This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Adware at bottom of browser screen

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

I have a computer running Windows 7 and generally use Firefox (version 16 currently) for browsing. Few days ago I been searching for an image and one of the results in Google Images redirected me to a strange website, at which this ad appeared for the first time. I thought this is something site-specific, however later similar adds starting popping up during all my browsing sessions with almost all the websites. Here I attach the screenshot:

[external image: Posted Image]

The dog in the corner is this very ad. Your forum does not have such advertising (I checked on another computer), as well as many other websites visiting which I see similar ads.

I scanned my computer with different malware removal tools including MalWare Bytes, Free Version of Ad-Aware, Norton, Super AntiSpyware. All of them detected certain threats but neither of these threats resolved the issue with the ads.

Also, searching for similar questions I found this thread on your forum - http://forums.whatthetech.com/index.php?showtopic=123243

The case is similar to mine, with the difference that I do not have redirecting of the addresses.

Here are the logs requested:

OTL logfile created on: 02.11.2012 13:47:42 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\George\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000419 | Country: Russia | Language: RUS | Date Format: dd.MM.yyyy

7,98 Gb Total Physical Memory | 6,00 Gb Available Physical Memory | 75,21% Memory free
15,96 Gb Paging File | 13,42 Gb Available in Paging File | 84,07% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 121,00 Gb Total Space | 32,85 Gb Free Space | 27,15% Space Free | Partition Type: NTFS
Drive D: | 160,20 Gb Total Space | 7,64 Gb Free Space | 4,77% Space Free | Partition Type: NTFS
Drive E: | 650,21 Gb Total Space | 7,02 Gb Free Space | 1,08% Space Free | Partition Type: NTFS
Drive F: | 232,88 Gb Total Space | 11,72 Gb Free Space | 5,03% Space Free | Partition Type: NTFS
Drive G: | 465,75 Gb Total Space | 6,13 Gb Free Space | 1,32% Space Free | Partition Type: NTFS
Drive H: | 465,75 Gb Total Space | 0,96 Gb Free Space | 0,21% Space Free | Partition Type: NTFS
Drive I: | 465,75 Gb Total Space | 0,85 Gb Free Space | 0,18% Space Free | Partition Type: NTFS
Drive J: | 465,75 Gb Total Space | 3,20 Gb Free Space | 0,69% Space Free | Partition Type: NTFS

Computer Name: INTEL-I5 | User Name: George | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012.11.02 13:45:42 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\George\Desktop\OTL.exe
PRC - [2012.10.27 08:04:25 | 000,917,984 | —- | M] (Mozilla Corporation) – C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2012.09.29 19:54:26 | 000,766,536 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012.09.29 19:54:26 | 000,676,936 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.09.29 19:54:26 | 000,399,432 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012.09.20 15:03:20 | 001,236,368 | —- | M] (Lavasoft Limited) – C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe
PRC - [2012.09.20 15:03:16 | 018,941,832 | —- | M] (Lavasoft Limited) – C:\Program Files (x86)\Ad-Aware Antivirus\AdAware.exe
PRC - [2012.09.12 14:22:30 | 001,807,560 | —- | M] (Adobe Systems, Inc.) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe
PRC - [2012.08.08 10:17:00 | 000,540,056 | —- | M] (Lavasoft) – C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe
PRC - [2012.08.04 14:41:24 | 001,022,352 | —- | M] (BitTorrent, Inc.) – C:\Program Files (x86)\uTorrent\uTorrent.exe
PRC - [2012.01.03 15:10:42 | 000,063,928 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011.12.19 13:20:06 | 003,289,032 | —- | M] (GFI Software) – C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe
PRC - [2011.09.08 15:38:22 | 003,425,688 | —- | M] (Tonec Inc.) – C:\Program Files (x86)\Internet Download Manager\IDMan.exe
PRC - [2011.04.05 10:39:46 | 001,518,976 | —- | M] () – C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Service.exe
PRC - [2010.07.01 16:31:36 | 002,153,336 | —- | M] () – C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe
PRC - [2010.01.22 21:48:02 | 000,638,976 | —- | M] (Drakenscripts.co.cc) – C:\Program Files (x86)\StickyNotes\SNTBHider.exe
PRC - [2009.12.11 17:24:24 | 000,816,392 | —- | M] (ABBYY) – C:\Program Files (x86)\Common Files\ABBYY\Lingvo\14.0\Licensing\NetworkLicenseServer.exe
PRC - [2009.12.11 17:24:04 | 001,774,856 | —- | M] (ABBYY (BIT Software)) – C:\Program Files (x86)\ABBYY Lingvo x3\LvAgent.exe


========== Modules (No Company Name) ==========

MOD - [2012.10.27 08:04:10 | 002,295,264 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2012.09.12 14:22:29 | 009,813,704 | —- | M] () – C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll
MOD - [2011.03.17 00:11:16 | 004,297,568 | —- | M] () – C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010.10.20 15:45:26 | 008,801,120 | —- | M] () – C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll


========== Services (SafeList) ==========

SRV:64bit: - [2012.07.11 20:54:58 | 000,140,672 | —- | M] (SUPERAntiSpyware.com) [Auto | Running] – C:\Program Files\SUPERAntiSpyware\SASCore64.exe – (!SASCORE)
SRV:64bit: - [2010.09.22 17:10:10 | 000,057,184 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe – (wlcrasvc)
SRV:64bit: - [2009.07.14 03:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2009.07.14 03:40:01 | 000,193,536 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\appmgmts.dll – (AppMgmt)
SRV - [2012.09.29 19:54:26 | 000,676,936 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2012.09.29 19:54:26 | 000,399,432 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe – (MBAMScheduler)
SRV - [2012.09.20 15:03:20 | 001,236,368 | —- | M] (Lavasoft Limited) [Auto | Running] – C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe – (Ad-Aware Service)
SRV - [2012.07.25 18:58:26 | 000,126,976 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe – (Te.Service)
SRV - [2012.07.25 18:13:16 | 000,139,776 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe – (fussvc)
SRV - [2012.07.13 13:28:36 | 000,160,944 | R— | M] (Skype Technologies) [Auto | Stopped] – C:\Program Files (x86)\Skype\Updater\Updater.exe – (SkypeUpdate)
SRV - [2012.07.09 00:40:10 | 000,104,912 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2012.01.03 15:10:42 | 000,063,928 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2011.12.19 13:20:06 | 003,289,032 | —- | M] (GFI Software) [Auto | Running] – C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe – (SBAMSvc)
SRV - [2011.11.24 20:59:24 | 000,008,192 | —- | M] () [Auto | Stopped] – C:\Windows\SysWOW64\srvany.exe – (KMService)
SRV - [2011.09.26 11:17:16 | 009,665,536 | —- | M] () [On_Demand | Stopped] – c:\wamp\bin\mysql\mysql5.5.16\bin\mysqld.exe – (wampmysqld)
SRV - [2011.09.26 11:06:54 | 000,021,504 | —- | M] (Apache Software Foundation) [On_Demand | Stopped] – c:\wamp\bin\apache\Apache2.2.21\bin\httpd.exe – (wampapache)
SRV - [2011.04.05 10:39:46 | 001,518,976 | —- | M] () [Auto | Running] – C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Service.exe – (AHDDC2)
SRV - [2010.07.01 16:31:36 | 002,153,336 | —- | M] () [Auto | Running] – C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe – (OS Selector)
SRV - [2010.02.19 13:37:14 | 000,517,096 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe – (SwitchBoard)
SRV - [2009.12.11 17:24:24 | 000,816,392 | —- | M] (ABBYY) [Auto | Running] – C:\Program Files (x86)\Common Files\ABBYY\Lingvo\14.0\Licensing\NetworkLicenseServer.exe – (ABBYY.Licensing.Lingvo.Desktop.14.0)
SRV - [2009.08.24 20:16:12 | 000,544,768 | —- | M] (mst software GmbH, Germany) [On_Demand | Stopped] – C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control 2\DfSdkS64.exe – (DfSdkS)
SRV - [2009.06.10 23:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012.11.01 16:08:06 | 000,055,384 | —- | M] (Sunbelt Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\SBREDrv.sys – (SBRE)
DRV:64bit: - [2012.09.29 19:54:26 | 000,025,928 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\mbam.sys – (MBAMProtector)
DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2011.12.19 12:44:24 | 000,060,536 | —- | M] (GFI Software) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\sbhips.sys – (sbhips)
DRV:64bit: - [2011.11.29 06:59:46 | 000,074,872 | —- | M] (GFI Software) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\sbapifs.sys – (sbapifs)
DRV:64bit: - [2011.11.15 05:50:14 | 000,125,376 | —- | M] (Power Software Ltd) [Kernel | System | Running] – C:\Windows\SysNative\drivers\scdemu.sys – (SCDEmu)
DRV:64bit: - [2011.11.03 03:01:00 | 000,056,208 | —- | M] (Rovi Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\PxHlpa64.sys – (PxHlpa64)
DRV:64bit: - [2011.09.08 16:12:20 | 000,143,984 | —- | M] (Tonec Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\idmwfp.sys – (IDMWFP)
DRV:64bit: - [2011.08.17 09:58:26 | 000,009,216 | —- | M] (Nokia) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbser_lowerfltjx64.sys – (UsbserFilt)
DRV:64bit: - [2011.08.17 09:58:22 | 000,009,216 | —- | M] (Nokia) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbser_lowerfltx64.sys – (upperdev)
DRV:64bit: - [2011.08.17 09:58:20 | 000,027,136 | —- | M] (Nokia) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\ccdcmbox64.sys – (nmwcdc)
DRV:64bit: - [2011.08.17 09:58:16 | 000,019,968 | —- | M] (Nokia) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\ccdcmbx64.sys – (nmwcd)
DRV:64bit: - [2011.07.22 18:26:56 | 000,014,928 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys – (SASDIFSV)
DRV:64bit: - [2011.07.12 23:55:18 | 000,012,368 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\saskutil64.sys – (SASKUTIL)
DRV:64bit: - [2011.06.15 23:07:10 | 000,276,576 | —- | M] (Acronis) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\snapman.sys – (snapman)
DRV:64bit: - [2011.06.04 23:41:47 | 000,834,544 | —- | M] () [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\sptd.sys – (sptd)
DRV:64bit: - [2011.04.13 14:04:38 | 000,045,432 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\point64.sys – (Point64)
DRV:64bit: - [2011.04.08 22:00:20 | 000,047,616 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\dc3d.sys – (dc3d)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2010.11.21 05:24:43 | 000,020,992 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\rdpvideominiport.sys – (RdpVideoMiniport)
DRV:64bit: - [2010.11.21 05:24:33 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010.11.21 05:23:48 | 000,117,248 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\tsusbhub.sys – (tsusbhub)
DRV:64bit: - [2010.11.21 05:23:48 | 000,088,960 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\Synth3dVsc.sys – (Synth3dVsc)
DRV:64bit: - [2010.11.21 05:23:48 | 000,071,168 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\dmvsc.sys – (dmvsc)
DRV:64bit: - [2010.11.21 05:23:48 | 000,034,816 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\terminpt.sys – (terminpt)
DRV:64bit: - [2010.11.21 05:23:48 | 000,032,768 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbser.sys – (usbser)
DRV:64bit: - [2010.11.21 05:23:47 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010.11.21 05:23:47 | 000,031,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbGD.sys – (TsUsbGD)
DRV:64bit: - [2010.11.15 18:05:02 | 000,364,520 | —- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\asmtxhci.sys – (asmtxhci)
DRV:64bit: - [2010.11.15 18:05:00 | 000,121,832 | —- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\asmthub3.sys – (asmthub3)
DRV:64bit: - [2010.10.26 10:08:08 | 000,406,632 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2010.10.19 23:34:26 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (MEIx64)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2007.08.08 12:47:16 | 000,193,312 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\V0330Vid.sys – (V0330VID)
DRV - [2012.07.24 18:59:11 | 000,036,480 | —- | M] (CACE Technologies, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\npf.sys – (npf)
DRV - [2012.07.13 16:13:14 | 000,070,264 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys – (VSPerfDrv110)
DRV - [2011.10.26 14:23:40 | 000,101,112 | —- | M] (GFI Software) [Kernel | System | Running] – C:\Windows\SysWOW64\drivers\SBREDrv.sys – (SBRE)
DRV - [2011.07.16 15:29:28 | 000,021,712 | —- | M] (Phoenix Technologies) [Kernel | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\DrvAgent64.SYS – (DrvAgent64)
DRV - [2009.07.14 03:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com/?ocid=OIE9HP
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/redirects/security…;pvid=20.2.0.19
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ru.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = ru
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = A0 D9 14 86 FF 22 CC 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" = http://safesearchr.lavasoft.com/?source=33…q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "korrespondent.net"
FF - prefs.js..extensions.enabledAddons: [removed]:7.3.29
FF - prefs.js..keyword.URL: "http://safesearchr.lavasoft.com/?source=3336ca5f&tbp=url&toolbarid=adawaretb&u=EF15A04EC6049C0776EC1A509245A9D4&q="
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_265.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.19: C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\George\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\George\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.11.01 11:49:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.10.27 08:04:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.11.01 11:49:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.10.27 08:04:08 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Users\George\AppData\Roaming\IDM\idmmzcc5 [2011.09.10 14:02:43 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\[removed]: C:\Users\George\AppData\Roaming\IDM\idmmzcc5 [2011.09.10 14:02:43 | 000,000,000 | —D | M]

[2011.06.05 01:11:18 | 000,000,000 | —D | M] (No name found) – C:\Users\George\AppData\Roaming\Mozilla\Extensions
[2012.11.01 11:49:27 | 000,000,000 | —D | M] (No name found) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions
[2012.11.01 11:49:28 | 000,000,000 | —D | M] (Ad-Aware Security Add-on) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c}
[2012.03.01 11:04:51 | 000,000,000 | —D | M] (Search Assistant) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions\{B3834E60-12A8-11E0-A289-939FDFD72085}
[2012.11.01 11:39:29 | 000,000,000 | —D | M] (Lavasoft Search Plugin) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions\jid1-yZwVFzbsyfMrqQ@jetpack
[2012.10.15 16:55:27 | 000,000,000 | —D | M] (IDM CC) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions\[removed]
[2012.11.01 06:43:05 | 000,000,000 | —D | M] (No name found) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions\trash
[2012.11.01 06:43:05 | 002,042,908 | —- | M] () (No name found) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions\[removed]
[2011.09.14 21:09:36 | 000,087,923 | R— | M] () (No name found) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions\{dd05fd3d-18df-4ce4-ae53-e795339c5f01}.xpi
[2012.10.26 06:39:57 | 002,042,937 | —- | M] () (No name found) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions\trash\[removed]
[2011.06.08 05:55:13 | 000,012,703 | —- | M] () – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\searchplugins\imdb.xml
[2011.08.04 01:15:27 | 000,009,695 | —- | M] () – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\searchplugins\lurkmore-ru.xml
[2011.06.08 18:24:35 | 000,001,701 | —- | M] () – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\searchplugins\rutrackerorg.xml
[2011.06.05 23:50:34 | 000,002,057 | —- | M] () – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\searchplugins\youtube-video-search.xml
[2012.10.27 08:04:00 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012.10.27 08:04:00 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012.10.27 08:04:26 | 000,261,600 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011.11.10 05:54:13 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011.10.27 15:45:50 | 000,083,456 | —- | M] (LiveVDO ) – C:\Program Files (x86)\mozilla firefox\plugins\npvsharetvplg.dll
[2012.11.01 11:49:30 | 000,000,616 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\adawaretb.xml
[2012.08.30 09:27:08 | 000,002,465 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.10.12 19:34:03 | 000,002,058 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: http://www.google.com/
CHR - default_search_provider: blekko (Enabled)
CHR - default_search_provider: search_url = http://safesearchr.lavasoft.com/?source=33…q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - homepage: http://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\George\AppData\Local\Google\Chrome\Application\22.0.1229.94\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\George\AppData\Local\Google\Chrome\Application\22.0.1229.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\George\AppData\Local\Google\Chrome\Application\22.0.1229.94\pdf.dll
CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files (x86)\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files (x86)\Veetle\plugins\npVeetle.dll
CHR - plugin: Google Update (Enabled) = C:\Users\George\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Angry Birds = C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.7_0\
CHR - Extension: Search Assistant = C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfelndikbdcohbdimnhdhhokfljdidgn\2.0.0\
CHR - Extension: vshare plugin = C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0\
CHR - Extension: Skype Click to Call = C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.10.0.9560_0\
CHR - Extension: LiveVDO plugin = C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbiamblgmkgbcgbcgejjgebalncpmhnp\1.3_0\

O1 HOSTS File: ([2012.10.31 17:42:11 | 000,001,398 | RHS- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 217.23.13.202 www.google-analytics.com.
O1 - Hosts: 217.23.13.202 ad-emea.doubleclick.net.
O1 - Hosts: 217.23.13.202 www.statcounter.com.
O1 - Hosts: 198.15.104.132 www.google-analytics.com.
O1 - Hosts: 198.15.104.132 ad-emea.doubleclick.net.
O1 - Hosts: 198.15.104.132 www.statcounter.com.
O2:64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll (Internet Download Manager, Tonec Inc.)
O2:64bit: - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitBHO64.dll (TechSmith Corporation)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 10\SnagitBHO.dll (TechSmith Corporation)
O2 - BHO: (Ad-Aware Security Add-on) - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\adawaretb\adawareDx.dll ()
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (IE5BarLauncherBHO Class) - {78F3A323-798E-4AEA-9A57-88F4B05FD5DD} - C:\Program Files (x86)\StartSearch plugin\ssBarLcher.dll File not found
O2 - BHO: (Microsoft Web Test Recorder 10.0 Helper) - {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} - C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3:64bit: - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitIEAddin64.dll (TechSmith Corporation)
O3 - HKLM\..\Toolbar: (Ad-Aware Security Add-on) - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\adawaretb\adawareDx.dll ()
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\SnagitIEAddin.dll (TechSmith Corporation)
O4:64bit: - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Ad-Aware Antivirus] C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher.exe (Lavasoft Limited)
O4 - HKLM..\Run: [Ad-Aware Browsing Protection] C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft)
O4 - HKLM..\Run: [Lingvo Launcher] C:\Program Files (x86)\ABBYY Lingvo x3\LvAgent.exe (ABBYY (BIT Software))
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [uTorrent] C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Users\George\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sticky Notes Taskbar Hider.lnk = C:\Program Files (x86)\StickyNotes\SNTBHider.exe (Drakenscripts.co.cc)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O8:64bit: - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8:64bit: - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O9 - Extra Button: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files (x86)\ICQ7.6\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files (x86)\ICQ7.6\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 10.2.0)
O16:64bit: - DPF: {CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_02)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_02)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwareup…13/CTPIDPDE.cab (Creative Software AutoUpdate Support Package 2)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} http://ccfiles.creative.com/Web/softwareup…015/CTSUEng.cab (Creative Software AutoUpdate 2)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareup…15118/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FD181FDC-6BF9-4094-9BF8-195BA15CE97D}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\K\Shell - "" = AutoRun
O33 - MountPoints2\K\Shell\AutoRun\command - "" = K:\vs_ultimate.exe
O33 - MountPoints2\L\Shell - "" = AutoRun
O33 - MountPoints2\L\Shell\AutoRun\command - "" = L:\autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: vidc.tsc2 - C:\Windows\SysWOW64\tsc2_codec64.dll (TechSmith Corporation)
Drivers32:64bit: vidc.tscc - C:\Windows\SysWOW64\tsccvid64.dll (TechSmith Corporation)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.tsc2 - C:\Windows\SysWOW64\tsc2_codec32.dll (TechSmith Corporation)
Drivers32: vidc.tscc - C:\Windows\SysWOW64\tsccvid.dll (TechSmith Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012.11.02 13:47:55 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\George\Desktop\HiJackThis.exe
[2012.11.02 13:45:36 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\George\Desktop\OTL.exe
[2012.11.02 13:16:26 | 000,000,000 | —D | C] – C:\Users\George\AppData\Roaming\Malwarebytes
[2012.11.02 13:16:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.11.02 13:16:15 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012.11.02 13:16:14 | 000,025,928 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2012.11.02 13:16:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.11.01 18:33:27 | 000,000,000 | —D | C] – C:\Users\George\AppData\Roaming\SUPERAntiSpyware.com
[2012.11.01 18:33:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2012.11.01 18:33:05 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2012.11.01 18:33:05 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2012.11.01 18:08:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\appmgmt
[2012.11.01 14:42:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\Lavasoft
[2012.11.01 14:23:11 | 000,000,000 | —D | C] – C:\ProgramData\Ad-Aware Antivirus
[2012.11.01 13:55:58 | 000,000,000 | —D | C] – C:\Users\George\AppData\Local\adawarebp
[2012.11.01 12:18:12 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ad-Aware Antivirus
[2012.11.01 12:18:00 | 000,060,536 | —- | C] (GFI Software) – C:\Windows\SysNative\drivers\sbhips.sys
[2012.11.01 12:17:59 | 000,045,936 | —- | C] (GFI Software) – C:\Windows\SysNative\sbbd.exe
[2012.11.01 12:17:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\Ad-Aware Antivirus
[2012.11.01 12:17:30 | 000,000,000 | —D | C] – C:\Users\George\AppData\Local\Downloaded Installations
[2012.11.01 11:44:48 | 000,000,000 | —D | C] – C:\Users\George\AppData\Roaming\LavasoftStatistics
[2012.11.01 11:39:35 | 000,000,000 | —D | C] – C:\ProgramData\blekko toolbars
[2012.11.01 11:39:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\adawaretb
[2012.11.01 11:27:12 | 000,000,000 | —D | C] – C:\Users\George\AppData\Roaming\Ad-Aware Antivirus
[2012.11.01 11:03:23 | 000,055,384 | —- | C] (Sunbelt Software) – C:\Windows\SysNative\drivers\SBREDrv.sys
[2012.11.01 10:51:52 | 000,000,000 | —D | C] – C:\Users\George\AppData\Local\adaware
[2012.11.01 10:51:47 | 000,000,000 | —D | C] – C:\ProgramData\Ad-Aware Browsing Protection
[2012.11.01 10:51:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Toolbar Cleaner
[2012.11.01 10:51:15 | 000,000,000 | —D | C] – C:\Windows\SysNative\DRVSTORE
[2012.11.01 10:51:12 | 000,000,000 | —D | C] – C:\ProgramData\Lavasoft
[2012.11.01 09:39:08 | 000,000,000 | —D | C] – C:\Users\George\AppData\Local\NPE
[2012.10.31 21:33:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Symantec Shared
[2012.10.31 21:30:59 | 000,000,000 | —D | C] – C:\ProgramData\Norton
[2012.10.31 21:26:05 | 000,000,000 | —D | C] – C:\ProgramData\NortonInstaller
[2012.10.31 20:03:22 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012.10.31 20:03:21 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2012.10.29 16:25:01 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2012.10.29 12:33:30 | 000,000,000 | —D | C] – C:\Users\George\Desktop\2012_10_29
[2012.10.27 20:53:14 | 000,000,000 | —D | C] – C:\Users\George\Desktop\2012_10_27
[2012.10.27 08:04:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2012.10.25 17:17:24 | 000,000,000 | —D | C] – C:\Users\George\Desktop\2012_10_25
[2012.10.24 12:02:08 | 000,000,000 | —D | C] – C:\Users\George\Desktop\2012_10_24
[2012.10.12 00:09:17 | 000,000,000 | —D | C] – C:\Users\George\Desktop\2012_10_12
[2012.10.11 16:58:24 | 000,000,000 | —D | C] – C:\Users\George\Desktop\2012_10_11
[2012.10.10 23:36:21 | 000,000,000 | —D | C] – C:\Users\George\Desktop\2012_10_10
[2012.10.10 05:00:21 | 005,559,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2012.10.10 05:00:21 | 003,914,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2012.10.10 05:00:20 | 003,968,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2012.10.10 05:00:16 | 001,162,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2012.10.10 05:00:16 | 000,424,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\KernelBase.dll
[2012.10.10 05:00:15 | 000,338,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\conhost.exe
[2012.10.10 05:00:15 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2012.10.10 05:00:15 | 000,215,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2012.10.10 05:00:15 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2012.10.10 05:00:15 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntvdm64.dll
[2012.10.10 05:00:14 | 000,362,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64win.dll
[2012.10.10 05:00:14 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2012.10.10 05:00:14 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64cpu.dll
[2012.10.10 05:00:14 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2012.10.10 05:00:14 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2012.10.10 05:00:14 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2012.10.10 05:00:14 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2012.10.10 05:00:14 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2012.10.10 05:00:14 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2012.10.10 05:00:14 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2012.10.10 05:00:13 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2012.10.10 05:00:09 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wintrust.dll
[2012.10.10 05:00:01 | 001,464,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2012.10.10 05:00:01 | 000,140,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2012.10.10 00:31:29 | 000,000,000 | —D | C] – C:\Users\George\Desktop\bin
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012.11.02 13:49:30 | 000,625,664 | —- | M] () – C:\Users\George\Desktop\dds.scr
[2012.11.02 13:47:59 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\George\Desktop\HiJackThis.exe
[2012.11.02 13:45:42 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\George\Desktop\OTL.exe
[2012.11.02 13:16:15 | 000,001,109 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.11.02 13:14:24 | 000,026,576 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.11.02 13:14:24 | 000,026,576 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.11.02 13:13:07 | 001,839,080 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012.11.02 13:13:07 | 000,792,274 | —- | M] () – C:\Windows\SysNative\perfh019.dat
[2012.11.02 13:13:07 | 000,721,924 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012.11.02 13:13:07 | 000,175,684 | —- | M] () – C:\Windows\SysNative\perfc019.dat
[2012.11.02 13:13:07 | 000,147,066 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012.11.02 13:09:21 | 000,233,423 | —- | M] () – C:\Users\George\Desktop\bookmarks-2012-11-02.json
[2012.11.02 13:07:09 | 000,001,868 | —- | M] () – C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
[2012.11.02 13:06:57 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012.11.02 13:06:52 | 2132,746,239 | -HS- | M] () – C:\hiberfil.sys
[2012.11.02 13:06:00 | 000,000,982 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1109903177-269762195-694080819-1000UA.job
[2012.11.02 11:57:00 | 000,000,390 | —- | M] () – C:\Windows\tasks\update-S-1-5-21-1109903177-269762195-694080819-1000.job
[2012.11.02 11:21:00 | 000,000,390 | —- | M] () – C:\Windows\tasks\update-sys.job
[2012.11.02 10:33:00 | 000,000,512 | —- | M] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 8a2a6511-ce7f-4545-b4a7-11f842f8cbdb.job
[2012.11.02 06:06:01 | 000,000,930 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1109903177-269762195-694080819-1000Core.job
[2012.11.02 02:00:03 | 000,000,512 | —- | M] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 57a291b1-ebd9-4043-9cbe-de77272c297c.job
[2012.11.01 18:33:07 | 000,001,808 | —- | M] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012.11.01 16:08:06 | 000,055,384 | —- | M] (Sunbelt Software) – C:\Windows\SysNative\drivers\SBREDrv.sys
[2012.11.01 15:01:39 | 000,007,618 | —- | M] () – C:\Users\George\AppData\Local\Resmon.ResmonCfg
[2012.10.31 21:28:42 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif
[2012.10.31 17:42:11 | 000,001,398 | RHS- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2012.10.25 18:14:20 | 017,541,748 | —- | M] () – C:\Users\George\Desktop\Assignment 1,2,3 George 101011.zip
[2012.10.25 13:12:28 | 000,485,225 | —- | M] () – C:\Users\George\Desktop\IMG_2639.jpg
[2012.10.25 13:05:01 | 000,449,736 | —- | M] () – C:\Users\George\Desktop\IMG_2643.jpg
[2012.10.24 12:08:43 | 019,045,148 | —- | M] () – C:\Users\George\Desktop\Assignment 4 George 101011.zip
[2012.10.24 07:18:16 | 000,162,792 | —- | M] () – C:\Users\George\Desktop\IMG_2858.jpg
[2012.10.23 08:28:31 | 000,030,463 | —- | M] () – C:\Users\George\Desktop\getImage.jpg
[2012.10.10 01:07:37 | 000,000,132 | —- | M] () – C:\Users\George\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2012.10.09 21:46:06 | 000,001,456 | —- | M] () – C:\Users\George\AppData\Local\Adobe Save for Web 12.0 Prefs
[2012.10.09 21:46:05 | 001,320,376 | —- | M] () – C:\Users\George\Desktop\Poster-Small.jpg
[2012.10.09 02:24:23 | 026,055,247 | —- | M] () – C:\Users\George\Desktop\Poster.jpg
[2012.10.08 19:31:35 | 013,416,742 | —- | M] () – C:\Users\George\Desktop\tia2011-print.pdf
[2012.10.05 00:20:02 | 000,086,729 | —- | M] () – C:\Users\George\Desktop\Picture1.png
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012.11.02 13:49:28 | 000,625,664 | —- | C] () – C:\Users\George\Desktop\dds.scr
[2012.11.02 13:16:15 | 000,001,109 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.11.02 13:09:19 | 000,233,423 | —- | C] () – C:\Users\George\Desktop\bookmarks-2012-11-02.json
[2012.11.01 18:33:35 | 000,000,512 | —- | C] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 8a2a6511-ce7f-4545-b4a7-11f842f8cbdb.job
[2012.11.01 18:33:34 | 000,000,512 | —- | C] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 57a291b1-ebd9-4043-9cbe-de77272c297c.job
[2012.11.01 18:33:07 | 000,001,808 | —- | C] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012.11.01 12:18:12 | 000,001,868 | —- | C] () – C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
[2012.10.25 18:14:19 | 017,541,748 | —- | C] () – C:\Users\George\Desktop\Assignment 1,2,3 George 101011.zip
[2012.10.25 13:12:28 | 000,485,225 | —- | C] () – C:\Users\George\Desktop\IMG_2639.jpg
[2012.10.25 13:05:01 | 000,449,736 | —- | C] () – C:\Users\George\Desktop\IMG_2643.jpg
[2012.10.24 12:08:42 | 019,045,148 | —- | C] () – C:\Users\George\Desktop\Assignment 4 George 101011.zip
[2012.10.24 07:18:16 | 000,162,792 | —- | C] () – C:\Users\George\Desktop\IMG_2858.jpg
[2012.10.23 08:28:29 | 000,030,463 | —- | C] () – C:\Users\George\Desktop\getImage.jpg
[2012.10.09 21:46:05 | 001,320,376 | —- | C] () – C:\Users\George\Desktop\Poster-Small.jpg
[2012.10.08 19:26:39 | 013,416,742 | —- | C] () – C:\Users\George\Desktop\tia2011-print.pdf
[2012.10.06 01:36:53 | 026,055,247 | —- | C] () – C:\Users\George\Desktop\Poster.jpg
[2012.10.05 00:20:01 | 000,086,729 | —- | C] () – C:\Users\George\Desktop\Picture1.png
[2012.09.10 21:57:09 | 000,000,021 | —- | C] () – C:\Windows\SurCode.INI
[2012.08.20 11:20:54 | 000,000,010 | —- | C] () – C:\Users\George\Infovis_FILE_HISTORY.cfg
[2012.05.26 06:23:29 | 000,003,584 | —- | C] () – C:\Windows\SysWow64\DrvFltIp.sys
[2012.05.25 11:21:22 | 000,003,584 | —- | C] () – C:\Users\George\AppData\Roaming\DrvFltIp.sys
[2012.05.12 15:51:03 | 000,000,034 | -H– | C] () – C:\Windows\SysWow64\Converter_sysquict.dat
[2012.04.20 03:10:29 | 003,596,288 | —- | C] () – C:\Windows\SysWow64\qt-dx331.dll
[2012.03.10 21:07:36 | 000,000,145 | —- | C] () – C:\Users\George\.appletviewer
[2012.02.21 18:23:30 | 000,000,043 | —- | C] () – C:\Windows\gswin64.ini
[2012.02.01 02:28:27 | 000,000,983 | —- | C] () – C:\Windows\eReg.dat
[2012.01.30 03:49:45 | 000,001,476 | —- | C] () – C:\Users\George\AppData\Local\UserProducts.xml
[2012.01.07 02:04:30 | 000,145,876 | -H– | C] () – C:\Windows\SysWow64\mlfcache.dat
[2011.12.09 00:00:54 | 000,000,019 | —- | C] () – C:\Windows\info9.ini
[2011.12.09 00:00:54 | 000,000,019 | —- | C] () – C:\Windows\info7.ini
[2011.12.09 00:00:52 | 001,747,456 | —- | C] () – C:\Windows\SysWow64\re_imageconv.dll
[2011.11.24 21:00:49 | 000,008,192 | —- | C] () – C:\Windows\SysWow64\srvany.exe
[2011.07.14 14:06:11 | 000,000,020 | —- | C] () – C:\Windows\NMCAutorunXP.ini
[2011.07.08 17:28:10 | 000,001,459 | —- | C] () – C:\Users\George\gsview64.ini
[2011.06.24 21:27:30 | 000,001,456 | —- | C] () – C:\Users\George\AppData\Local\Adobe Save for Web 12.0 Prefs
[2011.06.11 00:43:23 | 000,000,132 | —- | C] () – C:\Users\George\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2011.06.06 03:55:19 | 000,007,618 | —- | C] () – C:\Users\George\AppData\Local\Resmon.ResmonCfg
[2011.06.05 01:17:10 | 000,000,056 | -H– | C] () – C:\Windows\SysWow64\ezsidmv.dat
[2011.06.05 01:11:10 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2011.06.05 00:26:11 | 001,819,732 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011.06.04 23:31:01 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2011.06.04 23:30:56 | 000,021,262 | —- | C] () – C:\Windows\Ascd_tmp.ini

========== ZeroAccess Check ==========

[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012.06.09 07:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012.06.09 06:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009.07.14 03:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010.11.21 05:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009.07.14 03:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2011.01.21 19:26:28 | 000,005,858 | —- | M] () MD5=18E3D562E7E80B329AE5309E368FD567 – C:\Windows\PolicyDefinitions\ru-RU\Explorer.adml
[2011.01.21 19:26:28 | 000,005,858 | —- | M] () MD5=18E3D562E7E80B329AE5309E368FD567 – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_ru-ru_c81688edd50b74ab\Explorer.adml
[2010.11.21 09:06:30 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\PolicyDefinitions\en-US\Explorer.adml
[2010.11.21 09:06:30 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009.06.10 22:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\PolicyDefinitions\Explorer.admx
[2009.06.10 22:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx

< MD5 for: EXPLORER.BMP >
[2009.08.31 02:59:28 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\VCWizards\AppWiz\MFC\Application\templates\1028\explorer.bmp
[2009.08.31 02:59:28 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\VCWizards\AppWiz\MFC\Application\templates\1031\explorer.bmp
[2009.08.31 02:59:28 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\VCWizards\AppWiz\MFC\Application\templates\1033\explorer.bmp
[2009.08.31 02:59:28 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\VCWizards\AppWiz\MFC\Application\templates\1036\explorer.bmp
[2009.08.31 02:59:28 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\VCWizards\AppWiz\MFC\Application\templates\1040\explorer.bmp
[2009.08.31 02:59:28 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\VCWizards\AppWiz\MFC\Application\templates\1041\explorer.bmp
[2009.08.31 02:59:28 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\VCWizards\AppWiz\MFC\Application\templates\1042\explorer.bmp
[2009.08.31 02:59:28 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\VCWizards\AppWiz\MFC\Application\templates\1049\explorer.bmp
[2009.08.31 02:59:28 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\VCWizards\AppWiz\MFC\Application\templates\2052\explorer.bmp
[2009.08.31 02:59:28 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\VCWizards\AppWiz\MFC\Application\templates\3082\explorer.bmp
[2011.12.12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\1028\explorer.bmp
[2011.12.12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\1031\explorer.bmp
[2011.12.12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\1033\explorer.bmp
[2011.12.12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\1036\explorer.bmp
[2011.12.12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\1040\explorer.bmp
[2011.12.12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\1041\explorer.bmp
[2011.12.12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\1042\explorer.bmp
[2011.12.12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\1049\explorer.bmp
[2011.12.12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\2052\explorer.bmp
[2011.12.12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\3082\explorer.bmp

< MD5 for: EXPLORER.DESIGNER.VB >
[2011.12.12 13:52:40 | 000,036,545 | —- | M] () MD5=0BFA552D19A4A7F9130A71DFBBCB1407 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\ItemTemplates\VisualBasic\Windows Forms\1033\Explorer\explorer.designer.vb
[2011.12.12 13:52:40 | 000,036,545 | —- | M] () MD5=0BFA552D19A4A7F9130A71DFBBCB1407 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\ItemTemplatesCache\VisualBasic\Windows Forms\1033\Explorer\explorer.designer.vb

< MD5 for: EXPLORER.EXE >
[2011.02.26 07:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011.02.25 08:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011.02.25 08:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011.02.26 08:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010.11.21 05:24:25 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011.02.25 07:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011.02.25 07:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010.11.21 05:24:11 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2010.11.21 09:06:17 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2010.11.21 09:06:17 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2011.01.21 19:25:49 | 000,024,064 | —- | M] (Microsoft Corporation) MD5=55560C826AAF32C42126EE1F5189611F – C:\Windows\ru-RU\explorer.exe.mui
[2011.01.21 19:25:49 | 000,024,064 | —- | M] (Microsoft Corporation) MD5=55560C826AAF32C42126EE1F5189611F – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_ru-ru_ab089078de57cd42\explorer.exe.mui
[2010.11.21 09:06:19 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2010.11.21 09:06:19 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui
[2011.01.21 19:25:22 | 000,024,064 | —- | M] (Microsoft Corporation) MD5=C8A97DC216E7986AF093FB639118D404 – C:\Windows\SysWOW64\ru-RU\explorer.exe.mui
[2011.01.21 19:25:22 | 000,024,064 | —- | M] (Microsoft Corporation) MD5=C8A97DC216E7986AF093FB639118D404 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_ru-ru_b55d3acb12b88f3d\explorer.exe.mui

< MD5 for: EXPLORER.EXE.WINDOWS EXPLORER.MICROSOFT CORPORATION.6.1.7601.17567.ICO >
[2012.06.24 07:27:09 | 000,187,373 | —- | M] () MD5=59EF532FA50E1EC27DC50D43DA386BFB – C:\Users\George\AppData\Local\TechSmith\Snagit\DataStore\AppIcons\explorer.exe.Windows Explorer.Microsoft Corporation.6.1.7601.17567.ico

< MD5 for: EXPLORER.EXE-254441E9.PF >
[2012.11.02 13:48:02 | 000,039,902 | —- | M] () MD5=4F24A4D68707A7475BE0FA5DD26AAD70 – C:\Windows\Prefetch\EXPLORER.EXE-254441E9.pf

< MD5 for: EXPLORER.EXE-A80E4F97.PF >
[2012.11.02 13:48:12 | 000,182,486 | —- | M] () MD5=560AD06BC07C0FEF482BAB6495FC31FC – C:\Windows\Prefetch\EXPLORER.EXE-A80E4F97.pf

< MD5 for: EXPLORER.GIF >
[2009.08.31 02:59:28 | 000,003,342 | —- | M] () MD5=2C9E121C2DECEF61FED6EA977A30D90F – C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\VCWizards\AppWiz\MFC\Application\images\Explorer.gif
[2012.06.24 21:45:02 | 000,001,483 | —- | M] () MD5=4ABBABE57F99C84C4154DD289B766E5E – C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\images\Explorer.gif

< MD5 for: EXPLORER.PROPERTIES >
[2011.12.02 23:31:21 | 000,000,039 | —- | M] () MD5=2BB97C1EFB43BE88E1BBDB121CAA9327 – C:\Users\George\.netbeans\7.0\config\Preferences\org\openide\explorer.properties
[2012.08.20 05:21:20 | 000,000,039 | —- | M] () MD5=2BB97C1EFB43BE88E1BBDB121CAA9327 – C:\Users\George\AppData\Roaming\.gephi\0.8.1\dev\config\Preferences\org\openide\explorer.properties

< MD5 for: EXPLORER.RESX >
[2011.12.12 13:52:40 | 000,040,049 | —- | M] () MD5=B16D2C77324DE7222CB0EA55C7B32784 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\ItemTemplates\VisualBasic\Windows Forms\1033\Explorer\explorer.resx
[2011.12.12 13:52:40 | 000,040,049 | —- | M] () MD5=B16D2C77324DE7222CB0EA55C7B32784 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\ItemTemplatesCache\VisualBasic\Windows Forms\1033\Explorer\explorer.resx

< MD5 for: EXPLORER.VB >
[2011.12.12 13:52:40 | 000,008,501 | —- | M] () MD5=55808E7AF87B5C18B97707BEF8EBDDEA – C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\ItemTemplates\VisualBasic\Windows Forms\1033\Explorer\explorer.vb
[2011.12.12 13:52:40 | 000,008,501 | —- | M] () MD5=55808E7AF87B5C18B97707BEF8EBDDEA – C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\ItemTemplatesCache\VisualBasic\Windows Forms\1033\Explorer\explorer.vb

< MD5 for: EXPLORER.VSTEMPLATE >
[2011.12.12 13:52:40 | 000,006,491 | —- | M] () MD5=FB731348042E3356E2215A6747CE893C – C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\ItemTemplates\VisualBasic\Windows Forms\1033\Explorer\explorer.vstemplate
[2011.12.12 13:52:40 | 000,006,491 | —- | M] () MD5=FB731348042E3356E2215A6747CE893C – C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\ItemTemplatesCache\VisualBasic\Windows Forms\1033\Explorer\explorer.vstemplate

< MD5 for: EXPLORER.WSMODE >
[2012.08.20 05:21:54 | 000,000,476 | —- | M] () MD5=9885B0575BBF4AEC298B13D68EA7D346 – C:\Users\George\AppData\Roaming\.gephi\0.8.1\dev\config\Windows2Local-overview\Modes\explorer.wsmode
[2012.06.30 10:57:43 | 000,000,561 | —- | M] () MD5=E69F93B0A6A6DBEA0D1CF45EBB155EAF – C:\Users\George\.netbeans\7.0\config\Windows2Local\Modes\explorer.wsmode

< MD5 for: EXPLORER.ZIP >
[2009.06.03 20:15:06 | 000,020,394 | —- | M] () MD5=B469409C2B2A33C542190B720E11BD79 – C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip

< MD5 for: IEXPLORE.EXE >
[2012.06.02 13:47:54 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=004640AB259C1572EBD5FB0A32F63686 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20553_none_0dbfc836999db0ca\iexplore.exe
[2012.05.18 01:21:54 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=0129BB16161C2FD9A6B19111AB047198 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16446_none_1798a687b4d6030f\iexplore.exe
[2012.06.29 07:02:52 | 000,754,784 | —- | M] (Microsoft Corporation) MD5=1223ACBFC1093852DFF039E189599BBD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_0d45fcc9807373c2\iexplore.exe
[2012.08.24 09:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2012.08.24 09:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_1787d4dfb4e386f6\iexplore.exe
[2012.05.18 00:59:46 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=268982F1FD671A077C6A2AF41E351436 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20551_none_181271f4ce004017\iexplore.exe
[2012.08.24 13:23:44 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=2D53C5F71653EF94E7829846405D4ED2 – C:\Program Files\Internet Explorer\iexplore.exe
[2012.08.24 13:23:44 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=2D53C5F71653EF94E7829846405D4ED2 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_0d332a8d8082c4fb\iexplore.exe
[2012.06.02 11:08:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=34B01BBD8F00B6B9C9248DC4F1E3CD01 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16447_none_1799a6d1b4d51c66\iexplore.exe
[2012.05.18 04:51:05 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=4E99F42504A99D5024C2EFA015001937 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16446_none_0d43fc3580754114\iexplore.exe
[2012.08.24 12:49:07 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=5A150AFABB25BEA50CEDC8650A7B8A9E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_0dc3c95e999a1626\iexplore.exe
[2012.06.29 04:45:31 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=5D03518409F37D1483C98869D86E23FF – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_0dc0c880999cca21\iexplore.exe
[2012.06.02 14:52:21 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=610F6596921C4BAA8834ADBB9BE272EE – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16447_none_0d44fc7f80745a6b\iexplore.exe
[2012.08.24 09:49:25 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=62188720CE27B982B4285C03163C9FB3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_181873b0cdfad821\iexplore.exe
[2010.11.21 05:24:43 | 000,695,056 | —- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2012.09.29 19:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2011.06.04 23:53:53 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_17a944edb4ca4c7a\iexplore.exe
[2012.06.29 03:00:47 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=93569D46D79F9756ED077156496AFE23 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_179aa71bb4d435bd\iexplore.exe
[2012.06.02 10:51:58 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=BE967C74B89577B78FB57C061E12B04C – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20553_none_18147288cdfe72c5\iexplore.exe
[2010.11.21 05:25:08 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe
[2012.06.29 01:35:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=EB4105348272018D096FEB655CD1608C – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_181572d2cdfd8c1c\iexplore.exe
[2011.06.04 23:53:53 | 000,754,480 | —- | M] (Microsoft Corporation) MD5=F1424C1B9B1813BF825E45DF3790BC8A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_0d549a9b80698a7f\iexplore.exe
[2012.05.18 03:37:57 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=F8B2D47ED17C1D087D14EC747E5AC57A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20551_none_0dbdc7a2999f7e1c\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2011.06.04 23:53:53 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2011.06.04 23:53:53 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2011.06.04 23:53:53 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2011.06.04 23:53:53 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui
[2011.01.21 19:26:32 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=5E222432D3E4D833D6C967FE4FE81C79 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_ru-ru_5464562bc4198720\iexplore.exe.mui
[2011.06.07 19:19:03 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=984477F8913BF8CD2F5C12ADC7C0E183 – C:\Program Files\Internet Explorer\ru-RU\iexplore.exe.mui
[2011.06.07 19:19:03 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=984477F8913BF8CD2F5C12ADC7C0E183 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_ru-ru_502247c7091bc70d\iexplore.exe.mui
[2011.01.21 19:26:32 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=9A35E917E4B5C27A51B756BAF7D7F815 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_ru-ru_5eb9007df87a491b\iexplore.exe.mui
[2009.07.14 04:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_0b433e7773148b79\iexplore.exe.mui
[2011.06.07 19:19:03 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=EAEB8DCDDD67C6AF07598D5C2759B24B – C:\Program Files (x86)\Internet Explorer\ru-RU\iexplore.exe.mui
[2011.06.07 19:19:03 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=EAEB8DCDDD67C6AF07598D5C2759B24B – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_ru-ru_5a76f2193d7c8908\iexplore.exe.mui
[2009.07.14 04:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_1597e8c9a7754d74\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-4B6C9213.PF >
[2012.11.01 21:49:49 | 000,206,646 | —- | M] () MD5=2D7CA11B34DCC48D56AAA42B17EC184B – C:\Windows\Prefetch\IEXPLORE.EXE-4B6C9213.pf

< MD5 for: SERVICES >
[2009.06.10 23:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services

< MD5 for: SERVICES.CFG >
[2012.01.03 15:10:44 | 000,585,874 | —- | M] () MD5=0E19E0BEA7B159153258688CF8ED7716 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\Services.cfg

< MD5 for: SERVICES.EXE >
[2009.07.14 03:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009.07.14 03:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2010.11.21 09:06:16 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\SysNative\en-US\services.exe.mui
[2010.11.21 09:06:16 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui
[2011.01.21 19:25:41 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=EB63EE0FD3C4826F45845C6E83058570 – C:\Windows\SysNative\ru-RU\services.exe.mui
[2011.01.21 19:25:41 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=EB63EE0FD3C4826F45845C6E83058570 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_ru-ru_0f13507290ab300f\services.exe.mui

< MD5 for: SERVICES.H >
[2011.09.26 11:17:40 | 000,001,043 | —- | M] () MD5=EFA6260E75D8055649F88462E3E9E929 – C:\wamp\bin\mysql\mysql5.5.16\include\mysql\services.h

< MD5 for: SERVICES.LNK >
[2009.07.14 06:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009.07.14 06:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009.06.10 22:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2009.06.10 22:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof

< MD5 for: SERVICES.MSC >
[2011.01.21 19:25:34 | 000,092,790 | —- | M] () MD5=20037594600FF469A209FA3465ECBA8A – C:\Windows\SysNative\ru-RU\services.msc
[2011.01.21 19:25:43 | 000,092,790 | —- | M] () MD5=20037594600FF469A209FA3465ECBA8A – C:\Windows\SysWOW64\ru-RU\services.msc
[2011.01.21 19:25:34 | 000,092,790 | —- | M] () MD5=20037594600FF469A209FA3465ECBA8A – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_ru-ru_4955205e6714ca02\services.msc
[2011.01.21 19:25:43 | 000,092,790 | —- | M] () MD5=20037594600FF469A209FA3465ECBA8A – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_ru-ru_ed3684daaeb758cc\services.msc
[2010.11.21 09:06:14 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\en-US\services.msc
[2009.06.10 22:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\services.msc
[2010.11.21 09:06:17 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\en-US\services.msc
[2009.06.10 23:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2010.11.21 09:06:14 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009.06.10 22:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2010.11.21 09:06:17 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009.06.10 23:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009.07.13 22:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009.07.13 22:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml

< MD5 for: SERVICES.SETTINGS >
[2012.06.30 10:57:42 | 000,001,622 | —- | M] () MD5=36F72485C04D6C73C4926FD9112339C1 – C:\Users\George\.netbeans\7.0\config\Windows2Local\Components\services.settings

< MD5 for: SERVICES.WSTCGRP >
[2012.06.30 10:57:43 | 000,000,225 | —- | M] () MD5=E4AD31A486D75BC449F02775904D2430 – C:\Users\George\.netbeans\7.0\config\Windows2Local\Groups\InitialLayout\services.wstcgrp
[2012.06.30 10:57:43 | 000,000,225 | —- | M] () MD5=E4AD31A486D75BC449F02775904D2430 – C:\Users\George\.netbeans\7.0\config\Windows2Local\Groups\OpenedProjects\services.wstcgrp

< MD5 for: SERVICES.WSTCREF >
[2012.06.30 10:57:43 | 000,000,223 | —- | M] () MD5=7FDE98E6B2D9881C67AF64D47984210E – C:\Users\George\.netbeans\7.0\config\Windows2Local\Modes\leftSlidingSide\services.wstcref

< MD5 for: WINLOGON.ADML >
[2011.01.21 19:26:27 | 000,013,486 | —- | M] () MD5=0C0FE7ABF455EC3BCBE3EE70EE01E948 – C:\Windows\PolicyDefinitions\ru-RU\WinLogon.adml
[2011.01.21 19:26:27 | 000,013,486 | —- | M] () MD5=0C0FE7ABF455EC3BCBE3EE70EE01E948 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_ru-ru_3a1a1ae34797fc17\WinLogon.adml
[2010.11.21 09:06:30 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\PolicyDefinitions\en-US\WinLogon.adml
[2010.11.21 09:06:30 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009.06.10 23:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\PolicyDefinitions\WinLogon.admx
[2009.06.10 23:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2010.11.21 05:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010.11.21 05:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2012.09.29 19:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2010.11.21 09:06:14 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2010.11.21 09:06:14 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui
[2011.01.21 19:25:35 | 000,024,064 | —- | M] (Microsoft Corporation) MD5=61620C41698F9B2C6E5A594497B8A735 – C:\Windows\SysNative\ru-RU\winlogon.exe.mui
[2011.01.21 19:25:35 | 000,024,064 | —- | M] (Microsoft Corporation) MD5=61620C41698F9B2C6E5A594497B8A735 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_ru-ru_723faeae6bbaf822\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2010.11.21 09:06:15 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2010.11.21 09:06:15 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl
[2011.01.21 19:25:40 | 000,001,080 | —- | M] () MD5=AC3DB6214BE53F6D948067FDFAEA8467 – C:\Windows\SysNative\wbem\ru-RU\winlogon.mfl
[2011.01.21 19:25:40 | 000,001,080 | —- | M] () MD5=AC3DB6214BE53F6D948067FDFAEA8467 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_ru-ru_cdd0ecb18a04ce1d\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009.07.13 22:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2009.07.13 22:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2012.11.02 13:06:52 | 2132,746,239 | -HS- | M] () – C:\hiberfil.sys
[2012.11.02 13:06:52 | 4275,318,783 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009.07.14 07:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009.07.14 07:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009.07.14 07:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009.07.14 07:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009.06.10 22:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009.07.14 06:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011.06.04 23:56:31 | 000,000,221 | -HS- | M] () – C:\Users\George\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2012.11.02 13:47:59 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\George\Desktop\HiJackThis.exe
[2012.11.02 13:45:42 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\George\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >
[2012.05.29 09:35:38 | 000,001,422 | —- | M] () – C:\Windows\AppPatch\Custom\{fdfba1f3-74ae-4255-9c10-a0f552b4610f}.sdb

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 1360 bytes -> C:\ProgramData\Microsoft:4xkr54OEiolnkbB3gh0FD6W
@Alternate Data Stream - 1322 bytes -> C:\Users\George\AppData\Local\zwzMyxIsPOk:6wR7NFoi4b5qJsMYjkIeAi8sX7ur
@Alternate Data Stream - 1313 bytes -> C:\ProgramData\Microsoft:VzjVIwISJ0TLQ3v9LvRDbL1cqrbG
@Alternate Data Stream - 1295 bytes -> C:\ProgramData\Microsoft:z2kO985qGpXTXnglXv0KG7z

< End of report >
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post









Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error
Hello, mowman, thanks a lot for your time and effort. I did not yet post logs from all the programs that were listed in the instruction for creating new topic. Only first .txt file from OTL I included. Do you want to have a look at the rest? For now I include the ComboFix logs as you requested. ComboFix 12-11-02.02 - George 02.11.2012 14:56:32.1.4 - x64 Microsoft Windows 7 Ultimate 6.1.7601.1.1251.7.1033.18.8173.5590 [GMT 2:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Lavasoft Ad-Aware *Disabled/Updated* {445B48C3-0FA4-6B16-8F07-6506F305D800} FW: Lavasoft Ad-Aware *Disabled* {7C60C9E6-45CB-6A4E-A458-CC330DD69F7B} SP: Lavasoft Ad-Aware *Disabled/Updated* {FF3AA927-299E-6498-B5B7-5E74888292BD} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\StartSearch plugin c:\program files (x86)\StartSearch plugin\IEhelperActiveX.dll c:\program files (x86)\StartSearch plugin\StartBar.dll c:\program files (x86)\StartSearch plugin\uninst.exe c:\program files (x86)\StartSearch plugin\vshareplg.crx c:\users\George\AppData\Local\assembly\tmp c:\users\George\AppData\Roaming\DrvFltIp.sys c:\windows\SysWow64\azip32.dll c:\windows\SysWow64\d2d1debug1.dll c:\windows\SysWow64\drivers\npf.sys c:\windows\SysWow64\Packet.dll c:\windows\SysWow64\wpcap.dll H:\resycled . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . ——-\Service_npf . . ((((((((((((((((((((((((( Files Created from 2012-10-02 to 2012-11-02 ))))))))))))))))))))))))))))))) . . 2012-11-02 11:16 . 2012-11-02 11:16 ——– d—–w- c:\users\George\AppData\Roaming\Malwarebytes 2012-11-02 11:16 . 2012-11-02 11:16 ——– d—–w- c:\programdata\Malwarebytes 2012-11-02 11:16 . 2012-11-02 11:16 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2012-11-02 11:16 . 2012-09-29 17:54 25928 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-11-01 16:33 . 2012-11-01 16:33 ——– d—–w- c:\users\George\AppData\Roaming\SUPERAntiSpyware.com 2012-11-01 16:33 . 2012-11-01 17:12 ——– d—–w- c:\program files\SUPERAntiSpyware 2012-11-01 16:33 . 2012-11-01 16:33 ——– d—–w- c:\programdata\SUPERAntiSpyware.com 2012-11-01 16:08 . 2012-11-01 16:08 ——– d—–w- c:\windows\system32\appmgmt 2012-11-01 12:42 . 2012-11-01 12:42 ——– d—–w- c:\program files (x86)\Lavasoft 2012-11-01 12:23 . 2012-11-01 12:23 ——– d—–w- c:\programdata\Ad-Aware Antivirus 2012-11-01 10:18 . 2011-12-19 10:44 60536 —-a-w- c:\windows\system32\drivers\sbhips.sys 2012-11-01 10:17 . 2011-12-19 11:21 45936 —-a-w- c:\windows\system32\sbbd.exe 2012-11-01 10:17 . 2012-11-01 21:46 ——– d—–w- c:\program files (x86)\Ad-Aware Antivirus 2012-11-01 10:17 . 2012-11-01 10:17 ——– d—–w- c:\users\George\AppData\Local\Downloaded Installations 2012-11-01 09:44 . 2012-11-01 09:44 ——– d—–w- c:\users\George\AppData\Roaming\LavasoftStatistics 2012-11-01 09:39 . 2012-11-01 09:39 ——– d—–w- c:\programdata\blekko toolbars 2012-11-01 09:39 . 2012-11-01 09:49 ——– d—–w- c:\program files (x86)\adawaretb 2012-11-01 09:27 . 2012-11-01 12:17 ——– d—–w- c:\users\George\AppData\Roaming\Ad-Aware Antivirus 2012-11-01 09:03 . 2012-11-01 14:08 55384 —-a-w- c:\windows\system32\drivers\SBREDrv.sys 2012-11-01 08:51 . 2012-11-01 08:51 ——– d—–w- c:\users\George\AppData\Local\adaware 2012-11-01 08:51 . 2012-11-02 11:07 ——– d—–w- c:\programdata\Ad-Aware Browsing Protection 2012-11-01 08:51 . 2012-11-01 08:51 ——– d—–w- c:\program files (x86)\Toolbar Cleaner 2012-11-01 08:51 . 2012-11-01 16:08 ——– dc—-w- c:\windows\system32\DRVSTORE 2012-11-01 08:51 . 2012-11-01 16:08 ——– d—–w- c:\programdata\Lavasoft 2012-11-01 07:39 . 2012-11-01 07:39 ——– d—–w- c:\users\George\AppData\Local\NPE 2012-10-31 19:33 . 2012-11-01 09:31 ——– d—–w- c:\program files (x86)\Common Files\Symantec Shared 2012-10-31 19:30 . 2012-11-01 09:32 ——– d—–w- c:\programdata\Norton 2012-10-31 18:03 . 2012-10-31 18:03 ——– d—–w- c:\program files\CCleaner . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-10-11 01:03 . 2011-06-07 17:18 65309168 —-a-w- c:\windows\system32\MRT.exe 2012-09-25 02:46 . 2012-09-25 02:46 2562208 —-a-w- c:\programdata\Microsoft\VisualStudio\11.0\1033\ResourceCache.dll 2012-09-25 02:44 . 2011-06-04 21:29 1891072 —-a-w- c:\programdata\Microsoft\VisualStudio\10.0\1033\ResourceCache.dll 2012-09-14 00:50 . 2012-09-14 00:50 466456 —-a-w- c:\windows\system32\wrap_oal.dll 2012-09-14 00:50 . 2012-09-14 00:50 444952 —-a-w- c:\windows\SysWow64\wrap_oal.dll 2012-09-14 00:50 . 2012-09-14 00:50 122904 —-a-w- c:\windows\system32\OpenAL32.dll 2012-09-14 00:50 . 2012-09-14 00:50 109080 —-a-w- c:\windows\SysWow64\OpenAL32.dll 2012-09-12 12:22 . 2012-04-13 16:01 696520 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-09-12 12:22 . 2011-06-04 23:22 73416 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-08-24 11:15 . 2012-09-23 01:00 17810944 —-a-w- c:\windows\system32\mshtml.dll 2012-08-24 10:39 . 2012-09-23 01:00 10925568 —-a-w- c:\windows\system32\ieframe.dll 2012-08-24 10:31 . 2012-09-23 01:00 2312704 —-a-w- c:\windows\system32\jscript9.dll 2012-08-24 10:22 . 2012-09-23 01:00 1346048 —-a-w- c:\windows\system32\urlmon.dll 2012-08-24 10:21 . 2012-09-23 01:00 1392128 —-a-w- c:\windows\system32\wininet.dll 2012-08-24 10:20 . 2012-09-23 01:00 1494528 —-a-w- c:\windows\system32\inetcpl.cpl 2012-08-24 10:18 . 2012-09-23 01:00 237056 —-a-w- c:\windows\system32\url.dll 2012-08-24 10:17 . 2012-09-23 01:00 85504 —-a-w- c:\windows\system32\jsproxy.dll 2012-08-24 10:14 . 2012-09-23 01:00 173056 —-a-w- c:\windows\system32\ieUnatt.exe 2012-08-24 10:14 . 2012-09-23 01:00 816640 —-a-w- c:\windows\system32\jscript.dll 2012-08-24 10:13 . 2012-09-23 01:00 599040 —-a-w- c:\windows\system32\vbscript.dll 2012-08-24 10:12 . 2012-09-23 01:00 2144768 —-a-w- c:\windows\system32\iertutil.dll 2012-08-24 10:11 . 2012-09-23 01:00 729088 —-a-w- c:\windows\system32\msfeeds.dll 2012-08-24 10:10 . 2012-09-23 01:00 96768 —-a-w- c:\windows\system32\mshtmled.dll 2012-08-24 10:09 . 2012-09-23 01:00 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-08-24 10:04 . 2012-09-23 01:00 248320 —-a-w- c:\windows\system32\ieui.dll 2012-08-24 06:59 . 2012-09-23 01:00 1800704 —-a-w- c:\windows\SysWow64\jscript9.dll 2012-08-24 06:51 . 2012-09-23 01:00 1129472 —-a-w- c:\windows\SysWow64\wininet.dll 2012-08-24 06:51 . 2012-09-23 01:00 1427968 —-a-w- c:\windows\SysWow64\inetcpl.cpl 2012-08-24 06:47 . 2012-09-23 01:00 142848 —-a-w- c:\windows\SysWow64\ieUnatt.exe 2012-08-24 06:47 . 2012-09-23 01:00 420864 —-a-w- c:\windows\SysWow64\vbscript.dll 2012-08-24 06:43 . 2012-09-23 01:00 2382848 —-a-w- c:\windows\SysWow64\mshtml.tlb 2012-08-22 18:12 . 2012-09-11 23:46 1913200 —-a-w- c:\windows\system32\drivers\tcpip.sys 2012-08-22 18:12 . 2012-09-11 23:47 950128 —-a-w- c:\windows\system32\drivers\ndis.sys 2012-08-22 18:12 . 2012-09-11 23:46 376688 —-a-w- c:\windows\system32\drivers\netio.sys 2012-08-22 18:12 . 2012-09-11 23:46 288624 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS 2012-08-21 21:01 . 2012-09-26 08:55 245760 —-a-w- c:\windows\system32\OxpsConverter.exe 2012-08-20 17:38 . 2012-10-10 03:00 44032 —-a-w- c:\windows\apppatch\acwow64.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{6c97a91e-4524-4019-86af-2aa2d567bf5c}] 2012-09-20 20:06 87448 —-a-w- c:\program files (x86)\adawaretb\adawareDx.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{6c97a91e-4524-4019-86af-2aa2d567bf5c}"= "c:\program files (x86)\adawaretb\adawareDx.dll" [2012-09-20 87448] . [HKEY_CLASSES_ROOT\clsid\{6c97a91e-4524-4019-86af-2aa2d567bf5c}] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "uTorrent"="c:\program files (x86)\uTorrent\uTorrent.exe" [2012-08-04 1022352] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-10-16 5628800] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Ad-Aware Antivirus"="c:\program files (x86)\Ad-Aware Antivirus\AdAwareLauncher –windows-run" [X] "Lingvo Launcher"="c:\program files (x86)\ABBYY Lingvo x3\LvAgent.exe" [2009-12-11 1774856] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "Ad-Aware Browsing Protection"="c:\programdata\Ad-Aware Browsing Protection\adawarebp.exe" [2012-08-08 540056] . c:\users\George\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Sticky Notes Taskbar Hider.lnk - c:\program files (x86)\StickyNotes\SNTBHider.exe [2011-9-25 638976] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ad-Aware Service] @="Ad-Aware Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc] @="Service" . 2;2 SBAMSvc;Ad-Aware [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-07-08 123856] R2 KMService;KMService;c:\windows\system32\srvany.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944] R3 DfSdkS;Defragmentation-Service;c:\program files (x86)\Ashampoo\Ashampoo HDD Control 2\DfSdkS64.exe [2009-08-24 544768] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168] R3 DrvAgent64;DrvAgent64;c:\windows\SysWOW64\Drivers\DrvAgent64.SYS [2011-07-16 21712] R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 51740536] R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-21 20992] R3 sbhips;sbhips;c:\windows\system32\drivers\sbhips.sys [2011-12-19 60536] R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [2010-11-21 88960] R3 Te.Service;Te.Service;c:\program files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [2012-07-25 126976] R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2010-11-21 34816] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-21 117248] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 VSPerfDrv100;Performance Tools Driver 10.0;c:\program files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [2010-03-17 68440] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-06-06 1255736] R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-22 61976] R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 311656] R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 427880] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2011-11-03 56208] S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2011-06-04 834544] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368] S1 SBRE;SBRE;c:\windows\system32\drivers\SBREdrv.sys [2012-11-01 55384] S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2012-07-11 140672] S2 ABBYY.Licensing.Lingvo.Desktop.14.0;ABBYY Lingvo x3 Licencing Service;c:\program files (x86)\Common Files\ABBYY\Lingvo\14.0\Licensing\NetworkLicenseServer.exe [2009-12-11 816392] S2 Ad-Aware Service;Ad-Aware Service;c:\program files (x86)\Ad-Aware Antivirus\AdAwareService.exe [2012-09-20 1236368] S2 AHDDC2;Ashampoo HDD Control 2 Service;c:\program files (x86)\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Service.exe [2011-04-05 1518976] S2 IDMWFP;IDMWFP;c:\windows\system32\DRIVERS\idmwfp.sys [2011-09-08 143984] S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-09-29 399432] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-09-29 676936] S2 OS Selector;Активатор Acronis OS Selector;c:\program files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe [2010-07-01 2153336] S2 sbapifs;sbapifs;c:\windows\system32\DRIVERS\sbapifs.sys [2011-11-29 74872] S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys [2010-11-15 121832] S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys [2010-11-15 364520] S3 dc3d;MS Hardware Device Detection Driver;c:\windows\system32\DRIVERS\dc3d.sys [2011-04-08 47616] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-09-29 25928] S3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [2011-04-13 45432] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-10-26 406632] S3 V0330VID;WebCam Vista/Live! Cam Chat;c:\windows\system32\DRIVERS\V0330Vid.sys [2007-08-08 193312] . . — Other Services/Drivers In Memory — . *NewlyCreated* - WS2IFSL . Contents of the 'Scheduled Tasks' folder . 2012-11-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1109903177-269762195-694080819-1000Core.job - c:\users\George\AppData\Local\Google\Update\GoogleUpdate.exe [2011-06-09 22:16] . 2012-11-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1109903177-269762195-694080819-1000UA.job - c:\users\George\AppData\Local\Google\Update\GoogleUpdate.exe [2011-06-09 22:16] . 2012-11-02 c:\windows\Tasks\SUPERAntiSpyware Scheduled Task 57a291b1-ebd9-4043-9cbe-de77272c297c.job - c:\program files\SUPERAntiSpyware\SASTask.exe [2011-05-04 17:52] . 2012-11-02 c:\windows\Tasks\SUPERAntiSpyware Scheduled Task 8a2a6511-ce7f-4545-b4a7-11f842f8cbdb.job - c:\program files\SUPERAntiSpyware\SASTask.exe [2011-05-04 17:52] . 2012-11-02 c:\windows\Tasks\update-S-1-5-21-1109903177-269762195-694080819-1000.job - c:\program files (x86)\Skillbrains\Updater\Updater.exe [2012-01-30 20:09] . 2012-11-02 c:\windows\Tasks\update-sys.job - c:\program files (x86)\Skillbrains\Updater\Updater.exe [2012-01-30 20:09] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension] @="{CDC95B92-E27C-4745-A8C5-64A52A78855D}" [HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}] 2011-05-30 16:50 22408 —-a-w- c:\program files (x86)\Internet Download Manager\IDMShellExt64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-04-13 2399632] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=NIS&pvid=20.2.0.19 mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = local IE: Download all links with IDM - c:\program files (x86)\Internet Download Manager\IEGetAll.htm IE: Download with IDM - c:\program files (x86)\Internet Download Manager\IEExt.htm IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105 IE: {{7644E42D-B096-457F-8B5B-901238FC81AE} - c:\program files (x86)\ICQ7.6\ICQ.exe TCP: DhcpNameServer = 192.168.1.1 DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab FF - ProfilePath - c:\users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\ FF - prefs.js: browser.startup.homepage - korrespondent.net FF - prefs.js: keyword.URL - hxxp://safesearchr.lavasoft.com/?source=3336ca5f&tbp=url&toolbarid=adawaretb&u=EF15A04EC6049C0776EC1A509245A9D4&q= FF - prefs.js: network.proxy.type - 0 FF - ExtSQL: 2012-11-01 11:39; {87934c42-161d-45bc-8cef-ef18abe2a30c}; c:\users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c} FF - ExtSQL: 2012-11-01 11:39; jid1-yZwVFzbsyfMrqQ@jetpack; c:\users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions\jid1-yZwVFzbsyfMrqQ@jetpack FF - ExtSQL: !HIDDEN! 2011-07-12 18:57; [removed]; c:\users\George\AppData\Roaming\IDM\idmmzcc5 . - - - - ORPHANS REMOVED - - - - . BHO-{78F3A323-798E-4AEA-9A57-88F4B05FD5DD} - c:\program files (x86)\StartSearch plugin\ssBarLcher.dll Wow6432Node-HKCU-Run-AdobeBridge - (no file) AddRemove-LiveVDO plugin - c:\program files (x86)\StartSearch plugin\uninst.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-1109903177-269762195-694080819-1000_Classes\Wow6432Node\CLSID\{3d4f5533-7cbe-490e-8e46-0d365fce17b7}] @Denied: (Full) (Everyone) @Allowed: (Read) (RestrictedCode) "Model"=dword:0000013c "Therad"=dword:0000001b "MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a, 1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\ . [HKEY_USERS\S-1-5-21-1109903177-269762195-694080819-1000_Classes\Wow6432Node\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}] @Denied: (Full) (Everyone) "scansk"=hex(0):08,84,d5,5b,ee,73,55,36,23,66,aa,2f,49,53,2f,a2,c6,dc,80,90,18, 26,a3,2b,05,17,18,71,05,7e,bd,47,78,6b,81,ab,d7,3c,1f,2b,00,00,00,00,00,00,\ . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version] "Version"=hex:2f,b0,f9,3f,bb,f3,d9,06,f3,6f,93,31,fc,b5,30,e3,ae,ff,fc,e5,06, a5,d7,a9,66,ce,de,73,de,07,9f,c2,7c,4e,35,53,a6,95,7b,35,3a,e3,07,31,68,54,\ . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_257_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_257_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files (x86)\Ad-Aware Antivirus\SBAMSvc.exe . ************************************************************************** . Completion time: 2012-11-02 15:05:41 - machine was rebooted ComboFix-quarantined-files.txt 2012-11-02 13:05 . Pre-Run: 34 974 994 432 bytes free Post-Run: 37 007 306 752 bytes free . - - End Of File - - 577A36F74148DBB876AC885306EDA6A7
  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.







Next

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is not checked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the Back button.
  • Push Finish
http://www.eset.com/onlinescan/






Please download AdwCleaner from here and save it to your desktop.
  • Right click on AdwCleaner.exe and click "Run as Administrator" to run the tool.
  • Click on Delete.
A logfile will automatically open after the scan has finished.

Please post the content of that logfile in your reply.

You can find the logfile at C:\AdwCleaner[Rn].txt as well - (n is the scan number.)



Also tell me how the computer is running now.
The annoying ads disappeared after I ran the OTL and restarted the computer. Things seem to be better now. Here are the latest logs requested. Malwarebytes Anti-Malware (Trial) 1.65.1.1000 www.malwarebytes.org Database version: v2012.11.02.08 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 George :: INTEL-I5 [administrator] Protection: Disabled 02.11.2012 15:45:51 mbam-log-2012-11-02 (15-45-51).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 205697 Time elapsed: 2 minute(s), 18 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 5 HKCR\CLSID\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD} (PUP.VShareRedir) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD} (PUP.VShareRedir) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD} (PUP.VShareRedir) -> Quarantined and deleted successfully. HKCR\CLSID\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} (PUP.VShareRedir) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} (PUP.VShareRedir) -> Quarantined and deleted successfully. Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) ESET OnlineScan did not find any threats. # AdwCleaner v2.006 - Logfile created 11/02/2012 at 20:23:51 # Updated 30/10/2012 by Xplode # Operating system : Windows 7 Ultimate Service Pack 1 (64 bits) # User : George - INTEL-I5 # Boot Mode : Normal # Running from : C:\Users\George\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** File Deleted : C:\Program Files (x86)\Mozilla Firefox\Plugins\npvsharetvplg.dll Folder Deleted : C:\Program Files (x86)\vShare.tv plugin Folder Deleted : C:\ProgramData\blekko toolbars Folder Deleted : C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbiamblgmkgbcgbcgejjgebalncpmhnp ***** [Registry] ***** Key Deleted : HKCU\Software\AppDataLow\Software Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F97BFF8-488B-4107-BCEE-B161AB4E4183} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A1B48071-416D-474E-A13B-BE5456E7FC31} Key Deleted : HKCU\Software\Softonic Key Deleted : HKCU\Software\StartSearch Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Key Deleted : HKLM\SOFTWARE\Classes\AppID\BHO.DLL Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{79D60450-56C5-4A8C-9321-6D5BC2A81E5A} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{99C22A61-21BA-4F81-85FF-CDC9EB5DB10B} Key Deleted : HKLM\Software\Iminent Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F97BFF8-488B-4107-BCEE-B161AB4E4183} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A1B48071-416D-474E-A13B-BE5456E7FC31} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{8F97BFF8-488B-4107-BCEE-B161AB4E4183} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A1B48071-416D-474E-A13B-BE5456E7FC31} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pbiamblgmkgbcgbcgejjgebalncpmhnp Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\LiveVDO plugin Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16421 [OK] Registry is clean. -\\ Mozilla Firefox v16.0.2 (en-US) Profile name : default File : C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\prefs.js Deleted : user_pref("extensions.kango.storage.CachedhxxpRequest.hxxp://ring-tools.info/addons/firefox/update.x[…] Deleted : user_pref("extensions.kango.storage.CachedhxxpRequest.hxxp://ring-tools.info/addons/firefox/update.x[…] Deleted : user_pref("extensions.kango.storage.CachedhxxpRequest.hxxp://ring-tools.info/scripts/qa.php?product_[…] Deleted : user_pref("extensions.kango.storage.CachedhxxpRequest.hxxp://ring-tools.info/scripts/qa.php?product_[…] Deleted : user_pref("extensions.kango.storage.ga_first_time", "1337178982"); Deleted : user_pref("extensions.kango.storage.ga_hit_counter", "167"); Deleted : user_pref("extensions.kango.storage.ga_last_time", "1337178982"); Deleted : user_pref("extensions.kango.storage.ga_unique_id", "1337209330"); Deleted : user_pref("extensions.kango.storage.script_loader.data", "\"[{\\\"type\\\":\\\"content\\\",\\\"code\[…] Deleted : user_pref("extensions.kango.storage.statistics.user_guid", "\"{7C961EEB-A76C-460F-336C-8C3C84384334}[…] Deleted : user_pref("extensions.kango.storage.statistics.user_stat_sent", "\"Fri May 18 2012 04:36:19 GMT+0200[…] Deleted : user_pref("vshare.install.date", "1316027540"); Deleted : user_pref("vshare.install.finished", "1.0.0"); Deleted : user_pref("vshare.install.fresh", "false"); Deleted : user_pref("vshare.install.guid", "{ef3a07f2-1352-4f2e-84a0-d26af943c1f9}"); Deleted : user_pref("vshare.install.newtab", false); -\\ Google Chrome v22.0.1229.94 File : C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Preferences Deleted [l.57] : keyword = "blekko", ************************* AdwCleaner[S2].txt - [4408 octets] - [02/11/2012 20:23:51] ########## EOF - C:\AdwCleaner[S2].txt - [4468 octets] ##########
OTL logfile created on: 03.11.2012 9:11:43 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\George\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000419 | Country: Russia | Language: RUS | Date Format: dd.MM.yyyy

7,98 Gb Total Physical Memory | 6,10 Gb Available Physical Memory | 76,48% Memory free
15,96 Gb Paging File | 13,78 Gb Available in Paging File | 86,35% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 121,00 Gb Total Space | 33,92 Gb Free Space | 28,03% Space Free | Partition Type: NTFS
Drive D: | 160,20 Gb Total Space | 7,63 Gb Free Space | 4,76% Space Free | Partition Type: NTFS
Drive E: | 650,21 Gb Total Space | 7,02 Gb Free Space | 1,08% Space Free | Partition Type: NTFS
Drive F: | 232,88 Gb Total Space | 11,72 Gb Free Space | 5,03% Space Free | Partition Type: NTFS
Drive G: | 465,75 Gb Total Space | 6,13 Gb Free Space | 1,32% Space Free | Partition Type: NTFS
Drive H: | 465,75 Gb Total Space | 0,96 Gb Free Space | 0,21% Space Free | Partition Type: NTFS
Drive I: | 465,75 Gb Total Space | 0,85 Gb Free Space | 0,18% Space Free | Partition Type: NTFS
Drive J: | 465,75 Gb Total Space | 3,20 Gb Free Space | 0,69% Space Free | Partition Type: NTFS

Computer Name: INTEL-I5 | User Name: George | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012.11.02 13:45:42 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\George\Desktop\OTL.exe
PRC - [2012.09.29 19:54:26 | 000,766,536 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012.09.29 19:54:26 | 000,676,936 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.09.29 19:54:26 | 000,399,432 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012.09.20 15:03:20 | 001,236,368 | —- | M] (Lavasoft Limited) – C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe
PRC - [2012.08.08 10:17:00 | 000,540,056 | —- | M] (Lavasoft) – C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe
PRC - [2012.08.04 14:41:24 | 001,022,352 | —- | M] (BitTorrent, Inc.) – C:\Program Files (x86)\uTorrent\uTorrent.exe
PRC - [2012.01.03 15:10:44 | 001,494,424 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
PRC - [2012.01.03 15:10:42 | 000,063,928 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011.09.08 15:38:22 | 003,425,688 | —- | M] (Tonec Inc.) – C:\Program Files (x86)\Internet Download Manager\IDMan.exe
PRC - [2011.04.05 10:39:46 | 001,518,976 | —- | M] () – C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Service.exe
PRC - [2010.12.09 12:47:04 | 001,595,744 | —- | M] (Nullsoft, Inc.) – C:\Program Files (x86)\Winamp\winamp.exe
PRC - [2010.07.01 16:31:36 | 002,153,336 | —- | M] () – C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe
PRC - [2010.01.22 21:48:02 | 000,638,976 | —- | M] (Drakenscripts.co.cc) – C:\Program Files (x86)\StickyNotes\SNTBHider.exe
PRC - [2009.12.11 17:24:24 | 000,816,392 | —- | M] (ABBYY) – C:\Program Files (x86)\Common Files\ABBYY\Lingvo\14.0\Licensing\NetworkLicenseServer.exe
PRC - [2009.12.11 17:24:04 | 001,774,856 | —- | M] (ABBYY (BIT Software)) – C:\Program Files (x86)\ABBYY Lingvo x3\LvAgent.exe


========== Modules (No Company Name) ==========

MOD - [2012.01.03 15:10:44 | 000,249,232 | —- | M] () – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\sqlite.dll
MOD - [2011.06.04 23:44:04 | 000,154,624 | —- | M] () – C:\Program Files (x86)\Winamp\System\jpeg.w5s
MOD - [2011.06.04 23:44:04 | 000,090,112 | —- | M] () – C:\Program Files (x86)\Winamp\System\xml.w5s
MOD - [2011.06.04 23:44:04 | 000,086,528 | —- | M] () – C:\Program Files (x86)\Winamp\System\png.w5s
MOD - [2011.06.04 23:44:04 | 000,084,480 | —- | M] () – C:\Program Files (x86)\Winamp\System\playlist.w5s
MOD - [2011.06.04 23:44:04 | 000,083,968 | —- | M] () – C:\Program Files (x86)\Winamp\tataki.dll
MOD - [2011.06.04 23:44:04 | 000,047,616 | —- | M] () – C:\Program Files (x86)\Winamp\zlib.dll
MOD - [2011.06.04 23:44:04 | 000,035,328 | —- | M] () – C:\Program Files (x86)\Winamp\System\timer.w5s
MOD - [2011.06.04 23:44:04 | 000,021,504 | —- | M] () – C:\Program Files (x86)\Winamp\System\tagz.w5s
MOD - [2011.06.04 23:44:04 | 000,013,824 | —- | M] () – C:\Program Files (x86)\Winamp\System\primo.w5s
MOD - [2011.06.04 23:44:03 | 000,623,616 | —- | M] () – C:\Program Files (x86)\Winamp\System\jnetlib.w5s
MOD - [2011.06.04 23:44:03 | 000,313,344 | —- | M] () – C:\Program Files (x86)\Winamp\Plugins\in_wm.dll
MOD - [2011.06.04 23:44:03 | 000,288,256 | —- | M] () – C:\Program Files (x86)\Winamp\Plugins\in_mp3.dll
MOD - [2011.06.04 23:44:03 | 000,252,416 | —- | M] () – C:\Program Files (x86)\Winamp\Plugins\in_vorbis.dll
MOD - [2011.06.04 23:44:03 | 000,249,856 | —- | M] () – C:\Program Files (x86)\Winamp\Plugins\ml_devices.dll
MOD - [2011.06.04 23:44:03 | 000,240,128 | —- | M] () – C:\Program Files (x86)\Winamp\Plugins\ml_pmp.dll
MOD - [2011.06.04 23:44:03 | 000,237,056 | —- | M] () – C:\Program Files (x86)\Winamp\System\aacPlusDecoder.w5s
MOD - [2011.06.04 23:44:03 | 000,165,376 | —- | M] () – C:\Program Files (x86)\Winamp\Plugins\in_mod.dll
MOD - [2011.06.04 23:44:03 | 000,109,568 | —- | M] () – C:\Program Files (x86)\Winamp\Plugins\in_midi.dll
MOD - [2011.06.04 23:44:03 | 000,074,752 | —- | M] () – C:\Program Files (x86)\Winamp\Plugins\in_nsv.dll
MOD - [2011.06.04 23:44:03 | 000,052,224 | —- | M] () – C:\Program Files (x86)\Winamp\Plugins\out_ds.dll
MOD - [2011.06.04 23:44:03 | 000,050,688 | —- | M] () – C:\Program Files (x86)\Winamp\Plugins\in_mp4.dll
MOD - [2011.06.04 23:44:03 | 000,049,152 | —- | M] () – C:\Program Files (x86)\Winamp\Plugins\in_mkv.dll
MOD - [2011.06.04 23:44:03 | 000,044,544 | —- | M] () – C:\Program Files (x86)\Winamp\System\devices.w5s
MOD - [2011.06.04 23:44:03 | 000,043,008 | —- | M] () – C:\Program Files (x86)\Winamp\Plugins\in_flv.dll
MOD - [2011.06.04 23:44:03 | 000,023,552 | —- | M] () – C:\Program Files (x86)\Winamp\Plugins\in_swf.dll
MOD - [2011.06.04 23:44:03 | 000,023,040 | —- | M] () – C:\Program Files (x86)\Winamp\System\albumart.w5s
MOD - [2011.06.04 23:44:03 | 000,022,528 | —- | M] () – C:\Program Files (x86)\Winamp\Plugins\out_disk.dll
MOD - [2011.06.04 23:44:03 | 000,019,456 | —- | M] () – C:\Program Files (x86)\Winamp\System\gif.w5s
MOD - [2011.06.04 23:44:03 | 000,019,456 | —- | M] () – C:\Program Files (x86)\Winamp\System\bmp.w5s
MOD - [2011.06.04 23:44:03 | 000,018,432 | —- | M] () – C:\Program Files (x86)\Winamp\Plugins\out_wave.dll
MOD - [2011.06.04 23:44:03 | 000,016,896 | —- | M] () – C:\Program Files (x86)\Winamp\Plugins\in_wave.dll
MOD - [2011.06.04 23:44:03 | 000,016,896 | —- | M] () – C:\Program Files (x86)\Winamp\System\dlmgr.w5s
MOD - [2011.06.04 23:44:03 | 000,016,384 | —- | M] () – C:\Program Files (x86)\Winamp\System\gracenote.w5s
MOD - [2011.06.04 23:44:03 | 000,014,336 | —- | M] () – C:\Program Files (x86)\Winamp\System\filereader.w5s
MOD - [2011.06.04 23:44:03 | 000,007,168 | —- | M] () – C:\Program Files (x86)\Winamp\Plugins\in_linein.dll
MOD - [2011.06.04 23:44:02 | 001,737,216 | —- | M] () – C:\Program Files (x86)\Winamp\Plugins\gen_ff.dll
MOD - [2011.06.04 23:44:02 | 000,340,992 | —- | M] () – C:\Program Files (x86)\Winamp\Plugins\freeform\wacs\freetype\freetype.wac
MOD - [2011.06.04 23:44:02 | 000,307,200 | —- | M] () – C:\Program Files (x86)\Winamp\Plugins\gen_ml.dll
MOD - [2011.06.04 23:44:02 | 000,183,808 | —- | M] () – C:\Program Files (x86)\Winamp\Plugins\gen_jumpex.dll
MOD - [2011.06.04 23:44:02 | 000,102,400 | —- | M] () – C:\Program Files (x86)\Winamp\Plugins\in_cdda.dll
MOD - [2011.06.04 23:44:02 | 000,073,728 | —- | M] () – C:\Program Files (x86)\Winamp\nde.dll
MOD - [2011.06.04 23:44:02 | 000,072,192 | —- | M] () – C:\Program Files (x86)\Winamp\Plugins\in_dshow.dll
MOD - [2011.06.04 23:44:02 | 000,068,608 | —- | M] () – C:\Program Files (x86)\Winamp\Plugins\in_avi.dll
MOD - [2011.06.04 23:44:02 | 000,060,416 | —- | M] () – C:\Program Files (x86)\Winamp\Plugins\in_flac.dll
MOD - [2011.06.04 23:44:02 | 000,053,248 | —- | M] () – C:\Program Files (x86)\Winamp\nsutil.dll
MOD - [2011.06.04 23:44:02 | 000,027,648 | —- | M] () – C:\Program Files (x86)\Winamp\Plugins\gen_hotkeys.dll
MOD - [2011.06.04 23:44:02 | 000,025,600 | —- | M] () – C:\Program Files (x86)\Winamp\Plugins\gen_tray.dll
MOD - [2011.06.04 23:44:01 | 000,253,440 | —- | M] () – C:\Program Files (x86)\Winamp\libsndfile.dll
MOD - [2011.03.17 00:11:16 | 004,297,568 | —- | M] () – C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010.10.20 15:45:26 | 008,801,120 | —- | M] () – C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll


========== Services (SafeList) ==========

SRV:64bit: - [2012.07.11 20:54:58 | 000,140,672 | —- | M] (SUPERAntiSpyware.com) [Auto | Running] – C:\Program Files\SUPERAntiSpyware\SASCore64.exe – (!SASCORE)
SRV:64bit: - [2010.09.22 17:10:10 | 000,057,184 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe – (wlcrasvc)
SRV:64bit: - [2009.07.14 03:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2009.07.14 03:40:01 | 000,193,536 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\appmgmts.dll – (AppMgmt)
SRV - [2012.09.29 19:54:26 | 000,676,936 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2012.09.29 19:54:26 | 000,399,432 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe – (MBAMScheduler)
SRV - [2012.09.20 15:03:20 | 001,236,368 | —- | M] (Lavasoft Limited) [Auto | Running] – C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe – (Ad-Aware Service)
SRV - [2012.07.25 18:58:26 | 000,126,976 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe – (Te.Service)
SRV - [2012.07.25 18:13:16 | 000,139,776 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe – (fussvc)
SRV - [2012.07.13 13:28:36 | 000,160,944 | R— | M] (Skype Technologies) [Auto | Stopped] – C:\Program Files (x86)\Skype\Updater\Updater.exe – (SkypeUpdate)
SRV - [2012.07.09 00:40:10 | 000,104,912 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2012.01.03 15:10:42 | 000,063,928 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2011.12.19 13:20:06 | 003,289,032 | —- | M] (GFI Software) [Auto | Stopped] – C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe – (SBAMSvc)
SRV - [2011.11.24 20:59:24 | 000,008,192 | —- | M] () [Auto | Stopped] – C:\Windows\SysWOW64\srvany.exe – (KMService)
SRV - [2011.09.26 11:17:16 | 009,665,536 | —- | M] () [On_Demand | Stopped] – c:\wamp\bin\mysql\mysql5.5.16\bin\mysqld.exe – (wampmysqld)
SRV - [2011.09.26 11:06:54 | 000,021,504 | —- | M] (Apache Software Foundation) [On_Demand | Stopped] – c:\wamp\bin\apache\Apache2.2.21\bin\httpd.exe – (wampapache)
SRV - [2011.04.05 10:39:46 | 001,518,976 | —- | M] () [Auto | Running] – C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Service.exe – (AHDDC2)
SRV - [2010.07.01 16:31:36 | 002,153,336 | —- | M] () [Auto | Running] – C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe – (OS Selector)
SRV - [2010.02.19 13:37:14 | 000,517,096 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe – (SwitchBoard)
SRV - [2009.12.11 17:24:24 | 000,816,392 | —- | M] (ABBYY) [Auto | Running] – C:\Program Files (x86)\Common Files\ABBYY\Lingvo\14.0\Licensing\NetworkLicenseServer.exe – (ABBYY.Licensing.Lingvo.Desktop.14.0)
SRV - [2009.08.24 20:16:12 | 000,544,768 | —- | M] (mst software GmbH, Germany) [On_Demand | Stopped] – C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control 2\DfSdkS64.exe – (DfSdkS)
SRV - [2009.06.10 23:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012.11.01 16:08:06 | 000,055,384 | —- | M] (Sunbelt Software) [Kernel | System | Stopped] – C:\Windows\SysNative\drivers\SBREDrv.sys – (SBRE)
DRV:64bit: - [2012.09.29 19:54:26 | 000,025,928 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\mbam.sys – (MBAMProtector)
DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2011.12.19 12:44:24 | 000,060,536 | —- | M] (GFI Software) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\sbhips.sys – (sbhips)
DRV:64bit: - [2011.11.29 06:59:46 | 000,074,872 | —- | M] (GFI Software) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\sbapifs.sys – (sbapifs)
DRV:64bit: - [2011.11.15 05:50:14 | 000,125,376 | —- | M] (Power Software Ltd) [Kernel | System | Running] – C:\Windows\SysNative\drivers\scdemu.sys – (SCDEmu)
DRV:64bit: - [2011.11.03 03:01:00 | 000,056,208 | —- | M] (Rovi Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\PxHlpa64.sys – (PxHlpa64)
DRV:64bit: - [2011.09.08 16:12:20 | 000,143,984 | —- | M] (Tonec Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\idmwfp.sys – (IDMWFP)
DRV:64bit: - [2011.08.17 09:58:26 | 000,009,216 | —- | M] (Nokia) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbser_lowerfltjx64.sys – (UsbserFilt)
DRV:64bit: - [2011.08.17 09:58:22 | 000,009,216 | —- | M] (Nokia) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbser_lowerfltx64.sys – (upperdev)
DRV:64bit: - [2011.08.17 09:58:20 | 000,027,136 | —- | M] (Nokia) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\ccdcmbox64.sys – (nmwcdc)
DRV:64bit: - [2011.08.17 09:58:16 | 000,019,968 | —- | M] (Nokia) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\ccdcmbx64.sys – (nmwcd)
DRV:64bit: - [2011.07.22 18:26:56 | 000,014,928 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys – (SASDIFSV)
DRV:64bit: - [2011.07.12 23:55:18 | 000,012,368 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\saskutil64.sys – (SASKUTIL)
DRV:64bit: - [2011.06.15 23:07:10 | 000,276,576 | —- | M] (Acronis) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\snapman.sys – (snapman)
DRV:64bit: - [2011.06.04 23:41:47 | 000,834,544 | —- | M] () [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\sptd.sys – (sptd)
DRV:64bit: - [2011.04.13 14:04:38 | 000,045,432 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\point64.sys – (Point64)
DRV:64bit: - [2011.04.08 22:00:20 | 000,047,616 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\dc3d.sys – (dc3d)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2010.11.21 05:24:43 | 000,020,992 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\rdpvideominiport.sys – (RdpVideoMiniport)
DRV:64bit: - [2010.11.21 05:24:33 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010.11.21 05:23:48 | 000,117,248 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\tsusbhub.sys – (tsusbhub)
DRV:64bit: - [2010.11.21 05:23:48 | 000,088,960 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\Synth3dVsc.sys – (Synth3dVsc)
DRV:64bit: - [2010.11.21 05:23:48 | 000,071,168 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\dmvsc.sys – (dmvsc)
DRV:64bit: - [2010.11.21 05:23:48 | 000,034,816 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\terminpt.sys – (terminpt)
DRV:64bit: - [2010.11.21 05:23:48 | 000,032,768 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbser.sys – (usbser)
DRV:64bit: - [2010.11.21 05:23:47 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010.11.21 05:23:47 | 000,031,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbGD.sys – (TsUsbGD)
DRV:64bit: - [2010.11.15 18:05:02 | 000,364,520 | —- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\asmtxhci.sys – (asmtxhci)
DRV:64bit: - [2010.11.15 18:05:00 | 000,121,832 | —- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\asmthub3.sys – (asmthub3)
DRV:64bit: - [2010.10.26 10:08:08 | 000,406,632 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2010.10.19 23:34:26 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (MEIx64)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2007.08.08 12:47:16 | 000,193,312 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\V0330Vid.sys – (V0330VID)
DRV - [2012.07.13 16:13:14 | 000,070,264 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys – (VSPerfDrv110)
DRV - [2011.10.26 14:23:40 | 000,101,112 | —- | M] (GFI Software) [Kernel | System | Stopped] – C:\Windows\SysWOW64\drivers\SBREDrv.sys – (SBRE)
DRV - [2011.07.16 15:29:28 | 000,021,712 | —- | M] (Phoenix Technologies) [Kernel | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\DrvAgent64.SYS – (DrvAgent64)
DRV - [2009.07.14 03:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/redirects/security…;pvid=20.2.0.19
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = ru
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = A0 D9 14 86 FF 22 CC 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "korrespondent.net"
FF - prefs.js..extensions.enabledAddons: [removed]:7.3.29
FF - prefs.js..keyword.URL: "http://safesearchr.lavasoft.com/?source=3336ca5f&tbp=url&toolbarid=adawaretb&u=EF15A04EC6049C0776EC1A509245A9D4&q="
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_265.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.19: C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\George\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\George\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.11.01 11:49:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.11.02 20:23:52 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.11.01 11:49:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.11.02 20:23:52 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Users\George\AppData\Roaming\IDM\idmmzcc5 [2011.09.10 14:02:43 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\[removed]: C:\Users\George\AppData\Roaming\IDM\idmmzcc5 [2011.09.10 14:02:43 | 000,000,000 | —D | M]

[2011.06.05 01:11:18 | 000,000,000 | —D | M] (No name found) – C:\Users\George\AppData\Roaming\Mozilla\Extensions
[2012.11.01 11:49:27 | 000,000,000 | —D | M] (No name found) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions
[2012.11.01 11:49:28 | 000,000,000 | —D | M] (Ad-Aware Security Add-on) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c}
[2012.03.01 11:04:51 | 000,000,000 | —D | M] (Search Assistant) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions\{B3834E60-12A8-11E0-A289-939FDFD72085}
[2012.11.01 11:39:29 | 000,000,000 | —D | M] (Lavasoft Search Plugin) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions\jid1-yZwVFzbsyfMrqQ@jetpack
[2012.10.15 16:55:27 | 000,000,000 | —D | M] (IDM CC) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions\[removed]
[2012.11.01 06:43:05 | 000,000,000 | —D | M] (No name found) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions\trash
[2012.11.01 06:43:05 | 002,042,908 | —- | M] () (No name found) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions\[removed]
[2011.09.14 21:09:36 | 000,087,923 | R— | M] () (No name found) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions\{dd05fd3d-18df-4ce4-ae53-e795339c5f01}.xpi
[2012.10.26 06:39:57 | 002,042,937 | —- | M] () (No name found) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions\trash\[removed]
[2011.06.08 05:55:13 | 000,012,703 | —- | M] () – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\searchplugins\imdb.xml
[2011.08.04 01:15:27 | 000,009,695 | —- | M] () – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\searchplugins\lurkmore-ru.xml
[2011.06.08 18:24:35 | 000,001,701 | —- | M] () – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\searchplugins\rutrackerorg.xml
[2011.06.05 23:50:34 | 000,002,057 | —- | M] () – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\searchplugins\youtube-video-search.xml
[2012.10.27 08:04:00 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012.10.27 08:04:00 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012.10.27 08:04:26 | 000,261,600 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011.11.10 05:54:13 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2012.11.01 11:49:30 | 000,000,616 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\adawaretb.xml
[2012.08.30 09:27:08 | 000,002,465 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.10.12 19:34:03 | 000,002,058 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: http://www.google.com/
CHR - default_search_provider: blekko (Enabled)
CHR - default_search_provider: search_url = http://safesearchr.lavasoft.com/?source=33…q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - homepage: http://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\George\AppData\Local\Google\Chrome\Application\22.0.1229.94\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\George\AppData\Local\Google\Chrome\Application\22.0.1229.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\George\AppData\Local\Google\Chrome\Application\22.0.1229.94\pdf.dll
CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files (x86)\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files (x86)\Veetle\plugins\npVeetle.dll
CHR - plugin: Google Update (Enabled) = C:\Users\George\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Angry Birds = C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.7_0\
CHR - Extension: Search Assistant = C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfelndikbdcohbdimnhdhhokfljdidgn\2.0.0\
CHR - Extension: vshare plugin = C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0\
CHR - Extension: Skype Click to Call = C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.10.0.9560_0\

O1 HOSTS File: ([2012.11.02 15:01:10 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll (Internet Download Manager, Tonec Inc.)
O2:64bit: - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitBHO64.dll (TechSmith Corporation)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 10\SnagitBHO.dll (TechSmith Corporation)
O2 - BHO: (Ad-Aware Security Add-on) - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\adawaretb\adawareDx.dll ()
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Microsoft Web Test Recorder 10.0 Helper) - {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} - C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3:64bit: - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitIEAddin64.dll (TechSmith Corporation)
O3 - HKLM\..\Toolbar: (Ad-Aware Security Add-on) - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\adawaretb\adawareDx.dll ()
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\SnagitIEAddin.dll (TechSmith Corporation)
O4:64bit: - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Ad-Aware Antivirus] C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher.exe (Lavasoft Limited)
O4 - HKLM..\Run: [Ad-Aware Browsing Protection] C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft)
O4 - HKLM..\Run: [Lingvo Launcher] C:\Program Files (x86)\ABBYY Lingvo x3\LvAgent.exe (ABBYY (BIT Software))
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [uTorrent] C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - Startup: C:\Users\George\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sticky Notes Taskbar Hider.lnk = C:\Program Files (x86)\StickyNotes\SNTBHider.exe (Drakenscripts.co.cc)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8:64bit: - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O9 - Extra Button: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files (x86)\ICQ7.6\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files (x86)\ICQ7.6\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 10.2.0)
O16:64bit: - DPF: {CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_02)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_02)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwareup…13/CTPIDPDE.cab (Creative Software AutoUpdate Support Package 2)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} http://ccfiles.creative.com/Web/softwareup…015/CTSUEng.cab (Creative Software AutoUpdate 2)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareup…15118/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FD181FDC-6BF9-4094-9BF8-195BA15CE97D}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012.11.02 16:20:20 | 000,000,000 | —D | C] – C:\Users\George\AppData\Local\{E028B037-C16E-4771-B473-D48C2D2F1B40}
[2012.11.02 15:55:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2012.11.02 15:55:03 | 002,322,184 | —- | C] (ESET) – C:\Users\George\Desktop\esetsmartinstaller_enu.exe
[2012.11.02 15:05:44 | 000,000,000 | —D | C] – C:\Windows\temp
[2012.11.02 15:01:16 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2012.11.02 14:56:02 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012.11.02 14:56:02 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012.11.02 14:56:02 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012.11.02 14:55:59 | 000,000,000 | —D | C] – C:\Qoobox
[2012.11.02 14:55:51 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2012.11.02 14:54:26 | 004,994,057 | R— | C] (Swearware) – C:\Users\George\Desktop\ComboFix.exe
[2012.11.02 13:47:55 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\George\Desktop\HiJackThis.exe
[2012.11.02 13:45:36 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\George\Desktop\OTL.exe
[2012.11.02 13:16:26 | 000,000,000 | —D | C] – C:\Users\George\AppData\Roaming\Malwarebytes
[2012.11.02 13:16:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.11.02 13:16:15 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012.11.02 13:16:14 | 000,025,928 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2012.11.02 13:16:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.11.01 18:33:27 | 000,000,000 | —D | C] – C:\Users\George\AppData\Roaming\SUPERAntiSpyware.com
[2012.11.01 18:33:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2012.11.01 18:33:05 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2012.11.01 18:33:05 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2012.11.01 18:08:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\appmgmt
[2012.11.01 14:42:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\Lavasoft
[2012.11.01 14:23:11 | 000,000,000 | —D | C] – C:\ProgramData\Ad-Aware Antivirus
[2012.11.01 13:55:58 | 000,000,000 | —D | C] – C:\Users\George\AppData\Local\adawarebp
[2012.11.01 12:18:12 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ad-Aware Antivirus
[2012.11.01 12:18:00 | 000,060,536 | —- | C] (GFI Software) – C:\Windows\SysNative\drivers\sbhips.sys
[2012.11.01 12:17:59 | 000,045,936 | —- | C] (GFI Software) – C:\Windows\SysNative\sbbd.exe
[2012.11.01 12:17:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\Ad-Aware Antivirus
[2012.11.01 12:17:30 | 000,000,000 | —D | C] – C:\Users\George\AppData\Local\Downloaded Installations
[2012.11.01 11:44:48 | 000,000,000 | —D | C] – C:\Users\George\AppData\Roaming\LavasoftStatistics
[2012.11.01 11:39:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\adawaretb
[2012.11.01 11:27:12 | 000,000,000 | —D | C] – C:\Users\George\AppData\Roaming\Ad-Aware Antivirus
[2012.11.01 11:03:23 | 000,055,384 | —- | C] (Sunbelt Software) – C:\Windows\SysNative\drivers\SBREDrv.sys
[2012.11.01 10:51:52 | 000,000,000 | —D | C] – C:\Users\George\AppData\Local\adaware
[2012.11.01 10:51:47 | 000,000,000 | —D | C] – C:\ProgramData\Ad-Aware Browsing Protection
[2012.11.01 10:51:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Toolbar Cleaner
[2012.11.01 10:51:15 | 000,000,000 | —D | C] – C:\Windows\SysNative\DRVSTORE
[2012.11.01 10:51:12 | 000,000,000 | —D | C] – C:\ProgramData\Lavasoft
[2012.11.01 09:39:08 | 000,000,000 | —D | C] – C:\Users\George\AppData\Local\NPE
[2012.10.31 21:33:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Symantec Shared
[2012.10.31 21:30:59 | 000,000,000 | —D | C] – C:\ProgramData\Norton
[2012.10.31 21:26:05 | 000,000,000 | —D | C] – C:\ProgramData\NortonInstaller
[2012.10.31 20:03:22 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012.10.31 20:03:21 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2012.10.29 16:25:01 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2012.10.29 12:33:30 | 000,000,000 | —D | C] – C:\Users\George\Desktop\2012_10_29
[2012.10.27 20:53:14 | 000,000,000 | —D | C] – C:\Users\George\Desktop\2012_10_27
[2012.10.27 08:04:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2012.10.25 17:17:24 | 000,000,000 | —D | C] – C:\Users\George\Desktop\2012_10_25
[2012.10.24 12:02:08 | 000,000,000 | —D | C] – C:\Users\George\Desktop\2012_10_24
[2012.10.12 00:09:17 | 000,000,000 | —D | C] – C:\Users\George\Desktop\2012_10_12
[2012.10.11 16:58:24 | 000,000,000 | —D | C] – C:\Users\George\Desktop\2012_10_11
[2012.10.10 23:36:21 | 000,000,000 | —D | C] – C:\Users\George\Desktop\2012_10_10
[2012.10.10 05:00:21 | 005,559,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2012.10.10 05:00:21 | 003,914,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2012.10.10 05:00:20 | 003,968,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2012.10.10 05:00:16 | 001,162,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2012.10.10 05:00:16 | 000,424,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\KernelBase.dll
[2012.10.10 05:00:15 | 000,338,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\conhost.exe
[2012.10.10 05:00:15 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2012.10.10 05:00:15 | 000,215,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2012.10.10 05:00:15 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2012.10.10 05:00:15 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntvdm64.dll
[2012.10.10 05:00:14 | 000,362,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64win.dll
[2012.10.10 05:00:14 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2012.10.10 05:00:14 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64cpu.dll
[2012.10.10 05:00:14 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2012.10.10 05:00:14 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2012.10.10 05:00:14 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2012.10.10 05:00:14 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2012.10.10 05:00:14 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2012.10.10 05:00:14 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2012.10.10 05:00:14 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2012.10.10 05:00:13 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2012.10.10 05:00:09 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wintrust.dll
[2012.10.10 05:00:01 | 001,464,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2012.10.10 05:00:01 | 000,140,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2012.10.10 00:31:29 | 000,000,000 | —D | C] – C:\Users\George\Desktop\bin
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012.11.03 09:06:00 | 000,000,982 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1109903177-269762195-694080819-1000UA.job
[2012.11.03 07:57:00 | 000,000,390 | —- | M] () – C:\Windows\tasks\update-S-1-5-21-1109903177-269762195-694080819-1000.job
[2012.11.03 07:21:00 | 000,000,390 | —- | M] () – C:\Windows\tasks\update-sys.job
[2012.11.03 06:06:00 | 000,000,930 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1109903177-269762195-694080819-1000Core.job
[2012.11.03 02:33:00 | 000,000,512 | —- | M] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 8a2a6511-ce7f-4545-b4a7-11f842f8cbdb.job
[2012.11.03 02:00:00 | 000,000,512 | —- | M] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 57a291b1-ebd9-4043-9cbe-de77272c297c.job
[2012.11.02 20:36:38 | 000,026,576 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.11.02 20:36:38 | 000,026,576 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.11.02 20:35:15 | 001,839,080 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012.11.02 20:35:15 | 000,792,274 | —- | M] () – C:\Windows\SysNative\perfh019.dat
[2012.11.02 20:35:15 | 000,721,924 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012.11.02 20:35:15 | 000,175,684 | —- | M] () – C:\Windows\SysNative\perfc019.dat
[2012.11.02 20:35:15 | 000,147,066 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012.11.02 20:29:22 | 000,001,868 | —- | M] () – C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
[2012.11.02 20:29:09 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012.11.02 20:29:01 | 2132,746,239 | -HS- | M] () – C:\hiberfil.sys
[2012.11.02 15:57:29 | 000,540,977 | —- | M] () – C:\Users\George\Desktop\adwcleaner.exe
[2012.11.02 15:55:26 | 002,322,184 | —- | M] (ESET) – C:\Users\George\Desktop\esetsmartinstaller_enu.exe
[2012.11.02 15:01:10 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2012.11.02 14:55:15 | 004,994,057 | R— | M] (Swearware) – C:\Users\George\Desktop\ComboFix.exe
[2012.11.02 13:49:30 | 000,625,664 | —- | M] () – C:\Users\George\Desktop\dds.scr
[2012.11.02 13:47:59 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\George\Desktop\HiJackThis.exe
[2012.11.02 13:45:42 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\George\Desktop\OTL.exe
[2012.11.02 13:16:15 | 000,001,109 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.11.02 13:09:21 | 000,233,423 | —- | M] () – C:\Users\George\Desktop\bookmarks-2012-11-02.json
[2012.11.01 18:33:07 | 000,001,808 | —- | M] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012.11.01 16:08:06 | 000,055,384 | —- | M] (Sunbelt Software) – C:\Windows\SysNative\drivers\SBREDrv.sys
[2012.11.01 15:01:39 | 000,007,618 | —- | M] () – C:\Users\George\AppData\Local\Resmon.ResmonCfg
[2012.10.31 21:28:42 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif
[2012.10.25 18:14:20 | 017,541,748 | —- | M] () – C:\Users\George\Desktop\Assignment 1,2,3 George 101011.zip
[2012.10.25 13:12:28 | 000,485,225 | —- | M] () – C:\Users\George\Desktop\IMG_2639.jpg
[2012.10.25 13:05:01 | 000,449,736 | —- | M] () – C:\Users\George\Desktop\IMG_2643.jpg
[2012.10.24 12:08:43 | 019,045,148 | —- | M] () – C:\Users\George\Desktop\Assignment 4 George 101011.zip
[2012.10.24 07:18:16 | 000,162,792 | —- | M] () – C:\Users\George\Desktop\IMG_2858.jpg
[2012.10.23 08:28:31 | 000,030,463 | —- | M] () – C:\Users\George\Desktop\getImage.jpg
[2012.10.10 01:07:37 | 000,000,132 | —- | M] () – C:\Users\George\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2012.10.09 21:46:06 | 000,001,456 | —- | M] () – C:\Users\George\AppData\Local\Adobe Save for Web 12.0 Prefs
[2012.10.09 21:46:05 | 001,320,376 | —- | M] () – C:\Users\George\Desktop\Poster-Small.jpg
[2012.10.09 02:24:23 | 026,055,247 | —- | M] () – C:\Users\George\Desktop\Poster.jpg
[2012.10.08 19:31:35 | 013,416,742 | —- | M] () – C:\Users\George\Desktop\tia2011-print.pdf
[2012.10.05 00:20:02 | 000,086,729 | —- | M] () – C:\Users\George\Desktop\Picture1.png
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012.11.02 15:57:18 | 000,540,977 | —- | C] () – C:\Users\George\Desktop\adwcleaner.exe
[2012.11.02 14:56:02 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012.11.02 14:56:02 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012.11.02 14:56:02 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012.11.02 14:56:02 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012.11.02 14:56:02 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012.11.02 13:49:28 | 000,625,664 | —- | C] () – C:\Users\George\Desktop\dds.scr
[2012.11.02 13:16:15 | 000,001,109 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.11.02 13:09:19 | 000,233,423 | —- | C] () – C:\Users\George\Desktop\bookmarks-2012-11-02.json
[2012.11.01 18:33:35 | 000,000,512 | —- | C] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 8a2a6511-ce7f-4545-b4a7-11f842f8cbdb.job
[2012.11.01 18:33:34 | 000,000,512 | —- | C] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 57a291b1-ebd9-4043-9cbe-de77272c297c.job
[2012.11.01 18:33:07 | 000,001,808 | —- | C] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012.11.01 12:18:12 | 000,001,868 | —- | C] () – C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
[2012.10.25 18:14:19 | 017,541,748 | —- | C] () – C:\Users\George\Desktop\Assignment 1,2,3 George 101011.zip
[2012.10.25 13:12:28 | 000,485,225 | —- | C] () – C:\Users\George\Desktop\IMG_2639.jpg
[2012.10.25 13:05:01 | 000,449,736 | —- | C] () – C:\Users\George\Desktop\IMG_2643.jpg
[2012.10.24 12:08:42 | 019,045,148 | —- | C] () – C:\Users\George\Desktop\Assignment 4 George 101011.zip
[2012.10.24 07:18:16 | 000,162,792 | —- | C] () – C:\Users\George\Desktop\IMG_2858.jpg
[2012.10.23 08:28:29 | 000,030,463 | —- | C] () – C:\Users\George\Desktop\getImage.jpg
[2012.10.09 21:46:05 | 001,320,376 | —- | C] () – C:\Users\George\Desktop\Poster-Small.jpg
[2012.10.08 19:26:39 | 013,416,742 | —- | C] () – C:\Users\George\Desktop\tia2011-print.pdf
[2012.10.06 01:36:53 | 026,055,247 | —- | C] () – C:\Users\George\Desktop\Poster.jpg
[2012.10.05 00:20:01 | 000,086,729 | —- | C] () – C:\Users\George\Desktop\Picture1.png
[2012.09.10 21:57:09 | 000,000,021 | —- | C] () – C:\Windows\SurCode.INI
[2012.08.20 11:20:54 | 000,000,010 | —- | C] () – C:\Users\George\Infovis_FILE_HISTORY.cfg
[2012.05.26 06:23:29 | 000,003,584 | —- | C] () – C:\Windows\SysWow64\DrvFltIp.sys
[2012.05.12 15:51:03 | 000,000,034 | -H– | C] () – C:\Windows\SysWow64\Converter_sysquict.dat
[2012.04.20 03:10:29 | 003,596,288 | —- | C] () – C:\Windows\SysWow64\qt-dx331.dll
[2012.03.10 21:07:36 | 000,000,145 | —- | C] () – C:\Users\George\.appletviewer
[2012.02.21 18:23:30 | 000,000,043 | —- | C] () – C:\Windows\gswin64.ini
[2012.02.01 02:28:27 | 000,000,983 | —- | C] () – C:\Windows\eReg.dat
[2012.01.30 03:49:45 | 000,001,476 | —- | C] () – C:\Users\George\AppData\Local\UserProducts.xml
[2012.01.07 02:04:30 | 000,145,876 | -H– | C] () – C:\Windows\SysWow64\mlfcache.dat
[2011.12.09 00:00:54 | 000,000,019 | —- | C] () – C:\Windows\info9.ini
[2011.12.09 00:00:54 | 000,000,019 | —- | C] () – C:\Windows\info7.ini
[2011.12.09 00:00:52 | 001,747,456 | —- | C] () – C:\Windows\SysWow64\re_imageconv.dll
[2011.11.24 21:00:49 | 000,008,192 | —- | C] () – C:\Windows\SysWow64\srvany.exe
[2011.07.14 14:06:11 | 000,000,020 | —- | C] () – C:\Windows\NMCAutorunXP.ini
[2011.07.08 17:28:10 | 000,001,459 | —- | C] () – C:\Users\George\gsview64.ini
[2011.06.24 21:27:30 | 000,001,456 | —- | C] () – C:\Users\George\AppData\Local\Adobe Save for Web 12.0 Prefs
[2011.06.11 00:43:23 | 000,000,132 | —- | C] () – C:\Users\George\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2011.06.06 03:55:19 | 000,007,618 | —- | C] () – C:\Users\George\AppData\Local\Resmon.ResmonCfg
[2011.06.05 01:17:10 | 000,000,056 | -H– | C] () – C:\Windows\SysWow64\ezsidmv.dat
[2011.06.05 01:11:10 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2011.06.05 00:26:11 | 001,819,732 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011.06.04 23:31:01 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2011.06.04 23:30:56 | 000,021,262 | —- | C] () – C:\Windows\Ascd_tmp.ini

========== ZeroAccess Check ==========

[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012.06.09 07:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012.06.09 06:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009.07.14 03:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010.11.21 05:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009.07.14 03:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== Alternate Data Streams ==========

@Alternate Data Stream - 1360 bytes -> C:\ProgramData\Microsoft:4xkr54OEiolnkbB3gh0FD6W
@Alternate Data Stream - 1322 bytes -> C:\Users\George\AppData\Local\zwzMyxIsPOk:6wR7NFoi4b5qJsMYjkIeAi8sX7ur
@Alternate Data Stream - 1313 bytes -> C:\ProgramData\Microsoft:VzjVIwISJ0TLQ3v9LvRDbL1cqrbG
@Alternate Data Stream - 1295 bytes -> C:\ProgramData\Microsoft:z2kO985qGpXTXnglXv0KG7z

< End of report >
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :Otl
    @Alternate Data Stream - 1360 bytes -> C:\ProgramData\Microsoft:4xkr54OEiolnkbB3gh0FD6W
    @Alternate Data Stream - 1322 bytes -> C:\Users\George\AppData\Local\zwzMyxIsPOk:6wR7NFoi4b5qJsMYjkIeAi8sX7ur
    @Alternate Data Stream - 1313 bytes -> C:\ProgramData\Microsoft:VzjVIwISJ0TLQ3v9LvRDbL1cqrbG
    @Alternate Data Stream - 1295 bytes -> C:\ProgramData\Microsoft:z2kO985qGpXTXnglXv0KG7z
    
    
    :Commands
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
No ads with me. However, I cannot login into some websites. Also, Facebook does not work properly. Probably, .js modules do not load fully or smth like it, cause some functionality is just not there, and I know that it is JS based. The feed does not update as well. Here are the logs. Sorry for delay. All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== ADS C:\ProgramData\Microsoft:4xkr54OEiolnkbB3gh0FD6W deleted successfully. ADS C:\Users\George\AppData\Local\zwzMyxIsPOk:6wR7NFoi4b5qJsMYjkIeAi8sX7ur deleted successfully. ADS C:\ProgramData\Microsoft:VzjVIwISJ0TLQ3v9LvRDbL1cqrbG deleted successfully. ADS C:\ProgramData\Microsoft:z2kO985qGpXTXnglXv0KG7z deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 56478 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: George ->Temp folder emptied: 1369620 bytes ->Temporary Internet Files folder emptied: 12151270 bytes ->Java cache emptied: 13426428 bytes ->FireFox cache emptied: 417590922 bytes ->Google Chrome cache emptied: 233152149 bytes ->Flash cache emptied: 193898 bytes User: Public ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50333 bytes %systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 639 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 647,00 mb OTL by OldTimer - Version 3.2.69.0 log created on 11042012_201114 Files\Folders moved on Reboot… C:\Users\George\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. PendingFileRenameOperations files… Registry entries deleted on Reboot…
Solved the issue. I had cookies off in Firefox. Logging in on websites is fine with FF now. The rest of the browsers also don't have any problem with that. However, FF remains the only browser that has troubles with Facebook. Like, say, the header at the top, the panel with controls does not function properly in FF. Trying to open a preview of friend requests, notifications or messages simply does not work. This small window below does not appear. Also, switching between the lists does not work. I don't know whether this is related to what we did here, but the whole thing definitely started the day these ads first appeared.
I resolved the issue with Facebook. It was FF-specific and Mozilla forums helped me here. Are there any more steps to follow? If there no any, could you please provide any advice regarding the preventing measures that should be taken. Like, what anti-virus, anti-malware program should better be installed and what sort of checks should be done from time to time. Also, what did actually remove these ads? Which of the three programs I ran?

Also, what did actually remove these ads? Which of the three programs I ran?

Combofix



Like, what anti-virus, anti-malware program should better be installed and what sort of checks should be done from time to time.

I use Avira free and Malwarebytes free but it's up to the individual to decide. If you keep downloading torrents you will keep getting infected no matter what you use.





You appear clean of infections,please do the following.



ComboFix - Cleanup
Time for some housekeeping
  • Click Start…select Run from the menu.
  • Copy and paste the following into the text entry box:
    Combofix /Uninstall
  • Click the OK button. (See image below as reference.)
🖼Click to load external image (Posted Image)









Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.














Here are some recommendations to help you stay clean.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Visit Microsoft often to get the latest updates for your computer.
http://www.update.microsoft.com/



Make sure you are running a FIREWALL.The windows firewall is not sufficient to protect your system. It doesn't monitor outgoing traffic and this is a must.
Please read this article 'Safe Computing Practices'.
So how did I get infected in the first place.

please take a moment to read quietman7's excellent prevention tips in post 3 here
Click >>>> Tips to protect yourself against malware and reduce the potential for re-infection:

Preventing Infections in the Future

Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

  • Avoid gaming sites, underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users. The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications. Read P2P Software User Advisories and Risks of File-Sharing Technology.

Update Non-Microsoft Programs

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.


Thats it you are good to go.Safe surfing
Is there any preference when I choose between Microsoft Essentials or commercial reputable products like Norton AV, say? Or, Windows Defended and MBAM? Thanks a lot for your help. Truly appreciate it.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI