Documents\MyBB set-up guide.pdf
[2012/10/23 12:54:43 | 000,502,499 | —- | C] () – C:\Users\Honor\Documents\Install MyBB.zip
[2012/10/23 12:52:10 | 000,001,039 | —- | C] () – C:\Users\Honor\Desktop\Dropbox.lnk
[2012/10/23 12:50:56 | 000,001,049 | —- | C] () – C:\Users\Honor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2012/10/23 12:07:50 | 000,007,225 | —- | C] () – C:\Users\Honor\Documents\Upload.xml
[2012/10/23 12:01:40 | 000,007,229 | —- | C] () – C:\Users\Honor\Documents\FileZilla.xml
[2012/10/23 09:05:12 | 000,001,150 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Express Zip.lnk
[2012/10/23 09:05:12 | 000,001,138 | —- | C] () – C:\Users\Public\Desktop\Express Zip.lnk
[2012/10/23 08:59:16 | 000,736,614 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/10/23 08:58:39 | 000,000,238 | —- | C] () – C:\Windows\ODBCINST.INI
[2012/10/22 14:51:48 | 000,052,252 | —- | C] () – C:\Users\Honor\Documents\flowchart i.jpg
[2012/10/22 14:51:12 | 000,099,599 | —- | C] () – C:\Users\Honor\Documents\flowchart h.jpg
[2012/10/22 14:50:36 | 000,008,503 | —- | C] () – C:\Users\Honor\Documents\flowchart g.gif
[2012/10/22 14:49:42 | 000,090,344 | —- | C] () – C:\Users\Honor\Documents\flowchart e.png
[2012/10/22 14:47:38 | 000,036,694 | —- | C] () – C:\Users\Honor\Documents\flowchart d.gif
[2012/10/22 14:46:17 | 000,009,263 | —- | C] () – C:\Users\Honor\Documents\flowchart c.gif
[2012/10/22 14:42:13 | 000,220,340 | —- | C] () – C:\Users\Honor\Documents\flowchart b.png
[2012/10/22 14:41:45 | 000,040,892 | —- | C] () – C:\Users\Honor\Documents\flowchart a.jpg
[2012/10/22 12:19:25 | 000,076,627 | —- | C] () – C:\Users\Honor\Documents\Blinc.pdf
[2012/10/18 17:01:09 | 000,108,032 | —- | C] () – C:\Users\Honor\Documents\gordon diagram.pub
[2012/10/16 19:38:13 | 000,172,032 | —- | C] () – C:\Users\Honor\Documents\battle of hastings.pub
[2012/10/15 07:47:43 | 000,190,464 | —- | C] () – C:\Users\Honor\Documents\beekman.pub
[2012/10/14 17:45:42 | 001,497,088 | —- | C] () – C:\Users\Honor\Documents\charlie gordon 2.pub
[2012/10/14 16:09:54 | 000,001,791 | —- | C] () – C:\Users\Honor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
[2012/10/14 16:09:53 | 000,001,805 | —- | C] () – C:\Users\Honor\Desktop\Spotify.lnk
[2012/10/08 20:41:16 | 000,195,584 | —- | C] () – C:\Users\Honor\Documents\biology plan.pub
[2012/10/06 11:54:15 | 001,584,640 | —- | C] () – C:\Users\Honor\Documents\textiles diagrams.pub
[2012/10/04 17:08:09 | 001,647,104 | —- | C] () – C:\Users\Honor\Documents\mandarin.pub
[2012/10/03 16:50:17 | 000,387,072 | —- | C] () – C:\Users\Honor\Documents\birthday calendar.pub
[2012/09/30 13:15:04 | 000,269,824 | —- | C] () – C:\Users\Honor\Documents\geography revision 2.pub
[2011/01/20 17:30:42 | 000,000,000 | —- | C] () – C:\Windows\setup32.INI
[2011/01/08 14:32:07 | 000,005,632 | —- | C] () – C:\Users\Honor\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2009/07/14 05:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/09 06:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/09 05:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/14 02:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 13:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/14 02:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2011/12/31 10:59:36 | 000,000,000 | —D | M] – C:\Users\Honor\AppData\Roaming\Amazon
[2012/10/24 15:21:35 | 000,000,000 | —D | M] – C:\Users\Honor\AppData\Roaming\Bandoo
[2012/10/27 10:33:41 | 000,000,000 | —D | M] – C:\Users\Honor\AppData\Roaming\Dropbox
[2012/10/24 12:40:30 | 000,000,000 | —D | M] – C:\Users\Honor\AppData\Roaming\FileZilla
[2011/03/26 14:05:58 | 000,000,000 | —D | M] – C:\Users\Honor\AppData\Roaming\GARMIN
[2012/10/23 09:01:43 | 000,000,000 | —D | M] – C:\Users\Honor\AppData\Roaming\MySQL
[2012/10/24 13:44:39 | 000,000,000 | —D | M] – C:\Users\Honor\AppData\Roaming\Oracle
[2012/10/27 10:33:35 | 000,000,000 | —D | M] – C:\Users\Honor\AppData\Roaming\Spotify

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2011/02/26 07:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/26 06:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/14 02:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/26 06:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009/10/31 06:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/26 06:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/25 07:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 07:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 07:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 13:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009/08/03 07:19:07 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/25 06:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 06:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009/10/31 07:34:59 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/03 06:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 14:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009/10/31 07:38:38 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/03 06:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/14 02:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/31 07:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/02/26 07:26:45 | 002,870,784 | —- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009/08/03 07:17:37 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe

< MD5 for: SERVICES.EXE >
[2009/07/14 02:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/14 02:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SVCHOST.EXE >
[2009/07/14 02:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\SysWOW64\svchost.exe
[2009/07/14 02:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2012/09/29 19:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009/07/14 02:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\SysNative\svchost.exe
[2009/07/14 02:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 13:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\SysWOW64\userinit.exe
[2010/11/20 13:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/14 02:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009/07/14 02:39:48 | 000,030,208 | —- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010/11/20 14:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\SysNative\userinit.exe
[2010/11/20 14:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010/11/20 14:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 14:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/14 02:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2012/09/29 19:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/10/28 08:01:57 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009/10/28 07:24:40 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< %systemroot%\*. /rp /s >

< %systemdrive%\$Recycle.Bin|@;true;true;true >

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: WDC WD3200BEVT-75ZCT2 ATA Device
Partitions: 1
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE1 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: WDC WD3200BEVT-75ZCT2 ATA Device
Partitions: 2
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 298.00GB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #1, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 283.00MB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #1, Partition #1
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 298.00GB
Starting Offset: 297795584
Hidden sectors: 0


========== Files - Unicode (All) ==========
[2012/10/16 07:49:19 | 000,013,465 | —- | M] ()(C:\Users\Honor\Documents\??.docx) – C:\Users\Honor\Documents\中国.docx
[2012/10/16 07:49:17 | 000,013,465 | —- | C] ()(C:\Users\Honor\Documents\??.docx) – C:\Users\Honor\Documents\中国.docx
[2012/01/29 11:12:16 | 000,016,164 | —- | M] ()(C:\Users\Honor\Documents\????.docx) – C:\Users\Honor\Documents\蛮大日内.docx
[2012/01/28 21:37:36 | 000,016,164 | —- | C] ()(C:\Users\Honor\Documents\????.docx) – C:\Users\Honor\Documents\蛮大日内.docx

========== Alternate Data Streams ==========

@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:D1B5B4F1

< End of report >

and the extras.txt
OTL Extras logfile created on: 10/27/2012 10:58:35 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Honor\Documents
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

4.00 Gb Total Physical Memory | 1.73 Gb Available Physical Memory | 43.31% Memory free
7.99 Gb Paging File | 5.02 Gb Available in Paging File | 62.87% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 297.81 Gb Total Space | 249.35 Gb Free Space | 83.73% Space Free | Partition Type: NTFS
Drive F: | 298.09 Gb Total Space | 297.99 Gb Free Space | 99.97% Space Free | Partition Type: NTFS

Computer Name: HONOR-PC | User Name: Honor | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = ChromeHTML] – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = ChromeHTML] – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
http [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
http [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0FE6BFF6-0379-4992-9FCC-564FB91A316F}" = lport=445 | protocol=6 | dir=in | app=system |
"{10DD55B7-800B-4002-90AA-206F98A8E0C7}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{2591DADF-1722-49B0-B892-ECFF2AF93132}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{2C92E0BE-851F-488F-B7D5-42F32351B0FB}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{5E01B78B-58FB-4E70-8EF2-0CE336FCB996}" = lport=139 | protocol=6 | dir=in | app=system |
"{6053A5CF-D16F-4F91-A113-B3D6B2CDFAAC}" = rport=139 | protocol=6 | dir=out | app=system |
"{65279E50-83BA-4FE9-BE64-EC21707D4C28}" = rport=138 | protocol=17 | dir=out | app=system |
"{72F8A6D3-32C3-4F4A-8283-35D42EC75B32}" = rport=10243 | protocol=6 | dir=out | app=system |
"{786D1C36-DF10-4A6A-A0DD-EFF0C7B5B829}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{870196E1-4A59-4ADF-BA14-6747F48BD7F1}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{8ED10CAD-AAAC-49C7-B488-4F35256B10A5}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{9638B450-19A0-4F85-B5DB-0DC5939A7245}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{9DA52A26-C319-4069-8B71-8BA51E1509A7}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A02B16DB-1EE4-4891-99AE-ADB3F4189833}" = lport=10243 | protocol=6 | dir=in | app=system |
"{A8113988-0D17-4D06-9F09-064A48CFF2F4}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{AB53FED7-B19C-42EC-B6E2-007FB889709F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{C3853261-B0AB-4313-BEEA-A0F77412A3C5}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{C67A8234-64A5-4468-8EB1-A7CB5B00279D}" = rport=445 | protocol=6 | dir=out | app=system |
"{C8663A29-64F2-4855-9BC0-88595DC59D5E}" = lport=138 | protocol=17 | dir=in | app=system |
"{CCA79932-9DCE-45BC-BE83-D56B312489E1}" = rport=137 | protocol=17 | dir=out | app=system |
"{D819F10B-7147-4529-8084-722BDE6D090C}" = lport=2869 | protocol=6 | dir=in | app=system |
"{DBF031D2-9DE9-4F2E-8347-71D6F3F52F56}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{ED1A8692-7F95-4106-9964-3985FFE9F9C3}" = lport=137 | protocol=17 | dir=in | app=system |
"{FAD001BF-57A4-4B09-BBC7-6EFD5A676E25}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\outlook.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{060A857C-1A9A-45FC-B924-DF3606B95921}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{106ADFCB-1E37-4D78-B91D-32E2418BD03B}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{28EB4FDF-B818-49B5-AC51-1F658AA89DD9}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{2D2B00C6-B3E1-4460-96E0-212029D71799}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{2FA2FE44-EDFC-4B1A-8775-84C5861BFF7A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{334D5D7F-024C-41D0-B521-8C82AE35F5B4}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{3705AC58-26AE-44AB-8470-B6D823527231}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{38E0E887-2ADE-46A6-A7CA-58920A159B8C}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{4496550D-50FA-4930-B16E-70EC137351B3}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{4F3F1EC3-C20F-4C65-98D9-97B4B6DFAF07}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{5C14CB2F-C247-4517-86E9-11FFA6C019A2}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{846FE1D8-FED8-4DBD-A932-F4A566BC2011}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{85A3F5F6-B223-423E-B94D-2BD482E9B64A}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{8713107A-87E1-4580-9488-D2AEF0B960C5}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{940D3103-2188-43CD-BC73-0D2B24E2B9BE}" = protocol=6 | dir=out | app=system |
"{95591D61-3F60-46DF-AC70-5FB48AB3D3DF}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{9AB9863C-08D7-47AF-B495-E244CDBB6742}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{9B011FB3-115E-40FD-B446-A8A1F655298E}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{A06F36BA-9054-4E50-A009-26829985CA6C}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{A20B3B48-D6A0-4C28-AFAC-F9E2444B7CC8}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{AF8B4E25-0CB2-4A1E-8E54-48CC99F14DAC}" = protocol=6 | dir=in | app=c:\users\honor\appdata\roaming\dropbox\bin\dropbox.exe |
"{B31CC47D-5B61-40FC-B9B3-E759389819EF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{B518815E-3103-403B-8E59-02180A55D07C}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{BB96AC09-41EF-4679-816D-C0A04BC44BD0}" = protocol=17 | dir=in | app=c:\users\honor\appdata\roaming\dropbox\bin\dropbox.exe |
"{BEA530E7-3B6E-4036-9E82-22C9C9E73E1D}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{C41A8D72-5A1D-48FD-865A-BDEF8F8971F4}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{D1BE7097-7078-4F3E-90E1-1703290170BB}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{D2D34F76-9512-462E-B036-C3E995351C8F}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{DC723D58-FEB0-467E-954E-E9E371192CE5}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{E4FA40C1-0584-4CF0-8293-7CFF46D24856}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd dx\powerdvd.exe |
"{E83F2473-53BF-458D-8D39-071C04886D0C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{F3B119B4-8674-48BC-9E15-A9C45FD81E4A}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd dx\pdvddxsrv.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{1493B2AE-0261-47D2-B1AA-F4DAD0F6C48B}" = iTunes
"{3C481CDB-34E8-4CEF-B487-4C9C60530CFC}" = MySQL Connector C++ 1.1.0
"{41BC9E31-0D39-462E-8E4C-767B21A3B1C3}" = MobileMe Control Panel
"{5B6A2A7C-658E-4661-A254-3C36F5B63943}" = MySQL Connector C 6.0.2
"{5CA882E6-4BF0-4E55-B290-6C4EAD6E586E}" = MySQL Server 5.5
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{64FBA03C-575C-D688-1C80-A5773CE471F9}" = ATI Catalyst Install Manager
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{7446FE8D-C1F9-4D42-AAAE-5DBCE58605A6}" = Apple Mobile Device Support
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{87CF757E-C1F1-4D22-865C-00C6950B5258}" = Quickset64
"{8B485965-8EFE-464A-842F-CF8F18C3DFD7}" = iCloud
"{8C164C30-9086-42AA-91DD-B7D8C8CDFBB6}" = O2Micro Flash Memory Card Windows Driver
"{90140000-0028-0804-1000-0000000FF1CE}" = Microsoft Office IME (Chinese (Simplified)) 2010
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-002A-0804-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Chinese (Simplified)) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{BB2211D1-A5B5-4AEF-B0E6-DD7874ABF8EE}" = MySQL Connector/ODBC 5.1
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{E461C0B2-523B-2940-C5DF-D174284CE609}" = ccc-utility64
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"AxiomCoders FB Limiter_is1" = AxiomCoders FB Limiter version 1.5.0
"CCleaner" = CCleaner
"Dell Wireless WLAN Card Utility" = Dell Wireless WLAN Card Utility
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0293D4CF-0EDF-41E1-805C-C298460000AE}" = MySQL Documents 5.5
"{03CFDC67-5B03-EE5C-4176-F545B0D2F485}" = CCC Help Korean
"{0505C47B-6CBC-4DF5-9628-769566240F88}" = MySQL Connector J
"{0A2AC888-61DC-CD55-5969-8602A7E9716D}" = CCC Help Italian
"{0CF884B6-C6D8-EB7B-D2BF-2877C6F49EBC}" = CCC Help Swedish
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{14B95189-3DD8-4EAA-9B9B-67472FF12AD4}" = MySQL Installer
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{185CC275-907C-0D83-B0C2-7B065C5108D8}" = CCC Help Chinese Traditional
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23C3EF87-AD08-4F76-982D-1AE137485F08}" = MySQL Workbench 5.2 CE
"{2D963679-1FC7-4E13-9A81-343F6F49BCC4}" = BlackBerry Desktop Software 4.5
"{2ED967AD-FBB0-5355-F5F2-E7A03AAD4F71}" = Catalyst Control Center Localization All
"{30FA0F5C-B1A9-39EB-8148-3D574C0C8332}" = Catalyst Control Center Graphics Previews Common
"{35852FDE-7263-23EA-435F-44E4B61996D0}" = CCC Help Japanese
"{38404B7E-FF50-4525-8EA0-E1187E4171E4}" = MySQL For Excel 1.1.0
"{42929F0F-CE14-47AF-9FC7-FF297A603021}" = Dell Resource CD
"{445F6C1F-C48F-0CC9-A030-040D3EA42C93}" = Catalyst Control Center Graphics Full New
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{46E08E5F-02B4-E854-CD4F-ED3E4FEBE122}" = CCC Help French
"{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module
"{5681C7AB-E29D-4EE9-B0F0-809A28ECECFC}" = MySQL Notifier 1.0.3
"{5A841BCF-1C5B-E3DA-9475-892CA6576425}" = CCC Help Finnish
"{5B8741B6-4BEA-47D3-DB77-959C7FF35B39}" = Catalyst Control Center Graphics Full Existing
"{5FA16D15-FA5B-7F0F-7CBB-369E1E2937C9}" = CCC Help Spanish
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{61F27C5E-5274-0DB8-67CC-5253C6CF2B93}" = CCC Help Dutch
"{63EC2120-1742-4625-AA47-C6A8AEC9C64C}" = Apple Application Support
"{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module
"{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}" = Live! Cam Avatar Creator
"{6625CE8F-6E89-561F-D828-1B8535DEEBB6}" = Catalyst Control Center Core Implementation
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD DX
"{69533745-1E2D-4C98-8B4A-B7643EF9E1A2}" = Catalyst Control Center - Branding
"{6D2CCC4B-007D-EEE7-3E69-578B178A7B91}" = Catalyst Control Center Graphics Previews Vista
"{71E3D92F-2C51-B4E9-F2B6-EAF89C33E580}" = CCC Help Portuguese
"{77F218D6-EAF4-402C-36B1-C3F0EC62598D}" = ccc-core-static
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{86C527CC-4AF2-903C-7BFF-5975272CC645}" = Catalyst Control Center InstallProxy
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{87434D51-51DB-4109-B68F-A829ECDCF380}" = Accelerometer
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DDFDDE9-C206-F32E-66AD-D17558D7677E}" = CCC Help German
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0015-0804-0000-0000000FF1CE}" = Microsoft Office Access MUI (Chinese (Simplified)) 2010
"{90140000-0015-0804-0000-0000000FF1CE}_Office14.OMUI.zh-cn_{ED6EB6CE-E9BA-4D10-A9F5-AEC56263D9EB}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0804-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Chinese (Simplified)) 2010
"{90140000-0016-0804-0000-0000000FF1CE}_Office14.OMUI.zh-cn_{ED6EB6CE-E9BA-4D10-A9F5-AEC56263D9EB}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0017-0804-0000-0000000FF1CE}" = Microsoft Office SharePoint Designer MUI (Chinese (Simplified)) 2010
"{90140000-0017-0804-0000-0000000FF1CE}_Office14.OMUI.zh-cn_{AA2EEDEA-84E6-4494-9168-D07DEF2E19CA}" = Microsoft SharePoint Designer 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0804-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Chinese (Simplified)) 2010
"{90140000-0018-0804-0000-0000000FF1CE}_Office14.OMUI.zh-cn_{ED6EB6CE-E9BA-4D10-A9F5-AEC56263D9EB}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0804-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Chinese (Simplified)) 2010
"{90140000-0019-0804-0000-0000000FF1CE}_Office14.OMUI.zh-cn_{ED6EB6CE-E9BA-4D10-A9F5-AEC56263D9EB}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0804-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Chinese (Simplified)) 2010
"{90140000-001A-0804-0000-0000000FF1CE}_Office14.OMUI.zh-cn_{ED6EB6CE-E9BA-4D10-A9F5-AEC56263D9EB}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0804-0000-0000000FF1CE}" = Microsoft Office Word MUI (Chinese (Simplified)) 2010
"{90140000-001B-0804-0000-0000000FF1CE}_Office14.OMUI.zh-cn_{ED6EB6CE-E9BA-4D10-A9F5-AEC56263D9EB}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.OMUI.zh-cn_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0804-0000-0000000FF1CE}" = Microsoft Office Proof (Chinese (Simplified)) 2010
"{90140000-001F-0804-0000-0000000FF1CE}_Office14.OMUI.zh-cn_{A620ACD4-585E-40D3-80B9-FD31766D1E2A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0028-0804-0000-0000000FF1CE}" = Microsoft Office IME (Chinese (Simplified)) 2010
"{90140000-0028-0804-0000-0000000FF1CE}_Office14.OMUI.zh-cn_{394CF546-9CD3-4C0A-B380-F4CCFD44C873}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0028-0804-1000-0000000FF1CE}_Office14.OMUI.zh-cn_{FC0CF8F8-B41D-40F0-8341-1E377D771CE4}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0409-1000-0000000FF1CE}_Office14.SingleImage_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0804-1000-0000000FF1CE}_Office14.OMUI.zh-cn_{AF727EE3-C59D-481C-B092-EC7EDD2AF228}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.SingleImage_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0804-0000-0000000FF1CE}" = Microsoft Office Proofing (Chinese (Simplified)) 2010
"{90140000-002C-0804-0000-0000000FF1CE}_Office14.OMUI.zh-cn_{00EB89C1-EB14-40EE-89F8-A5A5D97B4F30}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0804-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Chinese (Simplified)) 2010
"{90140000-0044-0804-0000-0000000FF1CE}_Office14.OMUI.zh-cn_{ED6EB6CE-E9BA-4D10-A9F5-AEC56263D9EB}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0804-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Chinese (Simplified)) 2010
"{90140000-006E-0804-0000-0000000FF1CE}_Office14.OMUI.zh-cn_{C12630E0-EBCC-48F1-A0D3-BB8C05AC7306}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0804-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Chinese (Simplified)) 2010
"{90140000-00A1-0804-0000-0000000FF1CE}_Office14.OMUI.zh-cn_{ED6EB6CE-E9BA-4D10-A9F5-AEC56263D9EB}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0804-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Chinese (Simplified)) 2010
"{90140000-00BA-0804-0000-0000000FF1CE}_Office14.OMUI.zh-cn_{ED6EB6CE-E9BA-4D10-A9F5-AEC56263D9EB}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0100-0804-0000-0000000FF1CE}" = Microsoft Office O MUI (Chinese (Simplified)) 2010
"{90140000-0100-0804-0000-0000000FF1CE}_Office14.OMUI.zh-cn_{0D023A94-08DA-4B07-B878-B213433CF716}" = Microsoft Office 2010 Language Pack Service Pack 1 (SP1)
"{90140000-0101-0804-0000-0000000FF1CE}" = Microsoft Office X MUI (Chinese (Simplified)) 2010
"{90140000-0101-0804-0000-0000000FF1CE}_Office14.OMUI.zh-cn_{0799CC5C-199F-463F-81A0-671AF0F25D85}" = Microsoft Office 2010 Language Pack Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0116-0409-1000-0000000FF1CE}_Office14.SingleImage_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{92E19B5A-1985-49BF-9022-9CF4AD652C72}" = MySQL Connector Net 6.5.4
"{962A23F0-3466-492F-AC73-CCB86A1767ED}" = MySQL Examples and Samples 5.5
"{A2A4AC67-DC60-A92B-DD50-65BEE8FA8D71}" = CCC Help Russian
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.4)
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B9C5005C-56CA-38E4-A093-79F22ECA0427}" = CCC Help Norwegian
"{C779648B-410E-4BBA-B75B-5815BCEFE71D}" = Safari
"{DC93F14E-D2C9-D6D1-31B6-D31AC2AD3BB0}" = Catalyst Control Center Graphics Light
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center
"{E6E0F53B-B7B8-E052-5C32-76C885536A3E}" = CCC Help Danish
"{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F7FE3C6E-ECB8-0853-584F-BE19BA05B1B8}" = CCC Help Chinese Standard
"{FCC49808-C684-FEFA-3C02-46A04A7C9EBD}" = CCC Help English
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.9
"AVerMedia A335/A338 Hybrid TV Tuner" = AVerMedia A335/A338 Hybrid TV Tuner 2.2.64.33
"BlackBerry_{2D963679-1FC7-4E13-9A81-343F6F49BCC4}" = BlackBerry Desktop Software 4.5
"ClueFinders Years 5 & 6 Adventures" = ClueFinders Years 5 & 6 Adventures
"Dell Webcam Central" = Dell Webcam Central
"D'Fusion @Home Web Plug-In" = Total Immersion D'Fusion @Home Web Plug-In
"ExpressBurn" = Express Burn Disc Burning Software
"ExpressZip" = Express Zip
"FileZilla Client" = FileZilla Client 3.5.3
"FLV_Runner Toolbar" = FLV Runner Toolbar
"Google Chrome" = Google Chrome
"InstallShield_{8C164C30-9086-42AA-91DD-B7D8C8CDFBB6}" = O2Micro Flash Memory Card Windows Driver
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.1.1000
"McAfee Security Scan" = McAfee Security Scan Plus
"NIS" = Norton Internet Security
"Office14.OMUI.zh-cn" = Microsoft Office Language Pack 2010 - Chinese (PRC)/中文(简体)
"Office14.SingleImage" = Microsoft Office Professional 2010
"Pixillion" = Pixillion Image Converter
"Prism" = Prism Video File Converter
"Scratch" = Scratch
"Switch" = Switch Sound File Converter
"WavePad" = WavePad Sound Editor

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{79A765E1-C399-405B-85AF-466F52E918B0}" = Ask Toolbar Updater
"Dropbox" = Dropbox
"Spotify" = Spotify

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 10/26/2012 3:46:56 AM | Computer Name = Honor-PC | Source = Outlook | ID = 35
Description = ???????????????(??=0x8007043c)?

Error - 10/26/2012 3:47:00 AM | Computer Name = Honor-PC | Source = System Restore | ID = 8193
Description =

Error - 10/26/2012 5:50:26 AM | Computer Name = Honor-PC | Source = Application Error | ID = 1000
Description = Faulting application name: EXCEL.EXE, version: 14.0.6117.5003, time
stamp: 0x4f622ef8 Faulting module name: ole32.dll, version: 6.1.7601.17514, time
stamp: 0x4ce7b96f Exception code: 0xc0000005 Fault offset: 0x0003bc24 Faulting process
id: 0x1b8c Faulting application start time: 0x01cdb35ecd68dd92 Faulting application
path: C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE Faulting module
path: C:\Windows\syswow64\ole32.dll Report Id: 90c0f4a9-1f52-11e2-a843-0024e8d07245

Error - 10/26/2012 6:25:16 AM | Computer Name = Honor-PC | Source = Application Error | ID = 1000
Description = Faulting application name: EXCEL.EXE, version: 14.0.6117.5003, time
stamp: 0x4f622ef8 Faulting module name: ole32.dll, version: 6.1.7601.17514, time
stamp: 0x4ce7b96f Exception code: 0xc0000005 Fault offset: 0x0003bd41 Faulting process
id: 0x1ae0 Faulting application start time: 0x01cdb363f722f62e Faulting application
path: C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE Faulting module
path: C:\Windows\syswow64\ole32.dll Report Id: 6edfc753-1f57-11e2-a843-0024e8d07245

Error - 10/26/2012 9:43:03 AM | Computer Name = Honor-PC | Source = Outlook | ID = 34
Description = ???? Crawl Scope Manager,??=0x8007043c?

Error - 10/26/2012 9:43:03 AM | Computer Name = Honor-PC | Source = Outlook | ID = 34
Description = ???? Crawl Scope Manager,??=0x8007043c?

Error - 10/26/2012 9:43:03 AM | Computer Name = Honor-PC | Source = Outlook | ID = 35
Description = ???????????????(??=0x8007043c)?

Error - 10/26/2012 9:43:03 AM | Computer Name = Honor-PC | Source = Outlook | ID = 35
Description = ???????????????(??=0x8007043c)?

Error - 10/26/2012 9:43:25 AM | Computer Name = Honor-PC | Source = System Restore | ID = 8193
Description =

Error - 10/26/2012 9:43:28 AM | Computer Name = Honor-PC | Source = System Restore | ID = 8193
Description =

[ Media Center Events ]
Error - 3/13/2011 4:51:43 PM | Computer Name = Honor-PC | Source = MCUpdate | ID = 0
Description = 20:51:43 - Failed to retrieve MCESpotlight (Error: Unable to connect
to the remote server)

Error - 4/26/2011 10:49:22 AM | Computer Name = Honor-PC | Source = MCUpdate | ID = 0
Description = 15:49:22 - Error connecting to the internet. 15:49:22 - Unable
to contact server..

Error - 4/26/2011 10:49:39 AM | Computer Name = Honor-PC | Source = MCUpdate | ID = 0
Description = 15:49:27 - Error connecting to the internet. 15:49:27 - Unable
to contact server..

Error - 7/31/2011 4:04:35 PM | Computer Name = Honor-PC | Source = MCUpdate | ID = 0
Description = 21:04:34 - Error connecting to the internet. 21:04:35 - Unable
to contact server..

Error - 7/31/2011 4:04:46 PM | Computer Name = Honor-PC | Source = MCUpdate | ID = 0
Description = 21:04:40 - Error connecting to the internet. 21:04:40 - Unable
to contact server..

Error - 8/5/2011 4:20:07 AM | Computer Name = Honor-PC | Source = MCUpdate | ID = 0
Description = 09:20:07 - Failed to retrieve MCESpotlight (Error: The operation has
timed out)

Error - 8/5/2011 4:21:52 AM | Computer Name = Honor-PC | Source = MCUpdate | ID = 0
Description = 09:21:42 - Failed to retrieve Broadband (Error: The underlying connection
was closed: An unexpected error occurred on a receive.)

Error - 7/20/2012 4:34:01 PM | Computer Name = Honor-PC | Source = MCUpdate | ID = 0
Description = 21:34:01 - Failed to retrieve Directory (Error: The underlying connection
was closed: An unexpected error occurred on a receive.)

[ System Events ]
Error - 10/26/2012 9:45:51 AM | Computer Name = Honor-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the AC
Auto-update system service to connect.

Error - 10/26/2012 9:45:51 AM | Computer Name = Honor-PC | Source = Service Control Manager | ID = 7000
Description = The AC Auto-update system service failed to start due to the following
error: %%1053

Error - 10/26/2012 12:46:08 PM | Computer Name = Honor-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the AC
Auto-update system service to connect.

Error - 10/26/2012 12:46:08 PM | Computer Name = Honor-PC | Source = Service Control Manager | ID = 7000
Description = The AC Auto-update system service failed to start due to the following
error: %%1053

Error - 10/26/2012 3:22:47 PM | Computer Name = Honor-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the AC
Auto-update system service to connect.

Error - 10/26/2012 3:22:47 PM | Computer Name = Honor-PC | Source = Service Control Manager | ID = 7000
Description = The AC Auto-update system service failed to start due to the following
error: %%1053

Error - 10/26/2012 4:01:47 PM | Computer Name = Honor-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the AC
Auto-update system service to connect.

Error - 10/26/2012 4:01:47 PM | Computer Name = Honor-PC | Source = Service Control Manager | ID = 7000
Description = The AC Auto-update system service failed to start due to the following
error: %%1053

Error - 10/27/2012 5:33:45 AM | Computer Name = Honor-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the AC
Auto-update system service to connect.

Error - 10/27/2012 5:33:45 AM | Computer Name = Honor-PC | Source = Service Control Manager | ID = 7000
Description = The AC Auto-update system service failed to start due to the following
error: %%1053


< End of report >


Many thanks again for all your help

Kind regards

Mark
Hi markshelton,

Run OTL.exe Windows Vista and Windows 7 users Right Click and select "Run as Administrator"
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchnu.com
    IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
    IE - HKCU\..\URLSearchHook: {3bbd3c14-4c16-4989-8366-95bc9179779d} - C:\Program Files (x86)\FLV_Runner\prxtbFLV_.dll (Conduit Ltd.)
    IE - HKCU\..\SearchScopes\{8A7AEC63-66A8-41C9-815D-7B1772ACFAF7}: "URL" = http://websearch.ask.com/redirect?client=i…54-3DAB971485DA
    IE - HKCU\..\SearchScopes\{A3F56741-C55C-4800-959D-F01AA909298F}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT3201318
    IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://uk.ask.com/web?q={SEARCHTERMS}&…o=GB&ver=18
    CHR - homepage: http://www.searchnu.com
    CHR - homepage: http://www.searchnu.com
    O2 - BHO: (FLV Runner Toolbar) - {3bbd3c14-4c16-4989-8366-95bc9179779d} - C:\Program Files (x86)\FLV_Runner\prxtbFLV_.dll (Conduit Ltd.)
    O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
    O3 - HKLM\..\Toolbar: (FLV Runner Toolbar) - {3bbd3c14-4c16-4989-8366-95bc9179779d} - C:\Program Files (x86)\FLV_Runner\prxtbFLV_.dll (Conduit Ltd.)
    O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
    O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (FLV Runner Toolbar) - {3BBD3C14-4C16-4989-8366-95BC9179779D} - C:\Program Files (x86)\FLV_Runner\prxtbFLV_.dll (Conduit Ltd.)
    O4 - HKLM..\Run: [] File not found
    O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
    [2012/10/24 15:21:35 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Roaming\Bandoo
    [2012/10/23 10:40:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Conduit
    [2012/10/23 10:40:36 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Local\Conduit
    [2012/10/23 10:40:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\FLV_Runner
    
    :Commands
    [purity]
    [createrestorepoint]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
Next

Locate Malwarebytes' Anti-Malware (it should be on your desktop).

  • Right click and select "Run as Administrator" mbam-setup.exe and follow the prompts.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan as shown below.

    [external image: Posted Image]

  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Next

Please run Eset Online Scanner

Administrator rights are required to run ESET Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\Program Files\ESET\log.txt into your next reply.
In your next post please provide the following:
  • OTL.txt
  • MBAM log
  • ESET log.txt
HI OCD Here is the fourth log Kind regards, Mark All processes killed ========== OTL ========== HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{00000000-6E41-4FD3-8538-502F5495E5FC} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}\ deleted successfully. C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll moved successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{3bbd3c14-4c16-4989-8366-95bc9179779d} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3bbd3c14-4c16-4989-8366-95bc9179779d}\ deleted successfully. C:\Program Files (x86)\FLV_Runner\prxtbFLV_.dll moved successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8A7AEC63-66A8-41C9-815D-7B1772ACFAF7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8A7AEC63-66A8-41C9-815D-7B1772ACFAF7}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A3F56741-C55C-4800-959D-F01AA909298F}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3F56741-C55C-4800-959D-F01AA909298F}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}\ not found. Use Chrome's Settings page to change the HomePage. Use Chrome's Settings page to change the HomePage. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3bbd3c14-4c16-4989-8366-95bc9179779d}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3bbd3c14-4c16-4989-8366-95bc9179779d}\ not found. File C:\Program Files (x86)\FLV_Runner\prxtbFLV_.dll not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully. File C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{3bbd3c14-4c16-4989-8366-95bc9179779d} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3bbd3c14-4c16-4989-8366-95bc9179779d}\ not found. File C:\Program Files (x86)\FLV_Runner\prxtbFLV_.dll not found. 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found. File C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{3BBD3C14-4C16-4989-8366-95BC9179779D} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3BBD3C14-4C16-4989-8366-95BC9179779D}\ not found. File C:\Program Files (x86)\FLV_Runner\prxtbFLV_.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ApnUpdater deleted successfully. C:\Program Files (x86)\Ask.com\Updater\Updater.exe moved successfully. C:\Users\Honor\AppData\Roaming\Bandoo folder moved successfully. C:\Program Files (x86)\Conduit\Community Alerts folder moved successfully. C:\Program Files (x86)\Conduit folder moved successfully. C:\Users\Honor\AppData\Local\Conduit\CT3201318 folder moved successfully. C:\Users\Honor\AppData\Local\Conduit folder moved successfully. C:\Program Files (x86)\FLV_Runner folder moved successfully. ========== COMMANDS ========== Restore point Set: OTL Restore Point [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 56502 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Honor ->Temp folder emptied: 46378318 bytes ->Temporary Internet Files folder emptied: 250051384 bytes ->Google Chrome cache emptied: 18247941 bytes ->Apple Safari cache emptied: 0 bytes ->Flash cache emptied: 15370 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 13240 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 36048163 bytes RecycleBin emptied: 28795255 bytes Total Files Cleaned = 362.00 mb OTL by OldTimer - Version 3.2.69.0 log created on 10272012_220505 Files\Folders moved on Reboot… C:\Users\Honor\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. C:\Users\Honor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\ProgramData\AxiomCoders\LSPEngine\engine.log moved successfully. C:\Users\Honor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\CZD1G643\index[2].htm moved successfully. C:\Users\Honor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\8QWW1WNT\iframe[1].htm moved successfully. C:\Users\Honor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully. C:\Users\Honor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully. File\Folder C:\Users\Honor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{2D1F1D19-9782-4941-9C0C-C933D51468A3}.tmp not found! PendingFileRenameOperations files… Registry entries deleted on Reboot…
Hi markshelton,

Please copy and paste the logs into your reply, do not attach unless requested to do so.

= = = = = = = = = =

Run OTL.exe
Windows Vista and Windows 7 users Right Click and select "Run as Administrator"
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Files
    C:\Users\Honor\Downloads\BandooV8.exe
    
    :Commands
    [purity]
    [createrestorepoint]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
In your next post please provide the following:
  • OTL.txt
  • How is the computer running, any remaining issues?
Dear OCD

Many thanks for this.

I think the infection is still there. We discovered the infection when we noticed that two tabs opened up in IE when we clicked on the icon - one for Google and one for searchnu. Then we loaded Malwarebytes and this prevented the searchnu tab from opening - the tab said that it was unable to connect to the internet. If you then typed a website address into the google searchbox of the tab that said that it was unable to connect to the internet it returned the web address but a message appeared from Mawarebytes saying that it had successfully blocked access to a potentially malicious website: 207.232.22.60 type:ougoing. Port: - this number changes Process: iexplore.exe

When we now click on the explorer icon we still get two tabs but the first one is MSN rather than searchnu. But now, when we search for another address in either of the two tabs we get the Malwarebytes message about having blocked access to the site 207.232.22.60. Before it was just the tab that came up saying that it had been unable to connect to the internet
Many thanks again for your help on this
Kind regards,

Mark







OTL logfile created on: 10/29/2012 8:25:18 AM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Honor\Documents
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

4.00 Gb Total Physical Memory | 2.04 Gb Available Physical Memory | 51.10% Memory free
7.99 Gb Paging File | 5.53 Gb Available in Paging File | 69.16% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 297.81 Gb Total Space | 247.24 Gb Free Space | 83.02% Space Free | Partition Type: NTFS
Drive F: | 298.09 Gb Total Space | 297.99 Gb Free Space | 99.97% Space Free | Partition Type: NTFS

Computer Name: HONOR-PC | User Name: Honor | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Honor\My Documents\OTL.exe File not found
PRC - File not found
PRC - C:\Users\Honor\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Users\Honor\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe ()
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10m_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\STMicroelectronics\Accelerometer\FF_Protection.exe ()
PRC - C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)


========== Modules (No Company Name) ==========

MOD - C:\Users\Honor\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\STMicroelectronics\Accelerometer\FF_Protection.exe ()


========== Services (SafeList) ==========

SRV:64bit: - (MySQL55) – C:\Program Files\MySQL\MySQL Server 5.5\bin\mysqld.exe ()
SRV:64bit: - (ACProtector) – C:\Program Files\AxiomCoders\ACProtector\ACProtector.exe (AxiomCoders)
SRV:64bit: - (wltrysvc) – C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE ()
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (STacSV) – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (AESTFilters) – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\AESTSr64.exe (Andrea Electronics Corporation)
SRV:64bit: - (O2FLASH) – C:\Windows\SysNative\drivers\o2flash.exe (O2Micro International)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (NIS) – C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\ccSvcHst.exe (Symantec Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (McComponentHostService) – C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe (IDT, Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (AESTFilters) – C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\AESTSr64.exe (Andrea Electronics Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (SRTSPX) – C:\Windows\SysNative\drivers\NISx64\1309000.009\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\drivers\NISx64\1309000.009\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (ccSet_NIS) – C:\Windows\SysNative\drivers\NISx64\1309000.009\ccsetx64.sys (Symantec Corporation)
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\drivers\NISx64\1309000.009\symefa64.sys (Symantec Corporation)
DRV:64bit: - (SymNetS) – C:\Windows\SysNative\drivers\NISx64\1309000.009\symnets.sys (Symantec Corporation)
DRV:64bit: - (SymIRON) – C:\Windows\SysNative\drivers\NISx64\1309000.009\ironx64.sys (Symantec Corporation)
DRV:64bit: - (SymEvent) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (SymDS) – C:\Windows\SysNative\drivers\NISx64\1309000.009\symds64.sys (Symantec Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (BCM42RLY) – C:\Windows\SysNative\drivers\bcm42rly.sys (Broadcom Corporation)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ROOTMODEM) – C:\Windows\SysNative\drivers\rootmdm.sys (Microsoft Corporation)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation )
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (AtiHdmiService) – C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Research Inc.)
DRV:64bit: - (Acceler) – C:\Windows\SysNative\drivers\Acceler.sys (ST Microelectronics)
DRV:64bit: - (stdflt) – C:\Windows\SysNative\drivers\stdflt.sys (ST Microelectronics)
DRV:64bit: - (O2MDGRDR) – C:\Windows\SysNative\drivers\o2mdgx64.sys (O2Micro )
DRV:64bit: - (CtClsFlt) – C:\Windows\SysNative\drivers\CtClsFlt.sys (Creative Technology Ltd.)
DRV:64bit: - (RimUsb) – C:\Windows\SysNative\drivers\RimUsb_AMD64.sys (Research In Motion Limited)
DRV:64bit: - (RimVSerPort) – C:\Windows\SysNative\drivers\RimSerial_AMD64.sys (Research in Motion Ltd)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\VirusDefs\20121027.007\ex64.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\VirusDefs\20121027.007\eng64.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\BASHDefs\20121005.002\BHDrvx64.sys (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\IPSDefs\20121027.001\IDSviA64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2101}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2101}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {3bbd3c14-4c16-4989-8366-95bc9179779d} - No CLSID value found
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2101}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2101}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.co.uk/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-GB
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 31 65 2C 20 88 B4 CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2101}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…1I7ADFA_enGB413
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2101}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@t-immersion.com/DFusionHomeWebPlugIn: C:\Program Files (x86)\Total Immersion\DFusionHomeWebPlugIn\NPDFusionWebFirefox.dll (Total Immersion)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\IPSFFPlgn\ [2012/01/31 17:02:38 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\coFFPlgn\ [2012/10/29 08:20:37 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - homepage: http://www.searchnu.com
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://www.searchnu.com
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.79\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.94\pdf.dll
CHR - plugin: Skype Click to Call (Enabled) = C:\Users\Honor\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.10.0.9560_0\npSkypeChromePlugin.dll
CHR - plugin: Norton Confidential (Enabled) = C:\Users\Honor\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.5.6.10_0\npcoplgn.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: D'Fusion @Home Web Plug-In (2.30.11285.AR23) (Enabled) = C:\Program Files (x86)\Total Immersion\DFusionHomeWebPlugIn\NPDFusionWebFirefox.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
CHR - Extension: YouTube = C:\Users\Honor\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\Honor\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Skype Click to Call = C:\Users\Honor\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.10.0.9560_0\
CHR - Extension: Norton Identity Protection = C:\Users\Honor\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.5.6.10_0\
CHR - Extension: Gmail = C:\Users\Honor\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009/06/10 21:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\coieplg.dll (Symantec Corporation)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\coieplg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE (Dell Inc.)
O4:64bit: - HKLM..\Run: [FreeFallProtection] C:\Program Files (x86)\STMicroelectronics\Accelerometer\FF_Protection.exe ()
O4:64bit: - HKLM..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [dscactivate] C:\Program Files (x86)\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.)
O4 - HKCU..\Run: [Spotify] C:\Users\Honor\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd)
O4 - HKCU..\Run: [Spotify Web Helper] C:\Users\Honor\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe ()
O4 - Startup: C:\Users\Honor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Honor\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\AxiomLSPx64.dll (AxiomCoders)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\AxiomLSPx64.dll (AxiomCoders)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\AxiomLSPx64.dll (AxiomCoders)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\AxiomLSPx64.dll (AxiomCoders)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000015 - C:\Windows\AxiomLSPx64.dll (AxiomCoders)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\AxiomLSP.dll (AxiomCoders)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\AxiomLSP.dll (AxiomCoders)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\AxiomLSP.dll (AxiomCoders)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\AxiomLSP.dll (AxiomCoders)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Windows\AxiomLSP.dll (AxiomCoders)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FAB2BB9D-91E9-457E-9D42-75A7FCCBBC00} http://wondla.com/plugin/DFusionHomeWebPlugIn.Installer.exe (CDFusionActiveXCtl Object)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/2.9.3.0…inAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{83065E13-A9E6-4C79-B19A-99C9780E8BD0}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B090AE88-5745-4A13-B2CE-92B435EB45A7}: DhcpNameServer = 0.0.0.0
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/10/28 07:16:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2012/10/27 21:05:05 | 000,000,000 | —D | C] – C:\_OTL
[2012/10/27 09:56:38 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Honor\Documents\OTL.exe
[2012/10/27 09:49:29 | 000,000,000 | —D | C] – C:\New folder
[2012/10/25 06:58:07 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Roaming\Malwarebytes
[2012/10/25 06:57:56 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/10/25 06:57:54 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/10/25 06:57:50 | 000,025,928 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2012/10/25 06:57:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/10/24 14:21:28 | 000,000,000 | —D | C] – C:\ProgramData\boost_interprocess
[2012/10/24 14:13:49 | 000,000,000 | —D | C] – C:\Users\Honor\Documents\3148-1320190820-FaceBook-v1_Theme
[2012/10/24 12:44:39 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Roaming\Oracle
[2012/10/24 12:44:36 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Local\assembly
[2012/10/24 09:37:38 | 000,000,000 | —D | C] – C:\Users\Honor\Documents\2207-1281768339-thecure
[2012/10/24 09:25:04 | 000,000,000 | —D | C] – C:\Users\Honor\Documents\1830-1302322512-DarkFusion
[2012/10/24 06:40:03 | 000,000,000 | —D | C] – C:\Users\Honor\Documents\3120-1317633656-2.0 Inspired
[2012/10/23 16:46:04 | 000,000,000 | —D | C] – C:\Users\Honor\Documents\1407-1328561066-Google-SEO-1.6.3
[2012/10/23 15:21:06 | 000,000,000 | —D | C] – C:\Users\Honor\Documents\2283-1284663245-Archivio
[2012/10/23 14:41:30 | 000,000,000 | —D | C] – C:\Users\Honor\Documents\2125-1281218688-Apart 1
[2012/10/23 14:24:43 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Graphics Related Programs
[2012/10/23 14:24:43 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Audio Related Programs
[2012/10/23 14:24:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Video Related Programs
[2012/10/23 14:23:39 | 000,000,000 | —D | C] – C:\Users\Honor\Documents\2098-1281619591-BlueVision-ACP-12
[2012/10/23 11:55:06 | 000,000,000 | —D | C] – C:\Users\Honor\Documents\Install MyBB
[2012/10/23 11:52:10 | 000,000,000 | R–D | C] – C:\Users\Honor\Dropbox
[2012/10/23 11:50:38 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2012/10/23 11:49:48 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Roaming\Dropbox
[2012/10/23 09:49:03 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Roaming\FileZilla
[2012/10/23 09:48:52 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
[2012/10/23 09:48:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\FileZilla FTP Client
[2012/10/23 08:05:16 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
[2012/10/23 08:05:12 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Utilities
[2012/10/23 08:04:06 | 000,000,000 | —D | C] – C:\MyBB
[2012/10/23 08:01:43 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Roaming\MySQL
[2012/10/23 07:57:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MySQL
[2012/10/23 07:57:41 | 000,000,000 | —D | C] – C:\Program Files\MySQL
[2012/10/23 07:55:34 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MySQL
[2012/10/23 07:55:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\MySQL
[2012/10/23 07:55:27 | 000,000,000 | —D | C] – C:\ProgramData\MySQL
[2012/10/14 15:09:56 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Local\Spotify
[2012/10/14 15:08:46 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Roaming\Spotify
[2012/10/14 15:08:21 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Local\Deployment
[2012/10/14 15:08:21 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Local\Apps
[2012/10/10 06:20:33 | 001,162,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2012/10/10 06:20:33 | 000,424,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\KernelBase.dll
[2012/10/10 06:20:32 | 000,338,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\conhost.exe
[2012/10/10 06:20:32 | 000,215,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2012/10/10 06:20:30 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2012/10/10 06:20:30 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2012/10/10 06:20:29 | 000,362,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64win.dll
[2012/10/10 06:20:29 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntvdm64.dll
[2012/10/10 06:20:29 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2012/10/10 06:20:29 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64cpu.dll
[2012/10/10 06:20:29 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2012/10/10 06:20:29 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2012/10/10 06:20:29 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2012/10/10 06:20:29 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2012/10/10 06:20:29 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2012/10/10 06:20:29 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2012/10/10 06:20:29 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2012/10/10 06:20:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2012/10/10 06:20:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012/10/10 06:20:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2012/10/10 06:20:28 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2012/10/10 06:20:28 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2012/10/10 06:20:28 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2012/10/10 06:20:27 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2012/10/10 06:20:27 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2012/10/10 06:20:27 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2012/10/10 06:20:27 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2012/10/10 06:20:26 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2012/10/10 06:20:26 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2012/10/10 06:20:26 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2012/10/10 06:20:26 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2012/10/10 06:20:26 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2012/10/10 06:20:26 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2012/10/10 06:20:26 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2012/10/10 06:20:26 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012/10/10 06:20:26 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2012/10/10 06:20:26 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2012/10/10 06:20:26 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/10/10 06:20:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2012/10/10 06:20:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2012/10/10 06:20:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2012/10/10 06:20:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2012/10/10 06:20:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2012/10/10 06:20:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2012/10/10 06:20:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2012/10/10 06:20:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2012/10/10 06:20:25 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2012/10/10 06:20:25 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2012/10/10 06:20:25 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2012/10/10 06:20:24 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2012/10/10 06:20:00 | 005,559,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2012/10/10 06:19:56 | 003,968,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2012/10/10 06:19:56 | 003,914,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2012/10/10 06:19:49 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wintrust.dll
[2012/10/10 06:19:00 | 001,464,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2012/10/10 06:18:58 | 000,140,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2012/10/09 06:14:17 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2 C:\Users\Honor\Documents\*.tmp files -> C:\Users\Honor\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/10/29 08:29:05 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/10/29 08:28:31 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/10/29 08:28:31 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/10/29 08:25:06 | 000,731,420 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/10/29 08:25:06 | 000,632,284 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/10/29 08:25:06 | 000,112,086 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/10/29 08:20:49 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/10/29 08:20:11 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/10/29 08:20:03 | 3217,244,160 | -HS- | M] () – C:\hiberfil.sys
[2012/10/27 12:36:03 | 000,081,278 | —- | M] () – C:\Users\Honor\Documents\museum selection ltd.pdf
[2012/10/27 09:56:39 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Honor\Documents\OTL.exe
[2012/10/27 09:52:02 | 000,000,512 | —- | M] () – C:\Users\Honor\Documents\MBR.dat
[2012/10/26 12:33:37 | 000,281,088 | —- | M] () – C:\Users\Honor\Documents\ark critical study.pub
[2012/10/26 07:46:18 | 000,736,614 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/10/25 12:25:37 | 000,058,642 | —- | M] () – C:\Users\Honor\Documents\Craigton Limited.pdf
[2012/10/25 06:57:57 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/10/24 14:27:19 | 000,005,857 | —- | M] () – C:\Users\Honor\Documents\picaso_guernica.jpg
[2012/10/24 14:24:31 | 000,016,800 | —- | M] () – C:\Users\Honor\Documents\arnolfini_portrait.jpg
[2012/10/24 14:21:19 | 000,001,138 | —- | M] () – C:\Users\Public\Desktop\Upgrade Facebook Chat Experience with fTalk.lnk
[2012/10/24 14:13:31 | 000,294,326 | —- | M] () – C:\Users\Honor\Documents\3148-1320190820-FaceBook-v1_Theme.zip
[2012/10/24 11:14:56 | 000,240,625 | —- | M] () – C:\Users\Honor\Documents\oxford summer evening.png
[2012/10/24 09:52:01 | 000,024,281 | —- | M] () – C:\Users\Honor\Documents\oxford summer evening.jpg
[2012/10/23 16:22:18 | 000,454,472 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/10/23 14:24:39 | 000,001,156 | —- | M] () – C:\Users\Public\Desktop\Pixillion Image Converter.lnk
[2012/10/23 14:24:34 | 000,001,126 | —- | M] () – C:\Users\Public\Desktop\Switch Sound File Converter.lnk
[2012/10/23 14:24:14 | 000,001,110 | —- | M] () – C:\Users\Public\Desktop\Prism Video File Converter.lnk
[2012/10/23 12:14:41 | 000,536,329 | —- | M] () – C:\Users\Honor\Documents\MyBB set-up guide.pdf
[2012/10/23 11:54:43 | 000,502,499 | —- | M] () – C:\Users\Honor\Documents\Install MyBB.zip
[2012/10/23 11:52:11 | 000,001,039 | —- | M] () – C:\Users\Honor\Desktop\Dropbox.lnk
[2012/10/23 11:50:57 | 000,001,049 | —- | M] () – C:\Users\Honor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2012/10/23 11:07:50 | 000,007,225 | —- | M] () – C:\Users\Honor\Documents\Upload.xml
[2012/10/23 11:06:12 | 000,007,229 | —- | M] () – C:\Users\Honor\Documents\FileZilla.xml
[2012/10/23 08:05:12 | 000,001,138 | —- | M] () – C:\Users\Public\Desktop\Express Zip.lnk
[2012/10/23 07:58:39 | 000,000,238 | —- | M] () – C:\Windows\ODBCINST.INI
[2012/10/22 13:51:35 | 000,052,252 | —- | M] () – C:\Users\Honor\Documents\flowchart i.jpg
[2012/10/22 13:50:59 | 000,099,599 | —- | M] () – C:\Users\Honor\Documents\flowchart h.jpg
[2012/10/22 13:50:22 | 000,008,503 | —- | M] () – C:\Users\Honor\Documents\flowchart g.gif
[2012/10/22 13:49:31 | 000,090,344 | —- | M] () – C:\Users\Honor\Documents\flowchart e.png
[2012/10/22 13:47:25 | 000,036,694 | —- | M] () – C:\Users\Honor\Documents\flowchart d.gif
[2012/10/22 13:45:53 | 000,009,263 | —- | M] () – C:\Users\Honor\Documents\flowchart c.gif
[2012/10/22 13:42:01 | 000,220,340 | —- | M] () – C:\Users\Honor\Documents\flowchart b.png
[2012/10/22 13:41:29 | 000,040,892 | —- | M] () – C:\Users\Honor\Documents\flowchart a.jpg
[2012/10/22 11:19:26 | 000,076,627 | —- | M] () – C:\Users\Honor\Documents\Blinc.pdf
[2012/10/18 16:01:10 | 000,108,032 | —- | M] () – C:\Users\Honor\Documents\gordon diagram.pub
[2012/10/16 18:38:14 | 000,172,032 | —- | M] () – C:\Users\Honor\Documents\battle of hastings.pub
[2012/10/16 06:28:35 | 000,010,074 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1309000.009\VT20121008.022
[2012/10/15 17:35:14 | 000,190,464 | —- | M] () – C:\Users\Honor\Documents\beekman.pub
[2012/10/14 16:45:43 | 001,497,088 | —- | M] () – C:\Users\Honor\Documents\charlie gordon 2.pub
[2012/10/14 15:09:54 | 000,001,805 | —- | M] () – C:\Users\Honor\Desktop\Spotify.lnk
[2012/10/13 11:31:45 | 000,002,378 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2012/10/10 07:33:09 | 002,011,827 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1309000.009\Cat.DB
[2012/10/08 19:41:18 | 000,195,584 | —- | M] () – C:\Users\Honor\Documents\biology plan.pub
[2012/10/07 14:18:52 | 001,647,104 | —- | M] () – C:\Users\Honor\Documents\mandarin.pub
[2012/10/06 12:33:49 | 001,584,640 | —- | M] () – C:\Users\Honor\Documents\textiles diagrams.pub
[2012/10/06 10:54:26 | 002,502,656 | —- | M] () – C:\Users\Honor\Documents\textilers diagrams.pub
[2012/10/03 16:10:07 | 000,387,072 | —- | M] () – C:\Users\Honor\Documents\birthday calendar.pub
[2012/10/02 06:40:18 | 000,002,492 | —- | M] () – C:\Users\Public\Desktop\Norton Internet Security.lnk
[2012/09/30 12:15:06 | 000,269,824 | —- | M] () – C:\Users\Honor\Documents\geography revision 2.pub
[2012/09/29 18:54:26 | 000,025,928 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2 C:\Users\Honor\Documents\*.tmp files -> C:\Users\Honor\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/10/27 12:36:03 | 000,081,278 | —- | C] () – C:\Users\Honor\Documents\museum selection ltd.pdf
[2012/10/27 09:52:02 | 000,000,512 | —- | C] () – C:\Users\Honor\Documents\MBR.dat
[2012/10/26 12:33:36 | 000,281,088 | —- | C] () – C:\Users\Honor\Documents\ark critical study.pub
[2012/10/25 12:25:37 | 000,058,642 | —- | C] () – C:\Users\Honor\Documents\Craigton Limited.pdf
[2012/10/25 06:57:57 | 000,001,113 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/10/24 14:27:28 | 000,005,857 | —- | C] () – C:\Users\Honor\Documents\picaso_guernica.jpg
[2012/10/24 14:25:00 | 000,016,800 | —- | C] () – C:\Users\Honor\Documents\arnolfini_portrait.jpg
[2012/10/24 14:21:19 | 000,001,138 | —- | C] () – C:\Users\Public\Desktop\Upgrade Facebook Chat Experience with fTalk.lnk
[2012/10/24 14:13:30 | 000,294,326 | —- | C] () – C:\Users\Honor\Documents\3148-1320190820-FaceBook-v1_Theme.zip
[2012/10/24 11:14:56 | 000,240,625 | —- | C] () – C:\Users\Honor\Documents\oxford summer evening.png
[2012/10/24 09:52:18 | 000,024,281 | —- | C] () – C:\Users\Honor\Documents\oxford summer evening.jpg
[2012/10/23 14:24:38 | 000,001,168 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pixillion Image Converter.lnk
[2012/10/23 14:24:38 | 000,001,156 | —- | C] () – C:\Users\Public\Desktop\Pixillion Image Converter.lnk
[2012/10/23 14:24:33 | 000,001,126 | —- | C] () – C:\Users\Public\Desktop\Switch Sound File Converter.lnk
[2012/10/23 14:24:29 | 000,001,138 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Switch Sound File Converter.lnk
[2012/10/23 14:24:13 | 000,001,110 | —- | C] () – C:\Users\Public\Desktop\Prism Video File Converter.lnk
[2012/10/23 14:24:12 | 000,001,122 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Prism Video File Converter.lnk
[2012/10/23 12:14:41 | 000,536,329 | —- | C] () – C:\Users\Honor\Documents\MyBB set-up guide.pdf
[2012/10/23 11:54:43 | 000,502,499 | —- | C] () – C:\Users\Honor\Documents\Install MyBB.zip
[2012/10/23 11:52:10 | 000,001,039 | —- | C] () – C:\Users\Honor\Desktop\Dropbox.lnk
[2012/10/23 11:50:56 | 000,001,049 | —- | C] () – C:\Users\Honor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2012/10/23 11:07:50 | 000,007,225 | —- | C] () – C:\Users\Honor\Documents\Upload.xml
[2012/10/23 11:01:40 | 000,007,229 | —- | C] () – C:\Users\Honor\Documents\FileZilla.xml
[2012/10/23 08:05:12 | 000,001,150 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Express Zip.lnk
[2012/10/23 08:05:12 | 000,001,138 | —- | C] () – C:\Users\Public\Desktop\Express Zip.lnk
[2012/10/23 07:59:16 | 000,736,614 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/10/23 07:58:39 | 000,000,238 | —- | C] () – C:\Windows\ODBCINST.INI
[2012/10/22 13:51:48 | 000,052,252 | —- | C] () – C:\Users\Honor\Documents\flowchart i.jpg
[2012/10/22 13:51:12 | 000,099,599 | —- | C] () – C:\Users\Honor\Documents\flowchart h.jpg
[2012/10/22 13:50:36 | 000,008,503 | —- | C] () – C:\Users\Honor\Documents\flowchart g.gif
[2012/10/22 13:49:42 | 000,090,344 | —- | C] () – C:\Users\Honor\Documents\flowchart e.png
[2012/10/22 13:47:38 | 000,036,694 | —- | C] () – C:\Users\Honor\Documents\flowchart d.gif
[2012/10/22 13:46:17 | 000,009,263 | —- | C] () – C:\Users\Honor\Documents\flowchart c.gif
[2012/10/22 13:42:13 | 000,220,340 | —- | C] () – C:\Users\Honor\Documents\flowchart b.png
[2012/10/22 13:41:45 | 000,040,892 | —- | C] () – C:\Users\Honor\Documents\flowchart a.jpg
[2012/10/22 11:19:25 | 000,076,627 | —- | C] () – C:\Users\Honor\Documents\Blinc.pdf
[2012/10/18 16:01:09 | 000,108,032 | —- | C] () – C:\Users\Honor\Documents\gordon diagram.pub
[2012/10/16 18:38:13 | 000,172,032 | —- | C] () – C:\Users\Honor\Documents\battle of hastings.pub
[2012/10/15 06:47:43 | 000,190,464 | —- | C] () – C:\Users\Honor\Documents\beekman.pub
[2012/10/14 16:45:42 | 001,497,088 | —- | C] () – C:\Users\Honor\Documents\charlie gordon 2.pub
[2012/10/14 15:09:54 | 000,001,791 | —- | C] () – C:\Users\Honor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
[2012/10/14 15:09:53 | 000,001,805 | —- | C] () – C:\Users\Honor\Desktop\Spotify.lnk
[2012/10/08 19:41:16 | 000,195,584 | —- | C] () – C:\Users\Honor\Documents\biology plan.pub
[2012/10/06 10:54:15 | 001,584,640 | —- | C] () – C:\Users\Honor\Documents\textiles diagrams.pub
[2012/10/04 16:08:09 | 001,647,104 | —- | C] () – C:\Users\Honor\Documents\mandarin.pub
[2012/10/03 15:50:17 | 000,387,072 | —- | C] () – C:\Users\Honor\Documents\birthday calendar.pub
[2012/09/30 12:15:04 | 000,269,824 | —- | C] () – C:\Users\Honor\Documents\geography revision 2.pub
[2011/01/20 16:30:42 | 000,000,000 | —- | C] () – C:\Windows\setup32.INI
[2011/01/08 13:32:07 | 000,005,632 | —- | C] () – C:\Users\Honor\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2009/07/14 04:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/09 05:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/09 04:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/14 01:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 12:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/14 01:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== Files - Unicode (All) ==========
[2012/10/16 06:49:19 | 000,013,465 | —- | M] ()(C:\Users\Honor\Documents\??.docx) – C:\Users\Honor\Documents\中国.docx
[2012/10/16 06:49:17 | 000,013,465 | —- | C] ()(C:\Users\Honor\Documents\??.docx) – C:\Users\Honor\Documents\中国.docx
[2012/01/29 10:12:16 | 000,016,164 | —- | M] ()(C:\Users\Honor\Documents\????.docx) – C:\Users\Honor\Documents\蛮大日内.docx
[2012/01/28 20:37:36 | 000,016,164 | —- | C] ()(C:\Users\Honor\Documents\????.docx) – C:\Users\Honor\Documents\蛮大日内.docx

========== Alternate Data Streams ==========

@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:D1B5B4F1

< End of report >
Hi markshelton,

1. Is the browser issue isolated to Internet Explorer? (i.e. Firefox, Chrome)

2. You have some files that I need you to tell me what they are:

C:\Users\Honor\Documents\中国.docx
C:\Users\Honor\Documents\蛮大日内.docx

= = = = = = = = = =

Run OTL.exe
Windows Vista and Windows 7 users Right Click and select "Run as Administrator"
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2101}
    IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2101}: "URL" = http://dts.search-results.com/sr?src=ieb&a…q={searchTerms}
    IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2101}
    IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2101}: "URL" = http://dts.search-results.com/sr?src=ieb&a…q={searchTerms}
    IE - HKCU\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2101}
    IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2101}: "URL" = http://dts.search-results.com/sr?src=ieb&a…q={searchTerms}
    CHR - homepage: http://www.searchnu.com
    
    :Commands
    [purity]
    [createrestorepoint]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
In your next post please provide the following:
  • OTL.txt
  • Answer about browser issue & files listed above.
Hi OCD

Many thanks for your continued help.

When I boot up IE I still get two tabs rather than one. However, the Malwarebytes message now doesn't appear when I navigate on either tab. I installed Firefox and I don't get two tabs when I go into Firefox.

The two files you mention are homework and cam be deleted.

It would be good to elimiate the problem of the two tabs appearing when I go into IE if at all possible


Many thanks for your help.

Kind regards,

Mark



Please find the OTL logs below

OTL logfile created on: 10/30/2012 7:52:04 AM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Honor\Documents
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

4.00 Gb Total Physical Memory | 2.15 Gb Available Physical Memory | 53.77% Memory free
7.99 Gb Paging File | 5.83 Gb Available in Paging File | 73.02% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 297.81 Gb Total Space | 246.44 Gb Free Space | 82.75% Space Free | Partition Type: NTFS
Drive F: | 298.09 Gb Total Space | 297.99 Gb Free Space | 99.97% Space Free | Partition Type: NTFS

Computer Name: HONOR-PC | User Name: Honor | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Honor\My Documents\OTL.exe File not found
PRC - File not found
PRC - C:\Users\Honor\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Users\Honor\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe ()
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10m_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\STMicroelectronics\Accelerometer\FF_Protection.exe ()
PRC - C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)


========== Modules (No Company Name) ==========

MOD - C:\Users\Honor\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\STMicroelectronics\Accelerometer\FF_Protection.exe ()


========== Services (SafeList) ==========

SRV:64bit: - (MySQL55) – C:\Program Files\MySQL\MySQL Server 5.5\bin\mysqld.exe ()
SRV:64bit: - (ACProtector) – C:\Program Files\AxiomCoders\ACProtector\ACProtector.exe (AxiomCoders)
SRV:64bit: - (wltrysvc) – C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE ()
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (STacSV) – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (AESTFilters) – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\AESTSr64.exe (Andrea Electronics Corporation)
SRV:64bit: - (O2FLASH) – C:\Windows\SysNative\drivers\o2flash.exe (O2Micro International)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (NIS) – C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\ccSvcHst.exe (Symantec Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (McComponentHostService) – C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe (IDT, Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (AESTFilters) – C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\AESTSr64.exe (Andrea Electronics Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (SRTSPX) – C:\Windows\SysNative\drivers\NISx64\1309000.009\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\drivers\NISx64\1309000.009\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (ccSet_NIS) – C:\Windows\SysNative\drivers\NISx64\1309000.009\ccsetx64.sys (Symantec Corporation)
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\drivers\NISx64\1309000.009\symefa64.sys (Symantec Corporation)
DRV:64bit: - (SymNetS) – C:\Windows\SysNative\drivers\NISx64\1309000.009\symnets.sys (Symantec Corporation)
DRV:64bit: - (SymIRON) – C:\Windows\SysNative\drivers\NISx64\1309000.009\ironx64.sys (Symantec Corporation)
DRV:64bit: - (SymEvent) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (SymDS) – C:\Windows\SysNative\drivers\NISx64\1309000.009\symds64.sys (Symantec Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (BCM42RLY) – C:\Windows\SysNative\drivers\bcm42rly.sys (Broadcom Corporation)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ROOTMODEM) – C:\Windows\SysNative\drivers\rootmdm.sys (Microsoft Corporation)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation )
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (AtiHdmiService) – C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Research Inc.)
DRV:64bit: - (Acceler) – C:\Windows\SysNative\drivers\Acceler.sys (ST Microelectronics)
DRV:64bit: - (stdflt) – C:\Windows\SysNative\drivers\stdflt.sys (ST Microelectronics)
DRV:64bit: - (O2MDGRDR) – C:\Windows\SysNative\drivers\o2mdgx64.sys (O2Micro )
DRV:64bit: - (CtClsFlt) – C:\Windows\SysNative\drivers\CtClsFlt.sys (Creative Technology Ltd.)
DRV:64bit: - (RimUsb) – C:\Windows\SysNative\drivers\RimUsb_AMD64.sys (Research In Motion Limited)
DRV:64bit: - (RimVSerPort) – C:\Windows\SysNative\drivers\RimSerial_AMD64.sys (Research in Motion Ltd)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\VirusDefs\20121029.002\ex64.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\VirusDefs\20121029.002\eng64.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\BASHDefs\20121005.002\BHDrvx64.sys (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\IPSDefs\20121027.001\IDSviA64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {3bbd3c14-4c16-4989-8366-95bc9179779d} - No CLSID value found
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.co.uk/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-GB
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 31 65 2C 20 88 B4 CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…1I7ADFA_enGB413
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@t-immersion.com/DFusionHomeWebPlugIn: C:\Program Files (x86)\Total Immersion\DFusionHomeWebPlugIn\NPDFusionWebFirefox.dll (Total Immersion)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\IPSFFPlgn\ [2012/01/31 17:02:38 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\coFFPlgn\ [2012/10/30 07:46:30 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - homepage: http://www.searchnu.com
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://www.searchnu.com
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.79\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.94\pdf.dll
CHR - plugin: Skype Click to Call (Enabled) = C:\Users\Honor\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.10.0.9560_0\npSkypeChromePlugin.dll
CHR - plugin: Norton Confidential (Enabled) = C:\Users\Honor\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.5.6.10_0\npcoplgn.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: D'Fusion @Home Web Plug-In (2.30.11285.AR23) (Enabled) = C:\Program Files (x86)\Total Immersion\DFusionHomeWebPlugIn\NPDFusionWebFirefox.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
CHR - Extension: YouTube = C:\Users\Honor\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\Honor\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Skype Click to Call = C:\Users\Honor\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.10.0.9560_0\
CHR - Extension: Norton Identity Protection = C:\Users\Honor\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.5.6.10_0\
CHR - Extension: Gmail = C:\Users\Honor\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009/06/10 21:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\coieplg.dll (Symantec Corporation)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\coieplg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE (Dell Inc.)
O4:64bit: - HKLM..\Run: [FreeFallProtection] C:\Program Files (x86)\STMicroelectronics\Accelerometer\FF_Protection.exe ()
O4:64bit: - HKLM..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [dscactivate] C:\Program Files (x86)\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.)
O4 - HKCU..\Run: [Spotify] C:\Users\Honor\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd)
O4 - HKCU..\Run: [Spotify Web Helper] C:\Users\Honor\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe ()
O4 - Startup: C:\Users\Honor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Honor\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\AxiomLSPx64.dll (AxiomCoders)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\AxiomLSPx64.dll (AxiomCoders)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\AxiomLSPx64.dll (AxiomCoders)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\AxiomLSPx64.dll (AxiomCoders)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000015 - C:\Windows\AxiomLSPx64.dll (AxiomCoders)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\AxiomLSP.dll (AxiomCoders)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\AxiomLSP.dll (AxiomCoders)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\AxiomLSP.dll (AxiomCoders)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\AxiomLSP.dll (AxiomCoders)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Windows\AxiomLSP.dll (AxiomCoders)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FAB2BB9D-91E9-457E-9D42-75A7FCCBBC00} http://wondla.com/plugin/DFusionHomeWebPlugIn.Installer.exe (CDFusionActiveXCtl Object)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/2.9.3.0…inAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{83065E13-A9E6-4C79-B19A-99C9780E8BD0}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B090AE88-5745-4A13-B2CE-92B435EB45A7}: DhcpNameServer = 0.0.0.0
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/10/28 07:16:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2012/10/27 21:05:05 | 000,000,000 | —D | C] – C:\_OTL
[2012/10/27 09:56:38 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Honor\Documents\OTL.exe
[2012/10/27 09:49:29 | 000,000,000 | —D | C] – C:\New folder
[2012/10/25 06:58:07 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Roaming\Malwarebytes
[2012/10/25 06:57:56 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/10/25 06:57:54 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/10/25 06:57:50 | 000,025,928 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2012/10/25 06:57:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/10/24 14:21:28 | 000,000,000 | —D | C] – C:\ProgramData\boost_interprocess
[2012/10/24 14:13:49 | 000,000,000 | —D | C] – C:\Users\Honor\Documents\3148-1320190820-FaceBook-v1_Theme
[2012/10/24 12:44:39 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Roaming\Oracle
[2012/10/24 12:44:36 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Local\assembly
[2012/10/24 09:37:38 | 000,000,000 | —D | C] – C:\Users\Honor\Documents\2207-1281768339-thecure
[2012/10/24 09:25:04 | 000,000,000 | —D | C] – C:\Users\Honor\Documents\1830-1302322512-DarkFusion
[2012/10/24 06:40:03 | 000,000,000 | —D | C] – C:\Users\Honor\Documents\3120-1317633656-2.0 Inspired
[2012/10/23 16:46:04 | 000,000,000 | —D | C] – C:\Users\Honor\Documents\1407-1328561066-Google-SEO-1.6.3
[2012/10/23 15:21:06 | 000,000,000 | —D | C] – C:\Users\Honor\Documents\2283-1284663245-Archivio
[2012/10/23 14:41:30 | 000,000,000 | —D | C] – C:\Users\Honor\Documents\2125-1281218688-Apart 1
[2012/10/23 14:24:43 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Graphics Related Programs
[2012/10/23 14:24:43 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Audio Related Programs
[2012/10/23 14:24:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Video Related Programs
[2012/10/23 14:23:39 | 000,000,000 | —D | C] – C:\Users\Honor\Documents\2098-1281619591-BlueVision-ACP-12
[2012/10/23 11:55:06 | 000,000,000 | —D | C] – C:\Users\Honor\Documents\Install MyBB
[2012/10/23 11:52:10 | 000,000,000 | R–D | C] – C:\Users\Honor\Dropbox
[2012/10/23 11:50:38 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2012/10/23 11:49:48 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Roaming\Dropbox
[2012/10/23 09:49:03 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Roaming\FileZilla
[2012/10/23 09:48:52 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
[2012/10/23 09:48:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\FileZilla FTP Client
[2012/10/23 08:05:16 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
[2012/10/23 08:05:12 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Utilities
[2012/10/23 08:04:06 | 000,000,000 | —D | C] – C:\MyBB
[2012/10/23 08:01:43 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Roaming\MySQL
[2012/10/23 07:57:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MySQL
[2012/10/23 07:57:41 | 000,000,000 | —D | C] – C:\Program Files\MySQL
[2012/10/23 07:55:34 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MySQL
[2012/10/23 07:55:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\MySQL
[2012/10/23 07:55:27 | 000,000,000 | —D | C] – C:\ProgramData\MySQL
[2012/10/14 15:09:56 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Local\Spotify
[2012/10/14 15:08:46 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Roaming\Spotify
[2012/10/14 15:08:21 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Local\Deployment
[2012/10/14 15:08:21 | 000,000,000 | —D | C] – C:\Users\Honor\AppData\Local\Apps
[2012/10/10 06:20:33 | 001,162,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2012/10/10 06:20:33 | 000,424,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\KernelBase.dll
[2012/10/10 06:20:32 | 000,338,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\conhost.exe
[2012/10/10 06:20:32 | 000,215,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2012/10/10 06:20:30 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2012/10/10 06:20:30 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2012/10/10 06:20:29 | 000,362,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64win.dll
[2012/10/10 06:20:29 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntvdm64.dll
[2012/10/10 06:20:29 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2012/10/10 06:20:29 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64cpu.dll
[2012/10/10 06:20:29 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2012/10/10 06:20:29 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2012/10/10 06:20:29 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2012/10/10 06:20:29 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2012/10/10 06:20:29 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2012/10/10 06:20:29 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2012/10/10 06:20:29 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2012/10/10 06:20:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2012/10/10 06:20:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012/10/10 06:20:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2012/10/10 06:20:28 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2012/10/10 06:20:28 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2012/10/10 06:20:28 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2012/10/10 06:20:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2012/10/10 06:20:27 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2012/10/10 06:20:27 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2012/10/10 06:20:27 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2012/10/10 06:20:27 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2012/10/10 06:20:26 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2012/10/10 06:20:26 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2012/10/10 06:20:26 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2012/10/10 06:20:26 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2012/10/10 06:20:26 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2012/10/10 06:20:26 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2012/10/10 06:20:26 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2012/10/10 06:20:26 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012/10/10 06:20:26 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2012/10/10 06:20:26 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2012/10/10 06:20:26 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/10/10 06:20:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2012/10/10 06:20:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2012/10/10 06:20:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2012/10/10 06:20:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2012/10/10 06:20:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2012/10/10 06:20:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2012/10/10 06:20:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2012/10/10 06:20:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2012/10/10 06:20:25 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2012/10/10 06:20:25 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2012/10/10 06:20:25 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2012/10/10 06:20:24 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2012/10/10 06:20:00 | 005,559,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2012/10/10 06:19:56 | 003,968,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2012/10/10 06:19:56 | 003,914,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2012/10/10 06:19:49 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wintrust.dll
[2012/10/10 06:19:00 | 001,464,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2012/10/10 06:18:58 | 000,140,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2012/10/09 06:14:17 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2 C:\Users\Honor\Documents\*.tmp files -> C:\Users\Honor\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/10/30 07:54:31 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/10/30 07:54:31 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/10/30 07:51:39 | 000,731,420 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/10/30 07:51:39 | 000,632,284 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/10/30 07:51:39 | 000,112,086 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/10/30 07:47:04 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/10/30 07:45:52 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/10/30 07:45:46 | 3217,244,160 | -HS- | M] () – C:\hiberfil.sys
[2012/10/29 19:29:00 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/10/29 14:50:57 | 000,287,744 | —- | M] () – C:\Users\Honor\Documents\popart.pub
[2012/10/27 12:36:03 | 000,081,278 | —- | M] () – C:\Users\Honor\Documents\museum selection ltd.pdf
[2012/10/27 09:56:39 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Honor\Documents\OTL.exe
[2012/10/27 09:52:02 | 000,000,512 | —- | M] () – C:\Users\Honor\Documents\MBR.dat
[2012/10/26 12:33:37 | 000,281,088 | —- | M] () – C:\Users\Honor\Documents\ark critical study.pub
[2012/10/26 07:46:18 | 000,736,614 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/10/25 12:25:37 | 000,058,642 | —- | M] () – C:\Users\Honor\Documents\Craigton Limited.pdf
[2012/10/25 06:57:57 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/10/24 14:27:19 | 000,005,857 | —- | M] () – C:\Users\Honor\Documents\picaso_guernica.jpg
[2012/10/24 14:24:31 | 000,016,800 | —- | M] () – C:\Users\Honor\Documents\arnolfini_portrait.jpg
[2012/10/24 14:21:19 | 000,001,138 | —- | M] () – C:\Users\Public\Desktop\Upgrade Facebook Chat Experience with fTalk.lnk
[2012/10/24 14:13:31 | 000,294,326 | —- | M] () – C:\Users\Honor\Documents\3148-1320190820-FaceBook-v1_Theme.zip
[2012/10/24 11:14:56 | 000,240,625 | —- | M] () – C:\Users\Honor\Documents\oxford summer evening.png
[2012/10/24 09:52:01 | 000,024,281 | —- | M] () – C:\Users\Honor\Documents\oxford summer evening.jpg
[2012/10/23 16:22:18 | 000,454,472 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/10/23 14:24:39 | 000,001,156 | —- | M] () – C:\Users\Public\Desktop\Pixillion Image Converter.lnk
[2012/10/23 14:24:34 | 000,001,126 | —- | M] () – C:\Users\Public\Desktop\Switch Sound File Converter.lnk
[2012/10/23 14:24:14 | 000,001,110 | —- | M] () – C:\Users\Public\Desktop\Prism Video File Converter.lnk
[2012/10/23 12:14:41 | 000,536,329 | —- | M] () – C:\Users\Honor\Documents\MyBB set-up guide.pdf
[2012/10/23 11:54:43 | 000,502,499 | —- | M] () – C:\Users\Honor\Documents\Install MyBB.zip
[2012/10/23 11:52:11 | 000,001,039 | —- | M] () – C:\Users\Honor\Desktop\Dropbox.lnk
[2012/10/23 11:50:57 | 000,001,049 | —- | M] () – C:\Users\Honor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2012/10/23 11:07:50 | 000,007,225 | —- | M] () – C:\Users\Honor\Documents\Upload.xml
[2012/10/23 11:06:12 | 000,007,229 | —- | M] () – C:\Users\Honor\Documents\FileZilla.xml
[2012/10/23 08:05:12 | 000,001,138 | —- | M] () – C:\Users\Public\Desktop\Express Zip.lnk
[2012/10/23 07:58:39 | 000,000,238 | —- | M] () – C:\Windows\ODBCINST.INI
[2012/10/22 13:51:35 | 000,052,252 | —- | M] () – C:\Users\Honor\Documents\flowchart i.jpg
[2012/10/22 13:50:59 | 000,099,599 | —- | M] () – C:\Users\Honor\Documents\flowchart h.jpg
[2012/10/22 13:50:22 | 000,008,503 | —- | M] () – C:\Users\Honor\Documents\flowchart g.gif
[2012/10/22 13:49:31 | 000,090,344 | —- | M] () – C:\Users\Honor\Documents\flowchart e.png
[2012/10/22 13:47:25 | 000,036,694 | —- | M] () – C:\Users\Honor\Documents\flowchart d.gif
[2012/10/22 13:45:53 | 000,009,263 | —- | M] () – C:\Users\Honor\Documents\flowchart c.gif
[2012/10/22 13:42:01 | 000,220,340 | —- | M] () – C:\Users\Honor\Documents\flowchart b.png
[2012/10/22 13:41:29 | 000,040,892 | —- | M] () – C:\Users\Honor\Documents\flowchart a.jpg
[2012/10/22 11:19:26 | 000,076,627 | —- | M] () – C:\Users\Honor\Documents\Blinc.pdf
[2012/10/18 16:01:10 | 000,108,032 | —- | M] () – C:\Users\Honor\Documents\gordon diagram.pub
[2012/10/16 18:38:14 | 000,172,032 | —- | M] () – C:\Users\Honor\Documents\battle of hastings.pub
[2012/10/16 06:28:35 | 000,010,074 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1309000.009\VT20121008.022
[2012/10/15 17:35:14 | 000,190,464 | —- | M] () – C:\Users\Honor\Documents\beekman.pub
[2012/10/14 16:45:43 | 001,497,088 | —- | M] () – C:\Users\Honor\Documents\charlie gordon 2.pub
[2012/10/14 15:09:54 | 000,001,805 | —- | M] () – C:\Users\Honor\Desktop\Spotify.lnk
[2012/10/13 11:31:45 | 000,002,378 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2012/10/10 07:33:09 | 002,011,827 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1309000.009\Cat.DB
[2012/10/08 19:41:18 | 000,195,584 | —- | M] () – C:\Users\Honor\Documents\biology plan.pub
[2012/10/07 14:18:52 | 001,647,104 | —- | M] () – C:\Users\Honor\Documents\mandarin.pub
[2012/10/06 12:33:49 | 001,584,640 | —- | M] () – C:\Users\Honor\Documents\textiles diagrams.pub
[2012/10/06 10:54:26 | 002,502,656 | —- | M] () – C:\Users\Honor\Documents\textilers diagrams.pub
[2012/10/03 16:10:07 | 000,387,072 | —- | M] () – C:\Users\Honor\Documents\birthday calendar.pub
[2012/10/02 06:40:18 | 000,002,492 | —- | M] () – C:\Users\Public\Desktop\Norton Internet Security.lnk
[2012/09/30 12:15:06 | 000,269,824 | —- | M] () – C:\Users\Honor\Documents\geography revision 2.pub
[2 C:\Users\Honor\Documents\*.tmp files -> C:\Users\Honor\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/10/29 13:27:54 | 000,287,744 | —- | C] () – C:\Users\Honor\Documents\popart.pub
[2012/10/27 12:36:03 | 000,081,278 | —- | C] () – C:\Users\Honor\Documents\museum selection ltd.pdf
[2012/10/27 09:52:02 | 000,000,512 | —- | C] () – C:\Users\Honor\Documents\MBR.dat
[2012/10/26 12:33:36 | 000,281,088 | —- | C] () – C:\Users\Honor\Documents\ark critical study.pub
[2012/10/25 12:25:37 | 000,058,642 | —- | C] () – C:\Users\Honor\Documents\Craigton Limited.pdf
[2012/10/25 06:57:57 | 000,001,113 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/10/24 14:27:28 | 000,005,857 | —- | C] () – C:\Users\Honor\Documents\picaso_guernica.jpg
[2012/10/24 14:25:00 | 000,016,800 | —- | C] () – C:\Users\Honor\Documents\arnolfini_portrait.jpg
[2012/10/24 14:21:19 | 000,001,138 | —- | C] () – C:\Users\Public\Desktop\Upgrade Facebook Chat Experience with fTalk.lnk
[2012/10/24 14:13:30 | 000,294,326 | —- | C] () – C:\Users\Honor\Documents\3148-1320190820-FaceBook-v1_Theme.zip
[2012/10/24 11:14:56 | 000,240,625 | —- | C] () – C:\Users\Honor\Documents\oxford summer evening.png
[2012/10/24 09:52:18 | 000,024,281 | —- | C] () – C:\Users\Honor\Documents\oxford summer evening.jpg
[2012/10/23 14:24:38 | 000,001,168 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pixillion Image Converter.lnk
[2012/10/23 14:24:38 | 000,001,156 | —- | C] () – C:\Users\Public\Desktop\Pixillion Image Converter.lnk
[2012/10/23 14:24:33 | 000,001,126 | —- | C] () – C:\Users\Public\Desktop\Switch Sound File Converter.lnk
[2012/10/23 14:24:29 | 000,001,138 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Switch Sound File Converter.lnk
[2012/10/23 14:24:13 | 000,001,110 | —- | C] () – C:\Users\Public\Desktop\Prism Video File Converter.lnk
[2012/10/23 14:24:12 | 000,001,122 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Prism Video File Converter.lnk
[2012/10/23 12:14:41 | 000,536,329 | —- | C] () – C:\Users\Honor\Documents\MyBB set-up guide.pdf
[2012/10/23 11:54:43 | 000,502,499 | —- | C] () – C:\Users\Honor\Documents\Install MyBB.zip
[2012/10/23 11:52:10 | 000,001,039 | —- | C] () – C:\Users\Honor\Desktop\Dropbox.lnk
[2012/10/23 11:50:56 | 000,001,049 | —- | C] () – C:\Users\Honor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2012/10/23 11:07:50 | 000,007,225 | —- | C] () – C:\Users\Honor\Documents\Upload.xml
[2012/10/23 11:01:40 | 000,007,229 | —- | C] () – C:\Users\Honor\Documents\FileZilla.xml
[2012/10/23 08:05:12 | 000,001,150 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Express Zip.lnk
[2012/10/23 08:05:12 | 000,001,138 | —- | C] () – C:\Users\Public\Desktop\Express Zip.lnk
[2012/10/23 07:59:16 | 000,736,614 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/10/23 07:58:39 | 000,000,238 | —- | C] () – C:\Windows\ODBCINST.INI
[2012/10/22 13:51:48 | 000,052,252 | —- | C] () – C:\Users\Honor\Documents\flowchart i.jpg
[2012/10/22 13:51:12 | 000,099,599 | —- | C] () – C:\Users\Honor\Documents\flowchart h.jpg
[2012/10/22 13:50:36 | 000,008,503 | —- | C] () – C:\Users\Honor\Documents\flowchart g.gif
[2012/10/22 13:49:42 | 000,090,344 | —- | C] () – C:\Users\Honor\Documents\flowchart e.png
[2012/10/22 13:47:38 | 000,036,694 | —- | C] () – C:\Users\Honor\Documents\flowchart d.gif
[2012/10/22 13:46:17 | 000,009,263 | —- | C] () – C:\Users\Honor\Documents\flowchart c.gif
[2012/10/22 13:42:13 | 000,220,340 | —- | C] () – C:\Users\Honor\Documents\flowchart b.png
[2012/10/22 13:41:45 | 000,040,892 | —- | C] () – C:\Users\Honor\Documents\flowchart a.jpg
[2012/10/22 11:19:25 | 000,076,627 | —- | C] () – C:\Users\Honor\Documents\Blinc.pdf
[2012/10/18 16:01:09 | 000,108,032 | —- | C] () – C:\Users\Honor\Documents\gordon diagram.pub
[2012/10/16 18:38:13 | 000,172,032 | —- | C] () – C:\Users\Honor\Documents\battle of hastings.pub
[2012/10/15 06:47:43 | 000,190,464 | —- | C] () – C:\Users\Honor\Documents\beekman.pub
[2012/10/14 16:45:42 | 001,497,088 | —- | C] () – C:\Users\Honor\Documents\charlie gordon 2.pub
[2012/10/14 15:09:54 | 000,001,791 | —- | C] () – C:\Users\Honor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
[2012/10/14 15:09:53 | 000,001,805 | —- | C] () – C:\Users\Honor\Desktop\Spotify.lnk
[2012/10/08 19:41:16 | 000,195,584 | —- | C] () – C:\Users\Honor\Documents\biology plan.pub
[2012/10/06 10:54:15 | 001,584,640 | —- | C] () – C:\Users\Honor\Documents\textiles diagrams.pub
[2012/10/04 16:08:09 | 001,647,104 | —- | C] () – C:\Users\Honor\Documents\mandarin.pub
[2012/10/03 15:50:17 | 000,387,072 | —- | C] () – C:\Users\Honor\Documents\birthday calendar.pub
[2012/09/30 12:15:04 | 000,269,824 | —- | C] () – C:\Users\Honor\Documents\geography revision 2.pub
[2011/01/20 16:30:42 | 000,000,000 | —- | C] () – C:\Windows\setup32.INI
[2011/01/08 13:32:07 | 000,005,632 | —- | C] () – C:\Users\Honor\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2009/07/14 04:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/09 05:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/09 04:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/14 01:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 12:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/14 01:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== Files - Unicode (All) ==========
[2012/10/16 06:49:19 | 000,013,465 | —- | M] ()(C:\Users\Honor\Documents\??.docx) – C:\Users\Honor\Documents\中国.docx
[2012/10/16 06:49:17 | 000,013,465 | —- | C] ()(C:\Users\Honor\Documents\??.docx) – C:\Users\Honor\Documents\中国.docx
[2012/01/29 10:12:16 | 000,016,164 | —- | M] ()(C:\Users\Honor\Documents\????.docx) – C:\Users\Honor\Documents\蛮大日内.docx
[2012/01/28 20:37:36 | 000,016,164 | —- | C] ()(C:\Users\Honor\Documents\????.docx) – C:\Users\Honor\Documents\蛮大日内.docx

========== Alternate Data Streams ==========

@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:D1B5B4F1

< End of report >


All processes killed
========== OTL ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2101}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2101}\ not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2101}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2101}\ not found.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2101}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2101}\ not found.
Use Chrome's Settings page to change the HomePage.
========== COMMANDS ==========
Restore point Set: OTL Restore Point

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Honor
->Temp folder emptied: 6106885 bytes
->Temporary Internet Files folder emptied: 257536028 bytes
->Google Chrome cache emptied: 25187983 bytes
->Apple Safari cache emptied: 0 bytes
->Flash cache emptied: 2707 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 3738 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 275.00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 10302012_073736

Files\Folders moved on Reboot…
C:\Users\Honor\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\Honor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\ProgramData\AxiomCoders\LSPEngine\engine.log moved successfully.
C:\Users\Honor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\NWV7130F\index[1].htm moved successfully.
C:\Users\Honor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\JJW0TJS9\google_co_uk[1].htm moved successfully.
C:\Users\Honor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\53R0KSKS\iframe[1].htm moved successfully.
C:\Users\Honor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully.
C:\Users\Honor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully.
File\Folder C:\Users\Honor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{1500AC9F-1F0B-493C-9953-DABD4562633E}.tmp not found!
File\Folder C:\Users\Honor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{52F06C7B-D4A8-4CE3-B075-6B89E970F4DE}.tmp not found!
File\Folder C:\Users\Honor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{80ACBCB5-0321-487E-89C2-1DA2B5D79163}.tmp not found!
File\Folder C:\Users\Honor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{E830AA5F-4762-4B4E-A56D-B573D51B9709}.tmp not found!

PendingFileRenameOperations files…

Registry entries deleted on Reboot…
Hi markshelton,

Let's try and reset your Internet Explorer setting back to default to see if that clears up your two tab issue. After taking the steps outlined below please test Internet Explorer and post results in your next reply.

To Reset Internet Explorer Settings
  • Close all Internet Explorer and Windows Explorer windows that are currently open.
  • Open Internet Explorer.
  • Click the Tools button [external image: Posted Image], and then click Internet options.
  • Click the Advanced tab, and then click Reset.
  • Select the Delete personal settings check box if you would also like to remove browsing history, search providers, Accelerators, home pages, Tracking Protection, and ActiveX Filtering data.
  • In the Reset Internet Explorer Settings dialog box, click Reset.
  • When Internet Explorer finishes applying default settings, click Close, and then click OK.
  • Close Internet Explorer.
Next

Reset / Change Homepage in Chrome
  • Click the Chrome menu [external image: Posted Image] on the browser toolbar.
  • Select Settings.
  • Add the home button to the browser toolbar
    Home page button is off by default. Select the "Show Home button" checkbox in the "Appearance" section to show it on the browser toolbar.
  • Set your home page
    When the "Show Home button" checkbox is selected, a web address appears below it. This is the address you will want to change. (hxxp://www.searchnu.com)
    Click Change to enter a link (i.e. http://www.google.com). You can also choose the New Tab page as your home page.
In your next post please provide the following:
  • Did that fix your Internet Explorer issues?
  • Do you have any remaining issues we haven't addressed?
Dear OCD That's fixed it - all back to nromal. I really want to thank you for all your patience, commitment and efforts to help me - it's amazing to have this resource to help people out when they have problems. Kind regards, Mark
Hi markshelton,

That's fixed it - all back to normal

Great to hear. I would like to do one last scan just to be certain we haven't missed anything. Then we will do a little housekeeping and get you on your way. :D

  • Re-run OTL (it should be located on your desktop).
  • Windows Vista and Windows 7 users Right Click and select "Run as Administrator" on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Uncheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open one notepad window. OTL.Txt.
    Note:The log can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of the file, and post it with your next reply.
In your next post please provide the following:
  • OTL.txt

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI