This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

W32/Small.CA- Problem or false positive? [Solved]

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I'm running Win 7 x64 and Windows is reporting Win32/Small.CA
I have Sophos on the laptop, which hasn't detected anything, and have also tried MalwareBytes Ant-Malware, and ESET Online Scanner but none has detected anything.

Regarding symptoms, I have experienced none except a problem during a Windows update reboot (this immediately preceeded the Windows report of Win32/Small.CA)

Here is the report from Hijack This:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:35:45, on 12/01/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16457)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\vsnp2uvc.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe
C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe
C:\Program Files (x86)\BBC iPlayer Desktop\BBC iPlayer Desktop.exe
C:\Program Files (x86)\MagicDisc\MagicDisc.exe
C:\Program Files (x86)\Fujitsu\FUJ02E3\FUJ02E3.exe
C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
C:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exe
C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
C:\Program Files (x86)\Citrix\ICA Client\concentr.exe
C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe
C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe
C:\Program Files (x86)\Belkin\Router Setup and Monitor\dlnaPlugin.exe
C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe
C:\Program Files (x86)\Plex\Plex Media Server\PlexDlnaServer.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Simon\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ts.fujitsu.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ts.fujitsu.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [LoadFUJ02E3] C:\Program Files (x86)\Fujitsu\FUJ02E3\FUJ02E3.exe
O4 - HKLM\..\Run: [IndicatorUtility] C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
O4 - HKLM\..\Run: [snp2uvc] C:\Windows\vsnp2uvc.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\3.0"
O4 - HKLM\..\Run: [YouCam Mirror Tray icon] "C:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exe" /s
O4 - HKLM\..\Run: [Sophos AutoUpdate Monitor] C:\Program Files (x86)\Sophos\AutoUpdate\almon.exe
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] "C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe" -minimized
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [ConnectionCenter] "C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup
O4 - HKLM\..\Run: [InstaLAN] "C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe" startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [Plex Media Server] "C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe"
O4 - HKCU\..\Run: [NokiaSuite.exe] C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe -tray
O4 - .DEFAULT User Startup: LaunchCenter.lnk = C:\Program Files\Fujitsu\LaunchCenter\DelayLC.exe (User 'Default user')
O4 - Startup: BBC iPlayer Desktop.lnk = C:\Program Files (x86)\BBC iPlayer Desktop\BBC iPlayer Desktop.exe
O4 - Startup: MagicDisc.lnk = C:\Program Files (x86)\MagicDisc\MagicDisc.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {CC679CB8-DC4B-458B-B817-D447B3B6AC31} (Cisco AnyConnect Secure Mobility Client Web Control) - https://vpn.ucl.ac.uk/CACHE/stc/21/binaries/vpnweb.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E34F52FE-7769-46CE-8F8B-5E8ABAD2E9FC} (CSD ActiveX Installer) - https://vpn.ucl.ac.uk/CACHE/sdesktop/instal…ies/instweb.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\PROGRA~2\DVDGHO~1\DVDGHO~1.DLL,C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~1.DLL
O23 - Service: AffinegyService - Affinegy, Inc. - C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AuthenTec Fingerprint Service (ATService) - AuthenTec, Inc. - C:\Program Files\Fingerprint Sensor\ATService.exe
O23 - Service: Belkin Local Backup Service - Unknown owner - C:\Program Files\Belkin\Belkin USB Print and Storage Center\BkBackupScheduler.exe
O23 - Service: Belkin Network USB Helper - Unknown owner - C:\Program Files\Belkin\Belkin USB Print and Storage Center\Bkapcs.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PowerSavingUtilityService - FUJITSU LIMITED - C:\Program Files\Fujitsu\PSUtility\PSUService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Qualcomm Gobi 2000 Download Service (Sierra) (QDLService2kSierra) - QUALCOMM, Inc. - C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kSierra.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Limited - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Limited - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Sophos AutoUpdate Service - Sophos Limited - C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Sophos Web Intelligence Service (swi_service) - Sophos Limited - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe
O23 - Service: Sophos Web Intelligence Update (swi_update_64) - Sophos Limited - C:\ProgramData\Sophos\Web Intelligence\swi_update_64.exe
O23 - Service: Fujitsu Diagnostic Testhandler (TestHandler) - Fujitsu Technology Solutions - C:\Program Files (x86)\Fujitsu\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel® Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: Cisco AnyConnect Secure Mobility Agent (vpnagent) - Cisco Systems, Inc. - C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: WirelessSelectorService - Unknown owner - C:\Program Files\Fujitsu\WirelessSelector\WSUService.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: WTGService - Unknown owner - C:\Program Files (x86)\OneClickInternet\WTGService.exe

–
End of file - 16030 bytes


Not sure whether I have anything to worry about or not.

Thanks for your help and advice,
Simon
Hi and :welcome: simonjeaton :)

My name is Robybel.

I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please be adviced, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise, this will be a team effort.
This may cause a delay, but I will do my best to keep it as short as possible. Please bear with me, I will post back to you as soon as I can.


IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


Vista and Windows 7 users:

These tools MUST be run from the executable. (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

Having said that….Let's get going!! ;)
Hi simonjeaton ;)

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

=============================== Next =======================================


Scan with OTL
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    services.exe
    /md5stop
    %systemroot%\*. /rp /s
    %systemdrive%\$Recycle.Bin|@;true;true;true /fp
    DRIVES
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.

=============================== Next =======================================



Please download aswMBR.exe and save it to your desktop.
  • Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)
  • Allow it to update where necessary
  • Click Scan

  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.

On your next reply please post :
  • checkup.txt
  • OTL.txt
  • Extras.txt
  • aswMBR log

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Hi Robybel, thanks for your help

Here is the Log from Security Check:

Results of screen317's Security Check version 0.99.56
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 9
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Sophos Anti-Virus
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.70.0.1100
Java™ 6 Update 37
Java version out of Date!
Adobe Reader 9 Adobe Reader out of Date!
Google Chrome 22.0.1229.95
Google Chrome 23.0.1271.91
Google Chrome 23.0.1271.95
Google Chrome 23.0.1271.97
````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
Sophos Sophos Anti-Virus SavService.exe
Sophos Sophos Anti-Virus SAVAdminService.exe
Sophos Sophos Anti-Virus Web Intelligence swi_service.exe
Malwarebytes' Anti-Malware mbamscheduler.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 12% Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````


OTL.txt:

OTL logfile created on: 1/13/2013 9:44:37 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Simon\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.80 Gb Total Physical Memory | 2.06 Gb Available Physical Memory | 54.21% Memory free
7.60 Gb Paging File | 5.24 Gb Available in Paging File | 68.97% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 296.08 Gb Total Space | 192.37 Gb Free Space | 64.97% Space Free | Partition Type: NTFS

Computer Name: SIMON-LAPTOP | User Name: Simon | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Simon\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
PRC - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe ()
PRC - C:\Program Files (x86)\Plex\Plex Media Server\PlexDlnaServer.exe (Plex, Inc.)
PRC - C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe (Plex, Inc.)
PRC - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe (Sophos Limited)
PRC - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe (Sophos Limited)
PRC - C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe (Nokia)
PRC - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe (Nokia)
PRC - C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe (Nokia)
PRC - C:\Program Files (x86)\BBC iPlayer Desktop\BBC iPlayer Desktop.exe ()
PRC - C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe (Sophos Limited)
PRC - C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe (Sophos Limited)
PRC - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe (Sophos Limited)
PRC - C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe (Cisco Systems, Inc.)
PRC - C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (Cisco Systems, Inc.)
PRC - C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe (Affinegy, Inc.)
PRC - C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe (Affinegy, Inc.)
PRC - C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe (Affinegy, Inc.)
PRC - C:\Program Files (x86)\Belkin\Router Setup and Monitor\dlnaPlugin.exe (Affinegy, Inc.)
PRC - C:\Program Files (x86)\OneClickInternet\WTGService.exe ()
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe (FUJITSU LIMITED)
PRC - C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kSierra.exe (QUALCOMM, Inc.)
PRC - C:\Program Files (x86)\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
PRC - C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe (Citrix Systems, Inc.)
PRC - C:\Windows\vsnp2uvc.exe (Sonix)
PRC - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
PRC - C:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Fujitsu\FUJ02E3\FUJ02E3.exe (FUJITSU LIMITED)
PRC - C:\Program Files (x86)\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
PRC - C:\Program Files (x86)\Fujitsu\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe (Fujitsu Technology Solutions)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\ppgooglenaclpluginchrome.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\pdf.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\libglesv2.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\libegl.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\avutil-51.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\avformat-54.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\avcodec-54.dll ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\Exts\simplejson\_speedups.pyd ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\Exts\OpenSSL\SSL.pyd ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\Exts\OpenSSL\rand.pyd ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\Exts\OpenSSL\crypto.pyd ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\Exts\lxml\etree.pyd ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\Exts\lxml\objectify.pyd ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\DLLs\_ssl.pyd ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\DLLs\_socket.pyd ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\DLLs\_multiprocessing.pyd ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\DLLs\_hashlib.pyd ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\DLLs\_ctypes.pyd ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\DLLs\unicodedata.pyd ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\DLLs\select.pyd ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\DLLs\pyexpat.pyd ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\zlib1.dll ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\WebKit.dll ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\tag.dll ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\swscale-0.dll ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\sqlite3.dll ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\soci_sqlite3-vc80-3_0.dll ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\soci_core-vc80-3_0.dll ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\libxslt.dll ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\libxml2.dll ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\libexslt.dll ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\JavaScriptCore.dll ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\CFLite.dll ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\cairo.dll ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\avutil-50.dll ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\avformat-52.dll ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\avcodec-52.dll ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\phonon4.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\qjson.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\QtXmlPatterns4.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\QtXml4.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\QtWebKit4.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\QtScript4.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\QtSql4.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\QtNetwork4.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\QtOpenGL4.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\QtGui4.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\QtMultimediaKit1.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\QtDeclarative4.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\QtCore4.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\sqldrivers\qsqlite4.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\Imageformats\qjpeg4.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\Imageformats\qico4.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\Imageformats\qgif4.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\NService.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\CommonUpdateChecker.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\ssoengine.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\securestorage.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\mediaservice\dsengine.dll ()
MOD - C:\Program Files (x86)\BBC iPlayer Desktop\BBC iPlayer Desktop.exe ()
MOD - C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinServicePS.dll ()
MOD - C:\Program Files (x86)\Belkin\Router Setup and Monitor\gateways\GenericBelkinGatewayLOC.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
MOD - C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtGui4.dll ()
MOD - C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtXml4.dll ()
MOD - C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtCore4.dll ()
MOD - C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtNetwork4.dll ()
MOD - C:\Program Files (x86)\Belkin\Router Setup and Monitor\imageformats\qjpeg4.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (Belkin Local Backup Service) – C:\Program Files\Belkin\Belkin USB Print and Storage Center\BkBackupScheduler.exe ()
SRV:64bit: - (Belkin Network USB Helper) – C:\Program Files\Belkin\Belkin USB Print and Storage Center\Bkapcs.exe ()
SRV:64bit: - (ATService) – C:\Program Files\Fingerprint Sensor\ATService.exe (AuthenTec, Inc.)
SRV:64bit: - (PowerSavingUtilityService) – C:\Program Files\Fujitsu\PSUtility\PSUService.exe (FUJITSU LIMITED)
SRV:64bit: - (WirelessSelectorService) – C:\Program Files\Fujitsu\WirelessSelector\WSUService.exe ()
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (Skype C2C Service) – C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
SRV - (swi_service) – C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe (Sophos Limited)
SRV - (swi_update_64) – C:\ProgramData\Sophos\Web Intelligence\swi_update_64.exe (Sophos Limited)
SRV - (SAVAdminService) – C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe (Sophos Limited)
SRV - (ServiceLayer) – C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (Sophos AutoUpdate Service) – C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe (Sophos Limited)
SRV - (SAVService) – C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe (Sophos Limited)
SRV - (HPSLPSVC) – C:\Users\Simon\AppData\Local\Temp\7zS470B\HPSLPSVC64.DLL (Hewlett-Packard Co.)
SRV - (vpnagent) – C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (Cisco Systems, Inc.)
SRV - (AffinegyService) – C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe (Affinegy, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (WTGService) – C:\Program Files (x86)\OneClickInternet\WTGService.exe ()
SRV - (UNS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (QDLService2kSierra) – C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kSierra.exe (QUALCOMM, Inc.)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (TestHandler) – C:\Program Files (x86)\Fujitsu\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe (Fujitsu Technology Solutions)


========== Driver Services (SafeList) ==========

DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (pccsmcfd) – C:\Windows\SysNative\drivers\pccsmcfdx64.sys (Nokia)
DRV:64bit: - (SAVOnAccess) – C:\Windows\SysNative\drivers\savonaccess.sys (Sophos Limited)
DRV:64bit: - (nmwcdc) – C:\Windows\SysNative\drivers\ccdcmbox64.sys (Nokia)
DRV:64bit: - (nmwcd) – C:\Windows\SysNative\drivers\ccdcmbx64.sys (Nokia)
DRV:64bit: - (UsbserFilt) – C:\Windows\SysNative\drivers\usbser_lowerfltjx64.sys (Nokia)
DRV:64bit: - (upperdev) – C:\Windows\SysNative\drivers\usbser_lowerfltx64.sys (Nokia)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (FJGSDisk) – C:\Windows\SysNative\drivers\FJGSDisk.sys (FUJITSU LIMITED)
DRV:64bit: - (SophosBootDriver) – C:\Windows\SysNative\drivers\SophosBootDriver.sys (Sophos Plc)
DRV:64bit: - (vpnva) – C:\Windows\SysNative\drivers\vpnva64.sys (Cisco Systems, Inc.)
DRV:64bit: - (acsock) – C:\Windows\SysNative\drivers\acsock64.sys (Cisco Systems, Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (usbser) – C:\Windows\SysNative\drivers\usbser.sys (Microsoft Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) – C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (NETw5s64) – C:\Windows\SysNative\drivers\NETw5s64.sys (Intel Corporation)
DRV:64bit: - (e1kexpress) – C:\Windows\SysNative\drivers\e1k62x64.sys (Intel Corporation)
DRV:64bit: - (HECIx64) – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (Impcd) – C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (qcusbnetsra2k) – C:\Windows\SysNative\drivers\qcusbnetsra2k.sys (QUALCOMM Incorporated)
DRV:64bit: - (qcusbsersra2k) – C:\Windows\SysNative\drivers\qcusbsersra2k.sys (QUALCOMM Incorporated)
DRV:64bit: - (qcfiltersra2k) – C:\Windows\SysNative\drivers\qcfiltersra2k.sys (QUALCOMM Incorporated)
DRV:64bit: - (ApfiltrService) – C:\Windows\SysNative\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (ctxusbm) – C:\Windows\SysNative\drivers\ctxusbm.sys (Citrix Systems, Inc.)
DRV:64bit: - (SNP2UVC) – C:\Windows\SysNative\drivers\snp2uvc.sys ()
DRV:64bit: - (BthAvrcp) – C:\Windows\SysNative\drivers\BthAvrcp.sys (CSR, plc)
DRV:64bit: - (ATSwpWDF) – C:\Windows\SysNative\drivers\ATSwpWDF.sys (AuthenTec, Inc.)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (TPM) – C:\Windows\SysNative\drivers\tpm.sys (Microsoft Corporation)
DRV:64bit: - (sxuptp) – C:\Windows\SysNative\drivers\sxuptp.sys (silex technology, Inc.)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (mcdbus) – C:\Windows\SysNative\drivers\mcdbus.sys (MagicISO, Inc.)
DRV:64bit: - (FUJ02E3) – C:\Windows\SysNative\drivers\fuj02e3.sys (FUJITSU LIMITED)
DRV:64bit: - (FUJ02B1) – C:\Windows\SysNative\drivers\fuj02b1.sys (FUJITSU LIMITED)
DRV - (RSUSBSTOR) – C:\Windows\SysWOW64\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (mcdbus) – C:\Windows\SysWOW64\drivers\mcdbus.sys (MagicISO, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {1CC2B0B6-D56C-4D2C-BE3D-8AF2CD509512}
IE:64bit: - HKLM\..\SearchScopes\{1CC2B0B6-D56C-4D2C-BE3D-8AF2CD509512}: "URL" = http://www.google.com/search?q={searchTerm…amp;rlz=1I7FTSF
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {E7BAA1CF-0555-4603-8C61-4F4E8EFAAA17}
IE - HKLM\..\SearchScopes\{E7BAA1CF-0555-4603-8C61-4F4E8EFAAA17}: "URL" = http://www.google.com/search?q={searchTerm…amp;rlz=1I7FTSF

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ts.fujitsu.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.google.com/ig/redirectd [Binary data over 200 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.com/ig/redirectd [Binary data over 200 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ts.fujitsu.com
IE - HKCU\..\SearchScopes,DefaultScope = {E7BAA1CF-0555-4603-8C61-4F4E8EFAAA17}
IE - HKCU\..\SearchScopes\{E7BAA1CF-0555-4603-8C61-4F4E8EFAAA17}: "URL" = http://www.google.com/search?q={searchTerm…SF_enGB459GB461
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_37: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nokia.com/EnablerPlugin: C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)



========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 6 U37 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Nokia Suite Enabler Plugin (Enabled) = C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Java Deployment Toolkit 6.0.370.6 (Enabled) = C:\Windows\SysWOW64\npdeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: Google Drive = C:\Users\Simon\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\Simon\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\Simon\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Gmail = C:\Users\Simon\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009/06/10 21:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [ATSwpNav] C:\Program Files\Fingerprint Sensor\ATSwpNav.exe (AuthenTec, Inc.)
O4:64bit: - HKLM..\Run: [FDM7] C:\Program Files\Fujitsu\FDM7\FdmDaemon.exe (FUJITSU LIMITED)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [LoadBtnHnd] C:\Program Files\Fujitsu\Application Panel\BtnHnd.exe (FUJITSU LIMITED)
O4:64bit: - HKLM..\Run: [LoadFujitsuQuickTouch] C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe (FUJITSU LIMITED)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [PSUTility] C:\Program Files\Fujitsu\PSUtility\TrayManager.exe (FUJITSU LIMITED)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [snp2uvc] C:\Windows\vsnp2uvc.exe (Sonix)
O4:64bit: - HKLM..\Run: [SSUtility] C:\Program Files\Fujitsu\SSUtility\FJSSDMN.exe (FUJITSU LIMITED)
O4 - HKLM..\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [ConnectionCenter] C:\Program Files (x86)\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [IndicatorUtility] C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe (FUJITSU LIMITED)
O4 - HKLM..\Run: [InstaLAN] C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe (Affinegy, Inc.)
O4 - HKLM..\Run: [LoadFUJ02E3] C:\Program Files (x86)\Fujitsu\FUJ02E3\FUJ02E3.exe (FUJITSU LIMITED)
O4 - HKLM..\Run: [snp2uvc] C:\Windows\vsnp2uvc.exe (Sonix)
O4 - HKLM..\Run: [Sophos AutoUpdate Monitor] C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe (Sophos Limited)
O4 - HKLM..\Run: [YouCam Mirror Tray icon] C:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exe (CyberLink Corp.)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [NokiaSuite.exe] C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe (Nokia)
O4 - HKCU..\Run: [Plex Media Server] C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe (Plex, Inc.)
O4 - Startup: C:\Users\Simon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\BBC iPlayer Desktop.lnk = C:\Program Files (x86)\BBC iPlayer Desktop\BBC iPlayer Desktop.exe ()
O4 - Startup: C:\Users\Simon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk = C:\Program Files (x86)\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000020 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: ucl.ac.uk ([vpn] https in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CC679CB8-DC4B-458B-B817-D447B3B6AC31} https://vpn.ucl.ac.uk/CACHE/stc/21/binaries/vpnweb.cab (Cisco AnyConnect Secure Mobility Client Web Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E34F52FE-7769-46CE-8F8B-5E8ABAD2E9FC} https://vpn.ucl.ac.uk/CACHE/sdesktop/instal…ies/instweb.cab (CSD ActiveX Installer)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{671820B3-06AF-449D-A846-90672F1F700D}: DhcpNameServer = 4.2.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8673924F-90CB-4353-9F01-303ACA8A02A3}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~2.DLL) - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\sophos_detoured_x64.dll (Sophos Limited)
O20 - AppInit_DLLs: (C:\PROGRA~2\DVDGHO~1\DVDGHO~1.DLL) - C:\Program Files (x86)\DVD Ghost\DVDGhostAppInit.dll (BlazeVideo, Inc.)
O20 - AppInit_DLLs: (C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~1.DLL) - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\sophos_detoured.dll (Sophos Limited)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {569DAC0F-2791-46ab-8EFC-A54B77C04C20} - C:\Program Files (x86)\DVD Ghost\ExecuteHooker.dll (WWW.Region-Free-DVD.COM)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/01/13 21:34:50 | 004,732,416 | —- | C] (AVAST Software) – C:\Users\Simon\Desktop\aswMBR.exe
[2013/01/13 21:34:33 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Simon\Desktop\OTL.exe
[2013/01/10 21:49:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2013/01/10 21:26:18 | 000,000,000 | —D | C] – C:\Users\Simon\AppData\Roaming\Malwarebytes
[2013/01/10 21:24:04 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/01/10 21:24:03 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/01/10 21:24:02 | 000,024,176 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2013/01/10 21:24:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/01/10 21:23:29 | 000,000,000 | —D | C] – C:\Users\Simon\AppData\Local\Programs
[2013/01/10 16:05:12 | 000,750,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\win32spl.dll
[2013/01/10 16:05:12 | 000,492,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\win32spl.dll
[2013/01/10 16:04:50 | 000,424,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\KernelBase.dll
[2013/01/10 16:04:49 | 001,161,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2013/01/10 16:04:48 | 000,362,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64win.dll
[2013/01/10 16:04:48 | 000,338,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\conhost.exe
[2013/01/10 16:04:48 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2013/01/10 16:04:48 | 000,215,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2013/01/10 16:04:48 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64cpu.dll
[2013/01/10 16:04:47 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntvdm64.dll
[2013/01/10 16:04:47 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2013/01/10 16:04:47 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2013/01/10 16:04:47 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2013/01/10 16:04:47 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2013/01/10 16:04:47 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2013/01/10 16:04:47 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2013/01/10 16:04:47 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2013/01/10 16:04:47 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2013/01/10 16:04:47 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/01/10 16:04:47 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/01/10 16:04:47 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2013/01/10 16:04:47 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2013/01/10 16:04:47 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2013/01/10 16:04:47 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2013/01/10 16:04:47 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2013/01/10 16:04:47 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/01/10 16:04:47 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/01/10 16:04:47 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/01/10 16:04:47 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/01/10 16:04:47 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/01/10 16:04:47 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2013/01/10 16:04:47 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2013/01/10 16:04:47 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2013/01/10 16:04:47 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/01/10 16:04:47 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/01/10 16:04:47 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2013/01/10 16:04:47 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2013/01/10 16:04:47 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2013/01/10 16:04:47 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2013/01/10 16:04:47 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2013/01/10 16:04:47 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2013/01/10 16:04:47 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2013/01/10 16:04:47 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2013/01/10 16:04:47 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2013/01/10 16:04:47 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/01/10 16:04:47 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2013/01/10 16:04:47 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2013/01/10 16:04:46 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2013/01/10 16:04:46 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2013/01/10 16:04:46 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2013/01/10 16:04:46 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2013/01/10 16:04:46 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2013/01/10 16:04:46 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2013/01/10 16:04:46 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2013/01/10 16:04:46 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2013/01/10 16:04:46 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2013/01/10 16:04:46 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2013/01/10 16:04:46 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/01/10 16:04:46 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2013/01/10 16:04:46 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2013/01/10 16:04:46 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2013/01/10 16:04:46 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2013/01/10 16:04:46 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2013/01/10 16:04:46 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/01/10 16:04:46 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2013/01/10 16:04:46 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2013/01/10 16:04:46 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2013/01/10 16:04:46 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2013/01/10 16:04:46 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2013/01/10 16:04:46 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2013/01/10 16:04:46 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2013/01/10 16:04:30 | 000,800,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\usp10.dll
[2013/01/10 16:04:30 | 000,307,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncrypt.dll
[2013/01/10 16:04:27 | 000,441,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Wpc.dll
[2013/01/10 16:04:27 | 000,046,592 | —- | C] (Microsoft) – C:\Windows\SysWow64\fpb.rs
[2013/01/10 16:04:27 | 000,046,592 | —- | C] (Microsoft) – C:\Windows\SysNative\fpb.rs
[2013/01/10 16:04:27 | 000,045,568 | —- | C] (Microsoft) – C:\Windows\SysWow64\oflc-nz.rs
[2013/01/10 16:04:27 | 000,045,568 | —- | C] (Microsoft) – C:\Windows\SysNative\oflc-nz.rs
[2013/01/10 16:04:27 | 000,044,544 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegibbfc.rs
[2013/01/10 16:04:27 | 000,044,544 | —- | C] (Microsoft) – C:\Windows\SysNative\pegibbfc.rs
[2013/01/10 16:04:27 | 000,043,520 | —- | C] (Microsoft) – C:\Windows\SysWow64\csrr.rs
[2013/01/10 16:04:27 | 000,043,520 | —- | C] (Microsoft) – C:\Windows\SysNative\csrr.rs
[2013/01/10 16:04:27 | 000,040,960 | —- | C] (Microsoft) – C:\Windows\SysWow64\cob-au.rs
[2013/01/10 16:04:27 | 000,040,960 | —- | C] (Microsoft) – C:\Windows\SysNative\cob-au.rs
[2013/01/10 16:04:27 | 000,030,720 | —- | C] (Microsoft) – C:\Windows\SysWow64\usk.rs
[2013/01/10 16:04:27 | 000,030,720 | —- | C] (Microsoft) – C:\Windows\SysNative\usk.rs
[2013/01/10 16:04:27 | 000,021,504 | —- | C] (Microsoft) – C:\Windows\SysWow64\grb.rs
[2013/01/10 16:04:27 | 000,021,504 | —- | C] (Microsoft) – C:\Windows\SysNative\grb.rs
[2013/01/10 16:04:27 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegi-pt.rs
[2013/01/10 16:04:27 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysNative\pegi-pt.rs
[2013/01/10 16:04:27 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegi.rs
[2013/01/10 16:04:27 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysNative\pegi.rs
[2013/01/10 16:04:27 | 000,015,360 | —- | C] (Microsoft) – C:\Windows\SysWow64\djctq.rs
[2013/01/10 16:04:27 | 000,015,360 | —- | C] (Microsoft) – C:\Windows\SysNative\djctq.rs
[2013/01/10 16:04:26 | 002,746,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\gameux.dll
[2013/01/10 16:04:26 | 002,576,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\gameux.dll
[2013/01/10 16:04:26 | 000,308,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Wpc.dll
[2013/01/10 16:04:25 | 000,055,296 | —- | C] (Microsoft) – C:\Windows\SysWow64\cero.rs
[2013/01/10 16:04:25 | 000,055,296 | —- | C] (Microsoft) – C:\Windows\SysNative\cero.rs
[2013/01/10 16:04:25 | 000,051,712 | —- | C] (Microsoft) – C:\Windows\SysWow64\esrb.rs
[2013/01/10 16:04:25 | 000,051,712 | —- | C] (Microsoft) – C:\Windows\SysNative\esrb.rs
[2013/01/10 16:04:25 | 000,023,552 | —- | C] (Microsoft) – C:\Windows\SysWow64\oflc.rs
[2013/01/10 16:04:25 | 000,023,552 | —- | C] (Microsoft) – C:\Windows\SysNative\oflc.rs
[2013/01/10 16:04:25 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegi-fi.rs
[2013/01/10 16:04:25 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysNative\pegi-fi.rs
[2013/01/10 16:01:37 | 000,068,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\taskhost.exe
[2013/01/08 22:59:42 | 000,000,000 | —D | C] – C:\Users\Simon\Desktop\Dukto
[2013/01/08 22:56:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\Dukto
[2012/12/27 11:31:06 | 000,719,872 | —- | C] (Abysmal Software) – C:\Windows\SysWow64\devil.dll
[2012/12/27 11:31:06 | 000,719,872 | —- | C] (Abysmal Software) – C:\Windows\SysWow64\devil.dll
[2012/12/27 11:31:05 | 000,369,152 | —- | C] (The Public) – C:\Windows\SysWow64\avisynth.dll
[2012/12/27 11:31:02 | 000,070,656 | —- | C] (www.helixcommunity.org) – C:\Windows\SysWow64\yv12vfw.dll
[2012/12/27 11:31:02 | 000,070,656 | —- | C] (www.helixcommunity.org) – C:\Windows\SysWow64\i420vfw.dll
[2012/12/27 11:31:02 | 000,070,656 | —- | C] (www.helixcommunity.org) – C:\Windows\SysWow64\i420vfw.dll
[2012/12/27 11:30:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\AviSynth 2.5
[2012/12/27 11:29:14 | 000,278,528 | —- | C] (Real Networks, Inc) – C:\Windows\SysWow64\pncrt.dll
[2012/12/27 11:29:14 | 000,216,064 | RHS- | C] (MONOGRAM Multimedia, s.r.o.) – C:\Windows\SysWow64\nbDX.dll
[2012/12/27 11:29:14 | 000,186,880 | RHS- | C] (RadLight) – C:\Windows\SysWow64\RLOgg.ax
[2012/12/27 11:29:14 | 000,161,792 | RHS- | C] (Gabest) – C:\Windows\SysWow64\RealMediaDX.ax
[2012/12/27 11:29:14 | 000,092,672 | RHS- | C] (RadLight) – C:\Windows\SysWow64\RLVorbisDec.ax
[2012/12/27 11:29:14 | 000,090,112 | RHS- | C] (-) – C:\Windows\SysWow64\TTADSSplitter.ax
[2012/12/27 11:29:14 | 000,090,112 | RHS- | C] (-) – C:\Windows\SysWow64\TTADSDecoder.ax
[2012/12/27 11:29:14 | 000,067,584 | RHS- | C] (RadLight, LLC) – C:\Windows\SysWow64\RLTheoraDec.ax
[2012/12/27 11:29:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPER © Version 2010.bld.38 (May 2, 2010)
[2012/12/27 11:29:13 | 000,169,472 | RHS- | C] (Gabest) – C:\Windows\SysWow64\MatroskaDX.ax
[2012/12/27 11:29:13 | 000,163,328 | RHS- | C] (Gabest) – C:\Windows\SysWow64\flvDX.dll
[2012/12/27 11:29:13 | 000,031,232 | RHS- | C] (Hans Mayerl) – C:\Windows\SysWow64\msfDX.dll
[2012/12/27 11:29:12 | 000,179,200 | RHS- | C] (Gabest) – C:\Windows\SysWow64\DiracSplitter.ax
[2012/12/27 11:29:12 | 000,123,904 | RHS- | C] (CoreCodec) – C:\Windows\SysWow64\AVCDX.ax
[2012/12/27 11:29:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\eRightSoft
[2012/12/25 20:20:20 | 000,046,080 | —- | C] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2012/12/25 20:20:20 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2012/12/25 20:20:19 | 000,367,616 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2012/12/25 20:20:18 | 000,295,424 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2012/12/24 17:39:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
[2012/12/24 17:38:47 | 000,000,000 | —D | C] – C:\Users\Simon\Documents\Add-in Express
[2012/12/24 17:38:40 | 000,000,000 | —D | C] – C:\ProgramData\WinZip
[2012/12/24 17:38:37 | 000,000,000 | —D | C] – C:\Program Files\WinZip
[2012/12/24 17:23:33 | 000,000,000 | —D | C] – C:\Users\Simon\AppData\Roaming\WinRAR
[2012/12/24 17:23:33 | 000,000,000 | —D | C] – C:\Users\Simon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/12/24 17:23:33 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/12/24 17:23:09 | 000,000,000 | —D | C] – C:\Program Files\WinRAR
[2012/12/24 16:13:04 | 000,000,000 | —D | C] – C:\Users\Simon\AppData\Roaming\AVS4YOU
[2012/12/24 16:11:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\AVSMedia
[2012/12/24 16:10:53 | 001,700,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\GdiPlus.dll
[2012/12/24 16:10:52 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msxml3a.dll
[2012/12/24 16:10:52 | 000,000,000 | —D | C] – C:\ProgramData\AVS4YOU
[2012/12/24 16:10:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVS4YOU
[2012/12/18 22:39:49 | 000,000,000 | —D | C] – C:\ProgramData\Hewlett-Packard
[2012/12/15 07:51:30 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD Ghost
[2012/12/15 07:51:29 | 000,000,000 | —D | C] – C:\ProgramData\DVD X Studios
[2012/12/15 07:51:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\DVD Ghost

========== Files - Modified Within 30 Days ==========

[2013/01/13 21:36:46 | 000,856,731 | —- | M] () – C:\Users\Simon\Desktop\SecurityCheck (1).exe
[2013/01/13 21:35:53 | 004,732,416 | —- | M] (AVAST Software) – C:\Users\Simon\Desktop\aswMBR.exe
[2013/01/13 21:34:40 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Simon\Desktop\OTL.exe
[2013/01/13 21:29:00 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/01/13 21:29:00 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/01/13 21:21:30 | 000,001,095 | —- | M] () – C:\Users\Simon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\BBC iPlayer Desktop.lnk
[2013/01/13 21:20:57 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/01/13 21:20:28 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/01/13 21:20:20 | 3060,264,960 | -HS- | M] () – C:\hiberfil.sys
[2013/01/12 21:53:02 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/01/10 21:24:05 | 000,001,115 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/10 20:49:14 | 000,418,216 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/01/10 18:01:02 | 000,732,510 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/01/10 18:01:02 | 000,616,242 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/01/10 18:01:02 | 000,106,622 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/12/27 11:29:20 | 000,002,054 | —- | M] () – C:\Users\Public\Desktop\SUPER © Uninstall.lnk
[2012/12/27 11:29:20 | 000,002,030 | —- | M] () – C:\Users\Public\Desktop\SUPER ©.lnk
[2012/12/24 17:39:27 | 000,002,283 | —- | M] () – C:\Users\Public\Desktop\WinZip.lnk
[2012/12/19 11:27:15 | 000,840,192 | —- | M] () – C:\Users\Simon\Documents\Xmas2012.pub
[2012/12/19 11:10:20 | 000,150,506 | —- | M] () – C:\Users\Simon\Documents\Xmas2012.pdf
[2012/12/18 21:46:37 | 574,160,632 | —- | M] () – C:\Windows\MEMORY.DMP
[2012/12/18 20:55:55 | 000,726,799 | —- | M] () – C:\Users\Simon\Desktop\28072012256.jpg
[2012/12/16 17:11:22 | 000,046,080 | —- | M] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2012/12/16 14:45:03 | 000,367,616 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2012/12/16 14:13:28 | 000,295,424 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2012/12/16 14:13:20 | 000,034,304 | —- | M] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2012/12/15 07:54:07 | 000,002,380 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2012/12/15 07:51:35 | 000,001,043 | —- | M] () – C:\Windows\DVDXRestrictionFree.ini
[2012/12/15 07:51:34 | 000,000,014 | —- | M] () – C:\Windows\SysWow64\SysEngine2.SYS
[2012/12/15 07:51:31 | 000,001,020 | —- | M] () – C:\Users\Simon\Desktop\DVD Ghost.lnk

========== Files Created - No Company Name ==========

[2013/01/13 21:36:40 | 000,856,731 | —- | C] () – C:\Users\Simon\Desktop\SecurityCheck (1).exe
[2013/01/10 21:24:05 | 000,001,115 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/08 22:56:18 | 000,000,981 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dukto R5.lnk
[2012/12/27 11:31:03 | 000,027,648 | —- | C] () – C:\Windows\SysWow64\AVSredirect.dll
[2012/12/27 11:29:20 | 000,002,066 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPER © Uninstall.lnk
[2012/12/27 11:29:20 | 000,002,054 | —- | C] () – C:\Users\Public\Desktop\SUPER © Uninstall.lnk
[2012/12/27 11:29:20 | 000,002,042 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPER ©.lnk
[2012/12/27 11:29:20 | 000,002,030 | —- | C] () – C:\Users\Public\Desktop\SUPER ©.lnk
[2012/12/27 11:29:14 | 000,107,520 | RHS- | C] () – C:\Windows\SysWow64\RLMPCDec.ax
[2012/12/27 11:29:14 | 000,070,656 | RHS- | C] () – C:\Windows\SysWow64\RLAPEDec.ax
[2012/12/27 11:29:14 | 000,051,712 | RHS- | C] () – C:\Windows\SysWow64\RLSpeexDec.ax
[2012/12/27 11:29:13 | 000,120,832 | RHS- | C] () – C:\Windows\SysWow64\MPCDx.ax
[2012/12/27 11:29:13 | 000,097,280 | RHS- | C] () – C:\Windows\SysWow64\FLACDX.ax
[2012/12/27 11:29:12 | 000,227,328 | RHS- | C] () – C:\Windows\SysWow64\ac3DX.ax
[2012/12/27 11:29:12 | 000,175,104 | RHS- | C] () – C:\Windows\SysWow64\CoreAAC.ax
[2012/12/27 11:29:12 | 000,081,920 | RHS- | C] () – C:\Windows\SysWow64\aac_parser.ax
[2012/12/24 17:39:26 | 000,002,283 | —- | C] () – C:\Users\Public\Desktop\WinZip.lnk
[2012/12/20 19:48:07 | 023,261,324 | —- | C] () – C:\Users\Simon\Desktop\Young Gods - 03 - Track 3.wav
[2012/12/20 19:48:04 | 033,116,204 | —- | C] () – C:\Users\Simon\Desktop\Steinski - 01 - We'll be right back.wav
[2012/12/20 19:47:57 | 085,636,364 | —- | C] () – C:\Users\Simon\Desktop\can - 06 - vitamin c (remix).wav
[2012/12/20 19:47:17 | 221,464,378 | —- | C] () – C:\Users\Simon\Desktop\Boredoms - Super roots 7.WAV
[2012/12/20 19:47:09 | 093,049,882 | —- | C] () – C:\Users\Simon\Desktop\Boredoms - Super Roots 1.WAV
[2012/12/19 11:10:18 | 000,150,506 | —- | C] () – C:\Users\Simon\Documents\Xmas2012.pdf
[2012/12/18 22:22:24 | 000,840,192 | —- | C] () – C:\Users\Simon\Documents\Xmas2012.pub
[2012/12/18 20:54:07 | 000,726,799 | —- | C] () – C:\Users\Simon\Desktop\28072012256.jpg
[2012/12/15 07:51:34 | 000,001,043 | —- | C] () – C:\Windows\DVDXRestrictionFree.ini
[2012/12/15 07:51:34 | 000,000,014 | —- | C] () – C:\Windows\SysWow64\SysEngine2.SYS
[2012/12/15 07:51:31 | 000,001,020 | —- | C] () – C:\Users\Simon\Desktop\DVD Ghost.lnk
[2011/12/12 11:41:42 | 000,001,025 | —- | C] () – C:\Windows\SysWow64\sysprs7.dll
[2011/12/12 11:41:42 | 000,000,205 | —- | C] () – C:\Windows\SysWow64\lsprst7.dll
[2011/11/24 21:11:37 | 000,245,760 | —- | C] ( ) – C:\Windows\SysWow64\rsnp2uvc.dll
[2011/11/24 21:11:36 | 000,024,576 | —- | C] () – C:\Windows\snuvcdsm.exe
[2011/11/24 21:11:36 | 000,015,497 | —- | C] () – C:\Windows\snp2uvc.ini
[2011/07/28 01:12:36 | 000,870,544 | —- | C] () – C:\Windows\SysWow64\igkrng575.bin
[2011/07/28 01:12:36 | 000,208,896 | —- | C] () – C:\Windows\SysWow64\iglhsip32.dll
[2011/07/28 01:12:36 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\iglhcp32.dll
[2011/07/28 01:12:35 | 000,051,068 | —- | C] () – C:\Windows\SysWow64\igfcg575m.bin
[2011/07/28 01:12:34 | 000,127,896 | —- | C] () – C:\Windows\SysWow64\igcompkrng575.bin

========== ZeroAccess Check ==========

[2009/07/14 04:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/09 05:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/09 04:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/14 01:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 12:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/14 01:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2012/08/05 16:19:11 | 000,000,000 | —D | M] – C:\Users\Simon\AppData\Roaming\.minecraft
[2012/07/08 19:09:28 | 000,000,000 | —D | M] – C:\Users\Simon\AppData\Roaming\Avery
[2011/12/09 22:27:01 | 000,000,000 | —D | M] – C:\Users\Simon\AppData\Roaming\BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1
[2012/09/21 20:55:48 | 000,000,000 | —D | M] – C:\Users\Simon\AppData\Roaming\calibre
[2011/12/12 10:26:27 | 000,000,000 | —D | M] – C:\Users\Simon\AppData\Roaming\Cisco
[2012/12/03 22:31:57 | 000,000,000 | —D | M] – C:\Users\Simon\AppData\Roaming\DVDVideoSoft
[2012/06/11 20:24:16 | 000,000,000 | —D | M] – C:\Users\Simon\AppData\Roaming\GraphPad Software
[2013/01/05 11:13:36 | 000,000,000 | —D | M] – C:\Users\Simon\AppData\Roaming\HandBrake
[2012/06/09 13:14:56 | 000,000,000 | —D | M] – C:\Users\Simon\AppData\Roaming\ICAClient
[2011/11/25 11:22:09 | 000,000,000 | —D | M] – C:\Users\Simon\AppData\Roaming\ISI ResearchSoft
[2012/12/02 18:18:51 | 000,000,000 | —D | M] – C:\Users\Simon\AppData\Roaming\Nokia
[2011/12/05 15:21:24 | 000,000,000 | —D | M] – C:\Users\Simon\AppData\Roaming\OneClickInternet
[2011/11/28 20:47:27 | 000,000,000 | —D | M] – C:\Users\Simon\AppData\Roaming\PC Suite
[2012/06/11 20:20:22 | 000,000,000 | —D | M] – C:\Users\Simon\AppData\Roaming\Prism
[2012/09/28 15:54:52 | 000,000,000 | —D | M] – C:\Users\Simon\AppData\Roaming\SPSSInc

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2011/02/26 06:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/26 05:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/14 01:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/26 05:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2010/06/03 07:25:55 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/26 05:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/25 06:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 06:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 06:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 12:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2010/06/03 07:28:32 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/25 05:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 05:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/06/03 07:25:55 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2010/06/03 07:28:32 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 13:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2010/06/03 07:25:55 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2010/06/03 07:28:32 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/14 01:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2010/06/03 07:25:55 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/02/26 06:26:45 | 002,870,784 | —- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2010/06/03 07:28:32 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe

< MD5 for: SERVICES.EXE >
[2009/07/14 01:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/14 01:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SVCHOST.EXE >
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009/07/14 01:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\SysWOW64\svchost.exe
[2009/07/14 01:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009/07/14 01:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\SysNative\svchost.exe
[2009/07/14 01:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 12:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\SysWOW64\userinit.exe
[2010/11/20 12:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/14 01:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009/07/14 01:39:48 | 000,030,208 | —- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010/11/20 13:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\SysNative\userinit.exe
[2010/11/20 13:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010/11/20 13:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 13:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/14 01:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2010/06/03 07:25:55 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2010/06/03 07:25:55 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< %systemroot%\*. /rp /s >

< %systemdrive%\$Recycle.Bin|@;true;true;true /fp >

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: TOSHIBA MK3276GSX
Partitions: 2
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Unknown
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 2.00GB
Starting Offset: 6491136
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 296.00GB
Starting Offset: 2156713984
Hidden sectors: 0


========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\System32\config\systemprofile\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Roaming -> Junction
[C:\Windows\System32\config\systemprofile\Cookies] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies -> Junction
[C:\Windows\System32\config\systemprofile\Documents\My Music] -> C:\Windows\system32\config\systemprofile\Music -> Junction
[C:\Windows\System32\config\systemprofile\Documents\My Pictures] -> C:\Windows\system32\config\systemprofile\Pictures -> Junction
[C:\Windows\System32\config\systemprofile\Documents\My Videos] -> C:\Windows\system32\config\systemprofile\Videos -> Junction
[C:\Windows\System32\config\systemprofile\Local Settings] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\My Documents] -> C:\Windows\system32\config\systemprofile\Documents -> Junction
[C:\Windows\System32\config\systemprofile\NetHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts -> Junction
[C:\Windows\System32\config\systemprofile\PrintHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts -> Junction
[C:\Windows\System32\config\systemprofile\Recent] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent -> Junction
[C:\Windows\System32\config\systemprofile\SendTo] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo -> Junction
[C:\Windows\System32\config\systemprofile\Start Menu] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu -> Junction
[C:\Windows\System32\config\systemprofile\Templates] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates -> Junction
[C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\SysWOW64\config\systemprofile\AppData\Local\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Roaming -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Cookies] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Documents\My Music] -> C:\Windows\system32\config\systemprofile\Music -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Documents\My Pictures] -> C:\Windows\system32\config\systemprofile\Pictures -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Documents\My Videos] -> C:\Windows\system32\config\systemprofile\Videos -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Local Settings] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\SysWOW64\config\systemprofile\My Documents] -> C:\Windows\system32\config\systemprofile\Documents -> Junction
[C:\Windows\SysWOW64\config\systemprofile\NetHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts -> Junction
[C:\Windows\SysWOW64\config\systemprofile\PrintHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Recent] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent -> Junction
[C:\Windows\SysWOW64\config\systemprofile\SendTo] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Start Menu] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Templates] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates -> Junction

< End of report >

OTL Extras.txt

OTL Extras logfile created on: 1/13/2013 9:44:37 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Simon\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.80 Gb Total Physical Memory | 2.06 Gb Available Physical Memory | 54.21% Memory free
7.60 Gb Paging File | 5.24 Gb Available in Paging File | 68.97% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 296.08 Gb Total Space | 192.37 Gb Free Space | 64.97% Space Free | Partition Type: NTFS

Computer Name: SIMON-LAPTOP | User Name: Simon | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
"" =
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1F0F0933-A3AC-4761-B64C-771054E773DA}" = lport=137 | protocol=17 | dir=in | app=system |
"{21F035F2-6EA6-4834-AF64-1CFA618BE11C}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{23C4DA1B-1812-48C7-B91D-0A9EE8239A98}" = rport=137 | protocol=17 | dir=out | app=system |
"{25D3AD7B-D24E-465D-BEF2-E23ACA07617D}" = rport=445 | protocol=6 | dir=out | app=system |
"{261B51BF-A530-4633-8DE2-E35E7D2C11DC}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{2EE12A1A-0D5B-4A99-8F95-22748D3D23AE}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{331712FB-F150-4ADD-A510-8EDBFC1C4A9C}" = lport=445 | protocol=6 | dir=in | app=system |
"{41CCB107-2E6F-460D-AA2D-530645E6A0D2}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{4C15D242-1688-4023-A0A9-7817B4C30D1E}" = lport=139 | protocol=6 | dir=in | app=system |
"{5AE85D01-F4FF-4F20-8FA8-48E9A522F0DF}" = rport=10243 | protocol=6 | dir=out | app=system |
"{5C2AC382-1E1D-4129-9EA2-DA3625E8A66A}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{5C62C4E7-B5BE-4509-BF22-FA2DB77EA280}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{662A4F8F-EA57-435B-BB42-DBC08A561A5E}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{733D96BF-9851-4821-9942-B5F552602960}" = lport=19540 | protocol=17 | dir=in | name=sxuptp |
"{73A44E85-0A48-43E5-979F-67B253E31DB0}" = lport=2869 | protocol=6 | dir=in | app=system |
"{75E069EE-3DD7-4DF8-A393-F7A3F7E22B5F}" = rport=139 | protocol=6 | dir=out | app=system |
"{86DB48F0-E0A9-4FB8-B7AA-6D945F29DB61}" = lport=138 | protocol=17 | dir=in | app=system |
"{8A3122E6-F3CC-4C86-8A63-F434FC846953}" = lport=10243 | protocol=6 | dir=in | app=system |
"{977A371E-2095-4767-98A8-858F39F27B05}" = lport=2869 | protocol=6 | dir=in | app=system |
"{A2C13F32-2AB7-4C5B-B55F-D42DFE753977}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{ABAE4389-AB6A-448D-9245-E387C446C416}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{CB41997D-96A6-49BE-A770-9DA2E646A408}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{D185B953-BCB7-4C81-9BA7-BA5396679B16}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{DF8A85BB-43F2-4264-BF4F-9465F0CF65C7}" = rport=138 | protocol=17 | dir=out | app=system |
"{E6A71301-5A8C-4C6D-9BE2-F172EA95DB2F}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\outlook.exe |
"{E8A09A34-0A6C-44B2-8E3F-11849263E012}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{FD5A28A3-438C-4B0F-85CE-F210711B51D9}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04B5370D-D7E6-4A57-81DD-A532BB83F87F}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{0CB0223E-9175-4540-9562-8BD0A6D35F1B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{11462FD8-1CB8-471B-94F7-7B35BCC7C564}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe |
"{14B27719-BA20-49F7-8330-E2E3DD29BDFE}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{15A151E0-547C-47A4-A58F-BEBEC661A169}" = dir=in | app=c:\program files (x86)\nokia\nokia suite\nokiasuite.exe |
"{1BBC60D9-F7F0-412D-88EB-83E681B052A8}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{2ACAB05F-BDA1-4BC6-8E61-EF9282FD7F71}" = dir=in | app=c:\program files (x86)\belkin\router setup and monitor\belkinsetup.exe |
"{2D4DBDF9-48D8-4371-8373-1395C45DABC2}" = protocol=17 | dir=in | app=c:\users\simon\appdata\local\temp\7zs4df5\hppiw.exe |
"{2F99AE8F-D023-4C21-9D35-146FAB87A05F}" = protocol=6 | dir=in | app=c:\users\simon\appdata\local\temp\7zs470b\hppiw.exe |
"{31FAB52C-3717-4F74-9027-D6EF8A5D0556}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{3336CA53-C3DF-497A-9557-4D2B2ADE9F92}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{35CEBE87-DCB0-4EB7-BC88-4B5FB5856603}" = protocol=6 | dir=in | app=c:\users\simon\appdata\local\temp\7zs4df5\hppiw.exe |
"{3621461A-2EDF-442B-9538-C98C84C12240}" = dir=in | app=c:\program files\belkin\belkin usb print and storage center\connect.exe |
"{3A1D0966-8C84-45E4-B641-621818E0B142}" = dir=in | app=c:\program files (x86)\plex\plex media server\plex media server.exe |
"{3AC76EB3-BE47-4C27-A9C9-3F5377F9A0E9}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{3C15CA2B-C21F-4540-B877-3C559E080085}" = protocol=17 | dir=in | app=c:\program files (x86)\belkin\router setup and monitor\belkinsetup.exe |
"{3EAD5B1C-7605-4662-B4B4-9C7C2FD9BEA7}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{4F1DCAEC-7310-443C-9B55-205B06387B34}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{4FCF55F9-F4DB-4937-9D5A-56EB04DA41BF}" = dir=in | app=c:\program files (x86)\nokia\nokia suite\nokiasuite.exe |
"{5D2902DD-A2F8-4B32-BB46-9CF14A73AFFB}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{76BAB997-4384-41C1-9748-519CF6B633E0}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{77CEA844-20CA-4184-9483-BBF68DCF0F0F}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe |
"{8305FE9E-F352-4531-9CEB-4E09FD2DE574}" = dir=in | app=c:\program files (x86)\windows live\messenger\wlcsdk.exe |
"{8588EEEE-28E0-4BE2-82AA-0C586CF1D7D6}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{9269D624-2229-4B6D-BA9B-100805AC101A}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{987702A5-2EAA-4E88-A281-A5E2DAD698B2}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{A6FB92DB-2A90-4B29-8ED5-DB76A3D65C9C}" = dir=in | app=c:\program files (x86)\plex\plex media server\plexscripthost.exe |
"{ACB4ECC1-2818-4F24-B59A-08B047C3AEEF}" = protocol=17 | dir=in | app=c:\program files (x86)\belkin\router setup and monitor\belkinsetup.exe |
"{AE9FB886-7C99-4359-8F65-51981E2D2D4B}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{B31F623A-97CF-49AA-B2BB-AE091063534F}" = protocol=6 | dir=in | app=c:\program files (x86)\belkin\router setup and monitor\belkinsetup.exe |
"{B3D98184-278C-4A35-93D8-CA65CB00D578}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{BA53B046-A0E2-4F7D-B589-1D7555424C0C}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{BB1F80D3-DD8C-4773-9F9A-136AB7754A1F}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{BBDB291F-344C-4FDD-874E-A390AE0A73B9}" = protocol=6 | dir=in | app=c:\program files (x86)\belkin\router setup and monitor\belkinsetup.exe |
"{C1A36336-9BB9-4267-8193-B4480EBCA293}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{CCDD0F2F-08A7-4213-AF08-CD12F5F9A427}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{D3978596-0912-4AAE-B4D8-2550C0DF75AF}" = protocol=6 | dir=out | app=system |
"{D536A206-4606-4928-B822-AA625FDDEC30}" = dir=in | app=c:\program files (x86)\common files\nokia\service layer\a\nsl_host_process.exe |
"{E33B2E65-8493-40BD-84D8-F38F5C8FF584}" = protocol=17 | dir=in | app=c:\users\simon\appdata\local\temp\7zs470b\hppiw.exe |
"{E4BA6BAE-85D1-42A4-A5E1-8A271D1402D0}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{E72F068A-0C5D-4A73-9F90-FFAE47E309D3}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{E8344CB2-E9C1-4C42-9AA6-8E2EDDF9683F}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{EA7CD0B4-28FB-4B74-A187-11BD105E3349}" = dir=in | app=c:\program files (x86)\plex\plex media server\plexdlnaserver.exe |
"{EFF18AAA-39CD-4053-9689-D41FC3837782}" = dir=in | app=c:\program files (x86)\common files\nokia\service layer\a\nsl_host_process.exe |
"{F1B50C88-E46C-42B2-B91A-7D05F4C4F7DB}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{F51C3774-6694-4EFE-B95D-F823182945DB}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"TCP Query User{053D2956-1254-4217-838E-C6DF27062AB0}C:\program files\ibm\spss\statistics\21\jre\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\ibm\spss\statistics\21\jre\bin\javaw.exe |
"TCP Query User{818BA428-7B07-4135-A392-57D7196FCC36}C:\program files\ibm\spss\statistics\20\jre\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\ibm\spss\statistics\20\jre\bin\javaw.exe |
"TCP Query User{8991CDE7-9441-4517-9AA5-DD6B950A4F5E}C:\program files (x86)\plex\plex media center\plex.exe" = protocol=6 | dir=in | app=c:\program files (x86)\plex\plex media center\plex.exe |
"TCP Query User{8AA09A5F-8D59-43CE-82F5-2475484A73DE}C:\program files (x86)\belkin\router setup and monitor\dlnaplugin.exe" = protocol=6 | dir=in | app=c:\program files (x86)\belkin\router setup and monitor\dlnaplugin.exe |
"TCP Query User{DEF581D2-633F-4567-9B34-670BFD26923F}C:\program files\ibm\spss\statistics\20\jre\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\ibm\spss\statistics\20\jre\bin\javaw.exe |
"TCP Query User{E076B7B7-C424-4CAD-B972-19905EB85AE4}C:\program files (x86)\dukto\dukto.exe" = protocol=6 | dir=in | app=c:\program files (x86)\dukto\dukto.exe |
"TCP Query User{ED31CD8A-136C-4EAD-8454-B99B9B1D4F83}C:\program files\ibm\spss\statistics\21\jre\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\ibm\spss\statistics\21\jre\bin\javaw.exe |
"TCP Query User{FE067B99-4D48-4BE2-8C9F-74E692553CD4}C:\program files\ibm\spss\statistics\21\stats.exe" = protocol=6 | dir=in | app=c:\program files\ibm\spss\statistics\21\stats.exe |
"UDP Query User{01327C1D-CDBF-4B99-9859-5CED603F78F9}C:\program files\ibm\spss\statistics\21\stats.exe" = protocol=17 | dir=in | app=c:\program files\ibm\spss\statistics\21\stats.exe |
"UDP Query User{5AB15CD8-F335-4FD9-93C6-AFFDAA0CCE6D}C:\program files\ibm\spss\statistics\20\jre\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\ibm\spss\statistics\20\jre\bin\javaw.exe |
"UDP Query User{7331AB5F-09E8-4425-A254-AEB5B1AA2CEA}C:\program files (x86)\belkin\router setup and monitor\dlnaplugin.exe" = protocol=17 | dir=in | app=c:\program files (x86)\belkin\router setup and monitor\dlnaplugin.exe |
"UDP Query User{8EEA8E28-5B01-4564-AB55-6E6D70DBB0E1}C:\program files\ibm\spss\statistics\21\jre\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\ibm\spss\statistics\21\jre\bin\javaw.exe |
"UDP Query User{AA68A2A0-C2BD-4EDB-B1C2-76A8B82FD299}C:\program files\ibm\spss\statistics\21\jre\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\ibm\spss\statistics\21\jre\bin\javaw.exe |
"UDP Query User{C94C3764-7D15-461A-A024-F74B38F06C9A}C:\program files\ibm\spss\statistics\20\jre\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\ibm\spss\statistics\20\jre\bin\javaw.exe |
"UDP Query User{CE4F1D93-F0F3-4301-988B-D3C930449099}C:\program files (x86)\dukto\dukto.exe" = protocol=17 | dir=in | app=c:\program files (x86)\dukto\dukto.exe |
"UDP Query User{EEFBFF7B-BB5B-4EBE-B5CE-3B11FB31A270}C:\program files (x86)\plex\plex media center\plex.exe" = protocol=17 | dir=in | app=c:\program files (x86)\plex\plex media center\plex.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1E26B9C2-ED08-4EEA-83C8-A786502B41E5}" = IBM SPSS Statistics 21
"{4108974B-DE87-4AD4-9167-930C62C45691}" = Fujitsu Display Manager
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4D668D4F-FAA2-4726-834C-31F4614F312E}" = MSVC80_x64_v2
"{51692C66-5505-41B8-92A7-548C69FB867C}" = Wireless Selector
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6226477E-444F-4DFE-BA19-9F4F7D4565BC}" = LifeBook Application Panel
"{680EDA59-9266-44B4-949E-0C24F65DFF82}" = Microsoft_VC100_CRT_SP1_x64
"{6B99AF03-2668-4572-BD3D-8C7A5D103065}" = AuthenTec Fingerprint Software
"{7254349B-460B-488F-B4DB-A96100C5C48B}" = Power Saving Utility
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver
"{AB071C8B-873C-459F-ACA9-9EBE03C3E89B}" = MSVC90_x64
"{ABE8CE7E-01CC-4500-BAF5-FFC29EA108A1}" = Shock Sensor Utility
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240D7}" = WinZip 17.0
"{DD21DF96-E33D-40E5-B1A5-1274D6C51745}" = IBM SPSS Statistics - Essentials for R 21 64bit
"{E4F5E48E-7155-4CF9-88CD-7F377EC9AC54}" = Bonjour
"{E8A5B78F-4456-4511-AB3D-E7BFFB974A7A}" = Fujitsu System Extension Utility
"{EC314CDF-3521-482B-A21C-65AC95664814}" = Fujitsu MobilityCenter Extension Utility
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F" = Windows Driver Package - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0)
"Belkin USB Print and Storage Center" = Belkin USB Print and Storage Center
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"R for Windows 2.14.1_is1" = R for Windows 2.14.1
"WinRAR archiver" = WinRAR 4.20 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{038B5DDD-C8F5-4830-BA30-A34C58A417FF}" = MLwiN 2.25
"{0906982B-A432-4C06-8F01-C01BE1143779}" = Nokia Connectivity Cable Driver
"{0BCA9EFD-F2D6-4638-B053-8693BA0404BE}" = Citrix online plug-in (Web)
"{11096C51-BBE4-4B7B-AE03-034F12D7A635}" = Plex Media Server
"{15C418EB-7675-42be-B2B3-281952DA014D}" = Sophos AutoUpdate
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{1798D459-6B8B-474B-868D-1229EADA3B95}" = Adobe AIR
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20400dbd-e6db-45b8-9b6b-1dd7033818ec}" = Nero InfoTool Help
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2348b586-c9ae-46ce-936c-a68e9426e214}" = Nero StartSmart Help
"{26A24AE4-039D-4CA4-87B4-2F83216037FF}" = Java™ 6 Update 37
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{33cf58f5-48d8-4575-83d6-96f574e4d83a}" = Nero DriveSpeed
"{33EBF075-8593-4698-BDAF-CF8DED80BB5B}" = Nokia Suite
"{35B73650-6899-11DA-6784-00232A9018BE}" = GraphPad Prism 5
"{386C0311-B146-4CE0-89E5-8469A3583156}}_is1" = Dukto R5
"{399C37FB-08AF-493B-BFED-20FBD85EDF7F}" = FJ Camera
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4D43D635-6FDA-4fa5-AA9B-23CF73D058EA}" = Nero StartSmart OEM
"{5006A0E8-B9B0-48DF-981A-41D005B3E937}" = Stata 12
"{55392E52-1AAD-44C4-BE49-258FFE72434F}" = Citrix online plug-in (USB)
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{62ac81f6-bdd3-4110-9d36-3e9eaab40999}" = Nero CoverDesigner
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7748ac8c-18e3-43bb-959b-088faea16fb2}" = Nero StartSmart
"{7829db6f-a066-4e40-8912-cb07887c20bb}" = Nero BurnRights
"{812424AC-A8B5-44E6-8D48-07E939D1AD9A}" = Citrix online plug-in (HDX)
"{869200db-287a-4dc0-b02b-2b6787fbcd4c}" = Nero DiscSpeed
"{8BCAC105-C501-41F9-AED1-587024ABCA8C}" = Reference Manager 12 Professional Edition
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUS_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUS_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUS_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0409-1000-0000000FF1CE}_Office14.PROPLUS_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.PROPLUS_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.PROPLUS_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.PROPLUS_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0116-0409-1000-0000000FF1CE}_Office14.PROPLUS_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{9983CD31-473F-4808-8317-5346119F0187}" = eBay
"{9ACB414D-9347-40B6-A453-5EFB2DB59DFA}" = Sophos Anti-Virus
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F479685-180E-4C05-9400-D59292A1B29C}" = Windows Live Movie Maker
"{a5b693e6-2001-4c66-a142-fa92791c92ff}" = Nero 9 Essentials
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{ABC2FE47-8FD6-46FF-86D3-A0267CAF8247}" = MLwiN
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.2
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{ADB1DE83-FC42-4C3F-B64B-2AF2215EF88B}" = Cisco AnyConnect Secure Mobility Client
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{b2ec4a38-b545-4a00-8214-13fe0e915e6d}" = Advertising Center
"{B364DC2A-9783-4737-B795-D6F0562A41C5}" = calibre
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{BA0CC975-682B-4678-A35C-05E607F36387}" = Fujitsu Hotkey Utility
"{BA77F9D2-CD35-41EB-9BC9-769879DFF8A6}" = PC Connectivity Solution
"{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}" = Nero ControlCenter
"{cc019e3f-59d2-4486-8d4b-878105b62a71}" = Nero DiscSpeed Help
"{ce96f5a5-584d-4f8f-aa3e-9baed413db72}" = Nero CoverDesigner Help
"{CF53CF7C-D996-43EB-9904-DBED57C25625}" = Citrix online plug-in (DV)
"{D6A0DD73-6EF2-9A8D-6F60-4F338F922B37}" = BBC iPlayer Desktop
"{DC81F10E-E02C-11D3-AAE5-00A0C9C9038A}" = MLwiN
"{E3B64CC5-C011-40C0-92BC-7316CD5E5688}" = Microsoft_VC100_CRT_SP1_x86
"{e5c7d048-f9b4-4219-b323-8bdb01a2563d}" = Nero DriveSpeed Help
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{e8a80433-302b-4ff1-815d-fcc8eac482ff}" = Nero Installer
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{EF59DB7F-7426-426E-B862-7031F83ED304}" = SystemDiagnostics
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Graphics Media Accelerator Driver
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{f4041dce-3fe1-4e18-8a9e-9de65231ee36}" = Nero ControlCenter
"{F5D84887-8A6F-4993-8560-B3AA44CB620D}" = Avery Wizard 4.0
"{f6bdd7c5-89ed-4569-9318-469aa9732572}" = Nero BurnRights Help
"{F7708742-E734-4BC1-BEEB-F200DE21C5FC}" = Qualcomm Gobi 2000 Package for Sierra
"{fbcdfd61-7dcf-4e71-9226-873ba0053139}" = Nero InfoTool
"0222-0618-0114-4896" = Review Manager 5.1.7
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1" = BBC iPlayer Desktop
"Belkin Setup and Router Monitor_is1" = Belkin Setup and Router Monitor
"Cisco AnyConnect Secure Mobility Client" = Cisco AnyConnect Secure Mobility Client
"CitrixOnlinePluginPackWeb" = Citrix online plug-in - web
"Digital Editions" = Adobe Digital Editions
"DVD Ghost 2.62_is1" = DVD Ghost 2.62
"ESET Online Scanner" = ESET Online Scanner v3
"Google Chrome" = Google Chrome
"GraphPad Prism_is1" = GraphPad Prism 4
"GraphPad StatMate_is1" = GraphPad StatMate 2
"HandBrake" = HandBrake 0.9.8
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{4108974B-DE87-4AD4-9167-930C62C45691}" = Fujitsu Display Manager
"InstallShield_{51692C66-5505-41B8-92A7-548C69FB867C}" = Wireless Selector
"InstallShield_{6226477E-444F-4DFE-BA19-9F4F7D4565BC}" = LifeBook Application Panel
"InstallShield_{7254349B-460B-488F-B4DB-A96100C5C48B}" = Power Saving Utility
"InstallShield_{ABE8CE7E-01CC-4500-BAF5-FFC29EA108A1}" = Shock Sensor Utility
"InstallShield_{BA0CC975-682B-4678-A35C-05E607F36387}" = Fujitsu Hotkey Utility
"InstallShield_{E8A5B78F-4456-4511-AB3D-E7BFFB974A7A}" = Fujitsu System Extension Utility
"InstallShield_{EC314CDF-3521-482B-A21C-65AC95664814}" = Fujitsu MobilityCenter Extension Utility
"ISI ResearchSoft - Export Helper" = ISI ResearchSoft - Export Helper
"MagicDisc 2.7.106" = MagicDisc 2.7.106
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100
"Nokia Suite" = Nokia Suite
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"OneClickInternet" = OneClick Internet
"ST6UNST #1" = SiMin
"SUPER ©" = SUPER © Version 2010.bld.38 (May 2, 2010)
"Video Mover_is1" = Video Mover
"WinLiveSuite_Wave3" = Windows Live Essentials

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Amazon Kindle" = Amazon Kindle
"Plex" = Plex

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 1/8/2013 5:45:56 PM | Computer Name = Simon-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 1/8/2013 5:45:56 PM | Computer Name = Simon-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 8097

Error - 1/8/2013 5:45:56 PM | Computer Name = Simon-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 8097

Error - 1/8/2013 5:45:57 PM | Computer Name = Simon-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 1/8/2013 5:45:57 PM | Computer Name = Simon-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 9111

Error - 1/8/2013 5:45:57 PM | Computer Name = Simon-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 9111

Error - 1/8/2013 6:05:07 PM | Computer Name = Simon-Laptop | Source = Bonjour Service | ID = 100
Description = send_msg ERROR: failed to write 86 of 86 bytes to fd 600 errno 10054
(An existing connection was forcibly closed by the remote host.)

Error - 1/8/2013 6:05:07 PM | Computer Name = Simon-Laptop | Source = Bonjour Service | ID = 100
Description = 600: Could not write data to client because of error - aborting connection

Error - 1/8/2013 6:05:07 PM | Computer Name = Simon-Laptop | Source = Bonjour Service | ID = 100
Description = 600: DNSServiceQueryRecord Simon-Laptop.local. (AAAA)

Error - 1/8/2013 6:07:47 PM | Computer Name = Simon-Laptop | Source = Application Error | ID = 1000
Description = Faulting application name: Plex Media Server.exe, version: 0.9.7.3,
time stamp: 0x50ab4c64 Faulting module name: KERNELBASE.dll, version: 6.1.7601.17965,
time stamp: 0x506dbe50 Exception code: 0xc0dedead Fault offset: 0x0000c41f Faulting
process id: 0xa38 Faulting application start time: 0x01cdedec864c7d85 Faulting application
path: C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe Faulting
module path: C:\Windows\syswow64\KERNELBASE.dll Report Id: d5609098-59df-11e2-a182-b4749ff00525

[ Cisco AnyConnect Secure Mobility Client Events ]
Error - 1/12/2013 5:29:11 PM | Computer Name = Simon-Laptop | Source = acvpnui | ID = 67108865
Description = Function: ConnectMgr::activateConnectEvent File: .\ConnectMgr.cpp Line:
1089 NULL object. Cannot establish a connection at this time.

Error - 1/12/2013 6:33:55 PM | Computer Name = Simon-Laptop | Source = acvpnagent | ID = 67108866
Description = Function: CSocketTransport::callbackHandler File: .\IPC\SocketTransport.cpp
Line:
1280 Invoked Function: WSAGetOverlappedResult Return Code: 10054 (0x00002746) Description:
An existing connection was forcibly closed by the remote host.

Error - 1/12/2013 6:33:55 PM | Computer Name = Simon-Laptop | Source = acvpnagent | ID = 67108866
Description = Function: CSocketTransport::callbackHandler File: .\IPC\SocketTransport.cpp
Line:
1281 Invoked Function: WSARecv/WSARecvFrom Return Code: 0 (0x00000000) Description:
unknown

Error - 1/12/2013 6:33:55 PM | Computer Name = Simon-Laptop | Source = acvpnagent | ID = 67108866
Description = Function: CIpcTransport::OnSocketReadComplete File: .\IPC\IPCTransport.cpp
Line:
873 Invoked Function: CSocketTransport::readSocket Return Code: -31522801 (0xFE1F000F)
Description:
SOCKETTRANSPORT_ERROR_TRANSPORT_FAILURE

Error - 1/12/2013 6:33:55 PM | Computer Name = Simon-Laptop | Source = acvpnagent | ID = 67108866
Description = Function: CIpcDepot::OnIpcMessageReceived File: .\IPC\IPCDepot.cpp Line:
832 Invoked Function: CIpcTransport::OnSocketReadComplete Return Code: -31522801
(0xFE1F000F) Description: SOCKETTRANSPORT_ERROR_TRANSPORT_FAILURE

Error - 1/12/2013 6:33:55 PM | Computer Name = Simon-Laptop | Source = acvpnagent | ID = 67108866
Description = Function: CTcpTransport::writeSocketBlocking File: .\IPC\SocketTransport.cpp
Line:
1676 Invoked Function: WSASend Return Code: 10054 (0x00002746) Description: An existing
connection was forcibly closed by the remote host.

Error - 1/12/2013 6:33:55 PM | Computer Name = Simon-Laptop | Source = acvpnagent | ID = 67108866
Description = Function: CIpcTransport::terminateIpcConnection File: .\IPC\IPCTransport.cpp
Line:
384 Invoked Function: CSocketTransport::writeSocketBlocking Return Code: -31522805
(0xFE1F000B) Description: SOCKETTRANSPORT_ERROR_WRITE

Error - 1/13/2013 5:21:44 PM | Computer Name = Simon-Laptop | Source = acvpnui | ID = 67108866
Description = Function: CMainFrame::getDARTInstallDir File: .\mainfrm.cpp Line: 4214
Invoked
Function: MsiEnumProductsExW Return Code: 259 (0x00000103) Description: No more data
is available.

Error - 1/13/2013 5:21:45 PM | Computer Name = Simon-Laptop | Source = acvpnui | ID = 67108865
Description = Function: ConnectMgr::activateConnectEvent File: .\ConnectMgr.cpp Line:
1089 NULL object. Cannot establish a connection at this time.

Error - 1/13/2013 5:21:49 PM | Computer Name = Simon-Laptop | Source = acvpnagent | ID = 67108866
Description = Function: CThread::invokeRun File: .\Utility\Thread.cpp Line: 376 Invoked
Function: IRunnable::Run Return Code: -32047093 (0xFE17000B) Description: BROWSERPROXY_ERROR_NO_PROXY_FILE


[ System Events ]
Error - 12/18/2012 5:46:49 PM | Computer Name = Simon-Laptop | Source = EventLog | ID = 6008
Description = The previous system shutdown at 21:34:47 on ?18/?12/?2012 was unexpected.

Error - 12/18/2012 5:47:12 PM | Computer Name = Simon-Laptop | Source = BugCheck | ID = 1001
Description =

Error - 12/26/2012 9:30:49 AM | Computer Name = Simon-Laptop | Source = DCOM | ID = 10010
Description =

Error - 12/26/2012 9:30:56 AM | Computer Name = Simon-Laptop | Source = DCOM | ID = 10010
Description =

Error - 12/28/2012 3:21:09 PM | Computer Name = Simon-Laptop | Source = Service Control Manager | ID = 7034
Description = The Qualcomm Gobi 2000 Download Service (Sierra) service terminated
unexpectedly. It has done this 1 time(s).

Error - 1/4/2013 11:53:40 AM | Computer Name = Simon-Laptop | Source = Service Control Manager | ID = 7031
Description = The Windows Audio service terminated unexpectedly. It has done this
1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.

Error - 1/4/2013 11:53:40 AM | Computer Name = Simon-Laptop | Source = Service Control Manager | ID = 7031
Description = The DHCP Client service terminated unexpectedly. It has done this
1 time(s). The following corrective action will be taken in 120000 milliseconds:
Restart the service.

Error - 1/4/2013 11:53:40 AM | Computer Name = Simon-Laptop | Source = Service Control Manager | ID = 7031
Description = The Windows Event Log service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.

Error - 1/4/2013 11:53:40 AM | Computer Name = Simon-Laptop | Source = Service Control Manager | ID = 7031
Description = The TCP/IP NetBIOS Helper service terminated unexpectedly. It has
done this 1 time(s). The following corrective action will be taken in 100 milliseconds:
Restart the service.

Error - 1/4/2013 11:53:40 AM | Computer Name = Simon-Laptop | Source = Service Control Manager | ID = 7031
Description = The Security Center service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 120000 milliseconds:
Restart the service.


< End of report >

And here is the log from aswMBR:

aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software
Run date: 2013-01-13 22:07:22
—————————–
22:07:22.094 OS Version: Windows x64 6.1.7601 Service Pack 1
22:07:22.094 Number of processors: 4 586 0x2505
22:07:22.095 ComputerName: SIMON-LAPTOP UserName: Simon
22:07:23.720 Initialize success
22:14:43.567 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
22:14:43.582 Disk 0 Vendor: TOSHIBA_ GS00 Size: 305245MB BusType: 3
22:14:43.605 Disk 0 MBR read successfully
22:14:43.610 Disk 0 MBR scan
22:14:43.615 Disk 0 Windows 7 default MBR code
22:14:43.621 Disk 0 Partition 1 80 (A) 27 Hidden NTFS WinRE NTFS 2049 MB offset 12678
22:14:43.636 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 303187 MB offset 4212332
22:14:43.654 Disk 0 scanning C:\Windows\system32\drivers
22:14:51.579 Service scanning
22:15:27.649 Modules scanning
22:15:27.670 Disk 0 trace - called modules:
22:15:27.700 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys hal.dll
22:15:27.708 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004bc7060]
22:15:27.715 3 CLASSPNP.SYS[fffff88001d9b43f] -> nt!IofCallDriver -> [0xfffffa80049475d0]
22:15:28.058 5 ACPI.sys[fffff88000faa7a1] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa800494a050]
22:15:28.073 Scan finished successfully
22:16:22.100 Disk 0 MBR has been saved successfully to "C:\Users\Simon\Desktop\MBR.dat"
22:16:22.106 The log file has been saved successfully to "C:\Users\Simon\Desktop\aswMBR.txt"


Thanks again, I should imagine it's a bit tedious going through all those log files….

Simon

Attachments:

Hi simonjeaton ;)

Very good job ;)

AdwCleaner

  • Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

=============================== Next =======================================



Please read through these instructions to familarize yourself with what to expect when this tool runs

Refer to the ComboFix User's Guide


Download ComboFix from one of these locations:

Link 1
Link 2



* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================


Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs


====================================================


Double click on combofix.exe & follow the prompts.


When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.



On your next reply please post :
  • AdwCleaner log
  • Combofix log

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Hi Robybel, I've done the scans/fixes suggested and here are the logs. Could you tell me a bit more about what you've found on my computer? ADWCleaner: # AdwCleaner v2.105 - Logfile created 01/16/2013 at 11:01:14 # Updated 08/01/2013 by Xplode # Operating system : Windows 7 Professional Service Pack 1 (64 bits) # User : Simon - SIMON-LAPTOP # Boot Mode : Normal # Running from : C:\Users\Simon\Desktop\AdwCleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** File Deleted : C:\Users\Public\Desktop\eBay.lnk Folder Deleted : C:\ProgramData\boost_interprocess Folder Deleted : C:\ProgramData\Partner ***** [Registry] ***** Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5} Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [] ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16457 [OK] Registry is clean. -\\ Google Chrome v24.0.1312.52 File : C:\Users\Simon\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[S1].txt - [1343 octets] - [16/01/2013 11:01:14] ########## EOF - C:\AdwCleaner[S1].txt - [1403 octets] ########## And CombiFix: ComboFix 13-01-15.02 - Simon 16/01/2013 11:18:35.1.4 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1252.44.1033.18.3891.2312 [GMT 0:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Sophos Anti-Virus *Disabled/Updated* {65FBD860-96D8-75EF-C7ED-7BE27E6C498A} SP: Sophos Anti-Virus *Disabled/Updated* {DE9A3984-B0E2-7A61-FD5D-409005EB0337} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\boost_interprocess\20130116110231.109999 c:\programdata\boost_interprocess\20130116110231.109999\9334581e-7251-4ef7-a8ec-5bfe8e89ff68 c:\programdata\boost_interprocess\20130116110231.109999\plex_frame_mutex c:\users\Simon\AppData\Local\Microsoft\Windows\Temporary Internet Files\{11795A45-B9EA-4164-8ED1-1C31CE73974F}.xps c:\users\Simon\AppData\Local\Microsoft\Windows\Temporary Internet Files\{54136635-B8AC-4C80-815D-E16C22D9BEF4}.xps c:\users\Simon\AppData\Local\Microsoft\Windows\Temporary Internet Files\{73054D8C-2DC4-4007-ACB0-A62366360C93}.xps c:\users\Simon\AppData\Local\Microsoft\Windows\Temporary Internet Files\{D77CD482-E95E-413A-9FC3-49CA6B6B63BF}.xps c:\users\Simon\AppData\Local\Temp\1.tmp\F_IN_BOX.dll c:\users\Simon\AppData\Local\Temp\7zS470B\HPSLPSVC64.DLL c:\windows\SysWow64\AVSredirect.dll . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . ——-\Service_HPSLPSVC . . ((((((((((((((((((((((((( Files Created from 2012-12-16 to 2013-01-16 ))))))))))))))))))))))))))))))) . . 2013-01-16 11:32 . 2013-01-16 11:32 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-01-16 11:03 . 2013-01-16 11:28 ——– d—–w- c:\programdata\boost_interprocess 2013-01-16 10:59 . 2012-11-08 17:24 9125352 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{EC400927-7EA7-43ED-88F9-F68FA1C34C25}\mpengine.dll 2013-01-13 22:17 . 2013-01-13 22:17 ——– d—–w- c:\users\Simon\AppData\Local\WinZip 2013-01-10 21:49 . 2013-01-10 21:49 ——– d—–w- c:\program files (x86)\ESET 2013-01-10 21:26 . 2013-01-10 21:26 ——– d—–w- c:\users\Simon\AppData\Roaming\Malwarebytes 2013-01-10 21:24 . 2013-01-10 21:24 ——– d—–w- c:\programdata\Malwarebytes 2013-01-10 21:24 . 2013-01-10 21:24 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2013-01-10 21:24 . 2012-12-14 16:49 24176 —-a-w- c:\windows\system32\drivers\mbam.sys 2013-01-10 21:23 . 2013-01-10 21:23 ——– d—–w- c:\users\Simon\AppData\Local\Programs 2013-01-10 16:05 . 2012-11-09 05:45 750592 —-a-w- c:\windows\system32\win32spl.dll 2013-01-10 16:05 . 2012-11-09 04:43 492032 —-a-w- c:\windows\SysWow64\win32spl.dll 2013-01-10 16:03 . 2012-11-23 03:26 3149824 —-a-w- c:\windows\system32\win32k.sys 2013-01-10 16:01 . 2012-11-23 03:13 68608 —-a-w- c:\windows\system32\taskhost.exe 2013-01-08 22:56 . 2013-01-08 22:56 ——– d—–w- c:\program files (x86)\Dukto 2012-12-27 11:31 . 2004-02-22 10:11 719872 —-a-w- c:\windows\SysWow64\devil.dll 2012-12-27 11:31 . 2004-02-22 10:11 719872 —-a-w- c:\windows\SysWow64\devil.dll  2012-12-27 11:31 . 2009-09-27 09:39 369152 —-a-w- c:\windows\SysWow64\avisynth.dll 2012-12-27 11:31 . 2004-01-25 00:00 70656 —-a-w- c:\windows\SysWow64\yv12vfw.dll 2012-12-27 11:31 . 2004-01-25 00:00 70656 —-a-w- c:\windows\SysWow64\i420vfw.dll 2012-12-27 11:31 . 2004-01-25 00:00 70656 —-a-w- c:\windows\SysWow64\i420vfw.dll  2012-12-27 11:30 . 2012-12-27 11:30 ——– d—–w- c:\program files (x86)\AviSynth 2.5 2012-12-25 20:20 . 2012-12-16 17:11 46080 —-a-w- c:\windows\system32\atmlib.dll 2012-12-25 20:20 . 2012-12-16 14:13 34304 —-a-w- c:\windows\SysWow64\atmlib.dll 2012-12-25 20:20 . 2012-12-16 14:45 367616 —-a-w- c:\windows\system32\atmfd.dll 2012-12-25 20:20 . 2012-12-16 14:13 295424 —-a-w- c:\windows\SysWow64\atmfd.dll 2012-12-24 17:38 . 2013-01-13 22:16 ——– d—–w- c:\programdata\WinZip 2012-12-24 17:38 . 2012-12-24 17:39 ——– d—–w- c:\program files\WinZip 2012-12-24 17:23 . 2012-12-24 17:23 ——– d—–w- c:\program files\WinRAR 2012-12-24 16:13 . 2012-12-24 16:13 ——– d—–w- c:\users\Simon\AppData\Roaming\AVS4YOU 2012-12-24 16:11 . 2012-12-24 16:25 ——– d—–w- c:\program files (x86)\Common Files\AVSMedia 2012-12-24 16:10 . 2012-03-23 19:59 1700352 —-a-w- c:\windows\SysWow64\GdiPlus.dll 2012-12-24 16:10 . 2012-12-24 16:25 ——– d—–w- c:\program files (x86)\AVS4YOU 2012-12-24 16:10 . 2012-12-24 16:13 ——– d—–w- c:\programdata\AVS4YOU 2012-12-24 16:10 . 2012-03-23 19:59 24576 —-a-w- c:\windows\SysWow64\msxml3a.dll 2012-12-18 22:39 . 2012-12-18 22:39 ——– d—–w- c:\programdata\Hewlett-Packard 2012-12-18 22:39 . 2009-07-14 01:41 230400 —-a-w- c:\windows\system32\Spool\prtprocs\x64\hpzppw71.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-01-10 17:53 . 2011-12-12 10:29 67599240 —-a-w- c:\windows\system32\MRT.exe 2012-12-11 18:33 . 2012-12-11 18:24 286720 ——w- c:\windows\Setup1.exe 2012-12-11 18:33 . 2012-12-11 18:24 73216 —-a-w- c:\windows\ST6UNST.EXE 2012-11-30 04:45 . 2013-01-10 16:04 44032 —-a-w- c:\windows\apppatch\acwow64.dll 2012-11-29 18:07 . 2012-07-28 20:55 37400 —-a-w- c:\windows\system32\SophosBootTasks.exe 2012-11-27 21:18 . 2012-05-17 08:31 697272 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-11-27 21:18 . 2011-11-25 09:31 73656 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-11-16 09:33 . 2012-11-16 09:33 74752 —-a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2012-11-16 09:33 . 2012-11-16 09:33 161792 —-a-w- c:\windows\SysWow64\msls31.dll 2012-11-16 09:33 . 2012-11-16 09:33 86528 —-a-w- c:\windows\SysWow64\iesysprep.dll 2012-11-16 09:33 . 2012-11-16 09:33 76800 —-a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2012-11-16 09:33 . 2012-11-16 09:33 63488 —-a-w- c:\windows\SysWow64\tdc.ocx 2012-11-16 09:33 . 2012-11-16 09:33 48640 —-a-w- c:\windows\SysWow64\mshtmler.dll 2012-11-16 09:33 . 2012-11-16 09:33 367104 —-a-w- c:\windows\SysWow64\html.iec 2012-11-16 09:33 . 2012-11-16 09:33 110592 —-a-w- c:\windows\SysWow64\IEAdvpack.dll 2012-11-16 09:33 . 2012-11-16 09:33 74752 —-a-w- c:\windows\SysWow64\iesetup.dll 2012-11-16 09:33 . 2012-11-16 09:33 23552 —-a-w- c:\windows\SysWow64\licmgr10.dll 2012-11-16 09:33 . 2012-11-16 09:33 152064 —-a-w- c:\windows\SysWow64\wextract.exe 2012-11-16 09:33 . 2012-11-16 09:33 150528 —-a-w- c:\windows\SysWow64\iexpress.exe 2012-11-16 09:33 . 2012-11-16 09:33 35840 —-a-w- c:\windows\SysWow64\imgutil.dll 2012-11-16 09:33 . 2012-11-16 09:33 11776 —-a-w- c:\windows\SysWow64\mshta.exe 2012-11-16 09:33 . 2012-11-16 09:33 101888 —-a-w- c:\windows\SysWow64\admparse.dll 2012-11-16 09:33 . 2012-11-16 09:33 89088 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe 2012-11-16 09:33 . 2012-11-16 09:33 65024 —-a-w- c:\windows\system32\pngfilt.dll 2012-11-16 09:33 . 2012-11-16 09:33 55296 —-a-w- c:\windows\system32\msfeedsbs.dll 2012-11-16 09:33 . 2012-11-16 09:33 49664 —-a-w- c:\windows\system32\imgutil.dll 2012-11-16 09:33 . 2012-11-16 09:33 267776 —-a-w- c:\windows\system32\ieaksie.dll 2012-11-16 09:33 . 2012-11-16 09:33 222208 —-a-w- c:\windows\system32\msls31.dll 2012-11-16 09:33 . 2012-11-16 09:33 197120 —-a-w- c:\windows\system32\msrating.dll 2012-11-16 09:33 . 2012-11-16 09:33 163840 —-a-w- c:\windows\system32\ieakui.dll 2012-11-16 09:33 . 2012-11-16 09:33 149504 —-a-w- c:\windows\system32\occache.dll 2012-11-16 09:33 . 2012-11-16 09:33 145920 —-a-w- c:\windows\system32\iepeers.dll 2012-11-16 09:33 . 2012-11-16 09:33 12288 —-a-w- c:\windows\system32\mshta.exe 2012-11-16 09:33 . 2012-11-16 09:33 114176 —-a-w- c:\windows\system32\admparse.dll 2012-11-16 09:33 . 2012-11-16 09:33 91648 —-a-w- c:\windows\system32\SetIEInstalledDate.exe 2012-11-16 09:33 . 2012-11-16 09:33 89088 —-a-w- c:\windows\system32\ie4uinit.exe 2012-11-16 09:33 . 2012-11-16 09:33 82432 —-a-w- c:\windows\system32\icardie.dll 2012-11-16 09:33 . 2012-11-16 09:33 76800 —-a-w- c:\windows\system32\tdc.ocx 2012-11-16 09:33 . 2012-11-16 09:33 534528 —-a-w- c:\windows\system32\ieapfltr.dll 2012-11-16 09:33 . 2012-11-16 09:33 48640 —-a-w- c:\windows\system32\mshtmler.dll 2012-11-16 09:33 . 2012-11-16 09:33 452608 —-a-w- c:\windows\system32\dxtmsft.dll 2012-11-16 09:33 . 2012-11-16 09:33 448512 —-a-w- c:\windows\system32\html.iec 2012-11-16 09:33 . 2012-11-16 09:33 39936 —-a-w- c:\windows\system32\iernonce.dll 2012-11-16 09:33 . 2012-11-16 09:33 3695416 —-a-w- c:\windows\system32\ieapfltr.dat 2012-11-16 09:33 . 2012-11-16 09:33 282112 —-a-w- c:\windows\system32\dxtrans.dll 2012-11-16 09:33 . 2012-11-16 09:33 160256 —-a-w- c:\windows\system32\ieakeng.dll 2012-11-16 09:33 . 2012-11-16 09:33 135168 —-a-w- c:\windows\system32\IEAdvpack.dll 2012-11-16 09:33 . 2012-11-16 09:33 111616 —-a-w- c:\windows\system32\iesysprep.dll 2012-11-16 09:33 . 2012-11-16 09:33 10752 —-a-w- c:\windows\system32\msfeedssync.exe 2012-11-16 09:33 . 2012-11-16 09:33 85504 —-a-w- c:\windows\system32\iesetup.dll 2012-11-16 09:33 . 2012-11-16 09:33 403248 —-a-w- c:\windows\system32\iedkcs32.dll 2012-11-16 09:33 . 2012-11-16 09:33 30720 —-a-w- c:\windows\system32\licmgr10.dll 2012-11-16 09:33 . 2012-11-16 09:33 249344 —-a-w- c:\windows\system32\webcheck.dll 2012-11-16 09:33 . 2012-11-16 09:33 165888 —-a-w- c:\windows\system32\iexpress.exe 2012-11-16 09:33 . 2012-11-16 09:33 160256 —-a-w- c:\windows\system32\wextract.exe 2012-11-16 09:33 . 2012-11-16 09:33 103936 —-a-w- c:\windows\system32\inseng.dll 2012-11-14 07:06 . 2012-12-12 11:15 17811968 —-a-w- c:\windows\system32\mshtml.dll 2012-11-14 06:32 . 2012-12-12 11:15 10925568 —-a-w- c:\windows\system32\ieframe.dll 2012-11-14 06:11 . 2012-12-12 11:15 2312704 —-a-w- c:\windows\system32\jscript9.dll 2012-11-14 06:04 . 2012-12-12 11:15 1346048 —-a-w- c:\windows\system32\urlmon.dll 2012-11-14 06:04 . 2012-12-12 11:15 1392128 —-a-w- c:\windows\system32\wininet.dll 2012-11-14 06:02 . 2012-12-12 11:15 1494528 —-a-w- c:\windows\system32\inetcpl.cpl 2012-11-14 06:02 . 2012-12-12 11:15 237056 —-a-w- c:\windows\system32\url.dll 2012-11-14 05:59 . 2012-12-12 11:15 85504 —-a-w- c:\windows\system32\jsproxy.dll 2012-11-14 05:58 . 2012-12-12 11:15 816640 —-a-w- c:\windows\system32\jscript.dll 2012-11-14 05:57 . 2012-12-12 11:15 599040 —-a-w- c:\windows\system32\vbscript.dll 2012-11-14 05:57 . 2012-12-12 11:15 173056 —-a-w- c:\windows\system32\ieUnatt.exe 2012-11-14 05:55 . 2012-12-12 11:15 2144768 —-a-w- c:\windows\system32\iertutil.dll 2012-11-14 05:55 . 2012-12-12 11:15 729088 —-a-w- c:\windows\system32\msfeeds.dll 2012-11-14 05:53 . 2012-12-12 11:15 96768 —-a-w- c:\windows\system32\mshtmled.dll 2012-11-14 05:52 . 2012-12-12 11:15 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-11-14 05:46 . 2012-12-12 11:15 248320 —-a-w- c:\windows\system32\ieui.dll 2012-11-14 02:09 . 2012-12-12 11:15 1800704 —-a-w- c:\windows\SysWow64\jscript9.dll 2012-11-14 01:58 . 2012-12-12 11:15 1427968 —-a-w- c:\windows\SysWow64\inetcpl.cpl 2012-11-14 01:57 . 2012-12-12 11:15 1129472 —-a-w- c:\windows\SysWow64\wininet.dll 2012-11-14 01:49 . 2012-12-12 11:15 142848 —-a-w- c:\windows\SysWow64\ieUnatt.exe 2012-11-14 01:48 . 2012-12-12 11:15 420864 —-a-w- c:\windows\SysWow64\vbscript.dll 2012-11-14 01:44 . 2012-12-12 11:15 2382848 —-a-w- c:\windows\SysWow64\mshtml.tlb 2012-11-09 05:45 . 2012-12-12 09:45 2048 —-a-w- c:\windows\system32\tzres.dll 2012-11-09 04:42 . 2012-12-12 09:45 2048 —-a-w- c:\windows\SysWow64\tzres.dll 2012-11-02 05:59 . 2012-12-12 09:45 478208 —-a-w- c:\windows\system32\dpnet.dll 2012-11-02 05:11 . 2012-12-12 09:45 376832 —-a-w- c:\windows\SysWow64\dpnet.dll 2006-05-03 09:06 163328 –sh–r- c:\windows\SysWOW64\flvDX.dll 2007-02-21 10:47 31232 –sh–r- c:\windows\SysWOW64\msfDX.dll 2008-03-16 12:30 216064 –sh–r- c:\windows\SysWOW64\nbDX.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-11-24 39408] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2012-07-13 17420464] "Plex Media Server"="c:\program files (x86)\Plex\Plex Media Server\Plex Media Server.exe" [2012-11-20 3781864] "NokiaSuite.exe"="c:\program files (x86)\Nokia\Nokia Suite\NokiaSuite.exe" [2012-10-13 1088424] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "LoadFUJ02E3"="c:\program files (x86)\Fujitsu\FUJ02E3\FUJ02E3.exe" [2009-06-16 36712] "IndicatorUtility"="c:\program files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe" [2009-10-09 47976] "snp2uvc"="c:\windows\vsnp2uvc.exe" [2009-08-12 662016] "UCam_Menu"="c:\program files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504] "YouCam Mirror Tray icon"="c:\program files (x86)\CyberLink\YouCam\YouCamTray.exe" [2009-07-08 162912] "Sophos AutoUpdate Monitor"="c:\program files (x86)\Sophos\AutoUpdate\almon.exe" [2012-07-06 900160] "BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "Cisco AnyConnect Secure Mobility Agent for Windows"="c:\program files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe" [2011-09-09 523216] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-12-19 41208] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352] "ConnectionCenter"="c:\program files (x86)\Citrix\ICA Client\concentr.exe" [2009-09-12 103768] "InstaLAN"="c:\program files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe" [2011-05-27 2015136] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-09-17 254896] . c:\users\Simon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\startup\ BBC iPlayer Desktop.lnk - c:\program files (x86)\BBC iPlayer Desktop\BBC iPlayer Desktop.exe [2012-7-10 142336] MagicDisc.lnk - c:\program files (x86)\MagicDisc\MagicDisc.exe [2012-10-16 576000] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ LaunchCenter.lnk - c:\program files (x86)\Fujitsu\LaunchCenter\DelayLC.exe [2010-5-11 22528] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{569DAC0F-2791-46ab-8EFC-A54B77C04C20}"= "c:\program files (x86)\DVD Ghost\ExecuteHooker.dll" [2005-11-14 90112] . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) "AppInit_DLLs"=c:\progra~2\DVDGHO~1\DVDGhostAppInit.dll c:\progra~2\Sophos\SOPHOS~1\sophos_detoured.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService] @="service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SophosAntiVirus] "DisableMonitoring"=dword:00000001 . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944] R2 swi_update_64;Sophos Web Intelligence Update;c:\programdata\Sophos\Web Intelligence\swi_update_64.exe [2012-11-12 1998400] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-09-22 225280] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-11-28 1255736] R4 SophosBootDriver;SophosBootDriver;c:\windows\system32\DRIVERS\SophosBootDriver.sys [2011-10-23 25608] S0 FJGSDisk;G-Sensor Application Filter Driver;c:\windows\system32\DRIVERS\FJGSDisk.sys [2011-11-25 14696] S1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\DRIVERS\ctxusbm.sys [2009-09-08 87600] S1 SAVOnAccess;SAVOnAccess;c:\windows\system32\DRIVERS\savonaccess.sys [2012-06-15 144672] S2 ATService;AuthenTec Fingerprint Service;c:\program files\Fingerprint Sensor\ATService.exe [2009-07-31 2688248] S2 Belkin Local Backup Service;Belkin Local Backup Service;c:\program files\Belkin\Belkin USB Print and Storage Center\BkBackupScheduler.exe [2011-04-19 181760] S2 Belkin Network USB Helper;Belkin Network USB Helper;c:\program files\Belkin\Belkin USB Print and Storage Center\Bkapcs.exe [2010-02-09 55296] S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-14 398184] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-14 682344] S2 PowerSavingUtilityService;PowerSavingUtilityService;c:\program files\Fujitsu\PSUtility\PSUService.exe [2009-07-30 63336] S2 QDLService2kSierra;Qualcomm Gobi 2000 Download Service (Sierra);c:\program files (x86)\QUALCOMM\QDLService2k\QDLService2kSierra.exe [2009-10-01 329976] S2 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe [2012-11-12 216640] S2 SAVService;Sophos Anti-Virus;c:\program files (x86)\Sophos\Sophos Anti-Virus\SavService.exe [2012-06-15 139840] S2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-12-13 3290896] S2 swi_service;Sophos Web Intelligence Service;c:\program files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [2012-11-12 2869824] S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2009-11-01 2314240] S2 vpnagent;Cisco AnyConnect Secure Mobility Agent;c:\program files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe [2011-09-09 475088] S2 WirelessSelectorService;WirelessSelectorService;c:\program files\Fujitsu\WirelessSelector\WSUService.exe [2009-07-21 62312] S2 WTGService;WTGService;c:\program files (x86)\OneClickInternet\WTGService.exe [2009-11-27 312784] S3 acsock;acsock;c:\windows\system32\DRIVERS\acsock64.sys [2011-09-09 106408] S3 ATSwpWDF;AuthenTec TruePrint USB WDF Driver;c:\windows\system32\Drivers\ATSwpWDF.sys [2009-08-01 734720] S3 BthAvrcp;Bluetooth AVRCP Profile;c:\windows\system32\DRIVERS\BthAvrcp.sys [2009-08-13 29184] S3 e1kexpress;Intel® PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\DRIVERS\e1k62x64.sys [2009-11-01 283824] S3 FUJ02E3;Fujitsu FUJ02E3 Device Driver;c:\windows\system32\DRIVERS\FUJ02E3.sys [2006-11-01 7296] S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-11-01 56344] S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [2009-10-26 151936] S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2009-11-27 244736] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-12-14 24176] S3 NETw5s64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys [2009-11-01 6952960] S3 qcfiltersra2k;Gobi 2000 USB Composite Device Filter Driver(1199-9001);c:\windows\system32\DRIVERS\qcfiltersra2k.sys [2009-10-01 6400] S3 qcusbnetsra2k;Gobi 2000 USB-NDIS miniport(1199-9001);c:\windows\system32\DRIVERS\qcusbnetsra2k.sys [2009-10-01 235008] S3 qcusbsersra2k;Gobi 2000 USB Device for Legacy Serial Communication(1199-9001);c:\windows\system32\DRIVERS\qcusbsersra2k.sys [2009-10-01 121216] S3 sxuptp;SXUPTP Driver;c:\windows\system32\DRIVERS\sxuptp.sys [2009-06-22 291352] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-01-13 21:53 1606760 —-a-w- c:\program files (x86)\Google\Chrome\Application\24.0.1312.52\Installer\setup.exe . Contents of the 'Scheduled Tasks' folder . 2013-01-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-11-24 21:06] . 2013-01-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-11-24 21:06] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ATSwpNav"="c:\program files\Fingerprint Sensor\ATSwpNav -run" [X] "Apoint"="c:\program files\Apoint2K\Apoint.exe" [2009-10-16 323072] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-01-12 166424] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-01-12 390680] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-01-12 410136] "SSUtility"="c:\program files\Fujitsu\SSUtility\FJSSDMN.exe" [2009-07-22 282984] "PSUTility"="c:\program files\Fujitsu\PSUtility\TrayManager.exe" [2009-07-30 188264] "FDM7"="c:\program files\Fujitsu\FDM7\FdmDaemon.exe" [2009-10-27 164712] "LoadFujitsuQuickTouch"="c:\program files\Fujitsu\Application Panel\QuickTouch.exe" [2009-10-15 157544] "LoadBtnHnd"="c:\program files\Fujitsu\Application Panel\BtnHnd.exe" [2009-10-15 35176] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-08-05 8060960] "snp2uvc"="c:\windows\vsnp2uvc.exe" [2009-08-12 662016] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=c:\progra~2\Sophos\SOPHOS~1\sophos_detoured_x64.dll . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://ts.fujitsu.com mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105 LSP: c:\programdata\Sophos\Web Intelligence\swi_ifslsp.dll Trusted Zone: ucl.ac.uk\vpn TCP: DhcpNameServer = 192.168.2.1 DPF: {CC679CB8-DC4B-458B-B817-D447B3B6AC31} - hxxps://vpn.ucl.ac.uk/CACHE/stc/21/binaries/vpnweb.cab DPF: {E34F52FE-7769-46CE-8F8B-5E8ABAD2E9FC} - hxxps://vpn.ucl.ac.uk/CACHE/sdesktop/install/binaries/instweb.cab . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Toolbar-Locked - (no file) . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_110_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_110_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_110_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_110_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_110.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_110.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_110.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_110.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Nico Mak Computing\WinZip] "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe c:\program files (x86)\Bonjour\mDNSResponder.exe c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe c:\program files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe c:\program files (x86)\Sophos\AutoUpdate\ALsvc.exe c:\program files (x86)\Fujitsu\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe . ************************************************************************** . Completion time: 2013-01-16 11:50:28 - machine was rebooted ComboFix-quarantined-files.txt 2013-01-16 11:50 . Pre-Run: 215,782,957,056 bytes free Post-Run: 220,351,217,664 bytes free . - - End Of File - - D54DE444913DE85473935B6E90DC3555 Thanks again for your help Simon
Hi simonjeaton;)

Could you tell me a bit more about what you've found on my computer?

Your machine had some malware which has been removed. Let's continue and hopefully we will be able to optimize the performance of your machine.
—————————————–

Go to My Computer-> Tools-> Folder Options-> View tab:
  • Under the Hidden files and folders heading:
  • Select - Show hidden files and folders.
  • Uncheck- Hide protected operating system files (recommended) option.
  • Also, make sure there is no checkmark beside Hide file extensions for known file types.
  • Click OK. (Remember to Hide files and folders once done)


Please go to: VirusTotal
  • [external image: Posted Image]
  • Click the Browse button and search for the following file:

    c:\programdata\boost_interprocess\20130116110231.109999

  • Click Open
  • Then click Send File
  • Please be patient while the file is scanned.
  • Once the scan results appear, please provide them in your next reply.
If it says already scanned – click "reanalyze now"

Repeat for the following files

c:\programdata\boost_interprocess\20130116110231.109999\9334581e-7251-4ef7-a8ec-5bfe8e89ff68
c:\programdata\boost_interprocess\20130116110231.109999\plex_frame_mutex
c:\users\Simon\AppData\Local\Microsoft\Windows\Temporary Internet Files\{11795A45-B9EA-4164-8ED1-1C31CE73974F}.xps
c:\users\Simon\AppData\Local\Microsoft\Windows\Temporary Internet Files\{54136635-B8AC-4C80-815D-E16C22D9BEF4}.xps
c:\users\Simon\AppData\Local\Microsoft\Windows\Temporary Internet Files\{73054D8C-2DC4-4007-ACB0-A62366360C93}.xps
c:\users\Simon\AppData\Local\Microsoft\Windows\Temporary Internet Files\{D77CD482-E95E-413A-9FC3-49CA6B6B63BF}.xps
c:\users\Simon\AppData\Local\Temp\1.tmp\F_IN_BOX.dll
c:\users\Simon\AppData\Local\Temp\7zS470B\HPSLPSVC64.DLL
c:\windows\SysWow64\AVSredirect.dll


Please post the results in your next reply

=============================== Next =======================================



[external image: Posted Image] Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.


=============================== Next =======================================



Run OTL

  • Open OTL again and click the Quick Scan button (don't check the boxes beside LOP Check or Purity this time)
  • Post the OTL.txt log it produces in your next reply.


Please let me know how your pc is running and if there are any outstanding issues

On your next reply please post :
  • JRT log
  • OTL txt

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Hi Robybel,
this mostly went fine, except for a few problems with Virus Total; of the files you asked me to scan:

c:\programdata\boost_interprocess\20130116110231.109999
c:\users\Simon\AppData\Local\Temp\7zS470B\HPSLPSVC64.DLL
c:\windows\SysWow64\AVSredirect.dll
were not present (although c:\programdata\boost_interprocess\20130116110231.109999 is present as a folder only).

and I was not allowed access to the folder c:\users\Simon\AppData\Local\Microsoft\Windows\Temporary Internet Files from the Virus Scan Homepage
(although I can access the folder from an explorer window). I didn't want to copy them to the desktop or elsewhere in order to scan them, just in case.

so did not scan:
c:\users\Simon\AppData\Local\Microsoft\Windows\Temporary Internet Files\{11795A45-B9EA-4164-8ED1-1C31CE73974F}.xps
c:\users\Simon\AppData\Local\Microsoft\Windows\Temporary Internet Files\{54136635-B8AC-4C80-815D-E16C22D9BEF4}.xps
c:\users\Simon\AppData\Local\Microsoft\Windows\Temporary Internet Files\{73054D8C-2DC4-4007-ACB0-A62366360C93}.xps
c:\users\Simon\AppData\Local\Microsoft\Windows\Temporary Internet Files\{D77CD482-E95E-413A-9FC3-49CA6B6B63BF}.xps

Happy to try these again if you know how to get access to them.

Here are the results from the ones I could scan (only showing the Virus Engine when a positive has been found):

9334581e-7251-4ef7-a8ec-5bfe8e89ff68

SHA256: 0db201e8371010e5cd3b719cf6c131cea86e18ef7c5bdd394e23b352b8e54f9e
SHA1: 3101dd90ca740f799946b28e93662e644afcb518
MD5: 9c804b88b57028563115f330887de329
File size: 12 bytes ( 12 bytes )
File name: 9334581e-7251-4ef7-a8ec-5bfe8e89ff68
File type: unknown
Detection ratio: 0 / 45
Analysis date: 2013-01-17 17:05:17 UTC ( 1 minute ago )
00
Less details
Analysis
Comments
Votes
Additional information
Antivirus Result Update
Agnitum - 20130117
AhnLab-V3 - 20130117
AntiVir - 20130117
Antiy-AVL - 20130117
Avast - 20130117
AVG - 20130117
BitDefender - 20130117
ByteHero - 20130117
CAT-QuickHeal - 20130117
ClamAV - 20130117
Commtouch - 20130117
Comodo - 20130117
Emsisoft - 20130117
eSafe - 20130116
ESET-NOD32 - 20130117
F-Prot - 20130117
F-Secure - 20130117
Fortinet - 20130117
GData - 20130117
Ikarus - 20130117
Jiangmin - 20121221
K7AntiVirus - 20130117
Kaspersky - 20130117
Kingsoft - 20130115
Malwarebytes - 20130117
McAfee - 20130117
McAfee-GW-Edition - 20130117
Microsoft - 20130117
MicroWorld-eScan - 20130117
NANO-Antivirus - 20130117
Norman - 20130117
nProtect - 20130117
Panda - 20130117
PCTools - 20130117
Rising - 20130117
Sophos - 20130117
SUPERAntiSpyware - 20130117
Symantec - 20130117
TheHacker - 20130117
TotalDefense - 20130117
TrendMicro - 20130117
TrendMicro-HouseCall - 20130117
VBA32 - 20130117
VIPRE - 20130117
ViRobot - 20130117


SHA256:

f148ee984ca98aa97bc8d5a11a51bb18618e9a2dc0ec9e76e856a5a3ac508def
File name:
F-IN-BOX DLL Edition
Detection ratio:
0 / 46
Analysis date:
2013-01-17 17:27:48 UTC ( 0 minutes ago )


SHA256:
b76875c50ef704dbbf7f02c982445971d1bbd61aebe2e4b28ddc58a1d66317d5
File name:
plex_frame_mutex
Detection ratio:
1 / 46
Analysis date:

2013-01-17 17:15:41 UTC ( 23 minutes ago )
eSafe Win32.Trojan 20130116

Now JRT:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.4.3 (01.15.2013:1)
OS: Windows 7 Professional x64
Ran by [removed] on 17/01/2013 at 17:48:43.78
Blog: http://thisisudax.blogspot.com
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders

Failed to delete: [Folder] "C:\ProgramData\boost_interprocess"



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 17/01/2013 at 18:00:05.54
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


And the repeat of OTL……

OTL logfile created on: 1/17/2013 6:05:02 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Simon\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.80 Gb Total Physical Memory | 1.83 Gb Available Physical Memory | 48.18% Memory free
7.60 Gb Paging File | 5.05 Gb Available in Paging File | 66.41% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 296.08 Gb Total Space | 204.99 Gb Free Space | 69.23% Space Free | Partition Type: NTFS
Drive H: | 1.90 Gb Total Space | 0.02 Gb Free Space | 0.93% Space Free | Partition Type: FAT32

Computer Name: SIMON-LAPTOP | User Name: Simon | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Simon\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
PRC - C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe ()
PRC - C:\Program Files (x86)\Plex\Plex Media Server\PlexDlnaServer.exe (Plex, Inc.)
PRC - C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe (Plex, Inc.)
PRC - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe (Sophos Limited)
PRC - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe (Sophos Limited)
PRC - C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe (Nokia)
PRC - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe (Nokia)
PRC - C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe (Nokia)
PRC - C:\Program Files (x86)\BBC iPlayer Desktop\BBC iPlayer Desktop.exe ()
PRC - C:\ProgramData\Sophos\AutoUpdate\Cache\sophos_autoupdate1.dir\ALUpdate.exe (Sophos Limited)
PRC - C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe (Sophos Limited)
PRC - C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe (Sophos Limited)
PRC - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe (Sophos Limited)
PRC - C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (Cisco Systems, Inc.)
PRC - C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe (Affinegy, Inc.)
PRC - C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe (Affinegy, Inc.)
PRC - C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe (Affinegy, Inc.)
PRC - C:\Program Files (x86)\Belkin\Router Setup and Monitor\dlnaPlugin.exe (Affinegy, Inc.)
PRC - C:\Program Files (x86)\OneClickInternet\WTGService.exe ()
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe (FUJITSU LIMITED)
PRC - C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kSierra.exe (QUALCOMM, Inc.)
PRC - C:\Program Files (x86)\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
PRC - C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe (Citrix Systems, Inc.)
PRC - C:\Windows\vsnp2uvc.exe (Sonix)
PRC - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
PRC - C:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Fujitsu\FUJ02E3\FUJ02E3.exe (FUJITSU LIMITED)
PRC - C:\Program Files (x86)\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
PRC - C:\Program Files (x86)\Fujitsu\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe (Fujitsu Technology Solutions)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\ppgooglenaclpluginchrome.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\PepperFlash\pepflashplayer.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\pdf.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\libglesv2.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\libegl.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\ffmpegsumo.dll ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\Exts\simplejson\_speedups.pyd ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\Exts\OpenSSL\SSL.pyd ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\Exts\OpenSSL\rand.pyd ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\Exts\OpenSSL\crypto.pyd ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\Exts\lxml\etree.pyd ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\Exts\lxml\objectify.pyd ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\DLLs\_ssl.pyd ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\DLLs\_socket.pyd ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\DLLs\_multiprocessing.pyd ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\DLLs\_hashlib.pyd ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\DLLs\_ctypes.pyd ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\DLLs\unicodedata.pyd ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\DLLs\select.pyd ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\DLLs\pyexpat.pyd ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\zlib1.dll ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\WebKit.dll ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\tag.dll ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\swscale-0.dll ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\sqlite3.dll ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\soci_sqlite3-vc80-3_0.dll ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\soci_core-vc80-3_0.dll ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\libxslt.dll ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\libxml2.dll ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\libexslt.dll ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\JavaScriptCore.dll ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\CFLite.dll ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\cairo.dll ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\avutil-50.dll ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\avformat-52.dll ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\avcodec-52.dll ()
MOD - C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\phonon4.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\qjson.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\QtXmlPatterns4.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\QtXml4.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\QtWebKit4.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\QtScript4.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\QtSql4.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\QtNetwork4.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\QtOpenGL4.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\QtGui4.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\QtMultimediaKit1.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\QtDeclarative4.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\QtCore4.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\sqldrivers\qsqlite4.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\Imageformats\qjpeg4.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\Imageformats\qico4.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\Imageformats\qgif4.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\NService.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\CommonUpdateChecker.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\ssoengine.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\securestorage.dll ()
MOD - C:\Program Files (x86)\Nokia\Nokia Suite\mediaservice\dsengine.dll ()
MOD - C:\Program Files (x86)\BBC iPlayer Desktop\BBC iPlayer Desktop.exe ()
MOD - C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinServicePS.dll ()
MOD - C:\Program Files (x86)\Belkin\Router Setup and Monitor\gateways\GenericBelkinGatewayLOC.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
MOD - C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtGui4.dll ()
MOD - C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtXml4.dll ()
MOD - C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtCore4.dll ()
MOD - C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtNetwork4.dll ()
MOD - C:\Program Files (x86)\Belkin\Router Setup and Monitor\imageformats\qjpeg4.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (Belkin Local Backup Service) – C:\Program Files\Belkin\Belkin USB Print and Storage Center\BkBackupScheduler.exe ()
SRV:64bit: - (Belkin Network USB Helper) – C:\Program Files\Belkin\Belkin USB Print and Storage Center\Bkapcs.exe ()
SRV:64bit: - (ATService) – C:\Program Files\Fingerprint Sensor\ATService.exe (AuthenTec, Inc.)
SRV:64bit: - (PowerSavingUtilityService) – C:\Program Files\Fujitsu\PSUtility\PSUService.exe (FUJITSU LIMITED)
SRV:64bit: - (WirelessSelectorService) – C:\Program Files\Fujitsu\WirelessSelector\WSUService.exe ()
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (Skype C2C Service) – C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
SRV - (swi_service) – C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe (Sophos Limited)
SRV - (swi_update_64) – C:\ProgramData\Sophos\Web Intelligence\swi_update_64.exe (Sophos Limited)
SRV - (SAVAdminService) – C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe (Sophos Limited)
SRV - (ServiceLayer) – C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (Sophos AutoUpdate Service) – C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe (Sophos Limited)
SRV - (SAVService) – C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe (Sophos Limited)
SRV - (vpnagent) – C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (Cisco Systems, Inc.)
SRV - (AffinegyService) – C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe (Affinegy, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (WTGService) – C:\Program Files (x86)\OneClickInternet\WTGService.exe ()
SRV - (UNS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (QDLService2kSierra) – C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kSierra.exe (QUALCOMM, Inc.)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (TestHandler) – C:\Program Files (x86)\Fujitsu\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe (Fujitsu Technology Solutions)


========== Driver Services (SafeList) ==========

DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (pccsmcfd) – C:\Windows\SysNative\drivers\pccsmcfdx64.sys (Nokia)
DRV:64bit: - (SAVOnAccess) – C:\Windows\SysNative\drivers\savonaccess.sys (Sophos Limited)
DRV:64bit: - (nmwcdc) – C:\Windows\SysNative\drivers\ccdcmbox64.sys (Nokia)
DRV:64bit: - (nmwcd) – C:\Windows\SysNative\drivers\ccdcmbx64.sys (Nokia)
DRV:64bit: - (UsbserFilt) – C:\Windows\SysNative\drivers\usbser_lowerfltjx64.sys (Nokia)
DRV:64bit: - (upperdev) – C:\Windows\SysNative\drivers\usbser_lowerfltx64.sys (Nokia)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (FJGSDisk) – C:\Windows\SysNative\drivers\FJGSDisk.sys (FUJITSU LIMITED)
DRV:64bit: - (SophosBootDriver) – C:\Windows\SysNative\drivers\SophosBootDriver.sys (Sophos Plc)
DRV:64bit: - (vpnva) – C:\Windows\SysNative\drivers\vpnva64.sys (Cisco Systems, Inc.)
DRV:64bit: - (acsock) – C:\Windows\SysNative\drivers\acsock64.sys (Cisco Systems, Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (usbser) – C:\Windows\SysNative\drivers\usbser.sys (Microsoft Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) – C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (NETw5s64) – C:\Windows\SysNative\drivers\NETw5s64.sys (Intel Corporation)
DRV:64bit: - (e1kexpress) – C:\Windows\SysNative\drivers\e1k62x64.sys (Intel Corporation)
DRV:64bit: - (HECIx64) – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (Impcd) – C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (qcusbnetsra2k) – C:\Windows\SysNative\drivers\qcusbnetsra2k.sys (QUALCOMM Incorporated)
DRV:64bit: - (qcusbsersra2k) – C:\Windows\SysNative\drivers\qcusbsersra2k.sys (QUALCOMM Incorporated)
DRV:64bit: - (qcfiltersra2k) – C:\Windows\SysNative\drivers\qcfiltersra2k.sys (QUALCOMM Incorporated)
DRV:64bit: - (ApfiltrService) – C:\Windows\SysNative\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (ctxusbm) – C:\Windows\SysNative\drivers\ctxusbm.sys (Citrix Systems, Inc.)
DRV:64bit: - (SNP2UVC) – C:\Windows\SysNative\drivers\snp2uvc.sys ()
DRV:64bit: - (BthAvrcp) – C:\Windows\SysNative\drivers\BthAvrcp.sys (CSR, plc)
DRV:64bit: - (ATSwpWDF) – C:\Windows\SysNative\drivers\ATSwpWDF.sys (AuthenTec, Inc.)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (TPM) – C:\Windows\SysNative\drivers\tpm.sys (Microsoft Corporation)
DRV:64bit: - (sxuptp) – C:\Windows\SysNative\drivers\sxuptp.sys (silex technology, Inc.)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (mcdbus) – C:\Windows\SysNative\drivers\mcdbus.sys (MagicISO, Inc.)
DRV:64bit: - (FUJ02E3) – C:\Windows\SysNative\drivers\fuj02e3.sys (FUJITSU LIMITED)
DRV:64bit: - (FUJ02B1) – C:\Windows\SysNative\drivers\fuj02b1.sys (FUJITSU LIMITED)
DRV - (RSUSBSTOR) – C:\Windows\SysWOW64\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (mcdbus) – C:\Windows\SysWOW64\drivers\mcdbus.sys (MagicISO, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{1CC2B0B6-D56C-4D2C-BE3D-8AF2CD509512}: "URL" = http://www.google.com/search?q={searchTerm…amp;rlz=1I7FTSF
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{E7BAA1CF-0555-4603-8C61-4F4E8EFAAA17}: "URL" = http://www.google.com/search?q={searchTerm…amp;rlz=1I7FTSF

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.google.com/ig/redirectd [Binary data over 200 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ts.fujitsu.com
IE - HKCU\..\SearchScopes,DefaultScope = {E7BAA1CF-0555-4603-8C61-4F4E8EFAAA17}
IE - HKCU\..\SearchScopes\{E7BAA1CF-0555-4603-8C61-4F4E8EFAAA17}: "URL" = http://www.google.com/search?q={searchTerm…SF_enGB459GB461
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_37: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nokia.com/EnablerPlugin: C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)



========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}&sugkey;={google:suggestAPIKeyParameter}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 6 U37 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Nokia Suite Enabler Plugin (Enabled) = C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Java Deployment Toolkit 6.0.370.6 (Enabled) = C:\Windows\SysWOW64\npdeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: Google Drive = C:\Users\Simon\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\Simon\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\Simon\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Gmail = C:\Users\Simon\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2013/01/16 11:36:39 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [ATSwpNav] C:\Program Files\Fingerprint Sensor\ATSwpNav.exe (AuthenTec, Inc.)
O4:64bit: - HKLM..\Run: [FDM7] C:\Program Files\Fujitsu\FDM7\FdmDaemon.exe (FUJITSU LIMITED)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [LoadBtnHnd] C:\Program Files\Fujitsu\Application Panel\BtnHnd.exe (FUJITSU LIMITED)
O4:64bit: - HKLM..\Run: [LoadFujitsuQuickTouch] C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe (FUJITSU LIMITED)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [PSUTility] C:\Program Files\Fujitsu\PSUtility\TrayManager.exe (FUJITSU LIMITED)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [snp2uvc] C:\Windows\vsnp2uvc.exe (Sonix)
O4:64bit: - HKLM..\Run: [SSUtility] C:\Program Files\Fujitsu\SSUtility\FJSSDMN.exe (FUJITSU LIMITED)
O4 - HKLM..\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [ConnectionCenter] C:\Program Files (x86)\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [IndicatorUtility] C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe (FUJITSU LIMITED)
O4 - HKLM..\Run: [InstaLAN] C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe (Affinegy, Inc.)
O4 - HKLM..\Run: [LoadFUJ02E3] C:\Program Files (x86)\Fujitsu\FUJ02E3\FUJ02E3.exe (FUJITSU LIMITED)
O4 - HKLM..\Run: [snp2uvc] C:\Windows\vsnp2uvc.exe (Sonix)
O4 - HKLM..\Run: [Sophos AutoUpdate Monitor] C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe (Sophos Limited)
O4 - HKLM..\Run: [YouCam Mirror Tray icon] C:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exe (CyberLink Corp.)
O4 - HKCU..\Run: [NokiaSuite.exe] C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe (Nokia)
O4 - HKCU..\Run: [Plex Media Server] C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe (Plex, Inc.)
O4 - Startup: C:\Users\Simon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\BBC iPlayer Desktop.lnk = C:\Program Files (x86)\BBC iPlayer Desktop\BBC iPlayer Desktop.exe ()
O4 - Startup: C:\Users\Simon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk = C:\Program Files (x86)\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000020 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: ucl.ac.uk ([vpn] https in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CC679CB8-DC4B-458B-B817-D447B3B6AC31} https://vpn.ucl.ac.uk/CACHE/stc/21/binaries/vpnweb.cab (Cisco AnyConnect Secure Mobility Client Web Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E34F52FE-7769-46CE-8F8B-5E8ABAD2E9FC} https://vpn.ucl.ac.uk/CACHE/sdesktop/instal…ies/instweb.cab (CSD ActiveX Installer)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{671820B3-06AF-449D-A846-90672F1F700D}: DhcpNameServer = 4.2.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8673924F-90CB-4353-9F01-303ACA8A02A3}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\Sophos\SOPHOS~1\sophos_detoured_x64.dll) - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\sophos_detoured_x64.dll (Sophos Limited)
O20 - AppInit_DLLs: (C:\PROGRA~2\DVDGHO~1\DVDGhostAppInit.dll) - C:\Program Files (x86)\DVD Ghost\DVDGhostAppInit.dll (BlazeVideo, Inc.)
O20 - AppInit_DLLs: (C:\PROGRA~2\Sophos\SOPHOS~1\sophos_detoured.dll) - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\sophos_detoured.dll (Sophos Limited)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {569DAC0F-2791-46ab-8EFC-A54B77C04C20} - C:\Program Files (x86)\DVD Ghost\ExecuteHooker.dll (WWW.Region-Free-DVD.COM)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/07/01 14:56:58 | 000,000,051 | —- | M] () - H:\autorun.0nf – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/01/17 17:48:32 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/01/17 17:48:10 | 000,000,000 | —D | C] – C:\JRT
[2013/01/17 17:46:47 | 000,000,000 | —D | C] – C:\Users\Simon\AppData\Local\Sophos
[2013/01/16 11:36:46 | 000,000,000 | —D | C] – C:\$RECYCLE.BIN
[2013/01/16 11:14:44 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2013/01/16 11:14:43 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2013/01/16 11:14:42 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2013/01/16 11:14:23 | 000,000,000 | —D | C] – C:\Qoobox
[2013/01/16 11:13:51 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2013/01/16 11:06:33 | 005,022,206 | R— | C] (Swearware) – C:\Users\Simon\Desktop\ComboFix.exe
[2013/01/16 11:03:44 | 000,000,000 | —D | C] – C:\ProgramData\boost_interprocess
[2013/01/14 13:59:50 | 000,000,000 | —D | C] – C:\Config.Msi
[2013/01/13 22:17:05 | 000,000,000 | —D | C] – C:\Users\Simon\AppData\Local\WinZip
[2013/01/13 21:34:50 | 004,732,416 | —- | C] (AVAST Software) – C:\Users\Simon\Desktop\aswMBR.exe
[2013/01/13 21:34:33 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Simon\Desktop\OTL.exe
[2013/01/10 21:49:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2013/01/10 21:26:18 | 000,000,000 | —D | C] – C:\Users\Simon\AppData\Roaming\Malwarebytes
[2013/01/10 21:24:04 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/01/10 21:24:03 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/01/10 21:24:02 | 000,024,176 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2013/01/10 21:24:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/01/10 21:23:29 | 000,000,000 | —D | C] – C:\Users\Simon\AppData\Local\Programs
[2013/01/08 22:59:42 | 000,000,000 | —D | C] – C:\Users\Simon\Desktop\Dukto
[2013/01/08 22:56:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\Dukto
[2012/12/27 11:31:06 | 000,719,872 | —- | C] (Abysmal Software) – C:\Windows\SysWow64\devil.dll
[2012/12/27 11:31:06 | 000,719,872 | —- | C] (Abysmal Software) – C:\Windows\SysWow64\devil.dll
[2012/12/27 11:31:05 | 000,369,152 | —- | C] (The Public) – C:\Windows\SysWow64\avisynth.dll
[2012/12/27 11:31:02 | 000,070,656 | —- | C] (www.helixcommunity.org) – C:\Windows\SysWow64\yv12vfw.dll
[2012/12/27 11:31:02 | 000,070,656 | —- | C] (www.helixcommunity.org) – C:\Windows\SysWow64\i420vfw.dll
[2012/12/27 11:31:02 | 000,070,656 | —- | C] (www.helixcommunity.org) – C:\Windows\SysWow64\i420vfw.dll
[2012/12/27 11:30:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\AviSynth 2.5
[2012/12/27 11:29:14 | 000,278,528 | —- | C] (Real Networks, Inc) – C:\Windows\SysWow64\pncrt.dll
[2012/12/27 11:29:14 | 000,216,064 | RHS- | C] (MONOGRAM Multimedia, s.r.o.) – C:\Windows\SysWow64\nbDX.dll
[2012/12/27 11:29:14 | 000,186,880 | RHS- | C] (RadLight) – C:\Windows\SysWow64\RLOgg.ax
[2012/12/27 11:29:14 | 000,161,792 | RHS- | C] (Gabest) – C:\Windows\SysWow64\RealMediaDX.ax
[2012/12/27 11:29:14 | 000,092,672 | RHS- | C] (RadLight) – C:\Windows\SysWow64\RLVorbisDec.ax
[2012/12/27 11:29:14 | 000,090,112 | RHS- | C] (-) – C:\Windows\SysWow64\TTADSSplitter.ax
[2012/12/27 11:29:14 | 000,090,112 | RHS- | C] (-) – C:\Windows\SysWow64\TTADSDecoder.ax
[2012/12/27 11:29:14 | 000,067,584 | RHS- | C] (RadLight, LLC) – C:\Windows\SysWow64\RLTheoraDec.ax
[2012/12/27 11:29:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPER © Version 2010.bld.38 (May 2, 2010)
[2012/12/27 11:29:13 | 000,169,472 | RHS- | C] (Gabest) – C:\Windows\SysWow64\MatroskaDX.ax
[2012/12/27 11:29:13 | 000,163,328 | RHS- | C] (Gabest) – C:\Windows\SysWow64\flvDX.dll
[2012/12/27 11:29:13 | 000,031,232 | RHS- | C] (Hans Mayerl) – C:\Windows\SysWow64\msfDX.dll
[2012/12/27 11:29:12 | 000,179,200 | RHS- | C] (Gabest) – C:\Windows\SysWow64\DiracSplitter.ax
[2012/12/27 11:29:12 | 000,123,904 | RHS- | C] (CoreCodec) – C:\Windows\SysWow64\AVCDX.ax
[2012/12/27 11:29:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\eRightSoft
[2012/12/24 17:39:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
[2012/12/24 17:38:47 | 000,000,000 | —D | C] – C:\Users\Simon\Documents\Add-in Express
[2012/12/24 17:38:40 | 000,000,000 | —D | C] – C:\ProgramData\WinZip
[2012/12/24 17:38:37 | 000,000,000 | —D | C] – C:\Program Files\WinZip
[2012/12/24 17:23:33 | 000,000,000 | —D | C] – C:\Users\Simon\AppData\Roaming\WinRAR
[2012/12/24 17:23:33 | 000,000,000 | —D | C] – C:\Users\Simon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/12/24 17:23:33 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/12/24 17:23:09 | 000,000,000 | —D | C] – C:\Program Files\WinRAR
[2012/12/24 16:13:04 | 000,000,000 | —D | C] – C:\Users\Simon\AppData\Roaming\AVS4YOU
[2012/12/24 16:11:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\AVSMedia
[2012/12/24 16:10:52 | 000,000,000 | —D | C] – C:\ProgramData\AVS4YOU
[2012/12/24 16:10:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVS4YOU
[2012/12/18 22:39:49 | 000,000,000 | —D | C] – C:\ProgramData\Hewlett-Packard

========== Files - Modified Within 30 Days ==========

[2013/01/17 17:56:23 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/01/17 17:53:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/01/17 17:06:18 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/01/17 17:06:18 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/01/16 15:11:21 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/01/16 11:56:13 | 000,001,095 | —- | M] () – C:\Users\Simon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\BBC iPlayer Desktop.lnk
[2013/01/16 11:54:07 | 3060,264,960 | -HS- | M] () – C:\hiberfil.sys
[2013/01/16 11:36:39 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2013/01/16 11:06:49 | 005,022,206 | R— | M] (Swearware) – C:\Users\Simon\Desktop\ComboFix.exe
[2013/01/16 10:58:30 | 000,554,087 | —- | M] () – C:\Users\Simon\Desktop\AdwCleaner.exe
[2013/01/14 13:59:59 | 000,002,020 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2013/01/14 13:49:51 | 000,002,285 | —- | M] () – C:\Users\Simon\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/01/13 22:17:33 | 000,000,597 | —- | M] () – C:\Users\Simon\Desktop\MBR.zip
[2013/01/13 22:16:22 | 000,000,512 | —- | M] () – C:\Users\Simon\Desktop\MBR.dat
[2013/01/13 21:55:26 | 000,002,189 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/01/13 21:36:46 | 000,856,731 | —- | M] () – C:\Users\Simon\Desktop\SecurityCheck (1).exe
[2013/01/13 21:35:53 | 004,732,416 | —- | M] (AVAST Software) – C:\Users\Simon\Desktop\aswMBR.exe
[2013/01/13 21:34:40 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Simon\Desktop\OTL.exe
[2013/01/10 21:24:05 | 000,001,115 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/10 20:49:14 | 000,418,216 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/01/10 18:01:02 | 000,732,510 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/01/10 18:01:02 | 000,616,242 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/01/10 18:01:02 | 000,106,622 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/12/27 11:29:20 | 000,002,054 | —- | M] () – C:\Users\Public\Desktop\SUPER © Uninstall.lnk
[2012/12/27 11:29:20 | 000,002,030 | —- | M] () – C:\Users\Public\Desktop\SUPER ©.lnk
[2012/12/24 17:39:27 | 000,002,283 | —- | M] () – C:\Users\Public\Desktop\WinZip.lnk
[2012/12/19 11:27:15 | 000,840,192 | —- | M] () – C:\Users\Simon\Documents\Xmas2012.pub
[2012/12/19 11:10:20 | 000,150,506 | —- | M] () – C:\Users\Simon\Documents\Xmas2012.pdf
[2012/12/18 21:46:37 | 574,160,632 | —- | M] () – C:\Windows\MEMORY.DMP
[2012/12/18 20:55:55 | 000,726,799 | —- | M] () – C:\Users\Simon\Desktop\28072012256.jpg

========== Files Created - No Company Name ==========

[2013/01/16 11:14:44 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/01/16 11:14:43 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/01/16 11:14:43 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2013/01/16 11:14:42 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/01/16 11:14:42 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/01/16 10:58:10 | 000,554,087 | —- | C] () – C:\Users\Simon\Desktop\AdwCleaner.exe
[2013/01/13 22:17:33 | 000,000,597 | —- | C] () – C:\Users\Simon\Desktop\MBR.zip
[2013/01/13 22:16:22 | 000,000,512 | —- | C] () – C:\Users\Simon\Desktop\MBR.dat
[2013/01/13 21:36:40 | 000,856,731 | —- | C] () – C:\Users\Simon\Desktop\SecurityCheck (1).exe
[2013/01/10 21:24:05 | 000,001,115 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/08 22:56:18 | 000,000,981 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dukto R5.lnk
[2012/12/27 11:29:20 | 000,002,066 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPER © Uninstall.lnk
[2012/12/27 11:29:20 | 000,002,054 | —- | C] () – C:\Users\Public\Desktop\SUPER © Uninstall.lnk
[2012/12/27 11:29:20 | 000,002,042 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPER ©.lnk
[2012/12/27 11:29:20 | 000,002,030 | —- | C] () – C:\Users\Public\Desktop\SUPER ©.lnk
[2012/12/27 11:29:14 | 000,107,520 | RHS- | C] () – C:\Windows\SysWow64\RLMPCDec.ax
[2012/12/27 11:29:14 | 000,070,656 | RHS- | C] () – C:\Windows\SysWow64\RLAPEDec.ax
[2012/12/27 11:29:14 | 000,051,712 | RHS- | C] () – C:\Windows\SysWow64\RLSpeexDec.ax
[2012/12/27 11:29:13 | 000,120,832 | RHS- | C] () – C:\Windows\SysWow64\MPCDx.ax
[2012/12/27 11:29:13 | 000,097,280 | RHS- | C] () – C:\Windows\SysWow64\FLACDX.ax
[2012/12/27 11:29:12 | 000,227,328 | RHS- | C] () – C:\Windows\SysWow64\ac3DX.ax
[2012/12/27 11:29:12 | 000,175,104 | RHS- | C] () – C:\Windows\SysWow64\CoreAAC.ax
[2012/12/27 11:29:12 | 000,081,920 | RHS- | C] () – C:\Windows\SysWow64\aac_parser.ax
[2012/12/24 17:39:26 | 000,002,283 | —- | C] () – C:\Users\Public\Desktop\WinZip.lnk
[2012/12/20 19:48:07 | 023,261,324 | —- | C] () – C:\Users\Simon\Desktop\Young Gods - 03 - Track 3.wav
[2012/12/20 19:48:04 | 033,116,204 | —- | C] () – C:\Users\Simon\Desktop\Steinski - 01 - We'll be right back.wav
[2012/12/20 19:47:57 | 085,636,364 | —- | C] () – C:\Users\Simon\Desktop\can - 06 - vitamin c (remix).wav
[2012/12/20 19:47:17 | 221,464,378 | —- | C] () – C:\Users\Simon\Desktop\Boredoms - Super roots 7.WAV
[2012/12/20 19:47:09 | 093,049,882 | —- | C] () – C:\Users\Simon\Desktop\Boredoms - Super Roots 1.WAV
[2012/12/19 11:10:18 | 000,150,506 | —- | C] () – C:\Users\Simon\Documents\Xmas2012.pdf
[2012/12/18 22:22:24 | 000,840,192 | —- | C] () – C:\Users\Simon\Documents\Xmas2012.pub
[2012/12/18 20:54:07 | 000,726,799 | —- | C] () – C:\Users\Simon\Desktop\28072012256.jpg
[2012/12/15 07:51:34 | 000,001,043 | —- | C] () – C:\Windows\DVDXRestrictionFree.ini
[2012/12/15 07:51:34 | 000,000,014 | —- | C] () – C:\Windows\SysWow64\SysEngine2.SYS
[2011/12/12 11:41:42 | 000,001,025 | —- | C] () – C:\Windows\SysWow64\sysprs7.dll
[2011/12/12 11:41:42 | 000,000,205 | —- | C] () – C:\Windows\SysWow64\lsprst7.dll
[2011/11/24 21:11:37 | 000,245,760 | —- | C] ( ) – C:\Windows\SysWow64\rsnp2uvc.dll
[2011/11/24 21:11:36 | 000,024,576 | —- | C] () – C:\Windows\snuvcdsm.exe
[2011/11/24 21:11:36 | 000,015,497 | —- | C] () – C:\Windows\snp2uvc.ini
[2011/07/28 01:12:36 | 000,870,544 | —- | C] () – C:\Windows\SysWow64\igkrng575.bin
[2011/07/28 01:12:36 | 000,208,896 | —- | C] () – C:\Windows\SysWow64\iglhsip32.dll
[2011/07/28 01:12:36 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\iglhcp32.dll
[2011/07/28 01:12:35 | 000,051,068 | —- | C] () – C:\Windows\SysWow64\igfcg575m.bin
[2011/07/28 01:12:34 | 000,127,896 | —- | C] () – C:\Windows\SysWow64\igcompkrng575.bin

========== ZeroAccess Check ==========

[2009/07/14 04:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/09 05:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/09 04:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/14 01:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 12:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/14 01:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2012/08/05 16:19:11 | 000,000,000 | —D | M] – C:\Users\Simon\AppData\Roaming\.minecraft
[2012/07/08 19:09:28 | 000,000,000 | —D | M] – C:\Users\Simon\AppData\Roaming\Avery
[2011/12/09 22:27:01 | 000,000,000 | —D | M] – C:\Users\Simon\AppData\Roaming\BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1
[2012/09/21 20:55:48 | 000,000,000 | —D | M] – C:\Users\Simon\AppData\Roaming\calibre
[2011/12/12 10:26:27 | 000,000,000 | —D | M] – C:\Users\Simon\AppData\Roaming\Cisco
[2012/12/03 22:31:57 | 000,000,000 | —D | M] – C:\Users\Simon\AppData\Roaming\DVDVideoSoft
[2012/06/11 20:24:16 | 000,000,000 | —D | M] – C:\Users\Simon\AppData\Roaming\GraphPad Software
[2013/01/05 11:13:36 | 000,000,000 | —D | M] – C:\Users\Simon\AppData\Roaming\HandBrake
[2012/06/09 13:14:56 | 000,000,000 | —D | M] – C:\Users\Simon\AppData\Roaming\ICAClient
[2011/11/25 11:22:09 | 000,000,000 | —D | M] – C:\Users\Simon\AppData\Roaming\ISI ResearchSoft
[2012/12/02 18:18:51 | 000,000,000 | —D | M] – C:\Users\Simon\AppData\Roaming\Nokia
[2011/12/05 15:21:24 | 000,000,000 | —D | M] – C:\Users\Simon\AppData\Roaming\OneClickInternet
[2011/11/28 20:47:27 | 000,000,000 | —D | M] – C:\Users\Simon\AppData\Roaming\PC Suite
[2012/06/11 20:20:22 | 000,000,000 | —D | M] – C:\Users\Simon\AppData\Roaming\Prism
[2012/09/28 15:54:52 | 000,000,000 | —D | M] – C:\Users\Simon\AppData\Roaming\SPSSInc

========== Purity Check ==========



< End of report >

All the best,
Simon
Hi simonjeaton ;)

Follow these steps:

I recognize that your "Show hidden files and folders" is selected

Using Windows Explorer (Windows Key + E), locate the following folder, and DELETE them (if still present):

c:\programdata\boost_interprocess

(Remember to Hide files and folders once done)

Please let me know how your computer is running and if there are any outstanding issues
Hi simonjeaton ;)

I'm very happy :)

IT APPEARS THAT YOUR LOGS ARE NOW CLEAN :) SO LETS DO A COUPLE OF THINGS TO WRAP THIS UP!! :)

This infection appears to have been cleaned, but I can not give you any absolute guarantees. As a precaution, I would go ahead and change all of your passwords as this is especially important after an infection.



Unistall AdwCleaner

  • Double click on adwcleaner.exe to run the tool.
  • Click on Uninstall.
  • Confirm with yes.

Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.

Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted so they aren't cluttering up your desktop.

Java is very easily exploited these days and it's a good idea to disable Java in the browser

http://www.techsupportforum.com/forums/f50…ers-683721.html


Adobe Update to the latest version

On your computer exist an old version of Adobe products:

Adobe reader
  • Please go to this page, http://www.adobe.com/downloads/updates/
  • In Find product updates, scroll down the menu until you find the product you want to update.
  • Select it and click go.
  • At this point you will be directed to the update page, scroll down until you Updates/Programs and select the latest version of the product.
  • It will be 'directed to the download page, and then click proceed to download and follow the instructions.
  • Follow these steps for all products that require upgrade.

MOST IMPORTANT: You Need to Update Windows and IE to get all the Latest Security Patches to protect your computer from the malware that is around on the internet.

Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
Make your Mozilla Firefox more secure - This can be done by adding these add-ons:

2. Enable Protected Mode in Internet Explorer. This helps Windows Vista users stay more protected from attack by running Internet Explorer with restricted privileges as well as reducing the ability to write, alter or destroy data on your system or install malicious code. To make sure this is running follow these steps:
  • Open Internet Explorer
  • Click on Tools > Internet Options
  • Press Security tab
  • Select Internet zone then place check next to Enable Protected Mode if not already done
  • Do the same for Local Intranet, Trusted Sites and Restricted Sites and then press Apply
  • Restart Internet Explorer and in the bottom right corner of your screen you will see Protected Mode: On showing you it is enabled.

3. Use and update an anti-virus software - I can not overemphasize the need for you to use and update your anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

4. Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a firewall in its default configuration can lower your risk greatly. A tutorial on firewalls can be found here. **There are firewalls listed in this tutorial that could be downloaded and used but I would personally only recommend using one of the following two below:
Online Armor Free
Agnitum Outpost Firewall Free


5.SPYWARE PREVENTION
This is a good time to set up protection against further attacks. In light of your recent problem, I'm sure you'd like to avoid any future infections. Please read these well written articles:
6. Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers. For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

7. WOT (Web of Trust) As "Googling" is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites. WOT has an add-on available for Firefox, Internet Explorer as well as Google Chrome.

8.Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI