This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Windows has encountered a critical error [Solved]

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

So I'm not sure if I have some kind of virus or if my comp is on its way out (hopefully not, all parts are less than a year old apart from HDD). I have BSoD almost daily along with these errors:

Win32/Small.CA virus - This was flagged as by windows action center, after running my AV and it finding nothing, this message was gone.

Windows has encountered a critical error - This message appeared after I was using my computer for several hours. To which it restarted itself.

Today on Boot up i received this error ;

No AMD graphics driver is installed or the AMD driver is not functioning properly.

Windows must now restart because the DCOM server process launcher service terminated unexpectedly.

Here is the DDS.txt

.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by [removed] at 14:15:02.37 on 28/01/2013
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.11.2
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.8109.5195 [GMT 0:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\AVAST Software\Avast\afwServ.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe
C:\Program Files\Belkin\Belkin USB Print and Storage Center\BkBackupScheduler.exe
C:\Program Files\Belkin\Belkin USB Print and Storage Center\Bkapcs.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Belkin\Belkin USB Print and Storage Center\connect.exe
C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe
C:\Program Files (x86)\Belkin\Router Setup and Monitor\dlnaPlugin.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\RunDll32.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\User\Downloads\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=GB&userid=87fb5ffa-7fed-4760-8157-1cd1030e2963&searchtype=ds&q={searchTerms}
uStart Page = hxxp://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=GB&userid=87fb5ffa-7fed-4760-8157-1cd1030e2963&searchtype=hp
uSearch Bar = hxxp://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=GB&userid=87fb5ffa-7fed-4760-8157-1cd1030e2963&searchtype=ds&q={searchTerms}
uInternet Settings,ProxyOverride =
uSearchAssistant = hxxp://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=GB&userid=87fb5ffa-7fed-4760-8157-1cd1030e2963&searchtype=ds&q={searchTerms}
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
{ae07101b-46d4-4a98-af68-0333ea26e113}
{e7df6bff-55a5-4eb7-a673-4ed3e9456d39}
TB: {BA14329E-9550-4989-B3F2-9732E92D17CC} - No File
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: []
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
mRun: [InstaLAN] "C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe" startup
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\Installer\chrmstp.exe" –configure-user-settings –verbose-logging –system-level –multi-install –chrome
BHO-X64: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
TB-X64: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
{ae07101b-46d4-4a98-af68-0333ea26e113}
TB-X64: {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
TB-X64: {BA14329E-9550-4989-B3F2-9732E92D17CC} - No File
mRun-x64: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
mRun-x64: [IgfxTray] C:\Windows\system32\igfxtray.exe
mRun-x64: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
mRun-x64: [Persistence] C:\Windows\system32\igfxpers.exe
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\11nx87hu.default\
FF - prefs.js: browser.startup.homepage - hxxp://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=GB&userid=87fb5ffa-7fed-4760-8157-1cd1030e2963&searchtype=hp
FF - prefs.js: keyword.URL - hxxp://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=GB&userid=87fb5ffa-7fed-4760-8157-1cd1030e2963&searchtype=ds&q=
FF - plugin: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll
FF - plugin: C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypchub.dll
FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll
.
============= SERVICES / DRIVERS ===============
.
R0 aswNdis;avast! Firewall NDIS Filter Service;C:\Windows\System32\drivers\aswNdis.sys [2012-10-25 12368]
R0 aswNdis2;avast! Firewall Core Firewall Service;C:\Windows\System32\drivers\aswNdis2.sys [2012-10-25 262656]
R1 AppleCharger;AppleCharger;C:\Windows\System32\drivers\AppleCharger.sys [2012-4-6 21104]
R1 aswFW;avast! TDI Firewall driver;C:\Windows\System32\drivers\aswFW.sys [2012-10-25 132864]
R1 aswKbd;aswKbd;C:\Windows\System32\drivers\aswKbd.sys [2012-10-25 21136]
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2012-10-25 984144]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2012-10-25 370288]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-12-18 65192]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2012-12-19 240640]
R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2012-10-25 25232]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2012-10-25 71600]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-11-7 44808]
R2 avast! Firewall;avast! Firewall;C:\Program Files\AVAST Software\Avast\afwServ.exe [2012-11-7 133912]
R2 Belkin Local Backup Service;Belkin Local Backup Service;C:\Program Files\Belkin\Belkin USB Print and Storage Center\BkBackupScheduler.exe [2012-7-20 181760]
R2 Belkin Network USB Helper;Belkin Network USB Helper;C:\Program Files\Belkin\Belkin USB Print and Storage Center\Bkapcs.exe [2012-7-20 55296]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-1-24 398184]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-1-24 682344]
R2 sxuptp;SXUPTP Driver;C:\Windows\System32\drivers\sxuptp.sys [2012-7-20 291352]
R3 amdkmdag;amdkmdag;C:\Windows\System32\drivers\atikmdag.sys [2012-12-19 11278336]
R3 amdkmdap;amdkmdap;C:\Windows\System32\drivers\atikmpag.sys [2012-12-19 552960]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2012-11-6 96256]
R3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;C:\Windows\System32\drivers\EtronHub3.sys [2011-7-29 56960]
R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;C:\Windows\System32\drivers\EtronXHCI.sys [2011-7-29 79104]
R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2012-4-6 317440]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-1-24 24176]
R3 MEIx64;Intel® Management Engine Interface ;C:\Windows\System32\drivers\HECIx64.sys [2010-10-19 56344]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-4-6 535656]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-1-7 116648]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-11-9 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-7 251400]
S3 AppleChargerSrv;AppleChargerSrv;system32\AppleChargerSrv.exe –> system32\AppleChargerSrv.exe [?]
S3 cphs;Intel® Content Protection HECI Service;C:\Windows\SysWOW64\IntelCpHeciSvc.exe [2012-3-19 276248]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-1-7 116648]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-1-6 113120]
S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-1-9 174440]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-4-6 1255736]
.
=============== Created Last 30 ================
.
2013-01-27 15:31:50 ——– d—–w- C:\Program Files (x86)\AMD AVT
2013-01-27 15:31:41 ——– d—–w- C:\Program Files (x86)\AMD APP
2013-01-25 15:49:00 9161176 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{5FCF61C0-698E-4A37-BB7B-CFB820F9B8EF}\mpengine.dll
2013-01-24 17:59:28 ——– d—–w- C:\Users\User\AppData\Roaming\Malwarebytes
2013-01-24 17:59:20 ——– d—–w- C:\PROGRA~3\Malwarebytes
2013-01-24 17:59:19 24176 —-a-w- C:\Windows\System32\drivers\mbam.sys
2013-01-24 17:59:19 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-01-24 17:59:10 ——– d—–w- C:\Users\User\AppData\Local\Programs
2013-01-20 21:48:42 ——– d—–w- C:\Users\User\AppData\Local\Square Enix
2013-01-19 16:46:10 95648 —-a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-01-16 22:56:57 ——– d—–w- C:\Users\User\AppData\Local\Solid State Networks
2013-01-16 22:56:39 ——– d—–w- C:\Program Files (x86)\MeteorEntertainment
2013-01-09 15:25:00 750592 —-a-w- C:\Windows\System32\win32spl.dll
2013-01-09 15:25:00 492032 —-a-w- C:\Windows\SysWow64\win32spl.dll
2013-01-09 15:23:53 68608 —-a-w- C:\Windows\System32\taskhost.exe
2013-01-09 15:23:52 3149824 —-a-w- C:\Windows\System32\win32k.sys
2013-01-06 16:54:23 ——– d—–r- C:\Program Files (x86)\Skype
2013-01-06 16:50:16 ——– d—–w- C:\Users\User\AppData\Local\Macromedia
2013-01-06 16:45:37 ——– d—–w- C:\Windows\SysWow64\Adobe
.
==================== Find3M ====================
.
2013-01-11 20:37:50 281688 —-a-w- C:\Windows\SysWow64\PnkBstrB.xtr
2013-01-11 20:37:50 281688 —-a-w- C:\Windows\SysWow64\PnkBstrB.exe
2013-01-08 20:28:11 74248 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-01-08 20:28:11 697864 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-01-07 00:06:20 281688 —-a-w- C:\Windows\SysWow64\PnkBstrB.ex0
2013-01-03 16:50:05 76888 —-a-w- C:\Windows\SysWow64\PnkBstrA.exe
2012-12-19 20:50:14 5630200 —-a-w- C:\Windows\SysWow64\atiumdag.dll
2012-12-19 20:48:48 11278336 —-a-w- C:\Windows\System32\drivers\atikmdag.sys
2012-12-19 20:29:36 23461376 —-a-w- C:\Windows\System32\atio6axx.dll
2012-12-19 20:22:50 70144 —-a-w- C:\Windows\System32\coinst_9.012.dll
2012-12-19 20:19:46 163840 —-a-w- C:\Windows\System32\atiapfxx.exe
2012-12-19 20:18:04 51200 —-a-w- C:\Windows\System32\aticalrt64.dll
2012-12-19 20:18:02 46080 —-a-w- C:\Windows\SysWow64\aticalrt.dll
2012-12-19 20:17:54 44544 —-a-w- C:\Windows\System32\aticalcl64.dll
2012-12-19 20:17:52 44032 —-a-w- C:\Windows\SysWow64\aticalcl.dll
2012-12-19 20:17:40 16082944 —-a-w- C:\Windows\System32\aticaldd64.dll
2012-12-19 20:13:24 13703168 —-a-w- C:\Windows\SysWow64\aticaldd.dll
2012-12-19 20:12:44 18982400 —-a-w- C:\Windows\SysWow64\atioglxx.dll
2012-12-19 20:09:52 960512 —-a-w- C:\Windows\SysWow64\aticfx32.dll
2012-12-19 20:08:04 1151488 —-a-w- C:\Windows\System32\aticfx64.dll
2012-12-19 20:06:00 6681088 —-a-w- C:\Windows\SysWow64\atidxx32.dll
2012-12-19 19:59:44 5087744 —-a-w- C:\Windows\System32\atiumd6a.dll
2012-12-19 19:57:00 442368 —-a-w- C:\Windows\System32\atidemgy.dll
2012-12-19 19:56:46 550912 —-a-w- C:\Windows\System32\atieclxx.exe
2012-12-19 19:56:00 240640 —-a-w- C:\Windows\System32\atiesrxx.exe
2012-12-19 19:54:38 120320 —-a-w- C:\Windows\System32\atitmm64.dll
2012-12-19 19:54:22 21504 —-a-w- C:\Windows\System32\atimuixx.dll
2012-12-19 19:54:18 59392 —-a-w- C:\Windows\System32\atiedu64.dll
2012-12-19 19:54:12 43520 —-a-w- C:\Windows\SysWow64\ati2edxx.dll
2012-12-19 19:49:00 7370752 —-a-w- C:\Windows\System32\atidxx64.dll
2012-12-19 19:44:28 4162048 —-a-w- C:\Windows\SysWow64\atiumdva.dll
2012-12-19 19:44:12 6786560 —-a-w- C:\Windows\System32\atiumd64.dll
2012-12-19 19:33:50 56320 —-a-w- C:\Windows\System32\atimpc64.dll
2012-12-19 19:33:50 56320 —-a-w- C:\Windows\System32\amdpcom64.dll
2012-12-19 19:33:42 619008 —-a-w- C:\Windows\System32\atiadlxx.dll
2012-12-19 19:33:40 56832 —-a-w- C:\Windows\SysWow64\atimpc32.dll
2012-12-19 19:33:40 56832 —-a-w- C:\Windows\SysWow64\amdpcom32.dll
2012-12-19 19:33:32 421888 —-a-w- C:\Windows\SysWow64\atiadlxy.dll
2012-12-19 19:33:18 17920 —-a-w- C:\Windows\System32\atig6pxx.dll
2012-12-19 19:33:14 14848 —-a-w- C:\Windows\SysWow64\atiglpxx.dll
2012-12-19 19:33:14 14848 —-a-w- C:\Windows\System32\atiglpxx.dll
2012-12-19 19:33:10 41984 —-a-w- C:\Windows\System32\atig6txx.dll
2012-12-19 19:33:04 33280 —-a-w- C:\Windows\SysWow64\atigktxx.dll
2012-12-19 19:32:54 552960 —-a-w- C:\Windows\System32\drivers\atikmpag.sys
2012-12-19 19:31:14 130048 —-a-w- C:\Windows\System32\atiuxp64.dll
2012-12-19 19:31:08 109568 —-a-w- C:\Windows\SysWow64\atiuxpag.dll
2012-12-19 19:31:00 104448 —-a-w- C:\Windows\System32\atiu9p64.dll
2012-12-19 19:30:52 83968 —-a-w- C:\Windows\SysWow64\atiu9pag.dll
2012-12-19 19:30:16 53248 —-a-w- C:\Windows\System32\drivers\ati2erec.dll
2012-12-19 15:45:12 222720 —-a-w- C:\Windows\System32\clinfo.exe
2012-12-19 15:44:48 76288 —-a-w- C:\Windows\System32\OpenVideo64.dll
2012-12-19 15:44:42 65536 —-a-w- C:\Windows\SysWow64\OpenVideo.dll
2012-12-19 15:44:36 64000 —-a-w- C:\Windows\System32\OVDecode64.dll
2012-12-19 15:44:32 56320 —-a-w- C:\Windows\SysWow64\OVDecode.dll
2012-12-19 15:44:20 34518016 —-a-w- C:\Windows\System32\amdocl64.dll
2012-12-19 15:38:48 28732928 —-a-w- C:\Windows\SysWow64\amdocl.dll
2012-12-19 15:34:40 54784 —-a-w- C:\Windows\System32\OpenCL.dll
2012-12-19 15:34:38 50176 —-a-w- C:\Windows\SysWow64\OpenCL.dll
2012-12-18 03:20:29 859072 —-a-w- C:\Windows\SysWow64\npdeployJava1.dll
2012-12-18 03:20:29 779704 —-a-w- C:\Windows\SysWow64\deployJava1.dll
2012-12-18 02:48:32 155936 —-a-w- C:\Users\User\sdelete.exe
2012-12-16 17:11:22 46080 —-a-w- C:\Windows\System32\atmlib.dll
2012-12-16 14:45:03 367616 —-a-w- C:\Windows\System32\atmfd.dll
2012-12-16 14:13:28 295424 —-a-w- C:\Windows\SysWow64\atmfd.dll
2012-12-16 14:13:20 34304 —-a-w- C:\Windows\SysWow64\atmlib.dll
2012-12-07 13:20:16 441856 —-a-w- C:\Windows\System32\Wpc.dll
2012-12-07 13:15:31 2746368 —-a-w- C:\Windows\System32\gameux.dll
2012-12-07 12:26:17 308736 —-a-w- C:\Windows\SysWow64\Wpc.dll
2012-12-07 12:20:43 2576384 —-a-w- C:\Windows\SysWow64\gameux.dll
2012-12-07 11:20:04 30720 —-a-w- C:\Windows\System32\usk.rs
2012-12-07 11:20:03 43520 —-a-w- C:\Windows\System32\csrr.rs
2012-12-07 11:20:03 23552 —-a-w- C:\Windows\System32\oflc.rs
2012-12-07 11:20:01 45568 —-a-w- C:\Windows\System32\oflc-nz.rs
2012-12-07 11:20:01 44544 —-a-w- C:\Windows\System32\pegibbfc.rs
2012-12-07 11:20:01 20480 —-a-w- C:\Windows\System32\pegi-fi.rs
2012-12-07 11:20:00 20480 —-a-w- C:\Windows\System32\pegi-pt.rs
2012-12-07 11:19:59 20480 —-a-w- C:\Windows\System32\pegi.rs
2012-12-07 11:19:58 46592 —-a-w- C:\Windows\System32\fpb.rs
2012-12-07 11:19:57 40960 —-a-w- C:\Windows\System32\cob-au.rs
2012-12-07 11:19:57 21504 —-a-w- C:\Windows\System32\grb.rs
2012-12-07 11:19:57 15360 —-a-w- C:\Windows\System32\djctq.rs
2012-12-07 11:19:56 55296 —-a-w- C:\Windows\System32\cero.rs
2012-12-07 11:19:55 51712 —-a-w- C:\Windows\System32\esrb.rs
2012-11-30 05:45:35 362496 —-a-w- C:\Windows\System32\wow64win.dll
2012-11-30 05:45:35 243200 —-a-w- C:\Windows\System32\wow64.dll
2012-11-30 05:45:35 13312 —-a-w- C:\Windows\System32\wow64cpu.dll
2012-11-30 05:45:14 215040 —-a-w- C:\Windows\System32\winsrv.dll
2012-11-30 05:43:12 16384 —-a-w- C:\Windows\System32\ntvdm64.dll
2012-11-30 05:41:07 424448 —-a-w- C:\Windows\System32\KernelBase.dll
2012-11-30 04:54:00 5120 —-a-w- C:\Windows\SysWow64\wow32.dll
2012-11-30 04:53:59 274944 —-a-w- C:\Windows\SysWow64\KernelBase.dll
2012-11-30 03:23:48 338432 —-a-w- C:\Windows\System32\conhost.exe
2012-11-30 02:44:06 25600 —-a-w- C:\Windows\SysWow64\setup16.exe
2012-11-30 02:44:04 7680 —-a-w- C:\Windows\SysWow64\instnm.exe
2012-11-30 02:44:04 14336 —-a-w- C:\Windows\SysWow64\ntvdm64.dll
2012-11-30 02:44:03 2048 —-a-w- C:\Windows\SysWow64\user.exe
2012-11-30 02:38:59 6144 —ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2012-11-30 02:38:59 4608 —ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2012-11-30 02:38:59 3584 —ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2012-11-30 02:38:59 3072 —ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
.
============= FINISH: 14:15:46.90 ===============
Hello Derpina and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Run RogueKiller

IMPORTANT: Do not reboot your computer if at all possible otherwise the malware will reactivate and you will have to run RogueKiller again

Download RogueKiller to your desktop.
  • close all running programs
  • for Windows Vista/Seven, right click -> run as administrator, for XP simply double-click on RogueKiller.exe
  • when the prescan is finished, click on Scan
  • click on Report and copy/paste the content in your next post
  • NOTE: DO NOT attempt to remove anything that the scan detects.
If the program is blocked, continue to try it several times. If it still doesn’t work, (it could happen), rename it to winlogon.exe.

Please post the contents of the RKreport.txt in your next reply.

==================================

Run aswMBR
  • download aswMBR.exe to your desktop.
  • double click the aswMBR.exe to run it
  • if asked, accept the AVAST virus definition download
  • click the "Scan" button to start scan
  • on completion of the scan click Save log, save it to your desktop and post in your next reply. Note - do NOT attempt any Fix yet.
Logs to include with next post:

RKreport.txt
aswMBR log


Thanks

Satchfan
Thanks for response here are both of the logs.

RogueKiller V8.4.3 [Jan 27 2013] by Tigzy
mail : tigzyRKgmailcom
Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : User [Admin rights]
Mode : Scan – Date : 01/29/2013 17:28:16
| ARK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 2 ¤¤¤
[HJ DESK] HKLM\[…]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [NOT LOADED] ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
–> C:\Windows\system32\drivers\etc\hosts



¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: WDC WD10EADS-22M2B0 ATA Device +++++
— User —
[MBR] f99917808bf0dcd4c2e6015003a9cb37
[BSP] 73c3a5301e8dde82af4173f4015d42d1 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 953767 Mo
User = LL1 … OK!
User = LL2 … OK!

Finished : << RKreport[1]_S_01292013_02d1728.txt >>
RKreport[1]_S_01292013_02d1728.txt



And the Second



aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software
Run date: 2013-01-29 17:30:04
—————————–
17:30:04.353 OS Version: Windows x64 6.1.7601 Service Pack 1
17:30:04.353 Number of processors: 4 586 0x2A07
17:30:04.353 ComputerName: USER-PC UserName: User
17:30:05.804 Initialize success
17:30:05.929 AVAST engine defs: 13012901
17:30:21.498 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
17:30:21.498 Disk 0 Vendor: WDC_WD10EADS-22M2B0 01.00A01 Size: 953869MB BusType: 3
17:30:21.513 Disk 0 MBR read successfully
17:30:21.529 Disk 0 MBR scan
17:30:21.529 Disk 0 Windows 7 default MBR code
17:30:21.529 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
17:30:21.529 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 953767 MB offset 206848
17:30:21.545 Disk 0 scanning C:\Windows\system32\drivers
17:30:26.927 Service scanning
17:30:38.112 Modules scanning
17:30:38.112 Disk 0 trace - called modules:
17:30:38.143 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys
17:30:38.143 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007abb060]
17:30:38.658 3 CLASSPNP.SYS[fffff8800199443f] -> nt!IofCallDriver -> [0xfffffa800780b520]
17:30:38.658 5 ACPI.sys[fffff88000d867a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa80077f7680]
17:30:39.500 AVAST engine scan C:\Windows
17:30:41.840 AVAST engine scan C:\Windows\system32
17:32:13.038 AVAST engine scan C:\Windows\system32\drivers
17:32:19.746 AVAST engine scan C:\Users\User
17:34:53.984 AVAST engine scan C:\ProgramData
17:35:53.357 Scan finished successfully
17:36:21.125 Disk 0 MBR has been saved successfully to "C:\Users\User\Desktop\MBR.dat"
17:36:21.125 The log file has been saved successfully to "C:\Users\User\Desktop\aswMBR.txt"
Well, good news that those two scans were OK but you do have some malware that your DDS log showed up, so we need to use different tools to clear these up.

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.
  • run AdwCleaner and select Delete
  • when it has finished it will ask to reboot - allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply
===================================================

Download and run OTL
  • download OTL to your desktop.
  • double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • click Scan all users.
  • under Custom Scan paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    services.exe
    /md5stop
    %systemroot%\*. /rp /s
    DRIVES
    CREATERESTOREPOINT

  • click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long.
  • when the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
Logs to include with next post:

AdwCleaner log
OTL.txt
Extras.txt


Thanks

Satchfan
Thanks for another quick response, here are all 3 logs.

# AdwCleaner v2.109 - Logfile created 01/29/2013 at 19:25:06
# Updated 26/01/2013 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : User - USER-PC
# Boot Mode : Normal
# Running from : C:\Users\User\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

File Deleted : C:\END
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\ProgramData\Tarma Installer

***** [Registry] *****

Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\IGearSettings
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKCU\Software\SmartBar
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstallerStub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstallerStub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\QuickShare_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\QuickShare_RASMANCS
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Tarma Installer
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16457

Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Search Page] = hxxp://feed.snap.do/?publisher=QuickObrw&dpid;=QuickObrw&co;=GB&userid;=87fb5ffa-7fed-4760-8157-1cd1030e2963&searchtype;=ds&q;={searchTerms} –> hxxp://www.google.com
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://feed.snap.do/?publisher=QuickObrw&dpid;=QuickObrw&co;=GB&userid;=87fb5ffa-7fed-4760-8157-1cd1030e2963&searchtype;=hp –> hxxp://www.google.com
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Search Bar] = hxxp://feed.snap.do/?publisher=QuickObrw&dpid;=QuickObrw&co;=GB&userid;=87fb5ffa-7fed-4760-8157-1cd1030e2963&searchtype;=ds&q;={searchTerms} –> hxxp://www.google.com
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Search - Default_Search_URL] = hxxp://feed.snap.do/?publisher=QuickObrw&dpid;=QuickObrw&co;=GB&userid;=87fb5ffa-7fed-4760-8157-1cd1030e2963&searchtype;=ds&q;={searchTerms} –> hxxp://www.google.com
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Search - SearchAssistant] = hxxp://feed.snap.do/?publisher=QuickObrw&dpid;=QuickObrw&co;=GB&userid;=87fb5ffa-7fed-4760-8157-1cd1030e2963&searchtype;=ds&q;={searchTerms} –> hxxp://www.google.com

-\\ Mozilla Firefox v13.0.1 (en-US)

-\\ Google Chrome v24.0.1312.56

*************************

AdwCleaner[S1].txt - [4604 octets] - [29/01/2013 19:25:06]

########## EOF - C:\AdwCleaner[S1].txt - [4664 octets] ##########




OTL logfile created on: 29/01/2013 19:32:17 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\User\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

7.92 Gb Total Physical Memory | 6.38 Gb Available Physical Memory | 80.51% Memory free
15.84 Gb Paging File | 14.11 Gb Available in Paging File | 89.08% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.41 Gb Total Space | 670.13 Gb Free Space | 71.95% Space Free | Partition Type: NTFS

Computer Name: USER-PC | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/01/29 19:29:16 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
PRC - [2013/01/03 16:50:05 | 000,076,888 | —- | M] () – C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2012/12/18 14:28:08 | 000,065,192 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/12/14 16:49:28 | 000,682,344 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/12/14 16:49:28 | 000,512,360 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012/12/14 16:49:28 | 000,398,184 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/10/30 22:50:59 | 004,297,136 | —- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2012/10/30 22:50:59 | 000,044,808 | —- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2012/10/30 22:50:56 | 000,133,912 | —- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\afwServ.exe
PRC - [2011/05/27 14:57:30 | 000,562,592 | —- | M] (Affinegy, Inc.) – C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe
PRC - [2011/05/27 14:57:28 | 002,015,136 | —- | M] (Affinegy, Inc.) – C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe
PRC - [2011/05/27 14:57:26 | 007,025,568 | —- | M] (Affinegy, Inc.) – C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe
PRC - [2011/05/18 17:28:16 | 001,641,888 | —- | M] (Affinegy, Inc.) – C:\Program Files (x86)\Belkin\Router Setup and Monitor\dlnaPlugin.exe


========== Modules (No Company Name) ==========

MOD - [2011/05/27 14:57:32 | 000,022,944 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinServicePS.dll
MOD - [2011/05/27 14:08:56 | 000,660,480 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\gateways\GenericBelkinGatewayLOC.dll
MOD - [2010/08/22 20:01:36 | 007,187,456 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtGui4.dll
MOD - [2010/08/22 20:01:08 | 000,325,632 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtXml4.dll
MOD - [2010/08/22 20:01:06 | 001,954,304 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtCore4.dll
MOD - [2010/08/22 20:01:06 | 000,847,360 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtNetwork4.dll
MOD - [2010/08/22 19:32:34 | 000,119,808 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\imageformats\qjpeg4.dll


========== Services (SafeList) ==========

SRV:64bit: - [2012/12/19 19:56:00 | 000,240,640 | —- | M] (AMD) [Auto | Running] – C:\Windows\SysNative\atiesrxx.exe – (AMD External Events Utility)
SRV:64bit: - [2012/10/30 22:50:59 | 000,044,808 | —- | M] (AVAST Software) [Auto | Running] – C:\Program Files\AVAST Software\Avast\AvastSvc.exe – (avast! Antivirus)
SRV:64bit: - [2012/10/30 22:50:56 | 000,133,912 | —- | M] (AVAST Software) [Auto | Running] – C:\Program Files\AVAST Software\Avast\afwServ.exe – (avast! Firewall)
SRV:64bit: - [2011/04/19 15:31:16 | 000,181,760 | —- | M] () [Auto | Running] – C:\Program Files\Belkin\Belkin USB Print and Storage Center\BkBackupScheduler.exe – (Belkin Local Backup Service)
SRV:64bit: - [2010/04/06 15:30:38 | 000,031,272 | —- | M] () [On_Demand | Stopped] – C:\Windows\SysNative\AppleChargerSrv.exe – (AppleChargerSrv)
SRV:64bit: - [2010/02/09 14:55:52 | 000,055,296 | —- | M] () [Auto | Running] – C:\Program Files\Belkin\Belkin USB Print and Storage Center\Bkapcs.exe – (Belkin Network USB Helper)
SRV:64bit: - [2009/07/14 01:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2013/01/18 22:44:07 | 000,541,608 | —- | M] (Valve Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Steam\SteamService.exe – (Steam Client Service)
SRV - [2013/01/08 20:28:11 | 000,251,400 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2013/01/03 16:50:05 | 000,076,888 | —- | M] () [Auto | Running] – C:\Windows\SysWOW64\PnkBstrA.exe – (PnkBstrA)
SRV - [2012/12/18 14:28:08 | 000,065,192 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2012/12/14 16:49:28 | 000,682,344 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2012/12/14 16:49:28 | 000,398,184 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe – (MBAMScheduler)
SRV - [2012/11/09 11:21:24 | 000,160,944 | R— | M] (Skype Technologies) [Auto | Stopped] – C:\Program Files (x86)\Skype\Updater\Updater.exe – (SkypeUpdate)
SRV - [2012/06/14 22:20:14 | 000,113,120 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/03/19 22:44:20 | 000,276,248 | —- | M] (Intel Corporation) [On_Demand | Stopped] – C:\Windows\SysWOW64\IntelCpHeciSvc.exe – (cphs)
SRV - [2011/05/27 14:57:30 | 000,562,592 | —- | M] (Affinegy, Inc.) [Auto | Running] – C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe – (AffinegyService)
SRV - [2010/03/18 12:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 21:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/12/19 20:48:48 | 011,278,336 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\atikmdag.sys – (amdkmdag)
DRV:64bit: - [2012/12/19 19:32:54 | 000,552,960 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\atikmpag.sys – (amdkmdap)
DRV:64bit: - [2012/12/14 16:49:28 | 000,024,176 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\mbam.sys – (MBAMProtector)
DRV:64bit: - [2012/11/06 11:11:52 | 000,096,256 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\AtihdW76.sys – (AtiHDAudioService)
DRV:64bit: - [2012/10/30 22:51:56 | 000,059,728 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswTdi.sys – (aswTdi)
DRV:64bit: - [2012/10/30 22:51:55 | 000,984,144 | —- | M] (AVAST Software) [File_System | System | Running] – C:\Windows\SysNative\drivers\aswSnx.sys – (aswSnx)
DRV:64bit: - [2012/10/30 22:51:55 | 000,370,288 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswSP.sys – (aswSP)
DRV:64bit: - [2012/10/30 22:51:55 | 000,262,656 | —- | M] (AVAST Software) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\aswNdis2.sys – (aswNdis2)
DRV:64bit: - [2012/10/30 22:51:55 | 000,071,600 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\aswMonFlt.sys – (aswMonFlt)
DRV:64bit: - [2012/10/30 22:51:55 | 000,021,136 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswKbd.sys – (aswKbd)
DRV:64bit: - [2012/10/30 22:51:53 | 000,132,864 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswFW.sys – (aswFW)
DRV:64bit: - [2012/10/30 22:51:53 | 000,025,232 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\aswFsBlk.sys – (aswFsBlk)
DRV:64bit: - [2012/10/15 16:59:28 | 000,054,072 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswRdr2.sys – (aswRdr)
DRV:64bit: - [2012/09/21 09:26:08 | 000,012,368 | —- | M] (ALWIL Software) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\aswNdis.sys – (aswNdis)
DRV:64bit: - [2012/03/19 22:32:04 | 014,745,600 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2012/03/01 06:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2011/07/29 03:40:00 | 000,079,104 | —- | M] (Etron Technology Inc) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\EtronXHCI.sys – (EtronXHCI)
DRV:64bit: - [2011/07/29 03:40:00 | 000,056,960 | —- | M] (Etron Technology Inc) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\EtronHub3.sys – (EtronHub3)
DRV:64bit: - [2011/06/01 03:16:50 | 000,535,656 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2011/03/11 06:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/11 06:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2011/01/10 17:16:08 | 000,021,104 | —- | M] () [Kernel | System | Running] – C:\Windows\SysNative\drivers\AppleCharger.sys – (AppleCharger)
DRV:64bit: - [2010/11/21 03:24:33 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/11/21 03:23:47 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/21 03:23:47 | 000,031,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbGD.sys – (TsUsbGD)
DRV:64bit: - [2010/10/19 22:34:26 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (MEIx64)
DRV:64bit: - [2010/10/14 17:28:16 | 000,317,440 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcDAud.sys – (IntcDAud)
DRV:64bit: - [2009/08/13 21:10:18 | 000,073,984 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\xusb21.sys – (xusb21)
DRV:64bit: - [2009/07/14 01:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/14 01:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/14 01:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/07/14 00:01:09 | 000,679,936 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\xnacc.sys – (xnacc)
DRV:64bit: - [2009/06/22 15:50:00 | 000,291,352 | —- | M] (silex technology, Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\sxuptp.sys – (sxuptp)
DRV:64bit: - [2009/06/10 20:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 20:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 20:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 20:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/02/17 17:22:22 | 000,017,792 | —- | M] (ASUSTeK Computer Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\asusgsb.sys – (asusgsb)
DRV - [2009/07/14 01:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC


IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-21-1447855767-3573926289-1960894109-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com
IE - HKU\S-1-5-21-1447855767-3573926289-1960894109-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-1447855767-3573926289-1960894109-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKU\S-1-5-21-1447855767-3573926289-1960894109-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-1447855767-3573926289-1960894109-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-GB
IE - HKU\S-1-5-21-1447855767-3573926289-1960894109-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = FC CD F6 6E 29 EC CD 01 [binary data]
IE - HKU\S-1-5-21-1447855767-3573926289-1960894109-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
IE - HKU\S-1-5-21-1447855767-3573926289-1960894109-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
IE - HKU\S-1-5-21-1447855767-3573926289-1960894109-1000\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-1447855767-3573926289-1960894109-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKU\S-1-5-21-1447855767-3573926289-1960894109-1000\..\SearchScopes\{63B2D943-91F1-4a04-B9AA-390B3CE4A909}: "URL" = http://www.bing.com/search?q={searchTerms}…BR1&pc;=SPLH
IE - HKU\S-1-5-21-1447855767-3573926289-1960894109-1000\..\SearchScopes\{89702040-18AF-416b-B0E0-7012894C77FE}: "URL" = http://uk.search.yahoo.com/search?p={searc…amp;type=IEBDSV
IE - HKU\S-1-5-21-1447855767-3573926289-1960894109-1000\..\SearchScopes\{BABCB421-7CA1-4B5C-BB0A-2A118CB6305B}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2504091
IE - HKU\S-1-5-21-1447855767-3573926289-1960894109-1000\..\SearchScopes\{E0F00850-AE0D-48d9-BE93-10117BA27B60}: "URL" = http://www.google.com/cse?cx=partner-pub-3…q={searchTerms}
IE - HKU\S-1-5-21-1447855767-3573926289-1960894109-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1447855767-3573926289-1960894109-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://feed.snap.do/?publisher=QuickObrw&dpid;=QuickObrw&co;=GB&userid;=87fb5ffa-7fed-4760-8157-1cd1030e2963&searchtype;=hp"
FF - prefs.js..extensions.enabledAddons: [removed]:7.0.1474
FF - prefs.js..keyword.URL: "http://feed.snap.do/?publisher=QuickObrw&dpid;=QuickObrw&co;=GB&userid;=87fb5ffa-7fed-4760-8157-1cd1030e2963&searchtype;=ds&q;="
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_146.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.11.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@coreonline.com/run3d,version=1.0: C:\Users\User\AppData\LocalLow\Square Enix\nprun3d.dll (Square Enix)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012/11/07 00:10:40 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/01/06 16:49:39 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2013/01/06 16:50:02 | 000,000,000 | —D | M] (No name found) – C:\Users\User\AppData\Roaming\Mozilla\Extensions
[2013/01/10 17:39:01 | 000,000,000 | —D | M] (No name found) – C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\11nx87hu.default\extensions
[2013/01/06 16:57:13 | 000,804,627 | —- | M] () (No name found) – C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\11nx87hu.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013/01/09 17:31:55 | 000,022,867 | —- | M] () – C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\11nx87hu.default\searchplugins\Web Search.xml
[2013/01/06 16:49:39 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/11/07 00:10:40 | 000,000,000 | —D | M] (avast! WebRep) – C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2012/06/14 22:20:49 | 000,085,472 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/06/14 22:19:40 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/06/14 22:19:40 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: https://login.live.com/login.srf?wa=wsignin…=mai&snsc;=1
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}&sugkey;={google:suggestAPIKeyParameter},
CHR - homepage: https://login.live.com/login.srf?wa=wsignin…=mai&snsc;=1
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\pdf.dll
CHR - plugin: Conduit Chrome Plugin (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk\10.13.20.29_0\plugins/ConduitChromeApiPlugin.dll
CHR - plugin: Conduit Radio Plugin (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk\10.13.20.29_0\plugins/np-cwmp.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 7 U10 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Uplay PC (Enabled) = C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll
CHR - plugin: Java Deployment Toolkit 7.0.100.18 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - Extension: Bejeweled = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\adpkifcfcacgmnggcbpbjbkdijciiigm\2_0\
CHR - Extension: Google Drive = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Crime City = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdbacnnicmbpfcmiapnfjbefkggclmco\1_0\
CHR - Extension: AdBlock = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.56_0\
CHR - Extension: Old /r/leagueoflegends Theme = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\hphhelabfkiefgapcfagibfcopbebfbd\1.8_0\
CHR - Extension: avast! WebRep = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1474_0\
CHR - Extension: Green Farm = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbgdenhobifcbckaiohandoodkepleif\2.1.7.8_0\
CHR - Extension: Gmail = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009/06/10 21:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKU\S-1-5-21-1447855767-3573926289-1960894109-1000\..\Toolbar\WebBrowser: (no name) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - No CLSID value found.
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe (AMD)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [InstaLAN] C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe (Affinegy, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000 File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKU\.DEFAULT\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: sony.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: sony.com ([]* in )
O15 - HKU\S-1-5-21-1447855767-3573926289-1960894109-1000\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-1447855767-3573926289-1960894109-1000\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-1447855767-3573926289-1960894109-1000\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-1447855767-3573926289-1960894109-1000\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 10.10.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3AD91F80-4D5C-45E7-8D25-B6C5B3F817D9}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/01/29 19:29:13 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
[2013/01/29 17:27:49 | 000,000,000 | —D | C] – C:\Users\User\Desktop\RK_Quarantine
[2013/01/29 17:21:33 | 004,732,416 | —- | C] (AVAST Software) – C:\Users\User\Desktop\aswMBR.exe
[2013/01/27 15:31:52 | 000,000,000 | —D | C] – C:\ProgramData\ATI
[2013/01/27 15:31:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\AMD AVT
[2013/01/27 15:31:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\AMD APP
[2013/01/27 15:31:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[2013/01/24 17:59:28 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Malwarebytes
[2013/01/24 17:59:20 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/01/24 17:59:20 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/01/24 17:59:19 | 000,024,176 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2013/01/24 17:59:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/01/24 17:59:10 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Programs
[2013/01/20 21:50:27 | 000,000,000 | —D | C] – C:\Users\User\Documents\Hitman Blood Money
[2013/01/20 21:48:42 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Square Enix
[2013/01/19 16:46:10 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/01/19 16:46:10 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013/01/19 16:46:10 | 000,095,648 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/01/16 22:56:57 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Solid State Networks
[2013/01/16 22:56:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\MeteorEntertainment
[2013/01/16 22:56:39 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Meteor Entertainment
[2013/01/10 17:29:00 | 000,000,000 | —D | C] – C:\Users\User\Documents\Outlook Files
[2013/01/09 15:25:00 | 000,750,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\win32spl.dll
[2013/01/09 15:25:00 | 000,492,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\win32spl.dll
[2013/01/09 15:24:39 | 000,800,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\usp10.dll
[2013/01/09 15:24:39 | 000,307,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncrypt.dll
[2013/01/09 15:24:36 | 000,046,592 | —- | C] (Microsoft) – C:\Windows\SysWow64\fpb.rs
[2013/01/09 15:24:36 | 000,046,592 | —- | C] (Microsoft) – C:\Windows\SysNative\fpb.rs
[2013/01/09 15:24:36 | 000,045,568 | —- | C] (Microsoft) – C:\Windows\SysWow64\oflc-nz.rs
[2013/01/09 15:24:36 | 000,045,568 | —- | C] (Microsoft) – C:\Windows\SysNative\oflc-nz.rs
[2013/01/09 15:24:36 | 000,044,544 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegibbfc.rs
[2013/01/09 15:24:36 | 000,044,544 | —- | C] (Microsoft) – C:\Windows\SysNative\pegibbfc.rs
[2013/01/09 15:24:36 | 000,043,520 | —- | C] (Microsoft) – C:\Windows\SysWow64\csrr.rs
[2013/01/09 15:24:36 | 000,043,520 | —- | C] (Microsoft) – C:\Windows\SysNative\csrr.rs
[2013/01/09 15:24:36 | 000,040,960 | —- | C] (Microsoft) – C:\Windows\SysWow64\cob-au.rs
[2013/01/09 15:24:36 | 000,040,960 | —- | C] (Microsoft) – C:\Windows\SysNative\cob-au.rs
[2013/01/09 15:24:36 | 000,030,720 | —- | C] (Microsoft) – C:\Windows\SysWow64\usk.rs
[2013/01/09 15:24:36 | 000,030,720 | —- | C] (Microsoft) – C:\Windows\SysNative\usk.rs
[2013/01/09 15:24:36 | 000,021,504 | —- | C] (Microsoft) – C:\Windows\SysWow64\grb.rs
[2013/01/09 15:24:36 | 000,021,504 | —- | C] (Microsoft) – C:\Windows\SysNative\grb.rs
[2013/01/09 15:24:36 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegi.rs
[2013/01/09 15:24:36 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysNative\pegi.rs
[2013/01/09 15:24:36 | 000,015,360 | —- | C] (Microsoft) – C:\Windows\SysWow64\djctq.rs
[2013/01/09 15:24:36 | 000,015,360 | —- | C] (Microsoft) – C:\Windows\SysNative\djctq.rs
[2013/01/09 15:24:35 | 002,746,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\gameux.dll
[2013/01/09 15:24:35 | 002,576,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\gameux.dll
[2013/01/09 15:24:35 | 000,441,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Wpc.dll
[2013/01/09 15:24:35 | 000,308,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Wpc.dll
[2013/01/09 15:24:35 | 000,055,296 | —- | C] (Microsoft) – C:\Windows\SysWow64\cero.rs
[2013/01/09 15:24:35 | 000,055,296 | —- | C] (Microsoft) – C:\Windows\SysNative\cero.rs
[2013/01/09 15:24:35 | 000,051,712 | —- | C] (Microsoft) – C:\Windows\SysWow64\esrb.rs
[2013/01/09 15:24:35 | 000,051,712 | —- | C] (Microsoft) – C:\Windows\SysNative\esrb.rs
[2013/01/09 15:24:35 | 000,023,552 | —- | C] (Microsoft) – C:\Windows\SysWow64\oflc.rs
[2013/01/09 15:24:35 | 000,023,552 | —- | C] (Microsoft) – C:\Windows\SysNative\oflc.rs
[2013/01/09 15:24:35 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegi-pt.rs
[2013/01/09 15:24:35 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysNative\pegi-pt.rs
[2013/01/09 15:24:35 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegi-fi.rs
[2013/01/09 15:24:35 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysNative\pegi-fi.rs
[2013/01/09 15:24:10 | 000,424,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\KernelBase.dll
[2013/01/09 15:24:09 | 001,161,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2013/01/09 15:24:08 | 000,362,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64win.dll
[2013/01/09 15:24:08 | 000,338,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\conhost.exe
[2013/01/09 15:24:08 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2013/01/09 15:24:08 | 000,215,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2013/01/09 15:24:08 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntvdm64.dll
[2013/01/09 15:24:08 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2013/01/09 15:24:08 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64cpu.dll
[2013/01/09 15:24:08 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2013/01/09 15:24:08 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2013/01/09 15:24:08 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2013/01/09 15:24:08 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2013/01/09 15:24:08 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2013/01/09 15:24:08 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2013/01/09 15:24:08 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2013/01/09 15:24:08 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/01/09 15:24:08 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/01/09 15:24:08 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2013/01/09 15:24:08 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2013/01/09 15:24:08 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2013/01/09 15:24:08 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2013/01/09 15:24:08 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2013/01/09 15:24:08 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/01/09 15:24:08 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/01/09 15:24:08 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/01/09 15:24:08 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/01/09 15:24:08 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/01/09 15:24:08 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2013/01/09 15:24:08 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2013/01/09 15:24:08 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2013/01/09 15:24:08 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2013/01/09 15:24:08 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2013/01/09 15:24:08 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2013/01/09 15:24:08 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2013/01/09 15:24:08 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2013/01/09 15:24:08 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2013/01/09 15:24:08 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/01/09 15:24:08 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2013/01/09 15:24:08 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2013/01/09 15:24:06 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2013/01/09 15:24:06 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2013/01/09 15:24:06 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2013/01/09 15:24:06 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2013/01/09 15:24:06 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2013/01/09 15:24:06 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2013/01/09 15:24:06 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2013/01/09 15:24:06 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/01/09 15:24:06 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/01/09 15:24:06 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2013/01/09 15:24:06 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2013/01/09 15:24:06 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2013/01/09 15:24:06 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2013/01/09 15:24:06 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/01/09 15:24:06 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2013/01/09 15:24:06 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2013/01/09 15:24:06 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2013/01/09 15:24:06 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2013/01/09 15:24:06 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2013/01/09 15:24:06 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2013/01/09 15:24:06 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2013/01/09 15:24:06 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/01/09 15:24:06 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2013/01/09 15:24:06 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2013/01/09 15:24:06 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2013/01/09 15:24:06 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2013/01/09 15:24:06 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2013/01/09 15:24:06 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2013/01/09 15:24:06 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2013/01/09 15:23:53 | 000,068,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\taskhost.exe
[2013/01/07 20:10:54 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/01/06 17:05:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Google
[2013/01/06 16:54:23 | 000,000,000 | R–D | C] – C:\Program Files (x86)\Skype
[2013/01/06 16:54:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2013/01/06 16:54:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Skype
[2013/01/06 16:50:16 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Macromedia
[2013/01/06 16:49:51 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Mozilla
[2013/01/06 16:49:51 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Mozilla
[2013/01/06 16:49:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Maintenance Service
[2013/01/06 16:49:40 | 000,000,000 | —D | C] – C:\ProgramData\Mozilla
[2013/01/06 16:49:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2013/01/06 16:45:37 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Adobe
[2012/12/31 22:48:13 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
[2011/08/31 15:16:50 | 000,155,936 | —- | C] (Sysinternals) – C:\Users\User\sdelete.exe
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\User\Desktop\*.tmp files -> C:\Users\User\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/01/29 19:34:17 | 000,022,560 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/01/29 19:34:17 | 000,022,560 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/01/29 19:29:16 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
[2013/01/29 19:28:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/01/29 19:26:43 | 000,000,890 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/01/29 19:26:21 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/01/29 19:26:16 | 2082,299,903 | -HS- | M] () – C:\hiberfil.sys
[2013/01/29 19:23:06 | 000,580,235 | —- | M] () – C:\Users\User\Desktop\adwcleaner.exe
[2013/01/29 19:14:00 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/01/29 18:55:10 | 000,000,322 | —- | M] () – C:\Windows\tasks\HP Photo Creations Communicator.job
[2013/01/29 17:36:21 | 000,000,512 | —- | M] () – C:\Users\User\Desktop\MBR.dat
[2013/01/29 17:22:50 | 004,732,416 | —- | M] (AVAST Software) – C:\Users\User\Desktop\aswMBR.exe
[2013/01/29 17:21:15 | 000,768,512 | —- | M] () – C:\Users\User\Desktop\RogueKiller.exe
[2013/01/29 16:09:45 | 569,332,020 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/01/24 17:59:20 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/23 01:04:23 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2013/01/18 16:30:18 | 000,007,018 | —- | M] () – C:\Users\User\Documents\cc_20130118_163008.reg
[2013/01/18 16:28:57 | 000,000,822 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2013/01/12 03:30:18 | 000,095,648 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/01/12 03:26:16 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/01/12 03:24:49 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013/01/11 20:37:50 | 000,281,688 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.xtr
[2013/01/11 20:37:50 | 000,281,688 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.exe
[2013/01/09 17:14:15 | 000,418,896 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/01/09 16:53:53 | 000,778,702 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2013/01/09 16:53:53 | 000,661,302 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/01/09 16:53:53 | 000,125,388 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/01/09 16:53:46 | 000,778,702 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/01/08 20:28:11 | 000,697,864 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/01/08 20:28:11 | 000,074,248 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/01/08 00:03:20 | 761,440,108 | —- | M] () – C:\Users\User\Desktop\Gw2.dat
[2013/01/07 23:55:47 | 022,301,248 | —- | M] (ArenaNet) – C:\Users\User\Desktop\Gw2.exe
[2013/01/07 00:06:20 | 000,281,688 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.ex0
[2013/01/06 16:54:23 | 000,002,515 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2013/01/06 16:34:22 | 000,001,254 | —- | M] () – C:\Users\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/01/03 23:56:06 | 000,000,024 | —- | M] () – C:\Users\User\random.dat
[2013/01/03 21:13:38 | 000,000,043 | —- | M] () – C:\Users\User\jagex_cl_runescape_LIVE.dat
[2013/01/03 21:12:07 | 000,000,045 | —- | M] () – C:\Users\User\jagex_cl_loginapplet_LIVE.dat
[2013/01/03 16:50:05 | 000,076,888 | —- | M] () – C:\Windows\SysWow64\PnkBstrA.exe
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\User\Desktop\*.tmp files -> C:\Users\User\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/01/29 19:23:02 | 000,580,235 | —- | C] () – C:\Users\User\Desktop\adwcleaner.exe
[2013/01/29 17:36:21 | 000,000,512 | —- | C] () – C:\Users\User\Desktop\MBR.dat
[2013/01/29 17:21:10 | 000,768,512 | —- | C] () – C:\Users\User\Desktop\RogueKiller.exe
[2013/01/25 15:28:40 | 569,332,020 | —- | C] () – C:\Windows\MEMORY.DMP
[2013/01/24 17:59:20 | 000,001,113 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/18 16:30:12 | 000,007,018 | —- | C] () – C:\Users\User\Documents\cc_20130118_163008.reg
[2013/01/07 20:09:49 | 000,000,894 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/01/07 20:09:48 | 000,000,890 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/01/06 16:54:23 | 000,002,515 | —- | C] () – C:\Users\Public\Desktop\Skype.lnk
[2013/01/06 16:49:43 | 000,001,146 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012/11/12 15:04:01 | 000,000,045 | —- | C] () – C:\Users\User\jagex_cl_loginapplet_LIVE.dat
[2012/10/23 18:41:32 | 000,007,605 | —- | C] () – C:\Users\User\AppData\Local\Resmon.ResmonCfg
[2012/07/08 19:13:51 | 000,281,688 | —- | C] () – C:\Windows\SysWow64\PnkBstrB.exe
[2012/07/08 19:13:44 | 000,076,888 | —- | C] () – C:\Windows\SysWow64\PnkBstrA.exe
[2012/07/08 19:13:43 | 003,130,440 | —- | C] () – C:\Windows\SysWow64\pbsvc_blr.exe
[2012/06/29 19:39:11 | 000,000,092 | —- | C] () – C:\Users\User\AppData\Local\fusioncache.dat
[2012/05/04 20:01:13 | 000,778,702 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/05/02 13:58:10 | 000,029,184 | —- | C] () – C:\Windows\SysWow64\kdbsdk32.dll
[2012/04/20 15:36:56 | 000,000,262 | —- | C] () – C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2012/04/13 19:11:43 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2012/04/07 16:10:15 | 000,000,043 | —- | C] () – C:\Users\User\jagex_cl_runescape_LIVE.dat
[2012/04/07 16:10:15 | 000,000,024 | —- | C] () – C:\Users\User\random.dat
[2012/04/06 11:20:21 | 000,008,192 | —- | C] () – C:\Windows\SysWow64\drivers\IntelMEFWVer.dll
[2012/04/06 11:16:26 | 000,145,804 | —- | C] () – C:\Windows\SysWow64\igcompkrng600.bin
[2012/04/06 11:12:53 | 000,000,010 | —- | C] () – C:\Windows\GSetup.ini
[2012/03/19 22:25:58 | 000,058,880 | —- | C] () – C:\Windows\SysWow64\igdde32.dll
[2012/03/19 21:21:14 | 013,212,672 | —- | C] () – C:\Windows\SysWow64\ig4icd32.dll
[2012/03/09 04:31:26 | 000,204,952 | —- | C] () – C:\Windows\SysWow64\ativvsvl.dat
[2012/03/09 04:31:26 | 000,157,144 | —- | C] () – C:\Windows\SysWow64\ativvsva.dat
[2012/02/14 17:47:06 | 000,963,912 | —- | C] () – C:\Windows\SysWow64\igkrng600.bin
[2012/02/14 17:47:06 | 000,261,208 | —- | C] () – C:\Windows\SysWow64\igfcg600m.bin
[2011/09/28 16:44:14 | 000,179,271 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2011/09/12 22:06:16 | 000,003,917 | —- | C] () – C:\Windows\SysWow64\atipblag.dat

========== ZeroAccess Check ==========

[2009/07/14 04:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/09 05:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/09 04:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/14 01:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/21 03:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/14 01:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >
[2007/11/07 07:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe

< MD5 for: EXPLORER.EXE >
[2011/02/26 05:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011/02/25 06:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 06:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 06:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/21 03:24:25 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/02/25 05:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 05:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/11/21 03:24:11 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

< MD5 for: SERVICES.EXE >
[2009/07/14 01:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/14 01:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SVCHOST.EXE >
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009/07/14 01:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\SysWOW64\svchost.exe
[2009/07/14 01:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009/07/14 01:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\SysNative\svchost.exe
[2009/07/14 01:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/21 03:23:55 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\SysWOW64\userinit.exe
[2010/11/21 03:23:55 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010/11/21 03:24:28 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\SysNative\userinit.exe
[2010/11/21 03:24:28 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010/11/21 03:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/21 03:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe

< %systemroot%\*. /rp /s >

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: WDC WD10EADS-22M2B0 ATA Device
Partitions: 2
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 100.00MB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 931.00GB
Starting Offset: 105906176
Hidden sectors: 0


========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\System32\config\systemprofile\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Roaming -> Junction
[C:\Windows\System32\config\systemprofile\Cookies] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies -> Junction
[C:\Windows\System32\config\systemprofile\Documents\My Music] -> C:\Windows\system32\config\systemprofile\Music -> Junction
[C:\Windows\System32\config\systemprofile\Documents\My Pictures] -> C:\Windows\system32\config\systemprofile\Pictures -> Junction
[C:\Windows\System32\config\systemprofile\Documents\My Videos] -> C:\Windows\system32\config\systemprofile\Videos -> Junction
[C:\Windows\System32\config\systemprofile\Local Settings] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\My Documents] -> C:\Windows\system32\config\systemprofile\Documents -> Junction
[C:\Windows\System32\config\systemprofile\NetHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts -> Junction
[C:\Windows\System32\config\systemprofile\PrintHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts -> Junction
[C:\Windows\System32\config\systemprofile\Recent] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent -> Junction
[C:\Windows\System32\config\systemprofile\SendTo] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo -> Junction
[C:\Windows\System32\config\systemprofile\Start Menu] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu -> Junction
[C:\Windows\System32\config\systemprofile\Templates] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates -> Junction
[C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\SysWOW64\config\systemprofile\AppData\Local\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Roaming -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Cookies] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Documents\My Music] -> C:\Windows\system32\config\systemprofile\Music -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Documents\My Pictures] -> C:\Windows\system32\config\systemprofile\Pictures -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Documents\My Videos] -> C:\Windows\system32\config\systemprofile\Videos -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Local Settings] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\SysWOW64\config\systemprofile\My Documents] -> C:\Windows\system32\config\systemprofile\Documents -> Junction
[C:\Windows\SysWOW64\config\systemprofile\NetHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts -> Junction
[C:\Windows\SysWOW64\config\systemprofile\PrintHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Recent] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent -> Junction
[C:\Windows\SysWOW64\config\systemprofile\SendTo] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Start Menu] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Templates] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates -> Junction

< End of report >



OTL Extras logfile created on: 29/01/2013 19:32:17 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\User\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

7.92 Gb Total Physical Memory | 6.38 Gb Available Physical Memory | 80.51% Memory free
15.84 Gb Paging File | 14.11 Gb Available in Paging File | 89.08% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.41 Gb Total Space | 670.13 Gb Free Space | 71.95% Space Free | Partition Type: NTFS

Computer Name: USER-PC | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[HKEY_USERS\S-1-5-21-1447855767-3573926289-1960894109-1000\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
http [open] – "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
http [open] – "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00A1BD4D-C27E-4259-B39A-B7523BA31DBD}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{0DB18632-719A-4CED-959F-18D09644ED5D}" = lport=139 | protocol=6 | dir=in | app=system |
"{111A7768-034C-4CFC-883F-2DCB17AC9DF7}" = rport=445 | protocol=6 | dir=out | app=system |
"{1C7D4E1C-F713-40B0-A3B5-98D95D82C844}" = lport=138 | protocol=17 | dir=in | app=system |
"{2258FD3D-4005-4710-B213-6142F9660AD3}" = lport=19540 | protocol=17 | dir=in | name=sxuptp |
"{2307C2CE-9976-41D4-A061-467B778455A9}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |
"{2D3C2E51-8C9B-454E-8712-68BA9B995449}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{470D25AE-2F07-4EC9-A6D5-8A568F381E53}" = rport=138 | protocol=17 | dir=out | app=system |
"{52405A3B-0BEB-4F84-8E63-1B9987741F42}" = rport=137 | protocol=17 | dir=out | app=system |
"{5A83AB36-BB43-499B-8E58-A2B3A2368D67}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{5E126A60-8115-4C17-9A49-77C7EA46FBCD}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{6107AD74-BB60-4C1C-AFCE-23B81CE7C0D1}" = rport=10243 | protocol=6 | dir=out | app=system |
"{65428B12-4D21-490F-9498-E149C19D973A}" = lport=10243 | protocol=6 | dir=in | app=system |
"{66400551-1180-495D-BC7E-0C868696FDA3}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{69259B16-FCB0-4A7D-81F5-8EC6BC324E27}" = rport=139 | protocol=6 | dir=out | app=system |
"{77DB61EC-903F-4CD6-BC4B-714CCD27670A}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{79AE8CDD-004E-4B07-9189-4303FFF10344}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{7E80FB7D-7DFF-46DF-92F2-2FF893D9D3B3}" = lport=445 | protocol=6 | dir=in | app=system |
"{86449AAA-CBCB-4730-8913-9A58C81B8DEC}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{8AFF2EBF-895E-41A4-B0B9-06F7A50ED1A6}" = lport=2869 | protocol=6 | dir=in | app=system |
"{C6EB7CC5-3E38-44C2-B3C6-D87E3FE27E07}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{E170DF3C-AD55-4B4C-A561-BBB695BF1365}" = lport=49170 | protocol=6 | dir=in | name=akamai netsession interface |
"{E4574A52-B55A-4C58-A8E8-C9781272AB64}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{E84C621F-2DC4-4F43-AC90-DD0772754AB8}" = lport=137 | protocol=17 | dir=in | app=system |
"{F7E0D4CA-7DA3-4891-9805-63F63DB027B7}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{F825F10B-91DA-4821-BD18-7EBDEA6AF6BA}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{FF80DBD9-3CA4-4A91-8C93-E21809AC087F}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{018BBE3B-D3ED-427E-8DF7-10A5F9FF2949}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\batman2\runlauncher.bat |
"{01D86EE9-BA63-47D9-B11F-5E23BA7E0BE6}" = protocol=6 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"{021C8CAF-CFF3-43C1-946D-581C6D9ABA77}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\saints row the third\game_launcher.exe |
"{045C9E1A-F2E7-46E3-998F-990A74315C36}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{072831C8-AE2D-49DA-A06F-9857B3673780}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops ii\t6zm.exe |
"{07D2D9CC-BDF1-4D87-B44F-3EE758E38BAF}" = protocol=17 | dir=in | app=c:\program files\hp\hp deskjet 1050 j410 series\bin\usbsetup.exe |
"{0A7AF4D5-ED78-49F7-933C-C1099FE28C6D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\darksiders\darksiderspc.exe |
"{134D3849-F2FA-4B86-B98B-8F6F5CC7E3F8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\red faction armageddon\redfactionarmageddon.exe |
"{153C6685-A72D-4168-BB94-86F87629F7C6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\darksiders\darksiderspc.exe |
"{155FA35C-BEC1-46B4-BF16-DA614AC8D0DA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\batman2\binaries\win32\batmanac.exe |
"{157618B8-C6A5-46F0-933C-BAED3FE4E983}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{1E37C33B-F93B-4F40-BEE3-D73D3ACDB513}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{1EE15939-1CFE-49FA-92C3-6F4812726AE9}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal 2\portal2.exe |
"{1F15C94E-D649-464B-9CD4-175D52D553CE}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{29F088EA-3779-475D-90F5-CEE80FD322DC}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\amd driver updater, vista and 7, 64 bit\setup.exe |
"{2A75ABCA-883D-4639-BF9E-38E173A65039}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{2E195B4E-4ED1-472C-987A-212B443D0026}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\metro 2033\metro2033.exe |
"{2EA90583-A4B2-4AF8-89EF-4801F8214DDF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\batman2\runlauncher.bat |
"{2F1F8E36-78B8-4DFF-BF39-FDBCF20BB0DC}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dxhrml\dxhrml.exe |
"{31F9B89E-9185-4A9E-9C4D-19A51A5A0618}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\plants vs zombies\plantsvszombies.exe |
"{35F1DE9B-9645-42DC-B937-141F84AE58EF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\metro 2033\metro2033.exe |
"{394547EE-0FFF-42B8-9EE0-570FD3EFEECF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\far cry 3\bin\farcry3_d3d11.exe |
"{3D3342F3-D309-4333-BB77-10558C4D1B8E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\far cry 3\bin\farcry3.exe |
"{3F22A813-4D76-47CB-9583-F0BC2A9CC871}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe |
"{43A25263-78B3-4326-9D7D-8020E3823EC4}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{4476ADD2-D8CB-44D7-9DCC-E1299D117C24}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dishonored\binaries\win32\dishonored.exe |
"{48BCD623-8FFF-4954-9AE5-744DECA60FB1}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{4A3A2AD6-F69A-42A9-ABE2-67E55AE10605}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{5529C64A-FCEA-48CD-B269-187DE736CB60}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\deus ex - human revolution\dxhr.exe |
"{5D6F3277-868E-471E-AD57-568BF13A8C1D}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{5D996167-B623-4263-BE17-F5CFED384B04}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops ii\t6mp.exe |
"{604C9C23-6D47-42A0-8A28-8AB8C66230B5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bastion\bastion.exe |
"{629465EF-631C-4837-9F89-54DB6EF2FB30}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\skyrim\skyrimlauncher.exe |
"{6B7267C9-BE0F-42C9-AE55-9AF38CCEBE5D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\red faction armageddon\rf4_launcher.exe |
"{6E19CD9B-3464-48D9-9574-0CC10680444C}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{6E568653-D009-4127-989D-EB2594A5961A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\red faction armageddon\redfactionarmageddon_dx11.exe |
"{6F4A63C1-7A37-43B9-AEAB-078BE9D1DA10}" = protocol=17 | dir=in | app=c:\program files (x86)\belkin\router setup and monitor\belkinsetup.exe |
"{73D27C75-39BF-4D35-97F9-30597E584791}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{74266629-9B9C-47AC-BEBC-2DE883EB2670}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\far cry 3\bin\farcry3.exe |
"{7474F10F-9CB9-491F-BB8F-324F9D04F27D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe |
"{776F10A7-B49D-41DD-96FC-02E29361F367}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\far cry 3\bin\fc3updatersteam.exe |
"{7883892E-CF6E-45B9-B64F-BD172E59D59C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\batman2\binaries\win32\batmanac.exe |
"{79E1D9F9-285D-4614-8DC0-CB4026DBF052}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{7A56BE9A-BC91-4258-A8EA-2BF542A124A7}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{7A876B84-A43E-4195-874D-9AAC51947215}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{7CBB3F39-2E79-4BC6-B3C1-3F7E3B6CF3C3}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\saints row the third\game_launcher.exe |
"{7E31E05D-AACE-4AD4-83EE-BAE8116FEF24}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\payday the heist\payday_win32_release.exe |
"{7E5AB468-759D-4A58-8651-9656C462AFA4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\launcher.exe |
"{861A6B8E-E418-413A-A9CE-0554CBC06084}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\gotham city impostors\engine.exe |
"{8671845F-27A0-4A1F-90AD-6A7A0246CEF5}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{8BEC870F-4559-4698-B310-4C6F9DE16A58}" = protocol=6 | dir=in | app=c:\program files (x86)\belkin\router setup and monitor\belkinsetup.exe |
"{8FAA4B02-F628-45AE-A96C-FD8B9D32F57A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops ii\t6sp.exe |
"{9039FE6E-5134-4441-A239-49B68969E25E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops ii\t6zm.exe |
"{931CDAC7-6B6B-48E3-BD34-54CA61F7498A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{94CB7011-C845-4D46-8A53-2C6860D4BF91}" = dir=in | app=c:\program files (x86)\belkin\router setup and monitor\belkinsetup.exe |
"{979C9317-06B8-4EC9-AC8F-1572837C3B47}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dishonored\binaries\win32\dishonored.exe |
"{9B23D184-A444-41C2-A992-4CDC83BD02B3}" = protocol=6 | dir=in | app=c:\program files\hp\hp deskjet 1050 j410 series\bin\usbsetup.exe |
"{9C4E6B78-ECA8-4FDB-9D52-87EB5202D32D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\far cry 3\bin\farcry3_d3d11.exe |
"{9CEC688C-194E-4F19-A45D-D2DBEBCD13FF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\plants vs zombies\plantsvszombies.exe |
"{9CF3974F-EEB6-402C-AA5B-36C0F4C06C51}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{9E9C0EA7-A812-4017-8933-43A04C0B6D0D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe |
"{9EB05E39-519A-4722-ABAD-DEF0D35ECBAF}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{9F10F4E6-5A43-4CD6-99A7-16A03A310B3E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\payday the heist\payday_win32_release.exe |
"{9F8D0E36-2828-467A-A8B7-7A3B4D5FD2C5}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{A091972F-4DFE-4561-BF77-992494AE00C7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\red faction armageddon\rf4_launcher.exe |
"{A15E6A5C-FC9E-4AF1-AABF-7DE64E68F49C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal 2\portal2.exe |
"{A2AEFD1A-15F2-4322-BD40-21404C585759}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\skyrim\skyrimlauncher.exe |
"{A789C6AE-6F9E-42A8-B67A-03E8E39EBA91}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\far cry 3\bin\fc3updatersteam.exe |
"{A79D617E-20E4-4789-8875-DAC46865F72D}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{A7A079CB-04CA-4DCC-9193-EACB9589C929}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\gotham city impostors\impostors.exe |
"{A89785D4-DEAF-4BAA-B04D-C68A898110FF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{ABC28AA2-B68E-4E64-B057-789CDA5C681D}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{AD790D78-9A2C-432C-95E2-B8FF85A943FC}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{AE058D47-E2FD-4481-B8FF-8541B01DD656}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{AF62D737-1DF2-4C66-854A-6D2D1BA465F0}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{B5EC695F-04D1-467B-AEF6-280ABF81541F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{B5F37AA6-C303-4551-AAE1-67790CD854A8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bastion\bastion.exe |
"{B8D48CD6-3388-4F66-AA63-9329A3E753C2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops ii\t6mp.exe |
"{BA05C965-87F5-4295-B863-D7E66B162065}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\launcher.exe |
"{BB6121D3-F419-4E92-8D48-56548871595D}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{BE017BF2-9BD9-4262-8AF9-FF7719E478D7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\gotham city impostors\engine.exe |
"{BFA289DC-FAE9-40E7-B552-EEF2549D7D69}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\gotham city impostors\impostors.exe |
"{C1065C69-F680-4D59-8CE8-4D8BC3E55FF7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\wormsrevolution\wormsrevolution.exe |
"{C69F878E-0E36-4D9D-8BD8-FF56633607FE}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{C72F683D-03A2-415F-9D9D-C6AB9F5A698B}" = protocol=17 | dir=in | app=c:\program files (x86)\belkin\router setup and monitor\belkinsetup.exe |
"{C77FE893-8242-4852-BE1F-E4F307AF6F13}" = protocol=6 | dir=in | app=c:\program files (x86)\belkin\router setup and monitor\belkinsetup.exe |
"{CACC25C4-6240-4070-9407-3C3B8E96B590}" = protocol=6 | dir=out | app=system |
"{CD9A0703-DB31-4CC4-A806-3958076268EF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{D0D49643-612E-4A39-B48F-1DBFEA1D7E6B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\wormsrevolution\wormsrevolution.exe |
"{D135E569-306A-4EED-BBF5-359F747E7E8E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\red faction armageddon\redfactionarmageddon.exe |
"{D7C750D6-B7C3-471A-A0C1-3F18AF95D08F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe |
"{DB6D73D6-352D-412F-BA53-43D93315204F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops ii\t6sp.exe |
"{E128E459-8A07-4E00-822B-5E415232D5CC}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\amd driver updater, vista and 7, 64 bit\setup.exe |
"{E2C54F63-DC3F-48C1-AE8B-180FBCA1E065}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\deus ex - human revolution\dxhr.exe |
"{E476579E-8DC2-45C4-96A9-B84C63913E9A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{E5FE7906-E201-4022-BAFC-BE1E01EC4B0B}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{EAA04ED0-E034-42ED-81C3-38E97F5D2266}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{EBB458E8-392F-4D86-B67A-1E8731082A80}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{EE65F383-4F78-4818-81E8-0B03FE667DC4}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\red faction armageddon\redfactionarmageddon_dx11.exe |
"{F076FDD7-5860-4843-93B7-33DCE07FF044}" = protocol=17 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"{F1E5342E-BA43-4393-A957-08A2BAB04020}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{F4016852-763C-45FE-9382-ABBFD9820A4E}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{F5233A05-E03A-45D2-A4FD-4323771DB93E}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{F55FED4F-8DA1-4233-930C-F6CFDA823BE2}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{F779E6E2-FAE4-457F-9BFF-3BBC11BCCABD}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dxhrml\dxhrml.exe |
"{FD9ADE17-7279-42D2-B32D-F6C76C3ECE7F}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{FE0D29FD-49F2-493A-98CD-E5C7BDD56033}" = dir=in | app=c:\program files\belkin\belkin usb print and storage center\connect.exe |
"TCP Query User{5D5BCAD9-7C60-49DE-80A0-9CA3B24E5FCC}C:\users\user\desktop\gw2.exe" = protocol=6 | dir=in | app=c:\users\user\desktop\gw2.exe |
"TCP Query User{7CDD5E9E-8ED3-4A34-BBE9-4B850FB8CA27}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe |
"UDP Query User{A9561244-0202-4F34-94B4-D424B472B73B}C:\users\user\desktop\gw2.exe" = protocol=17 | dir=in | app=c:\users\user\desktop\gw2.exe |
"UDP Query User{FB418785-536B-4361-8478-A0E0A32C92F6}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{06DB2C4C-DC29-DA42-3B00-5581CBF545BB}" = AMD Drag and Drop Transcoding
"{1AB4DB8C-4123-45DC-B896-C67990F76DA4}" = HP Deskjet 1050 J410 series Product Improvement Study
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{4268BF51-DFDF-4178-8B8D-5D5752FCAA58}" = HP Deskjet 1050 J410 series Basic Device Software
"{4975DE61-6BF6-B9BC-1FDE-C04C5EC78E4C}" = AMD Media Foundation Decoders
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{5E03A267-415E-5383-FA8F-3CE4145663B9}" = AMD Catalyst Install Manager
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{89EE4A30-080F-2C95-6F78-C98D18FBD74D}" = AMD Accelerated Video Transcoding
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-0015-0409-1000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-1000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-1000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-1000-0000000FF1CE}_Office14.SingleImage_{0242505C-4E90-407F-9299-B5B275F50D86}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-1000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-1000-0000000FF1CE}_Office14.SingleImage_{B51389C8-2890-4633-81D8-47D2A7402274}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-1000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-1000-0000000FF1CE}_Office14.SingleImage_{1779650B-2E44-4A19-8DF6-3866D645764A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-1000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-1000-0000000FF1CE}_Office14.SingleImage_{270CA0B9-9881-44DB-BC3B-37C7E66A044A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-1000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{7BC9B5EB-125A-4E9B-97E1-8D85B5E960B8}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010
"{90140000-0043-0000-1000-0000000FF1CE}_Office14.SingleImage_{E8B6D35B-0B6F-4DCE-9493-859BF3809A7F}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0043-0409-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (English) 2010
"{90140000-0043-0409-1000-0000000FF1CE}_Office14.SingleImage_{FCD1C311-8B02-4DBD-BA46-1079C629577E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-1000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-1000-0000000FF1CE}_Office14.SingleImage_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-1000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-1000-0000000FF1CE}_Office14.SingleImage_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-1000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{9CF11D16-ECEB-90A5-A028-CA9E068D848B}" = ccc-utility64
"{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}" = Ventrilo Client for Windows x64
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Belkin USB Print and Storage Center" = Belkin USB Print and Storage Center
"CCleaner" = CCleaner
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Office14.SingleImage" = Microsoft Office Professional 2010
"WinRAR archiver" = WinRAR 4.11 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{017F8447-2A1D-0DDB-B5D7-CA2BFACE2886}" = CCC Help French
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{054E9A1C-3EA2-C657-E787-FD8DCF5C3D3B}" = CCC Help Czech
"{14DC0059-00F1-4F62-BD1A-AB23CD51A95E}" = Adobe AIR
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1DE2BD51-0300-772D-5E18-F337D95D5687}" = CCC Help German
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{224E8FEB-5C1F-077F-6FC5-602AC1AE644D}" = CCC Help Danish
"{26A24AE4-039D-4CA4-87B4-2F83216033FF}" = Java™ 6 Update 37
"{26A24AE4-039D-4CA4-87B4-2F83217010FF}" = Java 7 Update 11
"{275E9C49-C72F-D754-DEB7-77F10A9C00D8}" = CCC Help Japanese
"{30049739-BE95-6591-B504-E6D7057D49CC}" = CCC Help Spanish
"{3DECD372-76A1-4483-BF10-B547790A3261}" = ON_OFF Charge B11.0110.1
"{3F1EB155-F96E-EB7B-2EF2-7375490E0FA9}" = CCC Help English
"{456A5815-604D-4D72-94DF-346D2B978A59}_is1" = GOG.com Downloader version 3.0.52
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B023D7B-9E67-795D-FB31-B5E1F6DCA451}" = CCC Help Italian
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{54B7A3C7-0940-4C16-A509-FC3C3758D22A}_is1" = Amnesia - The Dark Descent
"{55F6C486-8C75-2A72-DAFE-CE78A624C9F7}" = CCC Help Russian
"{5AF23993-7152-1620-E43F-1B4542FB4F84}" = CCC Help Thai
"{5C90D8CF-F12A-41C6-9007-3B651A1F0D78}" = HP Deskjet 1050 J410 series Help
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{63326924-3CAF-C858-3A8F-8598C87019D7}" = Catalyst Control Center
"{63822E89-11AA-F8EC-D433-F72A85799EC0}" = CCC Help Greek
"{64467D47-FFE4-4FBC-ABBA-A0DB829A17EB}" = NVIDIA PhysX
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{660787DD-68B3-4E67-9073-4A66DD7AD193}" = ASUS VGA Driver
"{66361420-4905-AEB8-17AE-172FDD164A7E}" = CCC Help Polish
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{769F2A4B-84A3-9486-ADD2-9E5AB4B4E1E3}" = Catalyst Control Center InstallProxy
"{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}" = Microsoft Games for Windows - LIVE Redistributable
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8773DD1C-5FB2-95B5-5A93-0EFEAC900A4D}" = CCC Help Norwegian
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8CCBB0BF-9CC1-1A65-BB93-56012A460EE6}" = CCC Help Portuguese
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9FD6F1A8-5550-46AF-8509-271DF0E768B5}" = Dual-Core Optimizer
"{A0A3CE05-96CB-52E9-434E-074F3BB7807E}" = CCC Help Turkish
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9C64319-932F-D02B-B14C-FFFC3EC49E77}" = CCC Help Chinese Standard
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.5)
"{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update
"{B93EEE50-9C8F-45DF-95E4-3D85A6E242F3}" = DarksidersInstaller
"{C09DB932-7619-7B56-30E3-C0454811D6D7}" = CCC Help Korean
"{C22A4697-BD77-ACB1-744F-1FD0A0BFF798}" = CCC Help Swedish
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D4B457B2-260F-C561-CA87-703BD3B724CA}" = Catalyst Control Center Graphics Previews Common
"{D6CDB506-297D-AE70-0EF6-DE5185F961BE}" = CCC Help Chinese Traditional
"{D7AF16E7-5938-4369-BA54-B1ABD541BC32}" = Utility
"{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}" = Etron USB3.0 Host Controller
"{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}" = Catalyst Control Center - Branding
"{E5F05232-96B6-4552-A480-785A60A94B21}" = System Requirements Lab CYRI
"{EA17F4FC-FDBF-4CF8-A529-2D983132D053}" = Skype™ 6.0
"{ECFD508E-68A2-91B2-46DD-1D03D783D94B}" = Catalyst Control Center Localization All
"{EDE361D5-35A5-DA7D-3462-C3DABD24029B}" = CCC Help Hungarian
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Processor Graphics
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1E7DD6A-AE2D-D706-BEB3-937F76CA6AE9}" = CCC Help Finnish
"{F56F54DD-BCB2-1221-2CB7-E983A5CF9D15}" = CCC Help Dutch
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"8461-7759-5462-8226" = Vuze
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"avast" = avast! Internet Security
"Belkin Setup and Router Monitor_is1" = Belkin Setup and Router Monitor
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"Google Chrome" = Google Chrome
"Guild Wars" = Guild Wars
"HP Photo Creations" = HP Photo Creations
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100
"Mozilla Firefox 13.0.1 (x86 en-US)" = Mozilla Firefox 13.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NCLauncher_GameForge" = NC Launcher (GameForge)
"PunkBusterSvc" = PunkBuster Services
"SpeedFan" = SpeedFan (remove only)
"Steam App 107100" = Bastion
"Steam App 200170" = Worms Revolution
"Steam App 201280" = Deus Ex: Human Revolution - The Missing Link
"Steam App 202970" = Call of Duty: Black Ops II
"Steam App 202990" = Call of Duty: Black Ops II - Multiplayer
"Steam App 205100" = Dishonored
"Steam App 20540" = Company of Heroes: Tales of Valor
"Steam App 21170" = Gotham City Impostors
"Steam App 212910" = Call of Duty: Black Ops II - Zombies
"Steam App 220240" = Far Cry® 3
"Steam App 24240" = PAYDAY: The Heist
"Steam App 28050" = Deus Ex: Human Revolution
"Steam App 3590" = Plants vs. Zombies: Game of the Year
"Steam App 43110" = Metro 2033
"Steam App 4560" = Company of Heroes
"Steam App 49520" = Borderlands 2
"Steam App 50620" = Darksiders
"Steam App 550" = Left 4 Dead 2
"Steam App 55110" = Red Faction: Armageddon
"Steam App 55230" = Saints Row: The Third
"Steam App 57400" = Batman: Arkham City™
"Steam App 620" = Portal 2
"Steam App 72850" = The Elder Scrolls V: Skyrim
"Steam App 9340" = Company of Heroes: Opposing Fronts
"Super Meat Boy v1.5_is1" = Super Meat Boy v1.5
"Uplay" = Uplay
"Video Mover_is1" = Video Mover
"xvid" = XviD MPEG-4 Video Codec

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1447855767-3573926289-1960894109-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Square Enix Secure Launcher" = Square Enix Secure Launcher

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 25/01/2013 18:17:52 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application name: WLIDSVC.EXE, version: 6.500.3165.0, time
stamp: 0x4a8b055b Faulting module name: msxml3.dll, version: 8.110.7601.17988, time
stamp: 0x50920c3d Exception code: 0xc0000005 Fault offset: 0x0000000000002300 Faulting
process id: 0x9dc Faulting application start time: 0x01cdfb49ca181577 Faulting application
path: c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE Faulting
module path: C:\Windows\System32\msxml3.dll Report Id: 0eefe54b-673d-11e2-aa52-50e549e3d4df

Error - 25/01/2013 18:18:10 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application name: WLIDSVC.EXE, version: 6.500.3165.0, time
stamp: 0x4a8b055b Faulting module name: msxml3.dll, version: 8.110.7601.17988, time
stamp: 0x50920c3d Exception code: 0xc0000005 Fault offset: 0x0000000000002300 Faulting
process id: 0xcd0 Faulting application start time: 0x01cdfb49dafd39c9 Faulting application
path: c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE Faulting
module path: C:\Windows\System32\msxml3.dll Report Id: 199b3b36-673d-11e2-aa52-50e549e3d4df

Error - 25/01/2013 18:18:20 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application name: WLIDSVC.EXE, version: 6.500.3165.0, time
stamp: 0x4a8b055b Faulting module name: msxml3.dll, version: 8.110.7601.17988, time
stamp: 0x50920c3d Exception code: 0xc0000005 Fault offset: 0x0000000000002300 Faulting
process id: 0x1234 Faulting application start time: 0x01cdfb49e218d9cb Faulting application
path: c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE Faulting
module path: C:\Windows\System32\msxml3.dll Report Id: 1fdad10e-673d-11e2-aa52-50e549e3d4df

Error - 25/01/2013 18:18:21 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application name: wmpnetwk.exe, version: 12.0.7601.17514,
time stamp: 0x4ce7ae7f Faulting module name: msxml3.dll, version: 8.110.7601.17988,
time stamp: 0x50920c3d Exception code: 0xc0000005 Fault offset: 0x0000000000002300
Faulting
process id: 0x1034 Faulting application start time: 0x01cdfb49deb7b4d4 Faulting application
path: C:\Program Files\Windows Media Player\wmpnetwk.exe Faulting module path: C:\Windows\System32\msxml3.dll
Report
Id: 20354558-673d-11e2-aa52-50e549e3d4df

Error - 25/01/2013 18:18:56 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application name: wmpnetwk.exe, version: 12.0.7601.17514,
time stamp: 0x4ce7ae7f Faulting module name: msxml3.dll, version: 8.110.7601.17988,
time stamp: 0x50920c3d Exception code: 0xc0000005 Fault offset: 0x0000000000002300
Faulting
process id: 0xa14 Faulting application start time: 0x01cdfb49f72114dd Faulting application
path: C:\Program Files\Windows Media Player\wmpnetwk.exe Faulting module path: C:\Windows\System32\msxml3.dll
Report
Id: 3525b2a7-673d-11e2-aa52-50e549e3d4df

Error - 25/01/2013 18:19:27 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application name: wmpnetwk.exe, version: 12.0.7601.17514,
time stamp: 0x4ce7ae7f Faulting module name: msxml3.dll, version: 8.110.7601.17988,
time stamp: 0x50920c3d Exception code: 0xc0000005 Fault offset: 0x0000000000002300
Faulting
process id: 0xfcc Faulting application start time: 0x01cdfb4a096a3f00 Faulting application
path: C:\Program Files\Windows Media Player\wmpnetwk.exe Faulting module path: C:\Windows\System32\msxml3.dll
Report
Id: 4760dbef-673d-11e2-aa52-50e549e3d4df

Error - 25/01/2013 18:39:53 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application name: wmpnetwk.exe, version: 12.0.7601.17514,
time stamp: 0x4ce7ae7f Faulting module name: msxml3.dll, version: 8.110.7601.17988,
time stamp: 0x50920c3d Exception code: 0xc0000005 Fault offset: 0x0000000000002300
Faulting
process id: 0x934 Faulting application start time: 0x01cdfb4a17c70fc6 Faulting application
path: C:\Program Files\Windows Media Player\wmpnetwk.exe Faulting module path: C:\Windows\System32\msxml3.dll
Report
Id: 22276e34-6740-11e2-aa52-50e549e3d4df

Error - 26/01/2013 11:59:30 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application name: svchost.exe_BFE, version: 6.1.7600.16385,
time stamp: 0x4a5bc3c1 Faulting module name: ntdll.dll, version: 6.1.7601.17725,
time stamp: 0x4ec4aa8e Exception code: 0xc0000005 Fault offset: 0x000000000005324e
Faulting
process id: 0x774 Faulting application start time: 0x01cdfbde03f34c8d Faulting application
path: C:\Windows\system32\svchost.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report
Id: 5da4767e-67d1-11e2-bdf8-50e549e3d4df

Error - 26/01/2013 13:22:11 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application name: Skype.exe, version: 6.0.0.126, time stamp:
0x509ce778 Faulting module name: Skype.exe, version: 6.0.0.126, time stamp: 0x509ce778
Exception
code: 0xc0000005 Fault offset: 0x001c5730 Faulting process id: 0xc9c Faulting application
start time: 0x01cdfbe9abb827fb Faulting application path: C:\Program Files (x86)\Skype\Phone\Skype.exe
Faulting
module path: C:\Program Files (x86)\Skype\Phone\Skype.exe Report Id: ea934fbf-67dc-11e2-bdf8-50e549e3d4df

Error - 26/01/2013 13:42:00 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application name: svchost.exe_SysMain, version: 6.1.7600.16385,
time stamp: 0x4a5bc3c1 Faulting module name: sysmain.dll, version: 6.1.7601.17514,
time stamp: 0x4ce7c9db Exception code: 0xc0000005 Fault offset: 0x0000000000012caf
Faulting
process id: 0xabc Faulting application start time: 0x01cdfbde109afd62 Faulting application
path: C:\Windows\system32\svchost.exe Faulting module path: c:\windows\system32\sysmain.dll
Report
Id: af58b75a-67df-11e2-bdf8-50e549e3d4df

Error - 26/01/2013 13:43:01 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application name: svchost.exe_SysMain, version: 6.1.7600.16385,
time stamp: 0x4a5bc3c1 Faulting module name: sysmain.dll, version: 6.1.7601.17514,
time stamp: 0x4ce7c9db Exception code: 0xc0000005 Fault offset: 0x000000000001e59a
Faulting
process id: 0x448 Faulting application start time: 0x01cdfbec95bea648 Faulting application
path: C:\Windows\system32\svchost.exe Faulting module path: c:\windows\system32\sysmain.dll
Report
Id: d3b59158-67df-11e2-bdf8-50e549e3d4df

Error - 26/01/2013 14:41:12 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application name: BelkinRouterMonitor.exe, version: 4.0.6.24160,
time stamp: 0x4de00026 Faulting module name: QtCore4.dll, version: 4.5.3.0, time
stamp: 0x4ba3e827 Exception code: 0x80000003 Fault offset: 0x000e96dc Faulting process
id: 0xb34 Faulting application start time: 0x01cdfbf4a822e927 Faulting application
path: C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe
Faulting
module path: C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtCore4.dll
Report
Id: f4a47bbf-67e7-11e2-81eb-50e549e3d4df

Error - 26/01/2013 14:41:14 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application name: dlnaPlugin.exe, version: 0.9.0.1, time
stamp: 0x4dd449b0 Faulting module name: QtCore4.dll, version: 4.5.3.0, time stamp:
0x4ba3e827 Exception code: 0x80000003 Fault offset: 0x000e96dc Faulting process id:
0xa7c Faulting application start time: 0x01cdfbf4ac43cc21 Faulting application path:
C:\Program Files (x86)\Belkin\Router Setup and Monitor\dlnaPlugin.exe Faulting module
path: C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtCore4.dll Report
Id: f5a3002d-67e7-11e2-81eb-50e549e3d4df

Error - 28/01/2013 09:59:36 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application name: svchost.exe_Power, version: 6.1.7600.16385,
time stamp: 0x4a5bc3c1 Faulting module name: ole32.dll, version: 6.1.7601.17514,
time stamp: 0x4ce7c92c Exception code: 0xc0000005 Fault offset: 0x0000000000029158
Faulting
process id: 0x32c Faulting application start time: 0x01cdfd5f96e0bf40 Faulting application
path: C:\Windows\system32\svchost.exe Faulting module path: C:\Windows\system32\ole32.dll
Report
Id: f27a5cd8-6952-11e2-81e0-50e549e3d4df

Error - 28/01/2013 10:35:57 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application name: LolClient.exe, version: 2.0.2.12610, time
stamp: 0x4c00573a Faulting module name: Adobe AIR.dll, version: 3.1.0.4880, time
stamp: 0x4eb75fb9 Exception code: 0xc0000005 Fault offset: 0x00480048 Faulting process
id: 0x1460 Faulting application start time: 0x01cdfd64811cf759 Faulting application
path: C:\Riot Games\RADS\projects\lol_air_client\releases\0.0.0.233\deploy\LolClient.exe
Faulting
module path: C:\Riot Games\RADS\projects\lol_air_client\releases\0.0.0.233\deploy\Adobe
AIR\Versions\1.0\Adobe AIR.dll Report Id: 06ed6c4b-6958-11e2-ae6d-50e549e3d4df

Error - 28/01/2013 18:51:31 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application name: League of Legends.exe, version: 1.0.0.154,
time stamp: 0x50f5f2eb Faulting module name: fmodex.dll, version: 0.4.32.7, time
stamp: 0x4d2667ec Exception code: 0xc0000005 Fault offset: 0x0003ed98 Faulting process
id: 0x1b74 Faulting application start time: 0x01cdfda9dd049270 Faulting application
path: C:\Riot Games\League of Legends\RADS\solutions\lol_game_client_sln\releases\0.0.0.207\deploy\League
of Legends.exe Faulting module path: C:\Riot Games\League of Legends\RADS\solutions\lol_game_client_sln\releases\0.0.0.207\deploy\fmodex.dll
Report
Id: 416f7f83-699d-11e2-ae6d-50e549e3d4df

Error - 28/01/2013 19:50:35 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application name: League of Legends.exe, version: 1.0.0.154,
time stamp: 0x50f5f2eb Faulting module name: unknown, version: 0.0.0.0, time stamp:
0x00000000 Exception code: 0xc0000005 Fault offset: 0xff000000 Faulting process id:
0x1b30 Faulting application start time: 0x01cdfdaf06182f6b Faulting application path:
C:\Riot Games\RADS\solutions\lol_game_client_sln\releases\0.0.0.207\deploy\League
of Legends.exe Faulting module path: unknown Report Id: 81d27acd-69a5-11e2-ae6d-50e549e3d4df

Error - 29/01/2013 11:11:10 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application name: mbamservice.exe, version: 1.70.0.0, time
stamp: 0x50cb9148 Faulting module name: mbamservice.exe, version: 1.70.0.0, time
stamp: 0x50cb9148 Exception code: 0xc0000005 Fault offset: 0x000255a3 Faulting process
id: 0x8fc Faulting application start time: 0x01cdfe318fdecd8e Faulting application
path: C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe Faulting
module path: C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe Report
Id: 1c50b4cd-6a26-11e2-bdfe-50e549e3d4df

[ Media Center Events ]
Error - 09/04/2012 08:22:47 | Computer Name = User-PC | Source = MCUpdate | ID = 0
Description = 13:22:47 - Error connecting to the internet. 13:22:47 - Unable
to contact server..

[ System Events ]
Error - 29/01/2013 15:25:38 | Computer Name = User-PC | Source = Service Control Manager | ID = 7001
Description = The Peer Networking Grouping service depends on the Peer Name Resolution
Protocol service which failed to start because of the following error: %%-2140993535

Error - 29/01/2013 15:27:22 | Computer Name = User-PC | Source = PNRPSvc | ID = 102
Description =

Error - 29/01/2013 15:27:22 | Computer Name = User-PC | Source = Service Control Manager | ID = 7023
Description = The Peer Name Resolution Protocol service terminated with the following
error: %%-2140993535

Error - 29/01/2013 15:27:22 | Computer Name = User-PC | Source = Service Control Manager | ID = 7001
Description = The Peer Networking Grouping service depends on the Peer Name Resolution
Protocol service which failed to start because of the following error: %%-2140993535

Error - 29/01/2013 15:27:32 | Computer Name = User-PC | Source = PNRPSvc | ID = 102
Description =

Error - 29/01/2013 15:27:32 | Computer Name = User-PC | Source = PNRPSvc | ID = 102
Description =

Error - 29/01/2013 15:27:32 | Computer Name = User-PC | Source = Service Control Manager | ID = 7023
Description = The Peer Name Resolution Protocol service terminated with the following
error: %%-2140993535

Error - 29/01/2013 15:27:32 | Computer Name = User-PC | Source = Service Control Manager | ID = 7001
Description = The Peer Networking Grouping service depends on the Peer Name Resolution
Protocol service which failed to start because of the following error: %%-2140993535

Error - 29/01/2013 15:27:32 | Computer Name = User-PC | Source = Service Control Manager | ID = 7023
Description = The Peer Name Resolution Protocol service terminated with the following
error: %%-2140993535

Error - 29/01/2013 15:27:32 | Computer Name = User-PC | Source = Service Control Manager | ID = 7001
Description = The Peer Networking Grouping service depends on the Peer Name Resolution
Protocol service which failed to start because of the following error: %%-2140993535


< End of report >
Hi Derpina

That's looking a bit better but a few stragglers to deal with.

Note: If you have MalwareBytes Anti-Malware 1.6 or higher installed and are using the Pro version or trial version, please temporarily disable it for the duration of this fix as it may interfere with the successfully execution of the script below.

Run OTL
  • double click on the icon to run it.
  • copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    IE - HKU\S-1-5-21-1447855767-3573926289-1960894109-1000\..\SearchScopes\{63B2D943-91F1-4a04-B9AA-390B3CE4A909}: "URL" = http://www.bing.com/search?q={searchTerms}…BR1&pc=SPLH
    IE - HKU\S-1-5-21-1447855767-3573926289-1960894109-1000\..\SearchScopes\{89702040-18AF-416b-B0E0-7012894C77FE}: "URL" = http://uk.search.yahoo.com/search?p={searc…amp;type=IEBDSV
    IE - HKU\S-1-5-21-1447855767-3573926289-1960894109-1000\..\SearchScopes\{BABCB421-7CA1-4B5C-BB0A-2A118CB6305B}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2504091
    IE - HKU\S-1-5-21-1447855767-3573926289-1960894109-1000\..\SearchScopes\{E0F00850-AE0D-48d9-BE93-10117BA27B60}: "URL" = http://www.google.com/cse?cx=partner-pub-3…q={searchTerms}
    FF - prefs.js..browser.startup.homepage: "http://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=GB&userid=87fb5ffa-7fed-4760-8157-1cd1030e2963&searchtype=hp"
    FF - prefs.js..keyword.URL: "http://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=GB&userid=87fb5ffa-7fed-4760-8157-1cd1030e2963&searchtype=ds&q="
    FF - user.js - File not found
    CHR - plugin: Conduit Chrome Plugin (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk\10.13.20.29_0\plugins/ConduitChromeApiPlugin.dll
    CHR - plugin: Conduit Radio Plugin (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk\10.13.20.29_0\plugins/np-cwmp.dll
    O3 - HKU\S-1-5-21-1447855767-3573926289-1960894109-1000\..\Toolbar\WebBrowser: (no name) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - No CLSID value found.
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • click the Run Fix button at the top
  • let the program run unhindered, reboot when it is done
  • post a new OTL log.
Logs to include in the next post:

OTL fix log
New OTL log


Can you tell me if there is any improvement and what the current situation is.

Satchfan
So I ran the test and it came back with a notepad,

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry key HKEY_USERS\S-1-5-21-1447855767-3573926289-1960894109-1000\Software\Microsoft\Internet Explorer\SearchScopes\{63B2D943-91F1-4a04-B9AA-390B3CE4A909}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{63B2D943-91F1-4a04-B9AA-390B3CE4A909}\ not found.
Registry key HKEY_USERS\S-1-5-21-1447855767-3573926289-1960894109-1000\Software\Microsoft\Internet Explorer\SearchScopes\{89702040-18AF-416b-B0E0-7012894C77FE}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{89702040-18AF-416b-B0E0-7012894C77FE}\ not found.
Registry key HKEY_USERS\S-1-5-21-1447855767-3573926289-1960894109-1000\Software\Microsoft\Internet Explorer\SearchScopes\{BABCB421-7CA1-4B5C-BB0A-2A118CB6305B}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BABCB421-7CA1-4B5C-BB0A-2A118CB6305B}\ not found.
Registry key HKEY_USERS\S-1-5-21-1447855767-3573926289-1960894109-1000\Software\Microsoft\Internet Explorer\SearchScopes\{E0F00850-AE0D-48d9-BE93-10117BA27B60}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E0F00850-AE0D-48d9-BE93-10117BA27B60}\ not found.
Prefs.js: "http://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=GB&userid=87fb5ffa-7fed-4760-8157-1cd1030e2963&searchtype=hp" removed from browser.startup.homepage
Prefs.js: "http://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=GB&userid=87fb5ffa-7fed-4760-8157-1cd1030e2963&searchtype=ds&q=" removed from keyword.URL
File C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk\10.13.20.29_0\plugins/ConduitChromeApiPlugin.dll not found.
File C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk\10.13.20.29_0\plugins/np-cwmp.dll not found.
Registry value HKEY_USERS\S-1-5-21-1447855767-3573926289-1960894109-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{BA14329E-9550-4989-B3F2-9732E92D17CC} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BA14329E-9550-4989-B3F2-9732E92D17CC}\ not found.
Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\User\Desktop\cmd.bat deleted successfully.
C:\Users\User\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 56504 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

User: User
->Temp folder emptied: 400848501 bytes
->Temporary Internet Files folder emptied: 8524155 bytes
->Java cache emptied: 46098995 bytes
->FireFox cache emptied: 54866663 bytes
->Google Chrome cache emptied: 258697187 bytes
->Flash cache emptied: 57380 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 200704 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 572205 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 36045600 bytes
RecycleBin emptied: 5307322 bytes

Total Files Cleaned = 774.00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 01302013_012004

Files\Folders moved on Reboot…
C:\Users\User\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.

PendingFileRenameOperations files…

Registry entries deleted on Reboot…




You say to include a new OTL File does that mean you want me to run OTL again? With;



download OTL to your desktop.
double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
click Scan all users.
under Custom Scan paste this in

netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
services.exe
/md5stop
%systemroot%\*. /rp /s
DRIVES
CREATERESTOREPOINT

click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long.
when the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
Thanks for the "fix" log but I need a new OTL log.

  • open OTL again and click the Quick Scan button
  • post the OTL.txt log it produces in your next reply.
Please post back with the log.

I'm off for some beauty sleep now so I'll not answer again tonight. (tonight? 1.30 am so I think it's morning :) )
Thanks for the help so far, here is the log you wanted. Goodnight :)


OTL logfile created on: 30/01/2013 01:37:02 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\User\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

7.92 Gb Total Physical Memory | 5.52 Gb Available Physical Memory | 69.69% Memory free
15.84 Gb Paging File | 12.98 Gb Available in Paging File | 81.99% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.41 Gb Total Space | 670.38 Gb Free Space | 71.97% Space Free | Partition Type: NTFS

Computer Name: USER-PC | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/01/29 19:29:16 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
PRC - [2013/01/18 08:07:04 | 001,248,208 | —- | M] (Google Inc.) – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2013/01/03 16:50:05 | 000,076,888 | —- | M] () – C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2012/12/18 14:28:08 | 000,065,192 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/12/14 16:49:28 | 000,682,344 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/12/14 16:49:28 | 000,512,360 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012/12/14 16:49:28 | 000,398,184 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/10/30 22:50:59 | 004,297,136 | —- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2012/10/30 22:50:59 | 000,044,808 | —- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2012/10/30 22:50:56 | 000,133,912 | —- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\afwServ.exe
PRC - [2012/03/26 17:05:04 | 004,656,632 | —- | M] (Almico Software (www.almico.com)) – C:\Program Files (x86)\SpeedFan\speedfan.exe
PRC - [2011/05/27 14:57:30 | 000,562,592 | —- | M] (Affinegy, Inc.) – C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe
PRC - [2011/05/27 14:57:28 | 002,015,136 | —- | M] (Affinegy, Inc.) – C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe
PRC - [2011/05/27 14:57:26 | 007,025,568 | —- | M] (Affinegy, Inc.) – C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe
PRC - [2011/05/18 17:28:16 | 001,641,888 | —- | M] (Affinegy, Inc.) – C:\Program Files (x86)\Belkin\Router Setup and Monitor\dlnaPlugin.exe


========== Modules (No Company Name) ==========

MOD - [2013/01/30 01:35:12 | 000,192,512 | —- | M] () – C:\Users\User\AppData\Local\Temp\sfamcc00001.dll
MOD - [2013/01/30 01:35:12 | 000,158,720 | —- | M] () – C:\Users\User\AppData\Local\Temp\sfareca00001.dll
MOD - [2013/01/18 08:07:02 | 012,459,472 | —- | M] () – C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\PepperFlash\pepflashplayer.dll
MOD - [2013/01/18 08:06:15 | 000,597,968 | —- | M] () – C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\libglesv2.dll
MOD - [2013/01/18 08:06:15 | 000,124,368 | —- | M] () – C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\libegl.dll
MOD - [2011/05/27 14:57:32 | 000,022,944 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinServicePS.dll
MOD - [2011/05/27 14:08:56 | 000,660,480 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\gateways\GenericBelkinGatewayLOC.dll
MOD - [2010/08/22 20:01:36 | 007,187,456 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtGui4.dll
MOD - [2010/08/22 20:01:08 | 000,325,632 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtXml4.dll
MOD - [2010/08/22 20:01:06 | 001,954,304 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtCore4.dll
MOD - [2010/08/22 20:01:06 | 000,847,360 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtNetwork4.dll
MOD - [2010/08/22 19:32:34 | 000,119,808 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\imageformats\qjpeg4.dll


========== Services (SafeList) ==========

SRV:64bit: - [2012/12/19 19:56:00 | 000,240,640 | —- | M] (AMD) [Auto | Running] – C:\Windows\SysNative\atiesrxx.exe – (AMD External Events Utility)
SRV:64bit: - [2012/10/30 22:50:59 | 000,044,808 | —- | M] (AVAST Software) [Auto | Running] – C:\Program Files\AVAST Software\Avast\AvastSvc.exe – (avast! Antivirus)
SRV:64bit: - [2012/10/30 22:50:56 | 000,133,912 | —- | M] (AVAST Software) [Auto | Running] – C:\Program Files\AVAST Software\Avast\afwServ.exe – (avast! Firewall)
SRV:64bit: - [2011/04/19 15:31:16 | 000,181,760 | —- | M] () [Auto | Running] – C:\Program Files\Belkin\Belkin USB Print and Storage Center\BkBackupScheduler.exe – (Belkin Local Backup Service)
SRV:64bit: - [2010/04/06 15:30:38 | 000,031,272 | —- | M] () [On_Demand | Stopped] – C:\Windows\SysNative\AppleChargerSrv.exe – (AppleChargerSrv)
SRV:64bit: - [2010/02/09 14:55:52 | 000,055,296 | —- | M] () [Auto | Running] – C:\Program Files\Belkin\Belkin USB Print and Storage Center\Bkapcs.exe – (Belkin Network USB Helper)
SRV:64bit: - [2009/07/14 01:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2013/01/18 22:44:07 | 000,541,608 | —- | M] (Valve Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Steam\SteamService.exe – (Steam Client Service)
SRV - [2013/01/08 20:28:11 | 000,251,400 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2013/01/03 16:50:05 | 000,076,888 | —- | M] () [Auto | Running] – C:\Windows\SysWOW64\PnkBstrA.exe – (PnkBstrA)
SRV - [2012/12/18 14:28:08 | 000,065,192 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2012/12/14 16:49:28 | 000,682,344 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2012/12/14 16:49:28 | 000,398,184 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe – (MBAMScheduler)
SRV - [2012/11/09 11:21:24 | 000,160,944 | R— | M] (Skype Technologies) [Auto | Stopped] – C:\Program Files (x86)\Skype\Updater\Updater.exe – (SkypeUpdate)
SRV - [2012/06/14 22:20:14 | 000,113,120 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/03/19 22:44:20 | 000,276,248 | —- | M] (Intel Corporation) [On_Demand | Stopped] – C:\Windows\SysWOW64\IntelCpHeciSvc.exe – (cphs)
SRV - [2011/05/27 14:57:30 | 000,562,592 | —- | M] (Affinegy, Inc.) [Auto | Running] – C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe – (AffinegyService)
SRV - [2010/03/18 12:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 21:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/12/19 20:48:48 | 011,278,336 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\atikmdag.sys – (amdkmdag)
DRV:64bit: - [2012/12/19 19:32:54 | 000,552,960 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\atikmpag.sys – (amdkmdap)
DRV:64bit: - [2012/12/14 16:49:28 | 000,024,176 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\mbam.sys – (MBAMProtector)
DRV:64bit: - [2012/11/06 11:11:52 | 000,096,256 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\AtihdW76.sys – (AtiHDAudioService)
DRV:64bit: - [2012/10/30 22:51:56 | 000,059,728 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswTdi.sys – (aswTdi)
DRV:64bit: - [2012/10/30 22:51:55 | 000,984,144 | —- | M] (AVAST Software) [File_System | System | Running] – C:\Windows\SysNative\drivers\aswSnx.sys – (aswSnx)
DRV:64bit: - [2012/10/30 22:51:55 | 000,370,288 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswSP.sys – (aswSP)
DRV:64bit: - [2012/10/30 22:51:55 | 000,262,656 | —- | M] (AVAST Software) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\aswNdis2.sys – (aswNdis2)
DRV:64bit: - [2012/10/30 22:51:55 | 000,071,600 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\aswMonFlt.sys – (aswMonFlt)
DRV:64bit: - [2012/10/30 22:51:55 | 000,021,136 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswKbd.sys – (aswKbd)
DRV:64bit: - [2012/10/30 22:51:53 | 000,132,864 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswFW.sys – (aswFW)
DRV:64bit: - [2012/10/30 22:51:53 | 000,025,232 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\aswFsBlk.sys – (aswFsBlk)
DRV:64bit: - [2012/10/15 16:59:28 | 000,054,072 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswRdr2.sys – (aswRdr)
DRV:64bit: - [2012/09/21 09:26:08 | 000,012,368 | —- | M] (ALWIL Software) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\aswNdis.sys – (aswNdis)
DRV:64bit: - [2012/03/19 22:32:04 | 014,745,600 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2012/03/01 06:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2011/07/29 03:40:00 | 000,079,104 | —- | M] (Etron Technology Inc) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\EtronXHCI.sys – (EtronXHCI)
DRV:64bit: - [2011/07/29 03:40:00 | 000,056,960 | —- | M] (Etron Technology Inc) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\EtronHub3.sys – (EtronHub3)
DRV:64bit: - [2011/06/01 03:16:50 | 000,535,656 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2011/03/11 06:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/11 06:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2011/01/10 17:16:08 | 000,021,104 | —- | M] () [Kernel | System | Running] – C:\Windows\SysNative\drivers\AppleCharger.sys – (AppleCharger)
DRV:64bit: - [2010/11/21 03:24:33 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/11/21 03:23:47 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/21 03:23:47 | 000,031,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbGD.sys – (TsUsbGD)
DRV:64bit: - [2010/10/19 22:34:26 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (MEIx64)
DRV:64bit: - [2010/10/14 17:28:16 | 000,317,440 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcDAud.sys – (IntcDAud)
DRV:64bit: - [2009/08/13 21:10:18 | 000,073,984 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\xusb21.sys – (xusb21)
DRV:64bit: - [2009/07/14 01:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/14 01:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/14 01:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/07/14 00:01:09 | 000,679,936 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\xnacc.sys – (xnacc)
DRV:64bit: - [2009/06/22 15:50:00 | 000,291,352 | —- | M] (silex technology, Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\sxuptp.sys – (sxuptp)
DRV:64bit: - [2009/06/10 20:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 20:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 20:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 20:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/02/17 17:22:22 | 000,017,792 | —- | M] (ASUSTeK Computer Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\asusgsb.sys – (asusgsb)
DRV - [2009/07/14 01:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-GB
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = FC CD F6 6E 29 EC CD 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: ""
FF - prefs.js..extensions.enabledAddons: [removed]:7.0.1474
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_146.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.11.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@coreonline.com/run3d,version=1.0: C:\Users\User\AppData\LocalLow\Square Enix\nprun3d.dll (Square Enix)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012/11/07 00:10:40 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/01/06 16:49:39 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2013/01/06 16:50:02 | 000,000,000 | —D | M] (No name found) – C:\Users\User\AppData\Roaming\Mozilla\Extensions
[2013/01/10 17:39:01 | 000,000,000 | —D | M] (No name found) – C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\11nx87hu.default\extensions
[2013/01/06 16:57:13 | 000,804,627 | —- | M] () (No name found) – C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\11nx87hu.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013/01/09 17:31:55 | 000,022,867 | —- | M] () – C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\11nx87hu.default\searchplugins\Web Search.xml
[2013/01/06 16:49:39 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/11/07 00:10:40 | 000,000,000 | —D | M] (avast! WebRep) – C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2012/06/14 22:20:49 | 000,085,472 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/06/14 22:19:40 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/06/14 22:19:40 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: https://login.live.com/login.srf?wa=wsignin…=mai&snsc;=1
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}&sugkey;={google:suggestAPIKeyParameter},
CHR - homepage: https://login.live.com/login.srf?wa=wsignin…=mai&snsc;=1
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\pdf.dll
CHR - plugin: Conduit Chrome Plugin (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk\10.13.20.29_0\plugins/ConduitChromeApiPlugin.dll
CHR - plugin: Conduit Radio Plugin (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk\10.13.20.29_0\plugins/np-cwmp.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 7 U10 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Uplay PC (Enabled) = C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll
CHR - plugin: Java Deployment Toolkit 7.0.100.18 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - Extension: Bejeweled = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\adpkifcfcacgmnggcbpbjbkdijciiigm\2_0\
CHR - Extension: Google Drive = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Crime City = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdbacnnicmbpfcmiapnfjbefkggclmco\1_0\
CHR - Extension: AdBlock = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.56_0\
CHR - Extension: Old /r/leagueoflegends Theme = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\hphhelabfkiefgapcfagibfcopbebfbd\1.8_0\
CHR - Extension: avast! WebRep = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1474_0\
CHR - Extension: Gmail = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009/06/10 21:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe (AMD)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [InstaLAN] C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe (Affinegy, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000 File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 10.10.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3AD91F80-4D5C-45E7-8D25-B6C5B3F817D9}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/01/30 01:20:04 | 000,000,000 | —D | C] – C:\_OTL
[2013/01/29 19:29:13 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
[2013/01/29 17:27:49 | 000,000,000 | —D | C] – C:\Users\User\Desktop\RK_Quarantine
[2013/01/29 17:21:33 | 004,732,416 | —- | C] (AVAST Software) – C:\Users\User\Desktop\aswMBR.exe
[2013/01/27 15:31:52 | 000,000,000 | —D | C] – C:\ProgramData\ATI
[2013/01/27 15:31:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\AMD AVT
[2013/01/27 15:31:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\AMD APP
[2013/01/27 15:31:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[2013/01/24 17:59:28 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Malwarebytes
[2013/01/24 17:59:20 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/01/24 17:59:20 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/01/24 17:59:19 | 000,024,176 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2013/01/24 17:59:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/01/24 17:59:10 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Programs
[2013/01/20 21:50:27 | 000,000,000 | —D | C] – C:\Users\User\Documents\Hitman Blood Money
[2013/01/20 21:48:42 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Square Enix
[2013/01/16 22:56:57 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Solid State Networks
[2013/01/16 22:56:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\MeteorEntertainment
[2013/01/16 22:56:39 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Meteor Entertainment
[2013/01/10 17:29:00 | 000,000,000 | —D | C] – C:\Users\User\Documents\Outlook Files
[2013/01/07 20:10:54 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/01/06 17:05:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Google
[2013/01/06 16:54:23 | 000,000,000 | R–D | C] – C:\Program Files (x86)\Skype
[2013/01/06 16:54:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2013/01/06 16:54:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Skype
[2013/01/06 16:50:16 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Macromedia
[2013/01/06 16:49:51 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Mozilla
[2013/01/06 16:49:51 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Mozilla
[2013/01/06 16:49:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Maintenance Service
[2013/01/06 16:49:40 | 000,000,000 | —D | C] – C:\ProgramData\Mozilla
[2013/01/06 16:49:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2013/01/06 16:45:37 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Adobe
[2012/12/31 22:48:13 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
[2011/08/31 15:16:50 | 000,155,936 | —- | C] (Sysinternals) – C:\Users\User\sdelete.exe
[1 C:\Users\User\Desktop\*.tmp files -> C:\Users\User\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/01/30 01:28:57 | 000,022,560 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/01/30 01:28:57 | 000,022,560 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/01/30 01:28:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/01/30 01:21:34 | 000,000,890 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/01/30 01:21:21 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/01/30 01:21:16 | 2082,299,903 | -HS- | M] () – C:\hiberfil.sys
[2013/01/30 01:14:00 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/01/30 00:55:10 | 000,000,322 | —- | M] () – C:\Windows\tasks\HP Photo Creations Communicator.job
[2013/01/29 22:29:11 | 000,001,958 | —- | M] () – C:\Users\Public\Desktop\avast! Internet Security.lnk
[2013/01/29 22:29:09 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2013/01/29 19:29:16 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
[2013/01/29 19:23:06 | 000,580,235 | —- | M] () – C:\Users\User\Desktop\adwcleaner.exe
[2013/01/29 17:36:21 | 000,000,512 | —- | M] () – C:\Users\User\Desktop\MBR.dat
[2013/01/29 17:22:50 | 004,732,416 | —- | M] (AVAST Software) – C:\Users\User\Desktop\aswMBR.exe
[2013/01/29 17:21:15 | 000,768,512 | —- | M] () – C:\Users\User\Desktop\RogueKiller.exe
[2013/01/29 16:09:45 | 569,332,020 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/01/24 17:59:20 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/18 16:30:18 | 000,007,018 | —- | M] () – C:\Users\User\Documents\cc_20130118_163008.reg
[2013/01/18 16:28:57 | 000,000,822 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2013/01/11 20:37:50 | 000,281,688 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.xtr
[2013/01/11 20:37:50 | 000,281,688 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.exe
[2013/01/09 17:14:15 | 000,418,896 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/01/09 16:53:53 | 000,778,702 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2013/01/09 16:53:53 | 000,661,302 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/01/09 16:53:53 | 000,125,388 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/01/09 16:53:46 | 000,778,702 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/01/08 00:03:20 | 761,440,108 | —- | M] () – C:\Users\User\Desktop\Gw2.dat
[2013/01/07 23:55:47 | 022,301,248 | —- | M] (ArenaNet) – C:\Users\User\Desktop\Gw2.exe
[2013/01/07 00:06:20 | 000,281,688 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.ex0
[2013/01/06 16:54:23 | 000,002,515 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2013/01/06 16:34:22 | 000,001,254 | —- | M] () – C:\Users\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/01/03 23:56:06 | 000,000,024 | —- | M] () – C:\Users\User\random.dat
[2013/01/03 21:13:38 | 000,000,043 | —- | M] () – C:\Users\User\jagex_cl_runescape_LIVE.dat
[2013/01/03 21:12:07 | 000,000,045 | —- | M] () – C:\Users\User\jagex_cl_loginapplet_LIVE.dat
[2013/01/03 16:50:05 | 000,076,888 | —- | M] () – C:\Windows\SysWow64\PnkBstrA.exe
[1 C:\Users\User\Desktop\*.tmp files -> C:\Users\User\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/01/29 19:23:02 | 000,580,235 | —- | C] () – C:\Users\User\Desktop\adwcleaner.exe
[2013/01/29 17:36:21 | 000,000,512 | —- | C] () – C:\Users\User\Desktop\MBR.dat
[2013/01/29 17:21:10 | 000,768,512 | —- | C] () – C:\Users\User\Desktop\RogueKiller.exe
[2013/01/25 15:28:40 | 569,332,020 | —- | C] () – C:\Windows\MEMORY.DMP
[2013/01/24 17:59:20 | 000,001,113 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/18 16:30:12 | 000,007,018 | —- | C] () – C:\Users\User\Documents\cc_20130118_163008.reg
[2013/01/07 20:09:49 | 000,000,894 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/01/07 20:09:48 | 000,000,890 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/01/06 16:54:23 | 000,002,515 | —- | C] () – C:\Users\Public\Desktop\Skype.lnk
[2013/01/06 16:49:43 | 000,001,146 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012/11/12 15:04:01 | 000,000,045 | —- | C] () – C:\Users\User\jagex_cl_loginapplet_LIVE.dat
[2012/10/23 18:41:32 | 000,007,605 | —- | C] () – C:\Users\User\AppData\Local\Resmon.ResmonCfg
[2012/07/08 19:13:51 | 000,281,688 | —- | C] () – C:\Windows\SysWow64\PnkBstrB.exe
[2012/07/08 19:13:44 | 000,076,888 | —- | C] () – C:\Windows\SysWow64\PnkBstrA.exe
[2012/07/08 19:13:43 | 003,130,440 | —- | C] () – C:\Windows\SysWow64\pbsvc_blr.exe
[2012/06/29 19:39:11 | 000,000,092 | —- | C] () – C:\Users\User\AppData\Local\fusioncache.dat
[2012/05/04 20:01:13 | 000,778,702 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/05/02 13:58:10 | 000,029,184 | —- | C] () – C:\Windows\SysWow64\kdbsdk32.dll
[2012/04/20 15:36:56 | 000,000,262 | —- | C] () – C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2012/04/13 19:11:43 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2012/04/07 16:10:15 | 000,000,043 | —- | C] () – C:\Users\User\jagex_cl_runescape_LIVE.dat
[2012/04/07 16:10:15 | 000,000,024 | —- | C] () – C:\Users\User\random.dat
[2012/04/06 11:20:21 | 000,008,192 | —- | C] () – C:\Windows\SysWow64\drivers\IntelMEFWVer.dll
[2012/04/06 11:16:26 | 000,145,804 | —- | C] () – C:\Windows\SysWow64\igcompkrng600.bin
[2012/04/06 11:12:53 | 000,000,010 | —- | C] () – C:\Windows\GSetup.ini
[2012/03/19 22:25:58 | 000,058,880 | —- | C] () – C:\Windows\SysWow64\igdde32.dll
[2012/03/19 21:21:14 | 013,212,672 | —- | C] () – C:\Windows\SysWow64\ig4icd32.dll
[2012/03/09 04:31:26 | 000,204,952 | —- | C] () – C:\Windows\SysWow64\ativvsvl.dat
[2012/03/09 04:31:26 | 000,157,144 | —- | C] () – C:\Windows\SysWow64\ativvsva.dat
[2012/02/14 17:47:06 | 000,963,912 | —- | C] () – C:\Windows\SysWow64\igkrng600.bin
[2012/02/14 17:47:06 | 000,261,208 | —- | C] () – C:\Windows\SysWow64\igfcg600m.bin
[2011/09/28 16:44:14 | 000,179,271 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2011/09/12 22:06:16 | 000,003,917 | —- | C] () – C:\Windows\SysWow64\atipblag.dat

========== ZeroAccess Check ==========

[2009/07/14 04:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/09 05:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/09 04:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/14 01:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/21 03:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/14 01:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2012/04/06 12:22:12 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\AVG2012
[2013/01/18 16:29:48 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Azureus
[2012/06/01 15:32:31 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\capy
[2012/06/01 22:07:37 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\fltk.org
[2012/06/15 16:44:20 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Gyazo
[2012/04/06 18:55:11 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\LolClient
[2012/05/24 13:54:00 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\LolClient2
[2012/04/06 12:01:48 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Splashtop
[2012/04/22 02:12:05 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\SplitMediaLabs
[2012/11/26 00:37:05 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\SystemRequirementsLab
[2012/04/09 13:41:00 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Visan
[2012/08/23 13:38:09 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\wargaming.net

========== Purity Check ==========



< End of report >
Looking good but still a couple of entries in Chrome that I’d like to purge. Unfortunately, the easiest way to do so with Google Chrome is to uninstall and re-install it.
.
Uninstall Chrome and, if asked about user data or settings, remove those also.

Restart the computer and re-install Chrome

======================================

Download and run Junkware Removal Tool

[external image: Posted Image] Please download Junkware Removal Tool to your desktop.
  • shut down your protection software now to avoid potential conflicts.
  • run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator"
  • the tool will open and start scanning your system
  • please be patient as this can take a while to complete depending on your system's specifications
  • on completion, a log (JRT.txt) is saved to your desktop and will automatically open
  • post the contents of JRT.txt into your next message.
======================================

Run Malwarebytes’ Anti-Malware

I noticed that you have MBAM on your system: if you no longer have it, you can download it from here:
  • start Malwarebytes-Anti-Malware and update it, (“Update” tab}
  • once it is updated, click on “Scanner” tab, select Perform quick scan, then click Scan.
  • when the scan is complete, click OK, then Show Results to view the results.
  • be sure that everything is checked, and click Remove Selected.
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.
NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

Logs to include with the next post:

JRT.txt
Mbam.txt


Can you tell me if there are any outstanding problems.

Satchfan
Before I do any of that I want to let you know that upon boot up today I received a whole bunch of error messages, I could not upload them to this site so I will give you a link to view the pictures online. Here is the link to view the some of the error messages I received

http://imgur.com/a/2GVfx

I had to restore windows to yesterday, as no programs would loads. Also after restoring I can missing a few of the Icon Pictures for shortcuts. I'm not sure what went wrong, but hopefully you can figure out why. Everything was working perfectly fine last night, then like I said, today when I boot up, a mass of error messages,
I have no idea why that might have happened. Let's try running the tools I asked you to run in the earlier post and, as you've done a system restore, please include a new OTL log. Thanks Satchfan
The log from Malwarebytes showed nothing. Malwarebytes Anti-Malware (Trial) 1.70.0.1100 www.malwarebytes.org Database version: v2013.01.30.05 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 User :: USER-PC [administrator] Protection: Enabled 30/01/2013 15:46:06 mbam-log-2013-01-30 (15-46-06).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 215770 Time elapsed: 1 minute(s), 39 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
Here are the two OTL files that I got from hitting Quick Scan.

OTL logfile created on: 30/01/2013 16:02:03 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\User\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

7.92 Gb Total Physical Memory | 5.39 Gb Available Physical Memory | 68.12% Memory free
15.84 Gb Paging File | 12.93 Gb Available in Paging File | 81.63% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.41 Gb Total Space | 668.71 Gb Free Space | 71.79% Space Free | Partition Type: NTFS

Computer Name: USER-PC | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/01/30 16:01:22 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
PRC - [2013/01/18 08:07:04 | 001,248,208 | —- | M] (Google Inc.) – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2013/01/03 16:50:05 | 000,076,888 | —- | M] () – C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2012/12/18 14:28:08 | 000,065,192 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/10/30 22:50:59 | 004,297,136 | —- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2012/10/30 22:50:59 | 000,044,808 | —- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2012/10/30 22:50:56 | 000,133,912 | —- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\afwServ.exe
PRC - [2011/05/27 14:57:30 | 000,562,592 | —- | M] (Affinegy, Inc.) – C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe
PRC - [2011/05/27 14:57:28 | 002,015,136 | —- | M] (Affinegy, Inc.) – C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe
PRC - [2011/05/27 14:57:26 | 007,025,568 | —- | M] (Affinegy, Inc.) – C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe
PRC - [2011/05/18 17:28:16 | 001,641,888 | —- | M] (Affinegy, Inc.) – C:\Program Files (x86)\Belkin\Router Setup and Monitor\dlnaPlugin.exe


========== Modules (No Company Name) ==========

MOD - [2013/01/18 08:07:02 | 012,459,472 | —- | M] () – C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\PepperFlash\pepflashplayer.dll
MOD - [2013/01/18 08:07:02 | 000,460,240 | —- | M] () – C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\ppgooglenaclpluginchrome.dll
MOD - [2013/01/18 08:07:01 | 004,012,496 | —- | M] () – C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\pdf.dll
MOD - [2013/01/18 08:06:15 | 000,597,968 | —- | M] () – C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\libglesv2.dll
MOD - [2013/01/18 08:06:15 | 000,124,368 | —- | M] () – C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\libegl.dll
MOD - [2013/01/18 08:06:13 | 001,552,848 | —- | M] () – C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\ffmpegsumo.dll
MOD - [2011/05/27 14:57:32 | 000,022,944 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinServicePS.dll
MOD - [2011/05/27 14:08:56 | 000,660,480 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\gateways\GenericBelkinGatewayLOC.dll
MOD - [2010/08/22 20:01:36 | 007,187,456 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtGui4.dll
MOD - [2010/08/22 20:01:08 | 000,325,632 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtXml4.dll
MOD - [2010/08/22 20:01:06 | 001,954,304 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtCore4.dll
MOD - [2010/08/22 20:01:06 | 000,847,360 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtNetwork4.dll
MOD - [2010/08/22 19:32:34 | 000,119,808 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\imageformats\qjpeg4.dll


========== Services (SafeList) ==========

SRV:64bit: - [2012/12/19 19:56:00 | 000,240,640 | —- | M] (AMD) [Auto | Running] – C:\Windows\SysNative\atiesrxx.exe – (AMD External Events Utility)
SRV:64bit: - [2012/10/30 22:50:59 | 000,044,808 | —- | M] (AVAST Software) [Auto | Running] – C:\Program Files\AVAST Software\Avast\AvastSvc.exe – (avast! Antivirus)
SRV:64bit: - [2012/10/30 22:50:56 | 000,133,912 | —- | M] (AVAST Software) [Auto | Running] – C:\Program Files\AVAST Software\Avast\afwServ.exe – (avast! Firewall)
SRV:64bit: - [2011/04/19 15:31:16 | 000,181,760 | —- | M] () [Auto | Running] – C:\Program Files\Belkin\Belkin USB Print and Storage Center\BkBackupScheduler.exe – (Belkin Local Backup Service)
SRV:64bit: - [2010/04/06 15:30:38 | 000,031,272 | —- | M] () [On_Demand | Stopped] – C:\Windows\SysNative\AppleChargerSrv.exe – (AppleChargerSrv)
SRV:64bit: - [2010/02/09 14:55:52 | 000,055,296 | —- | M] () [Auto | Running] – C:\Program Files\Belkin\Belkin USB Print and Storage Center\Bkapcs.exe – (Belkin Network USB Helper)
SRV:64bit: - [2009/07/14 01:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2013/01/18 22:44:07 | 000,541,608 | —- | M] (Valve Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Steam\SteamService.exe – (Steam Client Service)
SRV - [2013/01/08 20:28:11 | 000,251,400 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2013/01/03 16:50:05 | 000,076,888 | —- | M] () [Auto | Running] – C:\Windows\SysWOW64\PnkBstrA.exe – (PnkBstrA)
SRV - [2012/12/18 14:28:08 | 000,065,192 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2012/12/14 16:49:28 | 000,682,344 | —- | M] (Malwarebytes Corporation) [Auto | Stopped] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2012/12/14 16:49:28 | 000,398,184 | —- | M] (Malwarebytes Corporation) [Auto | Stopped] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe – (MBAMScheduler)
SRV - [2012/11/09 11:21:24 | 000,160,944 | R— | M] (Skype Technologies) [Auto | Stopped] – C:\Program Files (x86)\Skype\Updater\Updater.exe – (SkypeUpdate)
SRV - [2012/06/14 22:20:14 | 000,113,120 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/03/19 22:44:20 | 000,276,248 | —- | M] (Intel Corporation) [On_Demand | Stopped] – C:\Windows\SysWOW64\IntelCpHeciSvc.exe – (cphs)
SRV - [2011/05/27 14:57:30 | 000,562,592 | —- | M] (Affinegy, Inc.) [Auto | Running] – C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe – (AffinegyService)
SRV - [2010/03/18 12:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 21:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/12/19 20:48:48 | 011,278,336 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\atikmdag.sys – (amdkmdag)
DRV:64bit: - [2012/12/19 19:32:54 | 000,552,960 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\atikmpag.sys – (amdkmdap)
DRV:64bit: - [2012/12/14 16:49:28 | 000,024,176 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysNative\drivers\mbam.sys – (MBAMProtector)
DRV:64bit: - [2012/11/06 11:11:52 | 000,096,256 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\AtihdW76.sys – (AtiHDAudioService)
DRV:64bit: - [2012/10/30 22:51:56 | 000,059,728 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswTdi.sys – (aswTdi)
DRV:64bit: - [2012/10/30 22:51:55 | 000,984,144 | —- | M] (AVAST Software) [File_System | System | Running] – C:\Windows\SysNative\drivers\aswSnx.sys – (aswSnx)
DRV:64bit: - [2012/10/30 22:51:55 | 000,370,288 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswSP.sys – (aswSP)
DRV:64bit: - [2012/10/30 22:51:55 | 000,262,656 | —- | M] (AVAST Software) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\aswNdis2.sys – (aswNdis2)
DRV:64bit: - [2012/10/30 22:51:55 | 000,071,600 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\aswMonFlt.sys – (aswMonFlt)
DRV:64bit: - [2012/10/30 22:51:55 | 000,021,136 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswKbd.sys – (aswKbd)
DRV:64bit: - [2012/10/30 22:51:53 | 000,132,864 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswFW.sys – (aswFW)
DRV:64bit: - [2012/10/30 22:51:53 | 000,025,232 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\aswFsBlk.sys – (aswFsBlk)
DRV:64bit: - [2012/10/15 16:59:28 | 000,054,072 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswRdr2.sys – (aswRdr)
DRV:64bit: - [2012/09/21 09:26:08 | 000,012,368 | —- | M] (ALWIL Software) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\aswNdis.sys – (aswNdis)
DRV:64bit: - [2012/03/19 22:32:04 | 014,745,600 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2012/03/01 06:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2011/07/29 03:40:00 | 000,079,104 | —- | M] (Etron Technology Inc) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\EtronXHCI.sys – (EtronXHCI)
DRV:64bit: - [2011/07/29 03:40:00 | 000,056,960 | —- | M] (Etron Technology Inc) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\EtronHub3.sys – (EtronHub3)
DRV:64bit: - [2011/06/01 03:16:50 | 000,535,656 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2011/03/11 06:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/11 06:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2011/01/10 17:16:08 | 000,021,104 | —- | M] () [Kernel | System | Running] – C:\Windows\SysNative\drivers\AppleCharger.sys – (AppleCharger)
DRV:64bit: - [2010/11/21 03:24:33 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/11/21 03:23:47 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/21 03:23:47 | 000,031,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbGD.sys – (TsUsbGD)
DRV:64bit: - [2010/10/19 22:34:26 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (MEIx64)
DRV:64bit: - [2010/10/14 17:28:16 | 000,317,440 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcDAud.sys – (IntcDAud)
DRV:64bit: - [2009/08/13 21:10:18 | 000,073,984 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\xusb21.sys – (xusb21)
DRV:64bit: - [2009/07/14 01:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/14 01:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/14 01:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/07/14 00:01:09 | 000,679,936 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\xnacc.sys – (xnacc)
DRV:64bit: - [2009/06/22 15:50:00 | 000,291,352 | —- | M] (silex technology, Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\sxuptp.sys – (sxuptp)
DRV:64bit: - [2009/06/10 20:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 20:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 20:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 20:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/02/17 17:22:22 | 000,017,792 | —- | M] (ASUSTeK Computer Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\asusgsb.sys – (asusgsb)
DRV - [2009/07/14 01:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snap.do/?publisher=QuickObrw&a;…q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.snap.do/?publisher=QuickObrw&a;…q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://feed.snap.do/?publisher=QuickObrw&a;…p;searchtype=hp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-GB
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = FC CD F6 6E 29 EC CD 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snap.do/?publisher=QuickObrw&a;…q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.snap.do/?publisher=QuickObrw&a;…q={searchTerms}
IE - HKCU\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE - HKCU\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.snap.do/?publisher=QuickObrw&a;…q={searchTerms}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{63B2D943-91F1-4a04-B9AA-390B3CE4A909}: "URL" = http://www.bing.com/search?q={searchTerms}…BR1&pc;=SPLH
IE - HKCU\..\SearchScopes\{89702040-18AF-416b-B0E0-7012894C77FE}: "URL" = http://uk.search.yahoo.com/search?p={searc…amp;type=IEBDSV
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={3DF88C6…mp;d=2012-04-06 17:52:12&v;=10.2.0.3&sap;=dsp&q;={searchTerms}
IE - HKCU\..\SearchScopes\{BABCB421-7CA1-4B5C-BB0A-2A118CB6305B}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2504091
IE - HKCU\..\SearchScopes\{E0F00850-AE0D-48d9-BE93-10117BA27B60}: "URL" = http://www.google.com/cse?cx=partner-pub-3…q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://feed.snap.do/?publisher=QuickObrw&dpid;=QuickObrw&co;=GB&userid;=87fb5ffa-7fed-4760-8157-1cd1030e2963&searchtype;=hp"
FF - prefs.js..extensions.enabledAddons: [removed]:7.0.1474
FF - prefs.js..keyword.URL: "http://feed.snap.do/?publisher=QuickObrw&dpid;=QuickObrw&co;=GB&userid;=87fb5ffa-7fed-4760-8157-1cd1030e2963&searchtype;=ds&q;="
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_146.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.11.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@coreonline.com/run3d,version=1.0: C:\Users\User\AppData\LocalLow\Square Enix\nprun3d.dll (Square Enix)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012/11/07 00:10:40 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/01/06 16:49:39 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2013/01/06 16:50:02 | 000,000,000 | —D | M] (No name found) – C:\Users\User\AppData\Roaming\Mozilla\Extensions
[2013/01/10 17:39:01 | 000,000,000 | —D | M] (No name found) – C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\11nx87hu.default\extensions
[2013/01/06 16:57:13 | 000,804,627 | —- | M] () (No name found) – C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\11nx87hu.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013/01/09 17:31:55 | 000,022,867 | —- | M] () – C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\11nx87hu.default\searchplugins\Web Search.xml
[2013/01/06 16:49:39 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/11/07 00:10:40 | 000,000,000 | —D | M] (avast! WebRep) – C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2012/06/14 22:20:49 | 000,085,472 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/06/14 22:19:40 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/06/14 22:19:40 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: https://login.live.com/login.srf?wa=wsignin…=mai&snsc;=1
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}&sugkey;={google:suggestAPIKeyParameter},
CHR - homepage: https://login.live.com/login.srf?wa=wsignin…=mai&snsc;=1
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\pdf.dll
CHR - plugin: Conduit Chrome Plugin (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk\10.13.20.29_0\plugins/ConduitChromeApiPlugin.dll
CHR - plugin: Conduit Radio Plugin (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk\10.13.20.29_0\plugins/np-cwmp.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 7 U10 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Uplay PC (Enabled) = C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll
CHR - plugin: Java Deployment Toolkit 7.0.100.18 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - Extension: Bejeweled = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\adpkifcfcacgmnggcbpbjbkdijciiigm\2_0\
CHR - Extension: Google Drive = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Crime City = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdbacnnicmbpfcmiapnfjbefkggclmco\1_0\
CHR - Extension: AdBlock = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.56_0\
CHR - Extension: Old /r/leagueoflegends Theme = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\hphhelabfkiefgapcfagibfcopbebfbd\1.8_0\
CHR - Extension: avast! WebRep = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1474_0\
CHR - Extension: Gmail = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009/06/10 21:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3:64bit: - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe (AMD)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [InstaLAN] C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe (Affinegy, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000 File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 10.10.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3AD91F80-4D5C-45E7-8D25-B6C5B3F817D9}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/01/30 16:01:18 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
[2013/01/30 01:20:04 | 000,000,000 | —D | C] – C:\_OTL
[2013/01/27 15:31:52 | 000,000,000 | —D | C] – C:\ProgramData\ATI
[2013/01/27 15:31:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\AMD AVT
[2013/01/27 15:31:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\AMD APP
[2013/01/27 15:31:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[2013/01/24 17:59:28 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Malwarebytes
[2013/01/24 17:59:20 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/01/24 17:59:20 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/01/24 17:59:19 | 000,024,176 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2013/01/24 17:59:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/01/24 17:59:10 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Programs
[2013/01/20 21:50:27 | 000,000,000 | —D | C] – C:\Users\User\Documents\Hitman Blood Money
[2013/01/20 21:48:42 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Square Enix
[2013/01/16 22:56:57 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Solid State Networks
[2013/01/16 22:56:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\MeteorEntertainment
[2013/01/16 22:56:39 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Meteor Entertainment
[2013/01/10 17:29:00 | 000,000,000 | —D | C] – C:\Users\User\Documents\Outlook Files
[2013/01/07 20:10:54 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/01/06 17:05:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Google
[2013/01/06 16:54:23 | 000,000,000 | R–D | C] – C:\Program Files (x86)\Skype
[2013/01/06 16:54:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2013/01/06 16:54:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Skype
[2013/01/06 16:50:16 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Macromedia
[2013/01/06 16:49:51 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Mozilla
[2013/01/06 16:49:51 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Mozilla
[2013/01/06 16:49:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Maintenance Service
[2013/01/06 16:49:40 | 000,000,000 | —D | C] – C:\ProgramData\Mozilla
[2013/01/06 16:49:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2013/01/06 16:45:37 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Adobe
[2012/12/31 22:48:13 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
[2011/08/31 15:16:50 | 000,155,936 | —- | C] (Sysinternals) – C:\Users\User\sdelete.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\User\Desktop\*.tmp files -> C:\Users\User\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/01/30 16:01:22 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
[2013/01/30 15:55:10 | 000,000,322 | —- | M] () – C:\Windows\tasks\HP Photo Creations Communicator.job
[2013/01/30 15:28:13 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/01/30 15:14:08 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/01/30 14:24:03 | 000,022,560 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/01/30 14:24:03 | 000,022,560 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/01/30 14:21:55 | 000,793,234 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/01/30 14:21:55 | 000,673,684 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/01/30 14:21:55 | 000,129,574 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/01/30 14:09:11 | 000,000,890 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/01/30 14:08:06 | 000,001,958 | —- | M] () – C:\Users\Public\Desktop\avast! Internet Security.lnk
[2013/01/30 14:08:02 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2013/01/30 14:07:28 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/01/30 14:07:25 | 2082,299,903 | -HS- | M] () – C:\hiberfil.sys
[2013/01/28 00:19:14 | 560,918,836 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/01/24 17:59:20 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/18 16:30:18 | 000,007,018 | —- | M] () – C:\Users\User\Documents\cc_20130118_163008.reg
[2013/01/18 16:28:57 | 000,000,822 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2013/01/11 20:37:50 | 000,281,688 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.xtr
[2013/01/11 20:37:50 | 000,281,688 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.exe
[2013/01/09 17:14:15 | 000,418,896 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/01/09 16:53:53 | 000,778,702 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2013/01/08 00:03:20 | 761,440,108 | —- | M] () – C:\Users\User\Desktop\Gw2.dat
[2013/01/07 23:55:47 | 022,301,248 | —- | M] (ArenaNet) – C:\Users\User\Desktop\Gw2.exe
[2013/01/07 00:06:20 | 000,281,688 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.ex0
[2013/01/06 16:54:23 | 000,002,515 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2013/01/06 16:34:22 | 000,001,254 | —- | M] () – C:\Users\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/01/03 23:56:06 | 000,000,024 | —- | M] () – C:\Users\User\random.dat
[2013/01/03 21:13:38 | 000,000,043 | —- | M] () – C:\Users\User\jagex_cl_runescape_LIVE.dat
[2013/01/03 21:12:07 | 000,000,045 | —- | M] () – C:\Users\User\jagex_cl_loginapplet_LIVE.dat
[2013/01/03 16:50:05 | 000,076,888 | —- | M] () – C:\Windows\SysWow64\PnkBstrA.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\User\Desktop\*.tmp files -> C:\Users\User\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/01/25 15:28:40 | 560,918,836 | —- | C] () – C:\Windows\MEMORY.DMP
[2013/01/24 17:59:20 | 000,001,113 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/18 16:30:12 | 000,007,018 | —- | C] () – C:\Users\User\Documents\cc_20130118_163008.reg
[2013/01/07 20:09:49 | 000,000,894 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/01/07 20:09:48 | 000,000,890 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/01/06 16:54:23 | 000,002,515 | —- | C] () – C:\Users\Public\Desktop\Skype.lnk
[2013/01/06 16:49:43 | 000,001,146 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012/11/12 15:04:01 | 000,000,045 | —- | C] () – C:\Users\User\jagex_cl_loginapplet_LIVE.dat
[2012/10/23 18:41:32 | 000,007,605 | —- | C] () – C:\Users\User\AppData\Local\Resmon.ResmonCfg
[2012/07/08 19:13:51 | 000,281,688 | —- | C] () – C:\Windows\SysWow64\PnkBstrB.exe
[2012/07/08 19:13:44 | 000,076,888 | —- | C] () – C:\Windows\SysWow64\PnkBstrA.exe
[2012/07/08 19:13:43 | 003,130,440 | —- | C] () – C:\Windows\SysWow64\pbsvc_blr.exe
[2012/06/29 19:39:11 | 000,000,092 | —- | C] () – C:\Users\User\AppData\Local\fusioncache.dat
[2012/05/04 20:01:13 | 000,778,702 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/05/02 13:58:10 | 000,029,184 | —- | C] () – C:\Windows\SysWow64\kdbsdk32.dll
[2012/04/20 15:36:56 | 000,000,262 | —- | C] () – C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2012/04/13 19:11:43 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2012/04/07 16:10:15 | 000,000,043 | —- | C] () – C:\Users\User\jagex_cl_runescape_LIVE.dat
[2012/04/07 16:10:15 | 000,000,024 | —- | C] () – C:\Users\User\random.dat
[2012/04/06 11:20:21 | 000,008,192 | —- | C] () – C:\Windows\SysWow64\drivers\IntelMEFWVer.dll
[2012/04/06 11:16:26 | 000,145,804 | —- | C] () – C:\Windows\SysWow64\igcompkrng600.bin
[2012/04/06 11:12:53 | 000,000,010 | —- | C] () – C:\Windows\GSetup.ini
[2012/03/19 22:25:58 | 000,058,880 | —- | C] () – C:\Windows\SysWow64\igdde32.dll
[2012/03/19 21:21:14 | 013,212,672 | —- | C] () – C:\Windows\SysWow64\ig4icd32.dll
[2012/03/09 04:31:26 | 000,204,952 | —- | C] () – C:\Windows\SysWow64\ativvsvl.dat
[2012/03/09 04:31:26 | 000,157,144 | —- | C] () – C:\Windows\SysWow64\ativvsva.dat
[2012/02/14 17:47:06 | 000,963,912 | —- | C] () – C:\Windows\SysWow64\igkrng600.bin
[2012/02/14 17:47:06 | 000,261,208 | —- | C] () – C:\Windows\SysWow64\igfcg600m.bin
[2011/09/28 16:44:14 | 000,179,271 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2011/09/12 22:06:16 | 000,003,917 | —- | C] () – C:\Windows\SysWow64\atipblag.dat

========== ZeroAccess Check ==========

[2009/07/14 04:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/09 05:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/09 04:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/14 01:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/21 03:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/14 01:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2012/04/06 12:22:12 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\AVG2012
[2013/01/18 16:29:48 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Azureus
[2012/06/01 15:32:31 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\capy
[2012/06/01 22:07:37 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\fltk.org
[2012/06/15 16:44:20 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Gyazo
[2012/04/06 18:55:11 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\LolClient
[2012/05/24 13:54:00 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\LolClient2
[2012/04/06 12:01:48 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Splashtop
[2012/04/22 02:12:05 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\SplitMediaLabs
[2012/11/26 00:37:05 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\SystemRequirementsLab
[2012/04/09 13:41:00 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Visan
[2012/08/23 13:38:09 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\wargaming.net

========== Purity Check ==========



< End of report >




OTL Extras logfile created on: 30/01/2013 16:02:03 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\User\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

7.92 Gb Total Physical Memory | 5.39 Gb Available Physical Memory | 68.12% Memory free
15.84 Gb Paging File | 12.93 Gb Available in Paging File | 81.63% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.41 Gb Total Space | 668.71 Gb Free Space | 71.79% Space Free | Partition Type: NTFS

Computer Name: USER-PC | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
http [open] – "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
http [open] – "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00A1BD4D-C27E-4259-B39A-B7523BA31DBD}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{0DB18632-719A-4CED-959F-18D09644ED5D}" = lport=139 | protocol=6 | dir=in | app=system |
"{111A7768-034C-4CFC-883F-2DCB17AC9DF7}" = rport=445 | protocol=6 | dir=out | app=system |
"{1C7D4E1C-F713-40B0-A3B5-98D95D82C844}" = lport=138 | protocol=17 | dir=in | app=system |
"{2258FD3D-4005-4710-B213-6142F9660AD3}" = lport=19540 | protocol=17 | dir=in | name=sxuptp |
"{2307C2CE-9976-41D4-A061-467B778455A9}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |
"{2D3C2E51-8C9B-454E-8712-68BA9B995449}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{470D25AE-2F07-4EC9-A6D5-8A568F381E53}" = rport=138 | protocol=17 | dir=out | app=system |
"{52405A3B-0BEB-4F84-8E63-1B9987741F42}" = rport=137 | protocol=17 | dir=out | app=system |
"{5A83AB36-BB43-499B-8E58-A2B3A2368D67}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{5E126A60-8115-4C17-9A49-77C7EA46FBCD}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{6107AD74-BB60-4C1C-AFCE-23B81CE7C0D1}" = rport=10243 | protocol=6 | dir=out | app=system |
"{65428B12-4D21-490F-9498-E149C19D973A}" = lport=10243 | protocol=6 | dir=in | app=system |
"{66400551-1180-495D-BC7E-0C868696FDA3}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{69259B16-FCB0-4A7D-81F5-8EC6BC324E27}" = rport=139 | protocol=6 | dir=out | app=system |
"{77DB61EC-903F-4CD6-BC4B-714CCD27670A}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{79AE8CDD-004E-4B07-9189-4303FFF10344}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{7E80FB7D-7DFF-46DF-92F2-2FF893D9D3B3}" = lport=445 | protocol=6 | dir=in | app=system |
"{86449AAA-CBCB-4730-8913-9A58C81B8DEC}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{8AFF2EBF-895E-41A4-B0B9-06F7A50ED1A6}" = lport=2869 | protocol=6 | dir=in | app=system |
"{C6EB7CC5-3E38-44C2-B3C6-D87E3FE27E07}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{E170DF3C-AD55-4B4C-A561-BBB695BF1365}" = lport=49170 | protocol=6 | dir=in | name=akamai netsession interface |
"{E4574A52-B55A-4C58-A8E8-C9781272AB64}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{E84C621F-2DC4-4F43-AC90-DD0772754AB8}" = lport=137 | protocol=17 | dir=in | app=system |
"{F7E0D4CA-7DA3-4891-9805-63F63DB027B7}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{F825F10B-91DA-4821-BD18-7EBDEA6AF6BA}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{FF80DBD9-3CA4-4A91-8C93-E21809AC087F}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{018BBE3B-D3ED-427E-8DF7-10A5F9FF2949}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\batman2\runlauncher.bat |
"{01D86EE9-BA63-47D9-B11F-5E23BA7E0BE6}" = protocol=6 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"{021C8CAF-CFF3-43C1-946D-581C6D9ABA77}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\saints row the third\game_launcher.exe |
"{045C9E1A-F2E7-46E3-998F-990A74315C36}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{072831C8-AE2D-49DA-A06F-9857B3673780}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops ii\t6zm.exe |
"{07D2D9CC-BDF1-4D87-B44F-3EE758E38BAF}" = protocol=17 | dir=in | app=c:\program files\hp\hp deskjet 1050 j410 series\bin\usbsetup.exe |
"{0A7AF4D5-ED78-49F7-933C-C1099FE28C6D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\darksiders\darksiderspc.exe |
"{134D3849-F2FA-4B86-B98B-8F6F5CC7E3F8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\red faction armageddon\redfactionarmageddon.exe |
"{153C6685-A72D-4168-BB94-86F87629F7C6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\darksiders\darksiderspc.exe |
"{155FA35C-BEC1-46B4-BF16-DA614AC8D0DA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\batman2\binaries\win32\batmanac.exe |
"{157618B8-C6A5-46F0-933C-BAED3FE4E983}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{1E37C33B-F93B-4F40-BEE3-D73D3ACDB513}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{1EE15939-1CFE-49FA-92C3-6F4812726AE9}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal 2\portal2.exe |
"{1F15C94E-D649-464B-9CD4-175D52D553CE}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{29F088EA-3779-475D-90F5-CEE80FD322DC}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\amd driver updater, vista and 7, 64 bit\setup.exe |
"{2A75ABCA-883D-4639-BF9E-38E173A65039}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{2E195B4E-4ED1-472C-987A-212B443D0026}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\metro 2033\metro2033.exe |
"{2EA90583-A4B2-4AF8-89EF-4801F8214DDF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\batman2\runlauncher.bat |
"{2F1F8E36-78B8-4DFF-BF39-FDBCF20BB0DC}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dxhrml\dxhrml.exe |
"{31F9B89E-9185-4A9E-9C4D-19A51A5A0618}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\plants vs zombies\plantsvszombies.exe |
"{35F1DE9B-9645-42DC-B937-141F84AE58EF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\metro 2033\metro2033.exe |
"{394547EE-0FFF-42B8-9EE0-570FD3EFEECF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\far cry 3\bin\farcry3_d3d11.exe |
"{3D3342F3-D309-4333-BB77-10558C4D1B8E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\far cry 3\bin\farcry3.exe |
"{3F22A813-4D76-47CB-9583-F0BC2A9CC871}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe |
"{43A25263-78B3-4326-9D7D-8020E3823EC4}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{4476ADD2-D8CB-44D7-9DCC-E1299D117C24}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dishonored\binaries\win32\dishonored.exe |
"{48BCD623-8FFF-4954-9AE5-744DECA60FB1}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{4A3A2AD6-F69A-42A9-ABE2-67E55AE10605}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{5529C64A-FCEA-48CD-B269-187DE736CB60}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\deus ex - human revolution\dxhr.exe |
"{5D6F3277-868E-471E-AD57-568BF13A8C1D}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{5D996167-B623-4263-BE17-F5CFED384B04}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops ii\t6mp.exe |
"{604C9C23-6D47-42A0-8A28-8AB8C66230B5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bastion\bastion.exe |
"{629465EF-631C-4837-9F89-54DB6EF2FB30}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\skyrim\skyrimlauncher.exe |
"{6B7267C9-BE0F-42C9-AE55-9AF38CCEBE5D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\red faction armageddon\rf4_launcher.exe |
"{6E19CD9B-3464-48D9-9574-0CC10680444C}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{6E568653-D009-4127-989D-EB2594A5961A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\red faction armageddon\redfactionarmageddon_dx11.exe |
"{6F4A63C1-7A37-43B9-AEAB-078BE9D1DA10}" = protocol=17 | dir=in | app=c:\program files (x86)\belkin\router setup and monitor\belkinsetup.exe |
"{73D27C75-39BF-4D35-97F9-30597E584791}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{74266629-9B9C-47AC-BEBC-2DE883EB2670}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\far cry 3\bin\farcry3.exe |
"{7474F10F-9CB9-491F-BB8F-324F9D04F27D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe |
"{776F10A7-B49D-41DD-96FC-02E29361F367}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\far cry 3\bin\fc3updatersteam.exe |
"{7883892E-CF6E-45B9-B64F-BD172E59D59C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\batman2\binaries\win32\batmanac.exe |
"{79E1D9F9-285D-4614-8DC0-CB4026DBF052}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{7A56BE9A-BC91-4258-A8EA-2BF542A124A7}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{7A876B84-A43E-4195-874D-9AAC51947215}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{7CBB3F39-2E79-4BC6-B3C1-3F7E3B6CF3C3}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\saints row the third\game_launcher.exe |
"{7E31E05D-AACE-4AD4-83EE-BAE8116FEF24}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\payday the heist\payday_win32_release.exe |
"{7E5AB468-759D-4A58-8651-9656C462AFA4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\launcher.exe |
"{861A6B8E-E418-413A-A9CE-0554CBC06084}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\gotham city impostors\engine.exe |
"{8671845F-27A0-4A1F-90AD-6A7A0246CEF5}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{8BEC870F-4559-4698-B310-4C6F9DE16A58}" = protocol=6 | dir=in | app=c:\program files (x86)\belkin\router setup and monitor\belkinsetup.exe |
"{8FAA4B02-F628-45AE-A96C-FD8B9D32F57A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops ii\t6sp.exe |
"{9039FE6E-5134-4441-A239-49B68969E25E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops ii\t6zm.exe |
"{931CDAC7-6B6B-48E3-BD34-54CA61F7498A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{94CB7011-C845-4D46-8A53-2C6860D4BF91}" = dir=in | app=c:\program files (x86)\belkin\router setup and monitor\belkinsetup.exe |
"{979C9317-06B8-4EC9-AC8F-1572837C3B47}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dishonored\binaries\win32\dishonored.exe |
"{9B23D184-A444-41C2-A992-4CDC83BD02B3}" = protocol=6 | dir=in | app=c:\program files\hp\hp deskjet 1050 j410 series\bin\usbsetup.exe |
"{9C4E6B78-ECA8-4FDB-9D52-87EB5202D32D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\far cry 3\bin\farcry3_d3d11.exe |
"{9CEC688C-194E-4F19-A45D-D2DBEBCD13FF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\plants vs zombies\plantsvszombies.exe |
"{9CF3974F-EEB6-402C-AA5B-36C0F4C06C51}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{9E9C0EA7-A812-4017-8933-43A04C0B6D0D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe |
"{9EB05E39-519A-4722-ABAD-DEF0D35ECBAF}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{9F10F4E6-5A43-4CD6-99A7-16A03A310B3E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\payday the heist\payday_win32_release.exe |
"{9F8D0E36-2828-467A-A8B7-7A3B4D5FD2C5}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{A091972F-4DFE-4561-BF77-992494AE00C7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\red faction armageddon\rf4_launcher.exe |
"{A15E6A5C-FC9E-4AF1-AABF-7DE64E68F49C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal 2\portal2.exe |
"{A2AEFD1A-15F2-4322-BD40-21404C585759}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\skyrim\skyrimlauncher.exe |
"{A789C6AE-6F9E-42A8-B67A-03E8E39EBA91}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\far cry 3\bin\fc3updatersteam.exe |
"{A79D617E-20E4-4789-8875-DAC46865F72D}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{A7A079CB-04CA-4DCC-9193-EACB9589C929}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\gotham city impostors\impostors.exe |
"{A89785D4-DEAF-4BAA-B04D-C68A898110FF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{ABC28AA2-B68E-4E64-B057-789CDA5C681D}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{AD790D78-9A2C-432C-95E2-B8FF85A943FC}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{AE058D47-E2FD-4481-B8FF-8541B01DD656}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{AF62D737-1DF2-4C66-854A-6D2D1BA465F0}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{B5EC695F-04D1-467B-AEF6-280ABF81541F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{B5F37AA6-C303-4551-AAE1-67790CD854A8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bastion\bastion.exe |
"{B8D48CD6-3388-4F66-AA63-9329A3E753C2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops ii\t6mp.exe |
"{BA05C965-87F5-4295-B863-D7E66B162065}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\launcher.exe |
"{BB6121D3-F419-4E92-8D48-56548871595D}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{BE017BF2-9BD9-4262-8AF9-FF7719E478D7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\gotham city impostors\engine.exe |
"{BFA289DC-FAE9-40E7-B552-EEF2549D7D69}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\gotham city impostors\impostors.exe |
"{C1065C69-F680-4D59-8CE8-4D8BC3E55FF7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\wormsrevolution\wormsrevolution.exe |
"{C69F878E-0E36-4D9D-8BD8-FF56633607FE}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{C72F683D-03A2-415F-9D9D-C6AB9F5A698B}" = protocol=17 | dir=in | app=c:\program files (x86)\belkin\router setup and monitor\belkinsetup.exe |
"{C77FE893-8242-4852-BE1F-E4F307AF6F13}" = protocol=6 | dir=in | app=c:\program files (x86)\belkin\router setup and monitor\belkinsetup.exe |
"{CACC25C4-6240-4070-9407-3C3B8E96B590}" = protocol=6 | dir=out | app=system |
"{CD9A0703-DB31-4CC4-A806-3958076268EF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{D0D49643-612E-4A39-B48F-1DBFEA1D7E6B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\wormsrevolution\wormsrevolution.exe |
"{D135E569-306A-4EED-BBF5-359F747E7E8E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\red faction armageddon\redfactionarmageddon.exe |
"{D7C750D6-B7C3-471A-A0C1-3F18AF95D08F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe |
"{DB6D73D6-352D-412F-BA53-43D93315204F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops ii\t6sp.exe |
"{E128E459-8A07-4E00-822B-5E415232D5CC}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\amd driver updater, vista and 7, 64 bit\setup.exe |
"{E2C54F63-DC3F-48C1-AE8B-180FBCA1E065}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\deus ex - human revolution\dxhr.exe |
"{E476579E-8DC2-45C4-96A9-B84C63913E9A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{E5FE7906-E201-4022-BAFC-BE1E01EC4B0B}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{EAA04ED0-E034-42ED-81C3-38E97F5D2266}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{EBB458E8-392F-4D86-B67A-1E8731082A80}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{EE65F383-4F78-4818-81E8-0B03FE667DC4}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\red faction armageddon\redfactionarmageddon_dx11.exe |
"{F076FDD7-5860-4843-93B7-33DCE07FF044}" = protocol=17 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"{F1E5342E-BA43-4393-A957-08A2BAB04020}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{F4016852-763C-45FE-9382-ABBFD9820A4E}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{F5233A05-E03A-45D2-A4FD-4323771DB93E}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{F55FED4F-8DA1-4233-930C-F6CFDA823BE2}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{F779E6E2-FAE4-457F-9BFF-3BBC11BCCABD}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dxhrml\dxhrml.exe |
"{FD9ADE17-7279-42D2-B32D-F6C76C3ECE7F}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{FE0D29FD-49F2-493A-98CD-E5C7BDD56033}" = dir=in | app=c:\program files\belkin\belkin usb print and storage center\connect.exe |
"TCP Query User{5D5BCAD9-7C60-49DE-80A0-9CA3B24E5FCC}C:\users\user\desktop\gw2.exe" = protocol=6 | dir=in | app=c:\users\user\desktop\gw2.exe |
"TCP Query User{7CDD5E9E-8ED3-4A34-BBE9-4B850FB8CA27}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe |
"UDP Query User{A9561244-0202-4F34-94B4-D424B472B73B}C:\users\user\desktop\gw2.exe" = protocol=17 | dir=in | app=c:\users\user\desktop\gw2.exe |
"UDP Query User{FB418785-536B-4361-8478-A0E0A32C92F6}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{06DB2C4C-DC29-DA42-3B00-5581CBF545BB}" = AMD Drag and Drop Transcoding
"{1AB4DB8C-4123-45DC-B896-C67990F76DA4}" = HP Deskjet 1050 J410 series Product Improvement Study
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{4268BF51-DFDF-4178-8B8D-5D5752FCAA58}" = HP Deskjet 1050 J410 series Basic Device Software
"{4975DE61-6BF6-B9BC-1FDE-C04C5EC78E4C}" = AMD Media Foundation Decoders
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{5E03A267-415E-5383-FA8F-3CE4145663B9}" = AMD Catalyst Install Manager
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{89EE4A30-080F-2C95-6F78-C98D18FBD74D}" = AMD Accelerated Video Transcoding
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-0015-0409-1000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-1000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-1000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-1000-0000000FF1CE}_Office14.SingleImage_{0242505C-4E90-407F-9299-B5B275F50D86}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-1000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-1000-0000000FF1CE}_Office14.SingleImage_{B51389C8-2890-4633-81D8-47D2A7402274}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-1000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-1000-0000000FF1CE}_Office14.SingleImage_{1779650B-2E44-4A19-8DF6-3866D645764A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-1000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-1000-0000000FF1CE}_Office14.SingleImage_{270CA0B9-9881-44DB-BC3B-37C7E66A044A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-1000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{7BC9B5EB-125A-4E9B-97E1-8D85B5E960B8}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010
"{90140000-0043-0000-1000-0000000FF1CE}_Office14.SingleImage_{E8B6D35B-0B6F-4DCE-9493-859BF3809A7F}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0043-0409-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (English) 2010
"{90140000-0043-0409-1000-0000000FF1CE}_Office14.SingleImage_{FCD1C311-8B02-4DBD-BA46-1079C629577E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-1000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-1000-0000000FF1CE}_Office14.SingleImage_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-1000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-1000-0000000FF1CE}_Office14.SingleImage_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-1000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{9CF11D16-ECEB-90A5-A028-CA9E068D848B}" = ccc-utility64
"{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}" = Ventrilo Client for Windows x64
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Belkin USB Print and Storage Center" = Belkin USB Print and Storage Center
"CCleaner" = CCleaner
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Office14.SingleImage" = Microsoft Office Professional 2010
"WinRAR archiver" = WinRAR 4.11 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{017F8447-2A1D-0DDB-B5D7-CA2BFACE2886}" = CCC Help French
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{054E9A1C-3EA2-C657-E787-FD8DCF5C3D3B}" = CCC Help Czech
"{14DC0059-00F1-4F62-BD1A-AB23CD51A95E}" = Adobe AIR
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1DE2BD51-0300-772D-5E18-F337D95D5687}" = CCC Help German
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{224E8FEB-5C1F-077F-6FC5-602AC1AE644D}" = CCC Help Danish
"{26A24AE4-039D-4CA4-87B4-2F83216033FF}" = Java™ 6 Update 37
"{26A24AE4-039D-4CA4-87B4-2F83217010FF}" = Java 7 Update 11
"{275E9C49-C72F-D754-DEB7-77F10A9C00D8}" = CCC Help Japanese
"{30049739-BE95-6591-B504-E6D7057D49CC}" = CCC Help Spanish
"{3DECD372-76A1-4483-BF10-B547790A3261}" = ON_OFF Charge B11.0110.1
"{3F1EB155-F96E-EB7B-2EF2-7375490E0FA9}" = CCC Help English
"{456A5815-604D-4D72-94DF-346D2B978A59}_is1" = GOG.com Downloader version 3.0.52
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B023D7B-9E67-795D-FB31-B5E1F6DCA451}" = CCC Help Italian
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{54B7A3C7-0940-4C16-A509-FC3C3758D22A}_is1" = Amnesia - The Dark Descent
"{55F6C486-8C75-2A72-DAFE-CE78A624C9F7}" = CCC Help Russian
"{5AF23993-7152-1620-E43F-1B4542FB4F84}" = CCC Help Thai
"{5C90D8CF-F12A-41C6-9007-3B651A1F0D78}" = HP Deskjet 1050 J410 series Help
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{63326924-3CAF-C858-3A8F-8598C87019D7}" = Catalyst Control Center
"{63822E89-11AA-F8EC-D433-F72A85799EC0}" = CCC Help Greek
"{64467D47-FFE4-4FBC-ABBA-A0DB829A17EB}" = NVIDIA PhysX
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{660787DD-68B3-4E67-9073-4A66DD7AD193}" = ASUS VGA Driver
"{66361420-4905-AEB8-17AE-172FDD164A7E}" = CCC Help Polish
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{769F2A4B-84A3-9486-ADD2-9E5AB4B4E1E3}" = Catalyst Control Center InstallProxy
"{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}" = Microsoft Games for Windows - LIVE Redistributable
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8773DD1C-5FB2-95B5-5A93-0EFEAC900A4D}" = CCC Help Norwegian
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8CCBB0BF-9CC1-1A65-BB93-56012A460EE6}" = CCC Help Portuguese
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9FD6F1A8-5550-46AF-8509-271DF0E768B5}" = Dual-Core Optimizer
"{A0A3CE05-96CB-52E9-434E-074F3BB7807E}" = CCC Help Turkish
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9C64319-932F-D02B-B14C-FFFC3EC49E77}" = CCC Help Chinese Standard
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.5)
"{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update
"{B93EEE50-9C8F-45DF-95E4-3D85A6E242F3}" = DarksidersInstaller
"{C09DB932-7619-7B56-30E3-C0454811D6D7}" = CCC Help Korean
"{C22A4697-BD77-ACB1-744F-1FD0A0BFF798}" = CCC Help Swedish
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D4B457B2-260F-C561-CA87-703BD3B724CA}" = Catalyst Control Center Graphics Previews Common
"{D6CDB506-297D-AE70-0EF6-DE5185F961BE}" = CCC Help Chinese Traditional
"{D7AF16E7-5938-4369-BA54-B1ABD541BC32}" = Utility
"{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}" = Etron USB3.0 Host Controller
"{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}" = Catalyst Control Center - Branding
"{E5F05232-96B6-4552-A480-785A60A94B21}" = System Requirements Lab CYRI
"{EA17F4FC-FDBF-4CF8-A529-2D983132D053}" = Skype™ 6.0
"{ECFD508E-68A2-91B2-46DD-1D03D783D94B}" = Catalyst Control Center Localization All
"{EDE361D5-35A5-DA7D-3462-C3DABD24029B}" = CCC Help Hungarian
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Processor Graphics
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1E7DD6A-AE2D-D706-BEB3-937F76CA6AE9}" = CCC Help Finnish
"{F56F54DD-BCB2-1221-2CB7-E983A5CF9D15}" = CCC Help Dutch
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"8461-7759-5462-8226" = Vuze
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"avast" = avast! Internet Security
"Belkin Setup and Router Monitor_is1" = Belkin Setup and Router Monitor
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"Google Chrome" = Google Chrome
"Guild Wars" = Guild Wars
"HP Photo Creations" = HP Photo Creations
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100
"Mozilla Firefox 13.0.1 (x86 en-US)" = Mozilla Firefox 13.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NCLauncher_GameForge" = NC Launcher (GameForge)
"PunkBusterSvc" = PunkBuster Services
"SpeedFan" = SpeedFan (remove only)
"Steam App 107100" = Bastion
"Steam App 200170" = Worms Revolution
"Steam App 201280" = Deus Ex: Human Revolution - The Missing Link
"Steam App 202970" = Call of Duty: Black Ops II
"Steam App 202990" = Call of Duty: Black Ops II - Multiplayer
"Steam App 205100" = Dishonored
"Steam App 20540" = Company of Heroes: Tales of Valor
"Steam App 21170" = Gotham City Impostors
"Steam App 212910" = Call of Duty: Black Ops II - Zombies
"Steam App 220240" = Far Cry® 3
"Steam App 24240" = PAYDAY: The Heist
"Steam App 28050" = Deus Ex: Human Revolution
"Steam App 3590" = Plants vs. Zombies: Game of the Year
"Steam App 43110" = Metro 2033
"Steam App 4560" = Company of Heroes
"Steam App 49520" = Borderlands 2
"Steam App 50620" = Darksiders
"Steam App 550" = Left 4 Dead 2
"Steam App 55110" = Red Faction: Armageddon
"Steam App 55230" = Saints Row: The Third
"Steam App 57400" = Batman: Arkham City™
"Steam App 620" = Portal 2
"Steam App 72850" = The Elder Scrolls V: Skyrim
"Steam App 9340" = Company of Heroes: Opposing Fronts
"Super Meat Boy v1.5_is1" = Super Meat Boy v1.5
"Uplay" = Uplay
"Video Mover_is1" = Video Mover
"xvid" = XviD MPEG-4 Video Codec

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Square Enix Secure Launcher" = Square Enix Secure Launcher

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 26/01/2013 13:22:11 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application name: Skype.exe, version: 6.0.0.126, time stamp:
0x509ce778 Faulting module name: Skype.exe, version: 6.0.0.126, time stamp: 0x509ce778
Exception
code: 0xc0000005 Fault offset: 0x001c5730 Faulting process id: 0xc9c Faulting application
start time: 0x01cdfbe9abb827fb Faulting application path: C:\Program Files (x86)\Skype\Phone\Skype.exe
Faulting
module path: C:\Program Files (x86)\Skype\Phone\Skype.exe Report Id: ea934fbf-67dc-11e2-bdf8-50e549e3d4df

Error - 26/01/2013 13:42:00 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application name: svchost.exe_SysMain, version: 6.1.7600.16385,
time stamp: 0x4a5bc3c1 Faulting module name: sysmain.dll, version: 6.1.7601.17514,
time stamp: 0x4ce7c9db Exception code: 0xc0000005 Fault offset: 0x0000000000012caf
Faulting
process id: 0xabc Faulting application start time: 0x01cdfbde109afd62 Faulting application
path: C:\Windows\system32\svchost.exe Faulting module path: c:\windows\system32\sysmain.dll
Report
Id: af58b75a-67df-11e2-bdf8-50e549e3d4df

Error - 26/01/2013 13:43:01 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application name: svchost.exe_SysMain, version: 6.1.7600.16385,
time stamp: 0x4a5bc3c1 Faulting module name: sysmain.dll, version: 6.1.7601.17514,
time stamp: 0x4ce7c9db Exception code: 0xc0000005 Fault offset: 0x000000000001e59a
Faulting
process id: 0x448 Faulting application start time: 0x01cdfbec95bea648 Faulting application
path: C:\Windows\system32\svchost.exe Faulting module path: c:\windows\system32\sysmain.dll
Report
Id: d3b59158-67df-11e2-bdf8-50e549e3d4df

Error - 26/01/2013 14:41:12 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application name: BelkinRouterMonitor.exe, version: 4.0.6.24160,
time stamp: 0x4de00026 Faulting module name: QtCore4.dll, version: 4.5.3.0, time
stamp: 0x4ba3e827 Exception code: 0x80000003 Fault offset: 0x000e96dc Faulting process
id: 0xb34 Faulting application start time: 0x01cdfbf4a822e927 Faulting application
path: C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe
Faulting
module path: C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtCore4.dll
Report
Id: f4a47bbf-67e7-11e2-81eb-50e549e3d4df

Error - 26/01/2013 14:41:14 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application name: dlnaPlugin.exe, version: 0.9.0.1, time
stamp: 0x4dd449b0 Faulting module name: QtCore4.dll, version: 4.5.3.0, time stamp:
0x4ba3e827 Exception code: 0x80000003 Fault offset: 0x000e96dc Faulting process id:
0xa7c Faulting application start time: 0x01cdfbf4ac43cc21 Faulting application path:
C:\Program Files (x86)\Belkin\Router Setup and Monitor\dlnaPlugin.exe Faulting module
path: C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtCore4.dll Report
Id: f5a3002d-67e7-11e2-81eb-50e549e3d4df

Error - 28/01/2013 09:59:36 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application name: svchost.exe_Power, version: 6.1.7600.16385,
time stamp: 0x4a5bc3c1 Faulting module name: ole32.dll, version: 6.1.7601.17514,
time stamp: 0x4ce7c92c Exception code: 0xc0000005 Fault offset: 0x0000000000029158
Faulting
process id: 0x32c Faulting application start time: 0x01cdfd5f96e0bf40 Faulting application
path: C:\Windows\system32\svchost.exe Faulting module path: C:\Windows\system32\ole32.dll
Report
Id: f27a5cd8-6952-11e2-81e0-50e549e3d4df

Error - 28/01/2013 10:35:57 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application name: LolClient.exe, version: 2.0.2.12610, time
stamp: 0x4c00573a Faulting module name: Adobe AIR.dll, version: 3.1.0.4880, time
stamp: 0x4eb75fb9 Exception code: 0xc0000005 Fault offset: 0x00480048 Faulting process
id: 0x1460 Faulting application start time: 0x01cdfd64811cf759 Faulting application
path: C:\Riot Games\RADS\projects\lol_air_client\releases\0.0.0.233\deploy\LolClient.exe
Faulting
module path: C:\Riot Games\RADS\projects\lol_air_client\releases\0.0.0.233\deploy\Adobe
AIR\Versions\1.0\Adobe AIR.dll Report Id: 06ed6c4b-6958-11e2-ae6d-50e549e3d4df

Error - 28/01/2013 18:51:31 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application name: League of Legends.exe, version: 1.0.0.154,
time stamp: 0x50f5f2eb Faulting module name: fmodex.dll, version: 0.4.32.7, time
stamp: 0x4d2667ec Exception code: 0xc0000005 Fault offset: 0x0003ed98 Faulting process
id: 0x1b74 Faulting application start time: 0x01cdfda9dd049270 Faulting application
path: C:\Riot Games\League of Legends\RADS\solutions\lol_game_client_sln\releases\0.0.0.207\deploy\League
of Legends.exe Faulting module path: C:\Riot Games\League of Legends\RADS\solutions\lol_game_client_sln\releases\0.0.0.207\deploy\fmodex.dll
Report
Id: 416f7f83-699d-11e2-ae6d-50e549e3d4df

Error - 28/01/2013 19:50:35 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application name: League of Legends.exe, version: 1.0.0.154,
time stamp: 0x50f5f2eb Faulting module name: unknown, version: 0.0.0.0, time stamp:
0x00000000 Exception code: 0xc0000005 Fault offset: 0xff000000 Faulting process id:
0x1b30 Faulting application start time: 0x01cdfdaf06182f6b Faulting application path:
C:\Riot Games\RADS\solutions\lol_game_client_sln\releases\0.0.0.207\deploy\League
of Legends.exe Faulting module path: unknown Report Id: 81d27acd-69a5-11e2-ae6d-50e549e3d4df

Error - 29/01/2013 11:11:10 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application name: mbamservice.exe, version: 1.70.0.0, time
stamp: 0x50cb9148 Faulting module name: mbamservice.exe, version: 1.70.0.0, time
stamp: 0x50cb9148 Exception code: 0xc0000005 Fault offset: 0x000255a3 Faulting process
id: 0x8fc Faulting application start time: 0x01cdfe318fdecd8e Faulting application
path: C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe Faulting
module path: C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe Report
Id: 1c50b4cd-6a26-11e2-bdfe-50e549e3d4df

Error - 29/01/2013 15:56:12 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application name: LolClient.exe, version: 2.0.2.12610, time
stamp: 0x4c00573a Faulting module name: Adobe AIR.dll, version: 3.1.0.4880, time
stamp: 0x4eb75fb9 Exception code: 0xc0000005 Fault offset: 0x00480048 Faulting process
id: 0xe3c Faulting application start time: 0x01cdfe5a1f0d02a6 Faulting application
path: C:\Riot Games\RADS\projects\lol_air_client\releases\0.0.0.233\deploy\LolClient.exe
Faulting
module path: C:\Riot Games\RADS\projects\lol_air_client\releases\0.0.0.233\deploy\Adobe
AIR\Versions\1.0\Adobe AIR.dll Report Id: edfb942d-6a4d-11e2-81e4-50e549e3d4df

Error - 29/01/2013 17:22:17 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application name: LolClient.exe, version: 2.0.2.12610, time
stamp: 0x4c00573a Faulting module name: Adobe AIR.dll, version: 3.1.0.4880, time
stamp: 0x4eb75fb9 Exception code: 0xc0000005 Fault offset: 0x0021d524 Faulting process
id: 0x6a8 Faulting application start time: 0x01cdfe5abd14d0c4 Faulting application
path: C:\Riot Games\RADS\projects\lol_air_client\releases\0.0.0.233\deploy\LolClient.exe
Faulting
module path: C:\Riot Games\RADS\projects\lol_air_client\releases\0.0.0.233\deploy\Adobe
AIR\Versions\1.0\Adobe AIR.dll Report Id: f4ff0930-6a59-11e2-81e4-50e549e3d4df

Error - 29/01/2013 21:22:16 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application name: svchost.exe_SysMain, version: 6.1.7600.16385,
time stamp: 0x4a5bc3c1 Faulting module name: sysmain.dll, version: 6.1.7601.17514,
time stamp: 0x4ce7c9db Exception code: 0xc0000005 Fault offset: 0x00000000000170c2
Faulting
process id: 0x860 Faulting application start time: 0x01cdfe8821d591cc Faulting application
path: C:\Windows\system32\svchost.exe Faulting module path: c:\windows\system32\sysmain.dll
Report
Id: 7b32de9c-6a7b-11e2-aa1d-50e549e3d4df

Error - 30/01/2013 09:50:26 | Computer Name = User-PC | Source = .NET Runtime | ID = 1026
Description =

Error - 30/01/2013 09:51:35 | Computer Name = User-PC | Source = Microsoft-Windows-CAPI2 | ID = 257
Description = The Cryptographic Services service failed to initialize the Catalog
Database. The ESENT error was: -107.

Error - 30/01/2013 09:51:35 | Computer Name = User-PC | Source = Microsoft-Windows-CAPI2 | ID = 257
Description = The Cryptographic Services service failed to initialize the Catalog
Database. The ESENT error was: -107.

Error - 30/01/2013 09:51:35 | Computer Name = User-PC | Source = Microsoft-Windows-CAPI2 | ID = 257
Description = The Cryptographic Services service failed to initialize the Catalog
Database. The ESENT error was: -107.

Error - 30/01/2013 10:08:53 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application name: mbamgui.exe, version: 1.70.0.0, time stamp:
0x50cb9162 Faulting module name: mbamgui.exe, version: 1.70.0.0, time stamp: 0x50cb9162
Exception
code: 0x40000015 Fault offset: 0x00038b55 Faulting process id: 0x750 Faulting application
start time: 0x01cdfef330e67f4c Faulting application path: C:\Program Files (x86)\Malwarebytes'
Anti-Malware\mbamgui.exe Faulting module path: C:\Program Files (x86)\Malwarebytes'
Anti-Malware\mbamgui.exe Report Id: 937abfcc-6ae6-11e2-aa00-50e549e3d4df

[ Media Center Events ]
Error - 09/04/2012 08:22:47 | Computer Name = User-PC | Source = MCUpdate | ID = 0
Description = 13:22:47 - Error connecting to the internet. 13:22:47 - Unable
to contact server..

[ System Events ]
Error - 30/01/2013 10:00:07 | Computer Name = User-PC | Source = Service Control Manager | ID = 7000
Description = The WMPNetworkSvc service failed to start due to the following error:
%%2

Error - 30/01/2013 10:11:27 | Computer Name = User-PC | Source = PNRPSvc | ID = 102
Description =

Error - 30/01/2013 10:11:27 | Computer Name = User-PC | Source = Service Control Manager | ID = 7023
Description = The Peer Name Resolution Protocol service terminated with the following
error: %%-2140993535

Error - 30/01/2013 10:11:27 | Computer Name = User-PC | Source = Service Control Manager | ID = 7001
Description = The Peer Networking Grouping service depends on the Peer Name Resolution
Protocol service which failed to start because of the following error: %%-2140993535

Error - 30/01/2013 10:11:38 | Computer Name = User-PC | Source = PNRPSvc | ID = 102
Description =

Error - 30/01/2013 10:11:38 | Computer Name = User-PC | Source = PNRPSvc | ID = 102
Description =

Error - 30/01/2013 10:11:38 | Computer Name = User-PC | Source = Service Control Manager | ID = 7023
Description = The Peer Name Resolution Protocol service terminated with the following
error: %%-2140993535

Error - 30/01/2013 10:11:38 | Computer Name = User-PC | Source = Service Control Manager | ID = 7001
Description = The Peer Networking Grouping service depends on the Peer Name Resolution
Protocol service which failed to start because of the following error: %%-2140993535

Error - 30/01/2013 10:11:38 | Computer Name = User-PC | Source = Service Control Manager | ID = 7023
Description = The Peer Name Resolution Protocol service terminated with the following
error: %%-2140993535

Error - 30/01/2013 10:11:38 | Computer Name = User-PC | Source = Service Control Manager | ID = 7001
Description = The Peer Networking Grouping service depends on the Peer Name Resolution
Protocol service which failed to start because of the following error: %%-2140993535


< End of report >
And finally here is the JTR Log. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 4.5.5 (01.30.2013:2) OS: Windows 7 Home Premium x64 Ran by [removed] on 30/01/2013 at 16:14:58.51 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully deleted: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\toolbar\\{ae07101b-46d4-4a98-af68-0333ea26e113} Successfully deleted: [Registry Value] hkey_current_user\software\microsoft\internet explorer\toolbar\webbrowser\\{ba14329e-9550-4989-b3f2-9732e92d17cc} Successfully repaired: [Registry Value] hkey_current_user\software\microsoft\internet explorer\main\\Start Page Successfully repaired: [Registry Value] hkey_users\.default\software\microsoft\internet explorer\main\\Start Page Successfully repaired: [Registry Value] hkey_users\s-1-5-18\software\microsoft\internet explorer\main\\Start Page Successfully repaired: [Registry Value] hkey_users\s-1-5-19\software\microsoft\internet explorer\main\\Start Page Successfully repaired: [Registry Value] hkey_users\s-1-5-20\software\microsoft\internet explorer\main\\Start Page Successfully repaired: [Registry Value] hkey_users\S-1-5-21-1447855767-3573926289-1960894109-1000\software\microsoft\internet explorer\main\\Start Page Successfully repaired: [Registry Value] hkey_current_user\software\microsoft\internet explorer\searchscopes\\DefaultScope Successfully repaired: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\searchscopes\\DefaultScope Successfully repaired: [Registry Value] hkey_users\.default\software\microsoft\internet explorer\searchscopes\\DefaultScope Successfully repaired: [Registry Value] hkey_users\s-1-5-18\software\microsoft\internet explorer\searchscopes\\DefaultScope Successfully repaired: [Registry Value] hkey_users\s-1-5-19\software\microsoft\internet explorer\searchscopes\\DefaultScope Successfully repaired: [Registry Value] hkey_users\s-1-5-20\software\microsoft\internet explorer\searchscopes\\DefaultScope Successfully repaired: [Registry Value] hkey_users\S-1-5-21-1447855767-3573926289-1960894109-1000\software\microsoft\internet explorer\searchscopes\\DefaultScope Successfully repaired: [Registry Value] hkey_current_user\software\microsoft\internet explorer\main\\Search Bar Successfully repaired: [Registry Value] hkey_users\S-1-5-21-1447855767-3573926289-1960894109-1000\software\microsoft\internet explorer\main\\Search Bar Successfully repaired: [Registry Value] hkey_current_user\software\microsoft\internet explorer\main\\Search Page Successfully repaired: [Registry Value] hkey_users\S-1-5-21-1447855767-3573926289-1960894109-1000\software\microsoft\internet explorer\main\\Search Page Successfully repaired: [Registry Value] hkey_current_user\software\microsoft\internet explorer\search\\Default_Search_URL Successfully repaired: [Registry Value] hkey_users\S-1-5-21-1447855767-3573926289-1960894109-1000\software\microsoft\internet explorer\search\\Default_Search_URL Successfully repaired: [Registry Value] hkey_current_user\software\microsoft\internet explorer\searchurl\\Default Successfully repaired: [Registry Value] hkey_users\S-1-5-21-1447855767-3573926289-1960894109-1000\software\microsoft\internet explorer\searchurl\\Default Successfully repaired: [Registry Value] hkey_current_user\software\microsoft\internet explorer\search\\SearchAssistant Successfully repaired: [Registry Value] hkey_users\S-1-5-21-1447855767-3573926289-1960894109-1000\software\microsoft\internet explorer\search\\SearchAssistant ~~~ Registry Keys Successfully deleted: [Registry Key] hkey_current_user\software\conduit Successfully deleted: [Registry Key] hkey_local_machine\software\conduit Successfully deleted: [Registry Key] hkey_current_user\software\igearsettings Successfully deleted: [Registry Key] hkey_current_user\software\smartbar Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\conduit Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\conduitsearchscopes Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\crossrider Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\pricegong Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\smartbar Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{3c471948-f874-49f5-b338-4f214a2ee0b1} Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{95b7759c-8c7f-4bf1-b163-73684a933233} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{ae07101b-46d4-4a98-af68-0333ea26e113} ~~~ Files Successfully deleted: [File] C:\eula.1028.txt Successfully deleted: [File] C:\eula.1031.txt Successfully deleted: [File] C:\eula.1033.txt Successfully deleted: [File] C:\eula.1036.txt Successfully deleted: [File] C:\eula.1040.txt Successfully deleted: [File] C:\eula.1041.txt Successfully deleted: [File] C:\eula.1042.txt Successfully deleted: [File] C:\eula.2052.txt Successfully deleted: [File] C:\install.res.1028.dll Successfully deleted: [File] C:\install.res.1031.dll Successfully deleted: [File] C:\install.res.1033.dll Successfully deleted: [File] C:\install.res.1036.dll Successfully deleted: [File] C:\install.res.1040.dll Successfully deleted: [File] C:\install.res.1041.dll Successfully deleted: [File] C:\install.res.1042.dll Successfully deleted: [File] C:\install.res.2052.dll Successfully deleted: [File] C:\install.res.3082.dll ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\tarma installer" Successfully deleted: [Folder] "C:\Users\User\appdata\local\conduit" Successfully deleted: [Folder] "C:\Users\User\appdata\locallow\conduit" Successfully deleted: [Folder] "C:\Users\User\appdata\locallow\pricegong" Successfully deleted: [Folder] "C:\Program Files (x86)\conduit" Successfully deleted: [Folder] "C:\Program Files (x86)\coupons" ~~~ FireFox Successfully deleted the following from C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\11nx87hu.default\prefs.js user_pref("browser.startup.homepage", "hxxp://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=GB&userid=87fb5ffa-7fed-4760-8157-1cd1030e2963&searchtype=hp"); user_pref("extensions.helperbar.SmartbarDisabled", false); user_pref("extensions.helperbar.SmartbarStateMinimaized", false); user_pref("keyword.URL", "hxxp://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=GB&userid=87fb5ffa-7fed-4760-8157-1cd1030e2963&searchtype=ds&q="); ~~~ Chrome Successfully deleted: [Registry Key] hkey_current_user\software\google\chrome\extensions\ojpijjmpahflnipadmlpgbjmagmjchkk Successfully deleted: [Registry Key] hkey_local_machine\software\google\chrome\extensions\ojpijjmpahflnipadmlpgbjmagmjchkk ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 30/01/2013 at 16:19:50.62 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI