This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

norton sent me here! [Solved]

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

ok so one of the admins from norton security sent me here because they thought something nasty might be going on in my pc. Yesterday i started up my pc went to run norton 360 and it wouldnt start up at all tried all icons nothing did a fresh reinstall got it to work for a scan but updates told me i had to restart so i did came back into windows wouldnt work again so i downloaded there removal and install tool for nortons and i did restarted then got BSOD and then rebooted into safe mode then i restarted in normal mode then couldnt access internet looked at windows messages saying 360 and windows defender is turned off so i tried and tried to get norton working but didnt want to turn on so i turned win defender on restarted my pc then i can use the internet this is the link to my post to norton: https://community.norton.com/t5/Norton-360/…p/908617#M86611

i have ran otl and this is what i got from it :
EXTRAS.txt

OTL Extras logfile created on: 2/11/2013 1:03:37 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Scotty\Downloads
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

15.95 Gb Total Physical Memory | 13.14 Gb Available Physical Memory | 82.36% Memory free
31.90 Gb Paging File | 28.64 Gb Available in Paging File | 89.78% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.66 Gb Total Space | 252.43 Gb Free Space | 54.21% Space Free | Partition Type: NTFS
Drive G: | 100.00 Mb Total Space | 69.87 Mb Free Space | 69.87% Space Free | Partition Type: NTFS

Computer Name: SCOTTY-PC | User Name: Scotty | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [GomAudio.Add] – C:\Program Files (x86)\GRETECH\GomAudio\GOMA.exe /add "%1" (Gretech Corporation)
Directory [GomAudio.AddCur] – C:\Program Files (x86)\GRETECH\GomAudio\GOMA.exe /addcur "%1" (Gretech Corporation)
Directory [GomAudio.Play] – C:\Program Files (x86)\GRETECH\GomAudio\GOMA.exe "%1" (Gretech Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [GomAudio.Add] – C:\Program Files (x86)\GRETECH\GomAudio\GOMA.exe /add "%1" (Gretech Corporation)
Directory [GomAudio.AddCur] – C:\Program Files (x86)\GRETECH\GomAudio\GOMA.exe /addcur "%1" (Gretech Corporation)
Directory [GomAudio.Play] – C:\Program Files (x86)\GRETECH\GomAudio\GOMA.exe "%1" (Gretech Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{06515A27-3ED2-4801-89FE-64664B18E3E0}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{0F78D719-822C-41B6-97E6-BD9388013738}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{121CD1F8-183F-410D-B238-531828119F87}" = rport=137 | protocol=17 | dir=out | app=system |
"{125AF3E3-6FCF-4719-8FB0-C02FB9A89B7E}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{18A239D1-919E-4241-93A7-4B5E0AFC4F7C}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{311EB61E-E437-4E4C-9670-E5D898E2436B}" = lport=445 | protocol=6 | dir=in | app=system |
"{336A08BD-D021-40F0-97A6-062E864AFD2C}" = rport=445 | protocol=6 | dir=out | app=system |
"{338F619B-F110-48C4-8DD8-3F4FACC9C300}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{6098C9D0-CD57-4B00-9D15-ED5271027D8E}" = rport=138 | protocol=17 | dir=out | app=system |
"{7708BB30-C841-45AD-9A7E-0CF06A2C04D5}" = lport=138 | protocol=17 | dir=in | app=system |
"{86E9E631-2461-4D07-96F5-8E37CBACC24D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{87726DFA-0EA6-481C-9A1A-458D4B1FB729}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{BC293D8D-D935-44EF-85A7-1C3744E8D017}" = rport=10243 | protocol=6 | dir=out | app=system |
"{CB572987-7FDF-4D4E-AD1E-2CA957BF6FC4}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{D352C616-984D-4D5A-9E76-B4114C7903DA}" = lport=139 | protocol=6 | dir=in | app=system |
"{D4D40B41-5AFE-4DFA-9C0D-9B287165154D}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{E91CFC87-449A-44DD-B8FA-09F265524968}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{F0D0A2CA-7A6D-4252-9D74-D7FAB4989BEE}" = lport=10243 | protocol=6 | dir=in | app=system |
"{F240CA2C-07EF-4A0B-91D5-76CFADE8E66F}" = lport=2869 | protocol=6 | dir=in | app=system |
"{F42ED7C4-D23C-439A-A2AC-C0B055DF422A}" = rport=139 | protocol=6 | dir=out | app=system |
"{FF99BE45-4F2F-4ED7-B42D-7368B105EFE0}" = lport=137 | protocol=17 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0069693A-F4FA-400C-9BEC-B07405338A67}" = dir=in | app=c:\users\scotty\documents\the war z\warz.exe |
"{01EFA469-1363-4385-85B2-F34E80F53DC4}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{02509364-73EB-44B9-9F02-CEDC15628F58}" = protocol=17 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"{085C8BF9-6A94-4084-BA99-F409C31CB7F7}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{110EBE58-D81D-4486-A508-6D3F64D7B465}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\expansion\beta\arma2oa.exe |
"{1B44082A-E9BF-4B0C-9525-AA110F2CBB3F}" = protocol=6 | dir=in | app=c:\program files (x86)\norton 360\engine64\20.2.1.22\uistub.exe |
"{1C581BC3-4431-4888-A679-2B2B1EC71408}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{1DEF38F0-3701-4485-BF54-18011DEE18C5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{22B7A4A0-01F8-4753-BD54-4A03F69A1181}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{25266B86-73CF-4F2E-A41B-AC7028B552BB}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2\arma2.exe |
"{2DA80237-FED2-4950-B0C1-6A68550FA77B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{3986EDB8-8A21-48E7-81E1-542B0C15A002}" = protocol=6 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe |
"{39FF4B59-5A3D-4D09-B63E-7EC040895153}" = protocol=17 | dir=in | app=c:\program files (x86)\vivox\c3\c3.exe |
"{3C4D3F33-B151-4CB6-8E60-842A45DA4B1B}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{3F475EA7-756F-4328-948E-8CB9382CDF1B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{4631C9F0-48B3-4DEF-9CF2-866DC676D779}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{50D1F595-1F37-4238-ADEE-27E9CA636F04}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\painkiller hell & damnation\binaries\win32\pkhdgame-win32-shipping.exe |
"{50D966E7-049E-43FE-803E-B45D7F2FE047}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{52898001-8E53-4237-879C-1B364C66A19A}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{587B0F0A-30A0-4CB9-B30E-E30239A8B512}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2\arma2.exe |
"{61180F6E-88B7-43BD-B834-DEF619CEB80D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\specops_theline\binaries\win32\specopstheline.exe |
"{65B03799-1E9E-424F-A16A-3FA7E11FA410}" = protocol=6 | dir=out | app=system |
"{66FBECA7-2132-428B-9F1A-B1CB01C2F560}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{6C3CEBA4-646E-4ED8-B277-AB9ECFD4B7B6}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{6FE51834-C44C-423E-8EBB-958030CB559D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7566B443-07EF-4EB6-8729-744BAB770C36}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\crysis 3 mp open beta\bin32\crysis 3 mp open beta.exe |
"{7905C7C1-8B9B-42ED-B544-A6F3B9DC3568}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\besetup\setup_battleyearma2oa.exe |
"{7CAB24EC-C29B-4E0B-AD22-3D99E801F493}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\arma2oa.exe |
"{7D3217A2-9342-44C0-AC08-1CB888C80B89}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{7E242367-E80A-48E5-9954-8018026DB06F}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{7E5D766C-1098-484B-8FB3-0A22BFE00E53}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sleepingdogs\hkship.exe |
"{8264117A-8726-4D4B-8D4A-4BD53913CA42}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\amd driver updater, vista and 7, 64 bit\setup.exe |
"{8B15BE8E-0F5C-4499-9C84-CD03687A1DA8}" = protocol=6 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"{8E108629-651C-4901-BF08-D891723603FF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9B8C8989-0A38-4E21-BA24-8FA0497AC3A4}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\payday the heist\payday_win32_release.exe |
"{9DFF0413-320A-47CE-AC55-DC46566AE06E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead island\deadislandgame.exe |
"{9F14DA69-B52B-47B0-A15F-1063F3A1E78C}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{9F78810C-5F73-4EF8-B472-E4C82AB31581}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\besetup\setup_battleyearma2oa.exe |
"{A0039B9A-E781-4DC4-B45C-3B2956158F00}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\3dmark vantage\3dmarkvantagelauncher.exe |
"{A1072BE5-64C9-4BB2-9C57-1AFC275C9339}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{A16613FA-0B67-4D91-BF07-FAE1742E4D2D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{B6E0E7A2-B14C-4F16-AE0D-E5FF71FD5CD8}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\crysis 3 mp open beta\bin32\crysis 3 mp open beta.exe |
"{B9C3402B-1CE1-4201-B1B7-D05BC973C1DE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\painkiller hell & damnation\binaries\win32\pkhdgame-win32-shipping.exe |
"{BADD035A-5619-4A77-86C0-9FA84C6006B4}" = protocol=17 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
"{BAF70A66-0D0B-4D6C-B68F-38B7BBCC89C4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead island\deadislandgame.exe |
"{BD90AAEB-5C7A-4B64-8794-62EBF4AA6236}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sleepingdogs\hkship.exe |
"{CF34E4F3-8270-4B9E-ADC7-56BFA29C34E5}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{D1E7A2AF-AD19-481B-84B8-5A605FCC03CA}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{D93B8EB8-2CBD-4620-B6E4-4BC7A86EF123}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{E33DDF4F-8713-4EB2-9B78-3AC202990B81}" = protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe |
"{E378C36D-2F29-43B5-BD57-E9CFCBF4F5F3}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{EAC5A995-A2FC-461C-94E3-D90AFD7EC8A2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\arma2oa.exe |
"{EC8FA9C9-846E-46BE-8840-5897804D7BD6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\expansion\beta\arma2oa.exe |
"{EE421A59-2E50-4F79-9D81-CCF3322A7A18}" = protocol=6 | dir=in | app=c:\program files (x86)\vivox\c3\c3.exe |
"{EE553752-4BA5-4A2F-90BC-6170C09275EF}" = protocol=6 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
"{EF0C8C0F-F36D-4CBF-A03B-B7650CB07ABE}" = dir=in | app=c:\program files (x86)\intel\extreme tuning utility\client\perftune.exe |
"{F287DDA6-98BF-47D6-9C72-0A0866E9A6CE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\payday the heist\payday_win32_release.exe |
"{F4873694-EC9B-47CB-91FB-B8F8DF3E0158}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\amd driver updater, vista and 7, 64 bit\setup.exe |
"{F5AEA7A0-88C9-4342-8ACB-F16F62A56DAF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\specops_theline\binaries\win32\specopstheline.exe |
"{F78EBD8D-A019-4E05-BAE1-4FE305B6005E}" = protocol=17 | dir=in | app=c:\program files (x86)\norton 360\engine64\20.2.1.22\uistub.exe |
"{F8682E4D-B089-46FF-9490-5319FBBECB2F}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{FF5BC929-16B3-4184-8B74-98E90E942407}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\3dmark vantage\3dmarkvantagelauncher.exe |
"{FF780CDF-B1F9-4C36-A802-916CE0D187A3}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"TCP Query User{8524AE10-288C-412C-BB0D-4A3718D3196B}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"TCP Query User{AADFB6D0-8250-4279-A87D-6C2C57ED8C70}C:\games\world_of_tanks\wotlauncher.exe" = protocol=6 | dir=in | app=c:\games\world_of_tanks\wotlauncher.exe |
"TCP Query User{C2E6836B-F312-4A6F-B5E7-A0C9E2131151}C:\program files (x86)\netgear genie\bin\netgeargenie.exe" = protocol=6 | dir=in | app=c:\program files (x86)\netgear genie\bin\netgeargenie.exe |
"TCP Query User{E29B2296-F8AA-4189-A9C3-8A3C504C65F9}C:\program files (x86)\netgear genie\bin\netgeargenie.exe" = protocol=6 | dir=in | app=c:\program files (x86)\netgear genie\bin\netgeargenie.exe |
"UDP Query User{51AC5313-7715-486A-AE15-E6A9E44E60D6}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"UDP Query User{79D76012-B35E-4DC3-B168-861F8820D0B6}C:\games\world_of_tanks\wotlauncher.exe" = protocol=17 | dir=in | app=c:\games\world_of_tanks\wotlauncher.exe |
"UDP Query User{846D7D13-8E27-4B38-9148-E2EE75D4617B}C:\program files (x86)\netgear genie\bin\netgeargenie.exe" = protocol=17 | dir=in | app=c:\program files (x86)\netgear genie\bin\netgeargenie.exe |
"UDP Query User{8F60C38D-E42A-452D-BD0E-15E660F84A40}C:\program files (x86)\netgear genie\bin\netgeargenie.exe" = protocol=17 | dir=in | app=c:\program files (x86)\netgear genie\bin\netgeargenie.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{09536BA1-E498-4CC3-B834-D884A67D7E34}" = Intel® Trusted Connect Service Client
"{1AFC919D-751B-A5D7-B17D-7C0067A65D2E}" = AMD Drag and Drop Transcoding
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{20384EBF-4F10-13F0-07C6-7A6C87FD83DF}" = AMD Catalyst Install Manager
"{477D05CA-C151-9CF5-22A1-9DF6DF543CD4}" = AMD Media Foundation Decoders
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1" = Revo Uninstaller Pro 2.5.9
"{6C9365EB-1F9E-4893-9196-3EC77C88D0C5}" = Intel® Turbo Boost Technology Monitor 2.6
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{C1ACBDBF-6F86-185A-E158-AB07893968FC}" = AMD Accelerated Video Transcoding
"{D1B033E8-A077-4B0D-9831-5798E19E861E}" = Intel® Smart Connect Technology 2.0 x64
"{D61EB116-6878-9676-F28F-54F6B647023C}" = ccc-utility64
"{DA2737A4-B639-96F4-1CC2-30D2919EE1FB}" = AMD Steady Video Plug-In
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"ASRock App Charger_is1" = ASRock App Charger v1.0.5
"ASRock SmartConnect_is1" = ASRock SmartConnect v1.0.6
"ASRock XFast RAM_is1" = ASRock XFast RAM v2.0.9
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.62.0
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"XFast LAN" = XFast LAN v6.61

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{009B1E9D-38AB-8B9E-DB07-8318DAAE1941}" = CCC Help Greek
"{009E5DF2-3F97-480B-89DA-F2D5E672E14A}_is1" = Live Update 5
"{022BC727-ACB7-4C1D-109C-177515714A32}" = Catalyst Control Center
"{02454664-23E6-46B3-9CB3-30870AE3645E}" = Crysis®3 MP Open Beta
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{07E46A4A-F2BA-FE48-9464-E11250502C6A}" = CCC Help Swedish
"{07E5C16F-9194-E31B-BB6C-C3E8FBD79C30}" = CCC Help English
"{0B30B8D2-9DE0-4EEC-AA68-8E1E77CD8322}" = Uninstall Helper
"{0B7C79A5-5CB2-4ABD-A9C1-92A6213CE8DD}_is1" = MSI Kombustor 2.5.0
"{0BEB28E4-E5EA-40DE-8982-1F13005DC08B}" = SlimDrivers
"{0F2CF890-D101-6CFA-8D99-0CFBF7EF4AD0}" = CCC Help Chinese Standard
"{10CFB5DF-985A-8320-B4D8-461CC1F83CBF}" = CCC Help Japanese
"{15E36881-D2F0-4730-B51C-4BE85647F702}" = Antec CC
"{1651B6FF-DC41-48F8-9B10-AAAEFC496933}" = Tt eSPORTS BLACK
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{22D071EF-A06A-6341-DFDA-FE448659A63C}" = CCC Help Portuguese
"{240C3DDD-C5E9-4029-9DF7-95650D040CF2}" = Intel® USB 3.0 eXtensible Host Controller Driver
"{26A24AE4-039D-4CA4-87B4-2F83217013FF}" = Java 7 Update 13
"{30909F74-4B46-2842-DECF-1C66F355338C}" = CCC Help Turkish
"{30DCE977-E0F0-41ED-BDEC-CDDB04064D0E}" = Living Waterfalls 2
"{365E16A2-FE3B-EA13-4EE0-88D570F82497}" = CCC Help Korean
"{3A9527CF-4E91-4683-A03F-F1AD022126E5}" = DirectX 9 Runtime
"{3C9D2B2E-53A2-4098-B931-2621C5D9822B}" = Living Marine Aquarium 2
"{3D8AB6C1-3932-F551-2AF0-ED0612AD4B26}" = CCC Help Dutch
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{3FD0C489-0F02-481a-A3E1-9754CD396761}" = Intel® Watchdog Timer Driver (Intel® WDT)
"{40AD5E62-A31A-C414-01BA-310100577C7E}" = CCC Help Chinese Traditional
"{42DCB650-F003-4535-A5CD-32AD815CD2DD}" = Play withSIX
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4F9E0D27-5525-E8C8-43D0-BA15C1A22E03}" = CCC Help Czech
"{59732216-a6be-4053-af5e-ad97705deb4c}" = Nero MediaHome 4 Essentials
"{5F187E71-93D7-4849-B5C2-1DD1747C81A7}" = Sonic CinePlayer Decoder Pack
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{61942EF5-2CD8-47D4-869C-2E9A8BB085F1}" = Asmedia ASM106x SATA Host Controller Driver
"{64467D47-FFE4-4FBC-ABBA-A0DB829A17EB}" = NVIDIA PhysX
"{647E62F0-F1BC-E0C3-EDF5-67716EE75014}" = CCC Help Hungarian
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{667DB2C0-AF52-021A-7CF6-DA8DD27AC215}" = CCC Help Italian
"{6A4C6C0F-8791-B753-742E-06C40A6E023C}" = CCC Help Polish
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7360EE49-7004-4626-A85A-CC48C2D63700}" = Intel Extreme Tuning Utility
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{79C61902-F44E-4190-A2B9-9B467B0380CE}" = CCC Help French
"{7B2CC3DF-64FA-44AE-8F57-B0F915147E4F}_is1" = Need For Speed™ World
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{87686C21-8A15-4b4d-A3F1-11141D9BE094}" = Battlefield Play4Free
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8CF25D78-1DA6-4206-B0CE-5FA8155E36E0}" = Antec CC Driver x64
"{8DC910CD-8EE3-4ffc-A4EB-9B02701059C4}" = Battlefield Heroes
"{91A3CEFE-A2C1-3E83-3789-F2BF8EC82106}" = CCC Help Thai
"{93B6F95C-7009-4CF3-886B-F80AA6101B14}" = Roxio GAMECAP
"{96CAEB1D-7BFB-2A98-EBB2-414C894F694F}" = CCC Help Danish
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A664A708-E454-4416-7D19-D0F10879522C}" = CCC Help German
"{A6C19562-4A16-48D7-BF08-76B0673FF218}" = IObit Apps Toolbar v6.7
"{A6C48A9F-694A-4234-B3AA-62590B668927}" = Intel® Manageability Engine Firmware Recovery Agent
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.01)
"{AFB907F5-C0E6-4753-8284-DE955EF86AC2}" = THX TruStudio
"{B2EC4A38-B545-4A00-8214-13FE0E915E6D}" = Advertising Center
"{BA7DBD3F-34B7-4872-860E-89E5B6AFA6AC}" = Roxio Game Capture
"{BC3051A7-1021-4B57-A3DA-AAC24566FAE7}_is1" = The War Z version 1.0
"{BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}" = Nero ControlCenter
"{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C71067FC-288F-4E0B-88C6-44DFDA8311E2}" = System Requirements Lab for Intel
"{C81A2FE0-3574-00A9-CED4-BDAA334CBE8E}" = Nero Online Upgrade
"{CD95F661-A5C4-44F5-A6AA-ECDD91C24011}" = WinZip 15.5
"{D6F46E2D-4FE2-5FAB-5C30-230E99563DEE}" = Catalyst Control Center InstallProxy
"{D774CBF9-D44D-41BD-9AAB-5E59C1791AFF}" = ROXIO GAMECAP
"{D9DA23F5-CE0B-EE04-B498-7EC8AFC9F232}" = CCC Help Finnish
"{DF5182CB-192B-A6C8-9707-D7214557691C}" = CCC Help Norwegian
"{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}" = Catalyst Control Center - Branding
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E6757654-CE6A-0D0B-BBE6-F6247F05B7CD}" = Catalyst Control Center Localization All
"{E829EED6-D748-40C8-92DF-87FD22E6BCEE}" = SlimCleaner
"{E8759AD8-3A58-77F1-D16D-F3C8F9E98722}" = Catalyst Control Center Graphics Previews Common
"{E8A80433-302B-4FF1-815D-FCC8EAC482FF}" = Nero Installer
"{EAB5AC2D-BDD5-4864-8380-904B3EB4B1E7}" = C3
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Processor Graphics
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1C39CBE-4521-BEC8-5238-4A8B55FEB6B7}" = CCC Help Russian
"{F4041DCE-3FE1-4E18-8A9E-9DE65231EE36}" = Nero ControlCenter
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"{FBFA39D2-C55A-56DC-7EBB-767FC31B04A3}" = CCC Help Spanish
"{FCB3772C-B7D0-4933-B1A9-3707EBACC573}" = Intel® SDK for OpenCL - CPU Only Runtime Package
"{FCF3DA77-F819-45BC-AC5E-743AA7A920C2}" = Roxio Game Capture
"3FD0C489-0F02-481a-A3E1-9754CD396761" = Intel® Watchdog Timer Driver (Intel® WDT)
"8461-7759-5462-8226" = Vuze
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Afterburner" = MSI Afterburner 2.3.1
"ASRock eXtreme Tuner_is1" = ASRock eXtreme Tuner v0.1.189
"ASRock InstantBoot_is1" = ASRock InstantBoot v1.29
"AVG Secure Search" = AVG Security Toolbar
"Battlelog Web Plugins" = Battlelog Web Plugins
"BattlEye for A2" = BattlEye Uninstall
"BattlEye for OA" = BattlEye for OA Uninstall
"CL-Eye Driver" = CL-Eye Driver
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"dBpoweramp Music Converter" = dBpoweramp Music Converter
"ESN Sonar-0.70.4" = ESN Sonar
"GOM Player" = GOM Player
"GomAudio" = GOM Audio
"Google Chrome" = Google Chrome
"MCLIENT" = Norton Management
"Metro 2033_R.G. Mechanics_is1" = Metro 2033
"N360" = Norton 360
"NETGEAR Genie" = NETGEAR Genie
"Origin" = Origin
"PokerStars" = PokerStars
"PS3 Media Server" = PS3 Media Server
"PunkBusterSvc" = PunkBuster Services
"Steam App 202170" = Sleeping Dogs™
"Steam App 214870" = Painkiller Hell & Damnation
"Steam App 219540" = ARMA 2: Operation Arrowhead Beta
"Steam App 221850" = 3DMark Vantage Demo
"Steam App 24240" = PAYDAY: The Heist
"Steam App 33910" = ARMA 2
"Steam App 33930" = ARMA 2: Operation Arrowhead
"Steam App 50300" = Spec Ops: The Line
"Steam App 550" = Left 4 Dead 2
"Steam App 91310" = Dead Island
"TechPowerUp GPU-Z" = TechPowerUp GPU-Z
"Uninstall Helper 2.0.0.0" = Uninstall Helper

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{79A765E1-C399-405B-85AF-466F52E918B0}" = Ask Toolbar Updater

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 2/10/2013 4:53:06 AM | Computer Name = Scotty-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 2/10/2013 5:57:05 AM | Computer Name = Scotty-PC | Source = Application Error | ID = 1000
Description = Faulting application name: chrome.exe, version: 24.0.1312.57, time
stamp: 0x510326ea Faulting module name: ntdll.dll, version: 6.1.7601.17725, time
stamp: 0x4ec49b8f Exception code: 0xc0000005 Fault offset: 0x000a1d68 Faulting process
id: 0x1880 Faulting application start time: 0x01ce0774fb749e3d Faulting application
path: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Faulting module
path: C:\Windows\SysWOW64\ntdll.dll Report Id: 3926b71b-7368-11e2-b550-bc5ff456270e

Error - 2/10/2013 5:57:10 AM | Computer Name = Scotty-PC | Source = Application Hang | ID = 1002
Description = The program chrome.exe version 24.0.1312.57 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 5e0 Start
Time: 01ce0774dbe3dd3b Termination Time: 7 Application Path: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

Report
Id: 37632e8f-7368-11e2-b550-bc5ff456270e

Error - 2/10/2013 9:37:15 AM | Computer Name = Scotty-PC | Source = Application Hang | ID = 1002
Description = The program SymErr.exe version 4.2.0.7 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Action Center control panel. Process ID: 1ec0 Start Time:
01ce078763190ed2 Termination Time: 1 Application Path: C:\Program Files (x86)\Norton
360\Engine\20.2.1.22\SymErr.exe Report Id: f2491a11-7386-11e2-b550-bc5ff456270e

Error - 2/10/2013 10:30:29 AM | Computer Name = Scotty-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 2/10/2013 8:13:18 PM | Computer Name = Scotty-PC | Source = ISCT Agent | ID = 1003
Description =

Error - 2/10/2013 9:29:18 PM | Computer Name = Scotty-PC | Source = ISCT Agent | ID = 1003
Description =

Error - 2/10/2013 9:36:27 PM | Computer Name = Scotty-PC | Source = Application Hang | ID = 1002
Description = The program ccSvcHst.exe version 12.2.1.4 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 1338 Start
Time: 01ce07f755d6c28c Termination Time: 4 Application Path: C:\Program Files (x86)\Norton
360\Engine\20.2.1.22\ccSvcHst.exe Report Id: 69893bbd-73eb-11e2-af4e-bc5ff456270e


Error - 2/10/2013 9:40:32 PM | Computer Name = Scotty-PC | Source = ISCT Agent | ID = 1003
Description =

Error - 2/10/2013 9:48:13 PM | Computer Name = Scotty-PC | Source = ISCT Agent | ID = 1003
Description =

Error - 2/10/2013 10:08:45 PM | Computer Name = Scotty-PC | Source = ISCT Agent | ID = 1003
Description =

Error - 2/10/2013 10:20:07 PM | Computer Name = Scotty-PC | Source = ISCT Agent | ID = 1003
Description =

[ System Events ]
Error - 1/18/2013 8:10:34 AM | Computer Name = Scotty-PC | Source = DCOM | ID = 10016
Description =

Error - 1/18/2013 8:11:06 AM | Computer Name = Scotty-PC | Source = Service Control Manager | ID = 7000
Description = The WinRing0_1_2_0 service failed to start due to the following error:
%%2

Error - 1/18/2013 7:06:06 PM | Computer Name = Scotty-PC | Source = DCOM | ID = 10016
Description =

Error - 1/18/2013 7:06:31 PM | Computer Name = Scotty-PC | Source = Service Control Manager | ID = 7000
Description = The WinRing0_1_2_0 service failed to start due to the following error:
%%2

Error - 1/19/2013 12:16:31 AM | Computer Name = Scotty-PC | Source = DCOM | ID = 10016
Description =

Error - 1/19/2013 12:16:44 AM | Computer Name = Scotty-PC | Source = Service Control Manager | ID = 7000
Description = The WinRing0_1_2_0 service failed to start due to the following error:
%%2

Error - 1/19/2013 2:19:15 AM | Computer Name = Scotty-PC | Source = bowser | ID = 8003
Description =

Error - 1/19/2013 4:27:42 AM | Computer Name = Scotty-PC | Source = bowser | ID = 8003
Description =

Error - 1/19/2013 1:08:36 PM | Computer Name = Scotty-PC | Source = Service Control Manager | ID = 7000
Description = The WinRing0_1_2_0 service failed to start due to the following error:
%%2

Error - 1/19/2013 1:09:24 PM | Computer Name = Scotty-PC | Source = DCOM | ID = 10016
Description =


< End of report >

OTL.txt
OTL logfile created on: 2/11/2013 1:03:37 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Scotty\Downloads
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

15.95 Gb Total Physical Memory | 13.14 Gb Available Physical Memory | 82.36% Memory free
31.90 Gb Paging File | 28.64 Gb Available in Paging File | 89.78% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.66 Gb Total Space | 252.43 Gb Free Space | 54.21% Space Free | Partition Type: NTFS
Drive G: | 100.00 Mb Total Space | 69.87 Mb Free Space | 69.87% Space Free | Partition Type: NTFS

Computer Name: SCOTTY-PC | User Name: Scotty | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Scotty\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
PRC - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe ()
PRC - C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
PRC - C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTSS.exe ()
PRC - C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe ()
PRC - C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
PRC - C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe (Spigot, Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe (SlimWare Utilities, Inc.)
PRC - C:\Program Files (x86)\Norton 360\Engine\20.2.1.22\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenie.exe ()
PRC - C:\Program Files (x86)\W3i\UninstallHelper\UninstallHelper.exe (W3i, LLC)
PRC - C:\Program Files (x86)\Norton Management\Engine\3.2.0.19\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\NETGEAR Genie\bin\genie2_tray.exe ()
PRC - C:\Program Files (x86)\Intel\Extreme Tuning Utility\XtuService.exe (Intel® Corporation)
PRC - C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe ()
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\MSI\Live Update 5\LU5.exe (Micro-Star International)
PRC - C:\Program Files (x86)\Antec CC\ChillControl V.exe (Antec Inc.)
PRC - C:\Program Files (x86)\Thermaltake\Tt eSPORTS BLACK\Black.exe (Thermaltake)
PRC - C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Windows Sidebar\sidebar.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\ppgooglenaclpluginchrome.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\pdf.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\libglesv2.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\libegl.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\ffmpegsumo.dll ()
MOD - C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
MOD - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\14.0.1\SiteSafety.dll ()
MOD - C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTSS.exe ()
MOD - C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe ()
MOD - C:\Users\Scotty\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.6.gadget\GetCoreTempInfoNET.dll ()
MOD - C:\Users\Scotty\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.6.gadget\SystemInfo.dll ()
MOD - C:\Users\Scotty\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.6.gadget\CoreTempReader.dll ()
MOD - C:\Program Files (x86)\Steam\bin\chromehtml.dll ()
MOD - C:\Program Files (x86)\Steam\bin\libcef.dll ()
MOD - C:\Program Files (x86)\MSI Afterburner\RTMUI.dll ()
MOD - C:\Program Files (x86)\MSI Afterburner\RTHAL.dll ()
MOD - C:\Program Files (x86)\MSI Afterburner\RTCore.dll ()
MOD - C:\Program Files (x86)\MSI Afterburner\RTUI.dll ()
MOD - C:\Program Files (x86)\MSI Afterburner\RTFC.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\b95e7795ea5951d09521cddfc03b5c4e\Microsoft.VisualBasic.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\302207b4fa3083899fd8ab4db98cecc5\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\7ffdaee3a54ffd1a5e3b008a5bde5ecf\IAStorUtil.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\389a1832a3da11e1b409cd6ae60cb9fa\IAStorCommon.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\0ac577a8ad6528ff03b50db5eeeac8be\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\90b89f6e8032310e9ac72a309fd49e83\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\dd20416f723ee13ffb4173ec1afc4ec4\System.Data.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\865d2bf19a7af7fab8660a42d92550fe\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\d908c91e24616e6b8d38c9da61038b25\Accessibility.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\cf827fe7bc99d9bcf0ba3621054ef527\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\195a77fcc6206f8bb35d419ff2cf0d72\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Steam\sdl.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avcodec-53.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avformat-53.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avutil-51.dll ()
MOD - C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\SaveMedia.dll ()
MOD - C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTMUI.dll ()
MOD - C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTSSHooks.dll ()
MOD - C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTUI.dll ()
MOD - C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTFC.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Map.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenie.exe ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Resource.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\SvtNetworkTool.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_RouterConfiguration.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_ParentalControl.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Internet.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Ui.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\InnerPlugin_Update.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Statistics.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\InnerPlugin_WirelessExport.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_NetworkProblem.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\Genie.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Wireless.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Airprint.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\DragonNetTool.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\DiagnoseDll.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\airprintdll.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\DiagnosePlugin.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\WSetupApiPlugin.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\QRCode.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\NetcardApi.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\SVTUtils.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\WSetupDll.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\drivers\libntgr_api.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\genie2_tray.exe ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\QtGui4.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\QtCore4.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\QtNetwork4.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\QtXml4.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qjpeg4.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qico4.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qgif4.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\libgcc_s_dw2-1.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\mingwm10.dll ()
MOD - C:\Program Files (x86)\MSI Afterburner\RTTSH.dll ()
MOD - C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTTSH.dll ()
MOD - C:\Program Files (x86)\Thermaltake\Tt eSPORTS BLACK\BlackHook.dll ()
MOD - C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (TurboBoost) – C:\Program Files\Intel\TurboBoost\TurboBoost.exe (Intel® Corporation)
SRV:64bit: - (ISCTAgent) – C:\Program Files\Intel\Intel® Smart Connect Technology Agent\iSCTAgent.exe ()
SRV:64bit: - (Intel® – C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel® Corporation)
SRV:64bit: - (cFosSpeedS) – C:\Program Files\ASRock\XFast LAN\spd.exe (cFos Software GmbH)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (vToolbarUpdater14.0.1) – C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe ()
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (Application Updater) – C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe (Spigot, Inc.)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (N360) – C:\Program Files (x86)\Norton 360\Engine\20.2.1.22\ccSvcHst.exe (Symantec Corporation)
SRV - (Futuremark SystemInfo Service) – C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe (Futuremark Corporation)
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (MCLIENT) – C:\Program Files (x86)\Norton Management\Engine\3.2.0.19\ccSvcHst.exe (Symantec Corporation)
SRV - (NETGEARGenieDaemon) – C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenieDaemon64.exe (NETGEAR)
SRV - (XTU3SERVICE) – C:\Program Files (x86)\Intel\Extreme Tuning Utility\XtuService.exe (Intel® Corporation)
SRV - (UNS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe ()
SRV - (jhi_service) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe (Intel Corporation)
SRV - (ICCS) – C:\Program Files (x86)\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe (Intel Corporation)
SRV - (IAStorDataMgrSvc) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (RoxMediaDBGame1X) – C:\Program Files (x86)\Common Files\Roxio Shared\Game1X\SharedCOM\RoxMediaDBGame1X.exe (Sonic Solutions)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (cphs) – C:\Windows\SysWOW64\IntelCpHeciSvc.exe (Intel Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (SWDUMon) – C:\Windows\SysNative\drivers\SWDUMon.sys ()
DRV:64bit: - (WPRO_41_2001) – C:\Windows\SysNative\drivers\WPRO_41_2001.sys ()
DRV:64bit: - (SymEvent) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (avgtp) – C:\Windows\SysNative\drivers\avgtpx64.sys (AVG Technologies)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (NPF) – C:\Windows\SysNative\drivers\npf.sys (CACE Technologies, Inc.)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\drivers\N360x64\1402010.016\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\drivers\N360x64\1402010.016\SymEFA64.sys (Symantec Corporation)
DRV:64bit: - (SymDS) – C:\Windows\SysNative\drivers\N360x64\1402010.016\SymDS64.sys (Symantec Corporation)
DRV:64bit: - (ccSet_MCLIENT) – C:\Windows\SysNative\drivers\MCLIENTx64\0302000.013\ccSetx64.sys (Symantec Corporation)
DRV:64bit: - (SymNetS) – C:\Windows\SysNative\drivers\N360x64\1402010.016\symnets.sys (Symantec Corporation)
DRV:64bit: - (SymIRON) – C:\Windows\SysNative\drivers\N360x64\1402010.016\Ironx64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) – C:\Windows\SysNative\drivers\N360x64\1402010.016\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (ccSet_N360) – C:\Windows\SysNative\drivers\N360x64\1402010.016\ccSetx64.sys (Symantec Corporation)
DRV:64bit: - (MEIx64) – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (ICCWDT) – C:\Windows\SysNative\drivers\ICCWDT.sys (Intel Corporation)
DRV:64bit: - (TurboB) – C:\Windows\SysNative\drivers\TurboB.sys (Intel® Corporation)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (ISCT) – C:\Windows\SysNative\drivers\ISCTD64.sys ()
DRV:64bit: - (imsevent) – C:\Windows\SysNative\drivers\imsevent.sys ()
DRV:64bit: - (ikbevent) – C:\Windows\SysNative\drivers\ikbevent.sys ()
DRV:64bit: - (iusb3xhc) – C:\Windows\SysNative\drivers\iusb3xhc.sys (Intel Corporation)
DRV:64bit: - (iusb3hub) – C:\Windows\SysNative\drivers\iusb3hub.sys (Intel Corporation)
DRV:64bit: - (iusb3hcs) – C:\Windows\SysNative\drivers\iusb3hcs.sys (Intel Corporation)
DRV:64bit: - (AsrRamDisk) – C:\Windows\SysNative\drivers\AsrRamDisk.sys (ASRock Inc.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (asahci64) – C:\Windows\SysNative\drivers\asahci64.sys (Asmedia Technology)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (cFosSpeed) – C:\Windows\SysNative\drivers\cfosspeed6.sys (cFos Software GmbH)
DRV:64bit: - (ASEUSBCC) – C:\Windows\SysNative\drivers\AseUSBCC.sys (Silicon Laboratories)
DRV:64bit: - (AsrAppCharger) – C:\Windows\SysNative\drivers\AsrAppCharger.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (Thermnaltake MS1 Filter) – C:\Windows\SysNative\drivers\MS1Filter.sys (Thermaltake)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (BVRPMPR5a64) – C:\Windows\SysNative\drivers\BVRPMPR5a64.SYS (Avanquest Software)
DRV:64bit: - (Revoflt) – C:\Windows\SysNative\drivers\revoflt.sys (VS Revo Group)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) – C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (WDC_SAM) – C:\Windows\SysNative\drivers\wdcsam64.sys (Western Digital Technologies)
DRV:64bit: - (IntcDAud) – C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (MBfilt) – C:\Windows\SysNative\drivers\MBfilt64.sys (Creative Technology Ltd.)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.1.22\Definitions\VirusDefs\20130209.009\ex64.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.1.22\Definitions\VirusDefs\20130209.009\eng64.sys (Symantec Corporation)
DRV - (RTCore64) – C:\Program Files (x86)\MSI Afterburner\RTCore64.sys ()
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.1.22\Definitions\IPSDefs\20120901.001\IDSviA64.sys (Symantec Corporation)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.1.22\Definitions\BASHDefs\20120928.001\BHDrvx64.sys (Symantec Corporation)
DRV - (iocbios2) – C:\Program Files (x86)\Intel\Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys (Intel Corporation)
DRV - (cpudrv64) – C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys ()
DRV - (Thermnaltake MS1 Filter) – C:\Windows\SysWOW64\drivers\MS1Filter.sys (Thermaltake)
DRV - (NTIOLib_1_0_4) – C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys (MSI)
DRV - (MSI_MSIBIOS_010507) – C:\Program Files (x86)\MSI\Live Update 5\msibios64_100507.sys (Your Corporation)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}: "URL" = http://searchfunmoods.com/results.php?f=4&…amp;cr=91816767
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://au.search.yahoo.com?type=198484&fr=spigot-yhp-ie
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\URLSearchHook: {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - C:\Program Files (x86)\IObit Apps Toolbar\IE\6.7\iobitappsToolbarIE.dll (Spigot, Inc.)
IE - HKCU\..\SearchScopes,DefaultScope = {C7EADF9A-79F4-4CE9-8835-FEA129ADAA22}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://au.search.yahoo.com/search?p={searc…m&type=ASRK
IE - HKCU\..\SearchScopes\{3F7BEE20-2911-4a67-9F67-EA9B652915AB}: "URL" = http://www.google.com/custom?client=pub-37…q={searchTerms}
IE - HKCU\..\SearchScopes\{8AD2049C-4EAA-43D8-8CE2-35AE14F796C3}: "URL" = http://websearch.ask.com/redirect?client=i…54-ADD5C8A467D3
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={C639E4D…mp;d=2012-11-10 22:14:37&v=13.2.0.4&sap=dsp&q={searchTerms}
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://nortonsafe.search.ask.com/web?q={SE…d&qsrc=2869
IE - HKCU\..\SearchScopes\{C7EADF9A-79F4-4CE9-8835-FEA129ADAA22}: "URL" = http://au.search.yahoo.com/search?fr=chr-g…p={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_149.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_149.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\14.0.1\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.140.0: C:\Program Files (x86)\Battlelog Web Plugins\1.140.0\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=2.1.2: C:\Program Files (x86)\Battlelog Web Plugins\2.1.2\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.13.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.13.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\FireFoxExt\14.0.2.14 [2013/01/25 00:43:33 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.1.22\IPSFFPlgn\ [2013/02/11 12:13:44 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.1.22\coFFPlgn\ [2013/02/11 12:22:12 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - homepage:
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter},
CHR - homepage:
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\pdf.dll
CHR - plugin: Norton Confidential (Enabled) = C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.1.0.30_0\npcoplgn.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Intel\u00AE Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll
CHR - plugin: Intel\u00AE Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll
CHR - Extension: Bejeweled = C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\adpkifcfcacgmnggcbpbjbkdijciiigm\2_0\
CHR - Extension: Turn Off the Lights = C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn\2.1.0.30_0\
CHR - Extension: Battlefield Heroes = C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehdakiococlfmjcbebbkjkfjhbieknh\5.0.196.0_0\
CHR - Extension: Adblock Plus = C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.3.4_0\
CHR - Extension: Crazy Rollercoaster = C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\eafhgomkapdagnpmmgilphbolnejepoc\1.3_0\
CHR - Extension: Car Games = C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\eegbfdjgceebepnmgnmefipjgkoapagb\0.4_0\
CHR - Extension: Fever For Speed (3D) = C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\eminoenajmbgbldibdnmammdjggeglfo\1.0_0\
CHR - Extension: Better Battlelog (BBLog) = C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbnkmpcicaafjhmnhiblopefjfacnmem\3.3.0_0\
CHR - Extension: Digital Clock = C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\gdkjifoifglkpcdffkenpinlbjgephlo\1.11_0\
CHR - Extension: ImageBot Photo Editor = C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\gngdfkmfhlbimnaglgofeloikojnnaka\2.0.1_0\
CHR - Extension: Pixlr Editor = C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmaknaampgiegkcjlimdiidlhopknpk\1.2_0\
CHR - Extension: Autodesk Homestyler = C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdmmkfaghgcicheaimnpffeeekheafkb\2.2_0\
CHR - Extension: Criminals In Action = C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\lodcgfknlnpepeiopmdkioopbnpghgme\1_0\
CHR - Extension: Planner 5D = C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcafejemebbngbglfoinpoaannbihjna\1.2.0.4_0\
CHR - Extension: Norton Identity Protection = C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.2.1.36_0\
CHR - Extension: Need for Speed World = C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\mnnelgnkomjdakpkjpkfehdipjifjmbk\1.0.0.4_0\
CHR - Extension: Battlefield Play4Free = C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\oiokahphinmbmakkehgelkmpolmnbkdh\1.0.80.5_0\
CHR - Extension: Bitdefender QuickScan = C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdnkcidphdcakpkheohlhocaicfamjie\0.9.9.118_0\
CHR - Extension: Google Reader = C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjjhlfkghdhmijklfnahfkpgmhcmfgcm\4.4_0\

O1 HOSTS File: ([2009/06/11 07:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (SteadyVideoBHO Class) - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
O2 - BHO: (IObit Apps Toolbar) - {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - C:\Program Files (x86)\IObit Apps Toolbar\IE\6.7\iobitappsToolbarIE.dll (Spigot, Inc.)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\20.2.1.22\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (SteadyVideoBHO Class) - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\20.2.1.22\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\14.0.2.14\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (IObit Apps Toolbar) - {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - C:\Program Files (x86)\IObit Apps Toolbar\IE\6.7\iobitappsToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\20.2.1.22\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\14.0.2.14\AVG Secure Search_toolbar.dll ()
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" File not found
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [THXCfg64] C:\Windows\SysNative\THXCfg64.DLL (Creative Technology Ltd.)
O4:64bit: - HKLM..\Run: [XFast LAN] C:\Program Files\ASRock\XFast LAN\cfosspeed.exe (cFos Software GmbH)
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [IMSS] C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PIconStartup.exe (Intel Corporation)
O4 - HKLM..\Run: [Live Update 5] C:\Program Files (x86)\MSI\Live Update 5\LU5.exe (Micro-Star International)
O4 - HKLM..\Run: [SearchSettings] C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [THX TruStudio NB Settings] C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Tt eSPORTS BLACK Gaming Mouse] C:\Program Files (x86)\Thermaltake\Tt eSPORTS BLACK\Black.exe (Thermaltake)
O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
O4 - HKCU..\Run: [ASRockXTU] File not found
O4 - HKCU..\Run: [C3] File not found
O4 - HKCU..\Run: [F3B86A9EB072ABC2F0F62B1D515F7C32AAE587FE._service_run] C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
O4 - HKCU..\Run: [LCLC Control Panel] C:\Program Files (x86)\Antec CC\ChillControl V.exe (Antec Inc.)
O4 - HKCU..\Run: [NETGEARGenie] C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenie.exe ()
O4 - HKCU..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\sidebar.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
O4 - HKCU..\Run: [UninstallHelper] C:\Program Files (x86)\W3i\UninstallHelper\UninstallHelper.exe (W3i, LLC)
O4 - HKCU..\Run: [zASRockInstantBoot] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe (PokerStars)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} http://ccfiles.creative.com/Web/softwareup…102/CTSUEng.cab (Creative Software AutoUpdate)
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwareup…13/CTPIDPDE.cab (Creative Software AutoUpdate Support Package 2)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareup…21022/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9039D649-4DA3-475A-849E-53C9DA5DF37D}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\viprotocol - No CLSID value found
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\14.0.1\ViProtocol.dll ()
O18:64bit: - Protocol\Filter\video/mp4 {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18:64bit: - Protocol\Filter\video/x-flv {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18 - Protocol\Filter\video/mp4 {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18 - Protocol\Filter\video/x-flv {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{1db5ccae-1319-11e2-9423-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{1db5ccae-1319-11e2-9423-806e6f6e6963}\Shell\AutoRun\command - "" = D:\ASRSetup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.FPS1 - frapsv64.dll (Beepa P/L)
Drivers32:64bit: VIDC.RTV1 - rtvcvfw64.dll ()
Drivers32: msacm.divxa32 - C:\Windows\SysWow64\msaud32_divx.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FPS1 - C:\Windows\SysWow64\frapsvid.dll (Beepa P/L)
Drivers32: VIDC.RTV1 - C:\Windows\SysWow64\rtvcvfw32.dll ()
Drivers32: vidc.VP60 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/02/11 12:13:18 | 000,177,312 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2013/02/11 12:13:18 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2013/02/11 12:13:18 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2013/02/11 12:13:05 | 001,133,216 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1402010.016\SymEFA64.sys
[2013/02/11 12:13:05 | 000,776,864 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1402010.016\srtsp64.sys
[2013/02/11 12:13:05 | 000,493,216 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1402010.016\SymDS64.sys
[2013/02/11 12:13:05 | 000,432,800 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1402010.016\symnets.sys
[2013/02/11 12:13:05 | 000,224,416 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1402010.016\Ironx64.sys
[2013/02/11 12:13:05 | 000,168,096 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1402010.016\ccSetx64.sys
[2013/02/11 12:13:05 | 000,037,496 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1402010.016\srtspx64.sys
[2013/02/11 12:13:05 | 000,023,448 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1402010.016\SymELAM.sys
[2013/02/11 12:12:59 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360
[2013/02/11 12:12:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\Norton 360
[2013/02/11 11:45:22 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2013/02/10 19:21:11 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\N360x64
[2013/02/10 19:21:11 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\N360x64\1402010.016
[2013/02/10 19:19:26 | 000,168,096 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\MCLIENTx64\0302000.013\ccSetx64.sys
[2013/02/10 19:19:24 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Management
[2013/02/10 19:19:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Norton Management
[2013/02/10 19:19:24 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\MCLIENTx64
[2013/02/10 19:19:24 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\MCLIENTx64\0302000.013
[2013/02/10 19:19:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\NortonInstaller
[2013/02/10 17:32:19 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Local\NPE
[2013/02/05 22:24:45 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CL-Eye Driver
[2013/02/05 22:24:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\Code Laboratories
[2013/02/05 15:22:29 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Roaming\Skype
[2013/02/05 15:22:09 | 000,000,000 | —D | C] – C:\ProgramData\Skype
[2013/02/03 01:34:23 | 000,262,560 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013/02/03 01:34:06 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/02/03 01:34:06 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013/02/03 01:34:06 | 000,095,648 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/02/01 01:27:52 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crysis 3 MP Open Beta
[2013/02/01 01:27:51 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\Common Files\EAInstaller
[2013/01/30 19:07:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
[2013/01/27 19:58:08 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Roaming\Apple Computer
[2013/01/26 12:16:54 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI Kombustor 2.5
[2013/01/26 12:16:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\MSI Kombustor 2.5
[2013/01/26 12:16:41 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Local\Programs
[2013/01/26 12:15:30 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner
[2013/01/26 10:29:58 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Roaming\iMobie
[2013/01/26 10:29:57 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Local\iMobie_Inc
[2013/01/25 10:40:29 | 000,026,432 | —- | C] (IObit) – C:\Windows\SysNative\RegistryDefragBootTime.exe
[2013/01/25 00:49:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Spigot
[2013/01/25 00:49:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\IObit Apps Toolbar
[2013/01/25 00:49:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\Application Updater
[2013/01/25 00:49:06 | 000,000,000 | —D | C] – C:\ProgramData\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}
[2013/01/25 00:49:05 | 000,000,000 | —D | C] – C:\ProgramData\IObit
[2013/01/25 00:49:04 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Roaming\IObit
[2013/01/25 00:49:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\IObit
[2013/01/21 17:42:47 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Local\Adobe
[2013/01/21 17:42:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\Adobe
[2013/01/21 14:56:12 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Roaming\QuickScan
[2013/01/21 14:41:38 | 000,000,000 | —D | C] – C:\ProgramData\Futuremark
[2013/01/21 14:40:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2013/01/21 14:39:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\Futuremark
[2013/01/21 09:56:27 | 000,000,000 | —D | C] – C:\ProgramData\ATI
[2013/01/21 09:56:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\AMD AVT
[2013/01/21 09:56:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\AMD APP
[2013/01/21 09:56:03 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[2013/01/20 22:05:35 | 000,000,000 | —D | C] – C:\.cache
[2013/01/19 09:19:11 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Roaming\AccurateRip
[2013/01/19 09:19:08 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\dBpoweramp Music Converter
[2013/01/19 09:19:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\Illustrate
[2013/01/18 23:56:34 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Roaming\Auslogics
[2013/01/16 18:18:36 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlimCleaner
[2013/01/16 18:18:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\SlimCleaner
[2013/01/15 16:07:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antec Inc
[2013/01/15 16:07:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\Antec CC
[2013/01/14 00:38:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\GPU-Z
[2013/01/13 18:35:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\VIO Player
[2013/01/13 18:30:59 | 000,000,000 | —D | C] – C:\ProgramData\APN
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/02/11 13:00:00 | 000,002,799 | —- | M] () – C:\ProgramData\Network_Meter_Data.csv
[2013/02/11 12:50:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/02/11 12:27:24 | 000,025,008 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/02/11 12:27:24 | 000,025,008 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/02/11 12:22:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/02/11 12:21:19 | 000,000,412 | —- | M] () – C:\Windows\tasks\SlimDrivers Startup.job
[2013/02/11 12:21:05 | 000,015,712 | —- | M] () – C:\Windows\SysNative\drivers\SWDUMon.sys
[2013/02/11 12:20:07 | 000,034,752 | —- | M] () – C:\Windows\SysNative\drivers\WPRO_41_2001.sys
[2013/02/11 12:20:04 | 000,000,354 | —- | M] () – C:\Windows\tasks\ROC_JAN2013_TB_rmv.job
[2013/02/11 12:20:02 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/02/11 12:19:56 | 000,000,828 | —- | M] () – C:\Windows\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
[2013/02/11 12:19:44 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/02/11 12:19:34 | 4254,613,502 | -HS- | M] () – C:\hiberfil.sys
[2013/02/11 12:18:44 | 000,000,095 | —- | M] () – C:\Users\Scotty\Documents\PCMeterV0.3.config
[2013/02/11 12:13:18 | 000,177,312 | —- | M] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2013/02/11 12:13:18 | 000,007,466 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2013/02/11 12:13:18 | 000,000,855 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2013/02/11 12:13:16 | 000,002,391 | —- | M] () – C:\Users\Public\Desktop\Norton 360.lnk
[2013/02/11 12:09:48 | 000,005,614 | —- | M] () – C:\Windows\SysWow64\Utility.xml
[2013/02/11 11:45:13 | 724,619,738 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/02/11 10:17:57 | 000,014,818 | —- | M] () – C:\Windows\SysNative\drivers\N360x64\1402010.016\VT20130115.021
[2013/02/10 19:21:44 | 001,823,543 | —- | M] () – C:\Windows\SysNative\drivers\N360x64\1402010.016\Cat.DB
[2013/02/10 19:19:11 | 000,001,275 | —- | M] () – C:\Users\Scotty\Desktop\Norton Installation Files.lnk
[2013/02/10 18:08:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
[2013/02/08 15:50:10 | 000,697,712 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/02/08 15:50:10 | 000,074,096 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/02/05 22:24:45 | 000,001,246 | —- | M] () – C:\Users\Public\Desktop\CL-Eye Test.lnk
[2013/02/05 22:24:44 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_Kernel_WinUSB_01009.Wdf
[2013/02/05 11:43:37 | 000,000,889 | —- | M] () – C:\Users\Scotty\AppData\Roaming\Network Meter_Settings.ini
[2013/02/03 01:34:03 | 000,861,088 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\npDeployJava1.dll
[2013/02/03 01:34:03 | 000,782,240 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\deployJava1.dll
[2013/02/03 01:34:03 | 000,262,560 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013/02/03 01:34:03 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/02/03 01:34:03 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013/02/03 01:34:03 | 000,095,648 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/02/02 18:15:35 | 000,000,578 | —- | M] () – C:\Users\Scotty\AppData\Roaming\All CPU MeterV3_Settings.ini
[2013/02/02 13:54:02 | 000,000,222 | —- | M] () – C:\Users\Scotty\Desktop\Painkiller Hell & Damnation.url
[2013/02/02 11:24:00 | 000,002,656 | —- | M] () – C:\{9D7B1E24-71C4-4B4A-8704-6C23A9447E0D}
[2013/02/01 01:27:52 | 000,001,428 | —- | M] () – C:\Users\Public\Desktop\Crysis 3 MP Open Beta.lnk
[2013/01/31 19:14:20 | 000,007,596 | —- | M] () – C:\Users\Scotty\AppData\Local\Resmon.ResmonCfg
[2013/01/31 11:00:53 | 000,000,292 | —- | M] () – C:\Users\Scotty\AppData\Roaming\GPU MeterV2_Settings.ini
[2013/01/30 19:07:40 | 000,000,869 | —- | M] () – C:\Users\Public\Desktop\CPUID CPU-Z.lnk
[2013/01/28 16:10:02 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/01/28 16:10:02 | 000,628,024 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/01/28 16:10:02 | 000,110,208 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/01/28 12:18:22 | 000,000,222 | —- | M] () – C:\Users\Scotty\Desktop\Sleeping Dogs.url
[2013/01/28 09:00:41 | 000,002,384 | —- | M] () – C:\{4136D721-BA39-406F-813D-3FFDBF5A947B}
[2013/01/26 12:16:54 | 000,001,092 | —- | M] () – C:\Users\Scotty\Desktop\MSI Kombustor 2.5.lnk
[2013/01/26 12:15:34 | 000,001,086 | —- | M] () – C:\Users\Scotty\Desktop\MSI Afterburner.lnk
[2013/01/25 00:42:59 | 000,037,720 | —- | M] (AVG Technologies) – C:\Windows\SysNative\drivers\avgtpx64.sys
[2013/01/24 00:31:38 | 000,002,456 | —- | M] () – C:\{0C9C7502-7347-4854-9CC1-0130B71328CC}
[2013/01/21 14:37:08 | 000,000,222 | —- | M] () – C:\Users\Scotty\Desktop\3DMark Vantage Demo.url
[2013/01/19 09:19:09 | 000,018,041 | —- | M] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp Music Converter.dat
[2013/01/19 09:18:49 | 007,261,256 | —- | M] () – C:\Windows\SysWow64\SpoonUninstall.exe
[2013/01/16 18:18:36 | 000,002,467 | —- | M] () – C:\Users\Public\Desktop\SlimCleaner.lnk
[2013/01/15 18:49:06 | 000,026,432 | —- | M] (IObit) – C:\Windows\SysNative\RegistryDefragBootTime.exe
[2013/01/15 16:07:16 | 000,002,747 | —- | M] () – C:\Users\Public\Desktop\ChillControl V.lnk
[2013/01/13 00:53:31 | 000,000,873 | —- | M] () – C:\sharks_log.html
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/02/11 12:13:18 | 000,007,466 | —- | C] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2013/02/11 12:13:18 | 000,000,855 | —- | C] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2013/02/11 12:13:16 | 000,002,391 | —- | C] () – C:\Users\Public\Desktop\Norton 360.lnk
[2013/02/11 12:13:00 | 000,009,670 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1402010.016\SymELAM64.cat
[2013/02/11 12:13:00 | 000,009,103 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1402010.016\SymVTcer.dat
[2013/02/11 12:13:00 | 000,007,611 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1402010.016\ccsetx64.cat
[2013/02/11 12:13:00 | 000,007,605 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1402010.016\srtspx64.cat
[2013/02/11 12:13:00 | 000,007,603 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1402010.016\SymEFA64.cat
[2013/02/11 12:13:00 | 000,007,601 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1402010.016\symnet64.cat
[2013/02/11 12:13:00 | 000,007,601 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1402010.016\srtsp64.cat
[2013/02/11 12:13:00 | 000,007,597 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1402010.016\SymDS64.cat
[2013/02/11 12:13:00 | 000,007,593 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1402010.016\iron.cat
[2013/02/11 12:13:00 | 000,003,433 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1402010.016\SymEFA.inf
[2013/02/11 12:13:00 | 000,002,851 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1402010.016\SymDS.inf
[2013/02/11 12:13:00 | 000,001,440 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1402010.016\SymNet.inf
[2013/02/11 12:13:00 | 000,001,437 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1402010.016\srtsp64.inf
[2013/02/11 12:13:00 | 000,001,418 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1402010.016\srtspx64.inf
[2013/02/11 12:13:00 | 000,000,996 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1402010.016\symELAM.inf
[2013/02/11 12:13:00 | 000,000,853 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1402010.016\ccSetx64.inf
[2013/02/11 12:13:00 | 000,000,767 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1402010.016\Iron.inf
[2013/02/11 12:13:00 | 000,000,172 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1402010.016\isolate.ini
[2013/02/11 11:45:13 | 724,619,738 | —- | C] () – C:\Windows\MEMORY.DMP
[2013/02/11 10:18:14 | 000,014,818 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1402010.016\VT20130115.021
[2013/02/10 19:21:29 | 001,823,543 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1402010.016\Cat.DB
[2013/02/10 19:19:24 | 000,007,611 | R— | C] () – C:\Windows\SysNative\drivers\MCLIENTx64\0302000.013\ccSetx64.cat
[2013/02/10 19:19:24 | 000,000,853 | R— | C] () – C:\Windows\SysNative\drivers\MCLIENTx64\0302000.013\ccSetx64.inf
[2013/02/10 19:19:24 | 000,000,172 | —- | C] () – C:\Windows\SysNative\drivers\MCLIENTx64\0302000.013\isolate.ini
[2013/02/10 09:39:52 | 000,001,275 | —- | C] () – C:\Users\Scotty\Desktop\Norton Installation Files.lnk
[2013/02/05 22:24:45 | 000,001,246 | —- | C] () – C:\Users\Public\Desktop\CL-Eye Test.lnk
[2013/02/05 22:24:44 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_Kernel_WinUSB_01009.Wdf
[2013/02/05 12:00:00 | 000,002,799 | —- | C] () – C:\ProgramData\Network_Meter_Data.csv
[2013/02/02 13:54:02 | 000,000,222 | —- | C] () – C:\Users\Scotty\Desktop\Painkiller Hell & Damnation.url
[2013/02/02 11:24:00 | 000,002,656 | —- | C] () – C:\{9D7B1E24-71C4-4B4A-8704-6C23A9447E0D}
[2013/02/01 01:27:52 | 000,001,428 | —- | C] () – C:\Users\Public\Desktop\Crysis 3 MP Open Beta.lnk
[2013/01/30 19:07:40 | 000,000,869 | —- | C] () – C:\Users\Public\Desktop\CPUID CPU-Z.lnk
[2013/01/28 12:18:22 | 000,000,222 | —- | C] () – C:\Users\Scotty\Desktop\Sleeping Dogs.url
[2013/01/28 09:00:40 | 000,002,384 | —- | C] () – C:\{4136D721-BA39-406F-813D-3FFDBF5A947B}
[2013/01/26 12:16:54 | 000,001,092 | —- | C] () – C:\Users\Scotty\Desktop\MSI Kombustor 2.5.lnk
[2013/01/26 12:15:34 | 000,001,086 | —- | C] () – C:\Users\Scotty\Desktop\MSI Afterburner.lnk
[2013/01/25 00:43:32 | 000,000,354 | —- | C] () – C:\Windows\tasks\ROC_JAN2013_TB_rmv.job
[2013/01/24 00:31:38 | 000,002,456 | —- | C] () – C:\{0C9C7502-7347-4854-9CC1-0130B71328CC}
[2013/01/21 17:42:06 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
[2013/01/21 14:37:08 | 000,000,222 | —- | C] () – C:\Users\Scotty\Desktop\3DMark Vantage Demo.url
[2013/01/19 09:19:09 | 007,261,256 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall.exe
[2013/01/19 09:19:09 | 000,018,041 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp Music Converter.dat
[2013/01/15 16:07:15 | 000,002,747 | —- | C] () – C:\Users\Public\Desktop\ChillControl V.lnk
[2013/01/07 17:34:21 | 000,000,292 | —- | C] () – C:\Users\Scotty\AppData\Roaming\GPU MeterV2_Settings.ini
[2012/12/10 09:30:57 | 000,000,706 | RHS- | C] () – C:\Users\Scotty\ntuser.pol
[2012/10/20 22:36:21 | 000,000,248 | —- | C] () – C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2012/10/17 09:59:52 | 000,270,240 | —- | C] () – C:\Windows\SysWow64\PnkBstrB.exe
[2012/10/17 09:59:43 | 000,076,888 | —- | C] () – C:\Windows\SysWow64\PnkBstrA.exe
[2012/10/16 18:22:30 | 000,000,889 | —- | C] () – C:\Users\Scotty\AppData\Roaming\Network Meter_Settings.ini
[2012/10/16 16:17:47 | 000,000,578 | —- | C] () – C:\Users\Scotty\AppData\Roaming\All CPU MeterV3_Settings.ini
[2012/10/13 23:12:21 | 000,007,596 | —- | C] () – C:\Users\Scotty\AppData\Local\Resmon.ResmonCfg
[2012/10/10 14:18:40 | 000,001,424 | —- | C] () – C:\Windows\THXCfg_SP_APOIM.ini
[2012/10/10 14:18:40 | 000,001,323 | —- | C] () – C:\Windows\THXCfg_HP_APOIM.ini
[2012/10/10 14:18:40 | 000,001,323 | —- | C] () – C:\Windows\THXCfg_APOIM.ini
[2012/10/10 14:18:38 | 000,190,464 | —- | C] () – C:\Windows\SysWow64\APOMngr.DLL
[2012/10/10 14:18:38 | 000,073,728 | —- | C] () – C:\Windows\SysWow64\CmdRtr.DLL
[2012/10/10 14:15:58 | 000,000,003 | —- | C] () – C:\Users\Scotty\AppData\Local\user_data.ini
[2012/10/10 02:22:34 | 000,064,512 | —- | C] () – C:\Windows\SysWow64\igdde32.dll
[2012/10/10 02:22:32 | 000,598,780 | —- | C] () – C:\Windows\SysWow64\igvpkrng700.bin
[2012/10/10 02:22:16 | 000,755,048 | —- | C] () – C:\Windows\SysWow64\igcodeckrng700.bin
[2012/09/29 05:45:06 | 000,247,296 | —- | C] () – C:\Windows\SysWow64\rtvcvfw32.dll
[2012/05/11 00:37:24 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2012/05/11 00:34:44 | 000,204,952 | —- | C] () – C:\Windows\SysWow64\ativvsvl.dat
[2012/05/11 00:34:44 | 000,157,144 | —- | C] () – C:\Windows\SysWow64\ativvsva.dat
[2012/05/11 00:34:44 | 000,003,917 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2012/05/02 13:58:10 | 000,029,184 | —- | C] () – C:\Windows\SysWow64\kdbsdk32.dll
[2012/03/19 23:37:12 | 000,755,188 | —- | C] () – C:\Windows\SysWow64\igkrng700.bin
[2012/03/19 23:37:12 | 000,561,508 | —- | C] () – C:\Windows\SysWow64\igfcg700m.bin
[2012/02/02 22:08:26 | 000,001,536 | —- | C] () – C:\Windows\SysWow64\IusEventLog.dll

========== ZeroAccess Check ==========

[2009/07/14 14:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/09 15:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/09 14:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/14 11:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 22:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/14 11:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013/01/18 23:56:34 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\Auslogics
[2013/02/10 01:23:11 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\Azureus
[2012/10/10 14:57:52 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\DeviceVm
[2013/01/26 10:29:58 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\iMobie
[2013/02/10 14:03:36 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\IObit
[2012/12/03 10:49:24 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\MAGIX
[2012/10/19 12:51:09 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\Metro 2033
[2012/11/11 09:52:12 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\Need for Speed World
[2013/01/01 21:55:17 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\Origin
[2012/11/10 22:33:46 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\PDAppFlex
[2013/01/10 16:15:41 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\Play withSIX
[2013/02/10 17:59:05 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\QuickScan
[2012/12/19 00:40:34 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2012/10/17 22:41:26 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\SystemRequirementsLab
[2012/10/13 23:07:09 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\Uniblue
[2013/01/05 12:40:41 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\Vuze Turbo Booster
[2012/11/26 23:59:21 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\W3i, LLC
[2012/10/21 14:37:40 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\wargaming.net

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2009/07/14 12:30:02 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\PolicyDefinitions\en-US\Explorer.adml
[2009/07/14 12:30:02 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/11 06:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\PolicyDefinitions\Explorer.admx
[2009/06/11 06:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2011/02/26 16:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/26 15:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/14 11:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/26 15:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009/10/31 15:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/26 15:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/25 16:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 16:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 16:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 22:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009/08/03 16:19:07 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/25 15:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 15:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009/10/31 16:34:59 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/03 15:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 23:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009/10/31 16:38:38 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/03 15:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/14 11:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/31 16:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/02/26 16:26:45 | 002,870,784 | —- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009/08/03 16:17:37 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2009/07/14 12:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2009/07/14 12:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2009/07/14 12:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2009/07/14 12:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui

< MD5 for: EXPLORER.EXE-A80E4F97.PF >
[2013/02/11 10:43:41 | 000,027,742 | —- | M] () MD5=8F48889EEFC49C25E0CE7FD0ACC08189 – C:\Windows\Prefetch\EXPLORER.EXE-A80E4F97.pf

< MD5 for: IEXPLORE.EXE >
[2012/11/14 12:56:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2012/11/14 12:56:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_178ed6e5b4dd3857\iexplore.exe
[2012/10/16 19:07:06 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_1787d4dfb4e386f6\iexplore.exe
[2012/10/08 18:37:24 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=270A1342BD5AF95CA25A586B4C2F1522 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16455_none_178cd651b4df05a9\iexplore.exe
[2009/07/14 11:17:29 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=2C32E3E596CFE660353753EABEFB0540 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_19ba3f8a72d988f3\iexplore.exe
[2012/10/16 19:07:05 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=2D53C5F71653EF94E7829846405D4ED2 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_0d332a8d8082c4fb\iexplore.exe
[2012/10/08 22:29:46 | 000,754,848 | —- | M] (Microsoft Corporation) MD5=49442BA6DCE4B4E3C1CB0AB193FE29AD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16455_none_0d382bff807e43ae\iexplore.exe
[2012/08/25 03:15:32 | 000,672,872 | —- | M] (Microsoft Corporation) MD5=4ADB84297505A1627DEEA18529BF4B16 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17115_none_1a05d46a72a0e4af\iexplore.exe
[2012/08/25 04:10:19 | 000,696,424 | —- | M] (Microsoft Corporation) MD5=85275D3D81C23C8A8D3C915888D11C66 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17115_none_0fb12a183e4022b4\iexplore.exe
[2010/11/20 23:28:25 | 000,695,056 | —- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2012/11/16 13:08:58 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=AC4957E154F750DF54F36ADC8E3E040D – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_0db6f8de99a3ff69\iexplore.exe
[2010/11/20 22:22:51 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe
[2012/08/25 03:10:38 | 000,672,872 | —- | M] (Microsoft Corporation) MD5=C6E8F6DB0FD7B28924D1CBC8AE03ECEE – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21313_none_1a8d72878bc04ef2\iexplore.exe
[2012/10/08 18:22:05 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=CECB15F834FC2B4B150449717ADE18DD – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20562_none_1808a252ce07755f\iexplore.exe
[2012/08/25 04:24:56 | 000,696,424 | —- | M] (Microsoft Corporation) MD5=E3C361C85ADECFF3A485E4FE17859E0F – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21313_none_1038c835575f8cf7\iexplore.exe
[2009/07/14 11:43:43 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=F2B0D41E1D08D0B2006DF5AA2E74C81E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_0f6595383e78c6f8\iexplore.exe
[2012/10/08 21:09:10 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=F61714ABCF9BF0CEF0A6249AD4FD490B – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20562_none_0db3f80099a6b364\iexplore.exe
[2012/11/14 12:19:28 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F691418EE9A6344AEB5C1B0518FBF8AE – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_180ba330ce04c164\iexplore.exe
[2012/11/14 17:11:18 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=FD0D2E1FAEBAE5031BE2EB8000D973F1 – C:\Program Files\Internet Explorer\iexplore.exe
[2012/11/14 17:11:18 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=FD0D2E1FAEBAE5031BE2EB8000D973F1 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_0d3a2c93807c765c\iexplore.exe

< MD5 for: IEXPLORE.EXE.CFG >
[2008/10/09 23:14:56 | 000,000,029 | —- | M] () MD5=14C57B5BD3C8168436AAC8858DCF0FCE – C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\ProfileTemplates\IExplore.exe.cfg

< MD5 for: IEXPLORE.EXE.MUI >
[2012/10/16 19:07:05 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2012/10/16 19:07:05 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2012/10/16 19:07:06 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2012/10/16 19:07:06 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui
[2009/07/14 12:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_09122aaf762607df\iexplore.exe.mui
[2009/07/14 12:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_0b433e7773148b79\iexplore.exe.mui
[2009/07/14 12:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_1366d501aa86c9da\iexplore.exe.mui
[2009/07/14 12:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_1597e8c9a7754d74\iexplore.exe.mui

< MD5 for: SERVICES >
[2009/06/11 07:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services

< MD5 for: SERVICES.CFG >
[2012/09/23 20:43:36 | 000,603,848 | R— | M] () MD5=81B120EAEE296F0E54F66C16C5A21367 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744BA0000000010\11.0.0\services.cfg
[2012/12/19 05:08:30 | 000,559,043 | —- | M] () MD5=BA25E8F1460C7453B7488FE4B42F6919 – C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Services\Services.cfg

< MD5 for: SERVICES.EXE >
[2009/07/14 11:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/14 11:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2009/07/14 12:25:40 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\SysNative\en-US\services.exe.mui
[2009/07/14 12:25:40 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui

< MD5 for: SERVICES.LNK >
[2009/07/14 14:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 14:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/11 06:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2009/06/11 06:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof

< MD5 for: SERVICES.MSC >
[2009/07/14 12:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\en-US\services.msc
[2009/06/11 06:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\services.msc
[2009/07/14 12:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\en-US\services.msc
[2009/06/11 07:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2009/07/14 12:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/11 06:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2009/07/14 12:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/11 07:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009/07/14 06:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/14 06:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml

< MD5 for: WINLOGON.ADML >
[2009/07/14 12:25:22 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\PolicyDefinitions\en-US\WinLogon.adml
[2009/07/14 12:25:22 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/11 07:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\PolicyDefinitions\WinLogon.admx
[2009/06/11 07:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2010/11/20 23:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 23:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/14 11:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009/10/28 17:01:57 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009/10/28 16:24:40 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2010/11/20 23:00:25 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2010/11/20 23:00:25 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui
[2009/07/14 12:29:52 | 000,022,528 | —- | M] (Microsoft Corporation) MD5=56D03B64B8C483C1D12A8E4577B3B332 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7600.16385_en-us_26ed83321dc778e1\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2009/07/14 12:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2009/07/14 12:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/14 06:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2009/07/14 06:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2013/02/11 12:19:34 | 4254,613,502 | -HS- | M] () – C:\hiberfil.sys
[2013/02/11 12:22:07 | 001,514,036 | —- | M] () – C:\IFRToolLog.txt
[2013/02/11 12:19:34 | 4241,166,333 | -HS- | M] () – C:\pagefile.sys
[2013/01/13 00:53:31 | 000,000,873 | —- | M] () – C:\sharks_log.html
[2013/01/24 00:31:38 | 000,002,456 | —- | M] () – C:\{0C9C7502-7347-4854-9CC1-0130B71328CC}
[2013/01/28 09:00:41 | 000,002,384 | —- | M] () – C:\{4136D721-BA39-406F-813D-3FFDBF5A947B}
[2013/02/02 11:24:00 | 000,002,656 | —- | M] () – C:\{9D7B1E24-71C4-4B4A-8704-6C23A9447E0D}

< %systemroot%\Fonts\*.com >
[2009/07/14 15:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 15:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 15:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 15:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/11 06:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/06/29 11:19:58 | 000,462,848 | —- | M] () – C:\Windows\Living Marine Aquarium 2.scr
[2007/12/18 23:12:36 | 001,950,197 | —- | M] (Freeze.com, LLC) – C:\Windows\Living Waterfalls 2 Full.scr
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 14:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/10/16 19:42:30 | 000,000,221 | -HS- | M] () – C:\Users\Scotty\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:07BF512B
@Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:D1B5B4F1

< End of report >
Hi and Welcome!! Retchy82 :)

My name is Robybel.

I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please be adviced, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise, this will be a team effort.
This may cause a delay, but I will do my best to keep it as short as possible. Please bear with me, I will post back to you as soon as I can.


IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


Vista and Windows 7 users:

These tools MUST be run from the executable. (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

Having said that….Let's get going!! ;)
Hi Retchy82 ;)

Please download aswMBR.exe and save it to your desktop.
  • Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)
  • Allow it to update where necessary
  • Click Scan

  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
=============================== Next =======================================


AdwCleaner

  • Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

=============================== Next =======================================


[external image: Posted Image] Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
On your next reply please post :
  • aswMBR log
  • AdwCleaner[S1].txt
  • JRT.txt

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
ok this is the first program you asked for :) aswMBR aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software Run date: 2013-02-12 17:34:28 —————————– 17:34:28.111 OS Version: Windows x64 6.1.7601 Service Pack 1 17:34:28.111 Number of processors: 4 586 0x3A09 17:34:28.111 ComputerName: SCOTTY-PC UserName: Scotty 17:34:33.873 Initialize success 17:36:46.418 AVAST engine defs: 13021101 17:39:29.770 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 17:39:29.772 Disk 0 Vendor: ST500DM0 KC45 Size: 476940MB BusType: 3 17:39:29.790 Disk 0 MBR read successfully 17:39:29.791 Disk 0 MBR scan 17:39:29.795 Disk 0 Windows 7 default MBR code 17:39:29.805 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048 17:39:29.817 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 476838 MB offset 206848 17:39:29.831 Disk 0 scanning C:\Windows\system32\drivers 17:39:44.681 Service scanning 17:40:01.147 Service MSICDSetup D:\CDriver64.sys **LOCKED** 21 17:40:18.926 Modules scanning 17:40:18.930 Disk 0 trace - called modules: 17:40:18.960 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys hal.dll 17:40:18.964 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800fba3060] 17:40:18.966 3 CLASSPNP.SYS[fffff88001fa543f] -> nt!IofCallDriver -> [0xfffffa800d182e40] 17:40:18.969 5 ACPI.sys[fffff88000f177a1] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0xfffffa800d189050] 17:40:20.180 AVAST engine scan C:\Windows 17:40:23.059 AVAST engine scan C:\Windows\system32 17:44:31.644 AVAST engine scan C:\Windows\system32\drivers 17:44:55.490 AVAST engine scan C:\Users\Scotty 17:53:54.056 AVAST engine scan C:\ProgramData 18:00:07.057 Scan finished successfully 18:13:39.964 Disk 0 MBR has been saved successfully to "C:\Users\Scotty\Desktop\MBR.dat" 18:13:39.967 The log file has been saved successfully to "C:\Users\Scotty\Desktop\aswMBR.txt"
adwcleaner # AdwCleaner v2.112 - Logfile created 02/12/2013 at 18:23:53 # Updated 10/02/2013 by Xplode # Operating system : Windows 7 Ultimate Service Pack 1 (64 bits) # User : Scotty - SCOTTY-PC # Boot Mode : Normal # Running from : C:\Users\Scotty\Downloads\adwcleaner0.exe # Option [Delete] ***** [Services] ***** Stopped & Deleted : Application Updater ***** [Files / Folders] ***** Deleted on reboot : C:\Program Files (x86)\Common Files\AVG Secure Search Folder Deleted : C:\Program Files (x86)\adawaretb Folder Deleted : C:\Program Files (x86)\Application Updater Folder Deleted : C:\Program Files (x86)\Ask.com Folder Deleted : C:\Program Files (x86)\AVG Secure Search Folder Deleted : C:\Program Files (x86)\Common Files\spigot Folder Deleted : C:\ProgramData\APN Folder Deleted : C:\ProgramData\AVG Secure Search Folder Deleted : C:\ProgramData\blekko toolbars Folder Deleted : C:\Users\Scotty\AppData\Local\APN Folder Deleted : C:\Users\Scotty\AppData\Local\AVG Secure Search Folder Deleted : C:\Users\Scotty\AppData\LocalLow\adawaretb Folder Deleted : C:\Users\Scotty\AppData\LocalLow\AskToolbar Folder Deleted : C:\Users\Scotty\AppData\LocalLow\AVG Secure Search Folder Deleted : C:\Users\Scotty\AppData\LocalLow\Funmoods Folder Deleted : C:\Users\Scotty\AppData\LocalLow\Search Settings Folder Deleted : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE} ***** [Registry] ***** Key Deleted : HKCU\Software\APN Key Deleted : HKCU\Software\APN PIP Key Deleted : HKCU\Software\AppDataLow\Software\AskToolbar Key Deleted : HKCU\Software\AppDataLow\Software\Search Settings Key Deleted : HKCU\Software\Ask.com Key Deleted : HKCU\Software\AVG Secure Search Key Deleted : HKCU\Software\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh Key Deleted : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0} Key Deleted : HKCU\Software\Search Settings Key Deleted : HKCU\Software\StartSearch Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} Key Deleted : HKLM\Software\APN Key Deleted : HKLM\Software\Application Updater Key Deleted : HKLM\Software\AskToolbar Key Deleted : HKLM\Software\AVG Secure Search Key Deleted : HKLM\Software\AVG Security Toolbar Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C} Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1 Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1 Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1 Key Deleted : HKLM\Software\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF Key Deleted : HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF Key Deleted : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol Key Deleted : HKLM\SOFTWARE\Classes\S Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1 Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94} Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1 Key Deleted : HKLM\Software\Freeze.com Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\FunmoodsSetup_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\FunmoodsSetup_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin Key Deleted : HKLM\Software\PIP Key Deleted : HKLM\Software\Search Settings Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{00000000-6E41-4FD3-8538-502F5495E5FC}] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SearchSettings] Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar] Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}] Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}] ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16457 [OK] Registry is clean. -\\ Google Chrome v24.0.1312.57 File : C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[R1].txt - [9923 octets] - [12/02/2013 18:21:50] AdwCleaner[S1].txt - [9815 octets] - [12/02/2013 18:23:53] ########## EOF - C:\AdwCleaner[S1].txt - [9875 octets] ##########
jrt.txt ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 4.6.2 (02.02.2013:2) OS: Windows 7 Ultimate x64 Ran by [removed] on Tue 12/02/2013 at 18:36:20.30 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] hkey_local_machine\software\classes\installer\upgradecodes\f928123a039649549966d4c29d35b1c9 ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\w3i" Successfully deleted: [Folder] "C:\Users\Scotty\AppData\Roaming\w3i, llc" Successfully deleted: [Folder] "C:\Users\Scotty\appdata\local\adawarebp" Successfully deleted: [Folder] "C:\Program Files (x86)\w3i" Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin" ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on Tue 12/02/2013 at 18:41:10.34 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Hi Retchy82 ;)

P2P Programs:

P2P programs are a major source of Malware infections.
From your log I see you have uTorrent We do not pass judgment on file-sharing, however we must inform you that engaging in this activity and having this kind of software installed on your system will always make you more susceptible to Malware infections.
The use of P2P programs may be contributing to your current situation, and you would certainly be doing yourself a favour by removing them.
If you wish to keep the program(s), please do not use them until your computer is cleaned.

Information regarding the risk of using these programs can be found from here and here


=============================== Next =======================================



Please read through these instructions to familarize yourself with what to expect when this tool runs

Refer to the ComboFix User's Guide


Download ComboFix from one of these locations:

Link 1
Link 2



* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================


Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs


====================================================


Double click on combofix.exe & follow the prompts.


When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.
COMBOFIX ComboFix 13-02-13.02 - Scotty 14/02/2013 13:58:38.1.4 - x64 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.61.1033.18.16333.13821 [GMT 10:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\ntuser.dat c:\windows\SysWow64\Packet.dll c:\windows\SysWow64\wpcap.dll . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . ——-\Legacy_NPF ——-\Service_NPF . . ((((((((((((((((((((((((( Files Created from 2013-01-14 to 2013-02-14 ))))))))))))))))))))))))))))))) . . 2013-02-14 04:06 . 2013-02-14 04:06 94656 —-a-w- c:\windows\system32\WPRO_41_2001woem.tmp 2013-02-13 02:08 . 2013-02-13 02:08 ——– d—–w- c:\users\Scotty\AppData\Roaming\Avira 2013-02-13 02:03 . 2012-12-03 07:08 99912 —-a-w- c:\windows\system32\drivers\avgntflt.sys 2013-02-13 02:03 . 2012-12-03 07:08 129216 —-a-w- c:\windows\system32\drivers\avipbb.sys 2013-02-13 02:03 . 2012-11-16 10:17 27800 —-a-w- c:\windows\system32\drivers\avkmgr.sys 2013-02-13 02:03 . 2013-02-13 02:03 ——– d—–w- c:\programdata\Avira 2013-02-13 01:42 . 2013-02-13 01:44 ——– d—–w- c:\users\Scotty\AppData\Local\AviraSpeedup 2013-02-13 01:42 . 2013-02-13 02:03 ——– d—–w- c:\program files (x86)\Avira 2013-02-13 00:30 . 2013-01-09 01:10 996352 —-a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll 2013-02-13 00:30 . 2013-01-08 22:01 768000 —-a-w- c:\program files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll 2013-02-13 00:25 . 2013-02-13 00:25 ——– d—–w- c:\users\Scotty\AppData\Local\adawarebp 2013-02-12 08:36 . 2013-02-12 08:36 ——– d—–w- c:\windows\ERUNT 2013-02-12 08:35 . 2013-02-12 08:35 ——– d—–w- C:\JRT 2013-02-12 08:24 . 2013-02-12 08:24 121 —-a-w- c:\windows\DeleteOnReboot.bat 2013-02-12 02:00 . 2013-02-12 02:00 ——– d—–w- c:\program files (x86)\Trend Micro 2013-02-12 01:43 . 2013-02-12 03:21 234544 —-a-w- c:\windows\RegBootClean64.exe 2013-02-12 01:25 . 2013-02-13 01:28 ——– d—–w- c:\users\Scotty\AppData\Local\Trend Micro 2013-02-12 01:24 . 2013-02-13 01:28 ——– d—–w- c:\programdata\Trend Micro 2013-02-11 09:48 . 2013-02-12 01:16 ——– d—–w- c:\program files (x86)\Common Files\Symantec Shared 2013-02-11 05:34 . 2012-12-16 20:43 38096 —-a-w- c:\windows\system32\drivers\gfiark.sys 2013-02-11 04:32 . 2013-02-11 04:32 ——– d—–w- c:\users\Scotty\AppData\Roaming\LavasoftStatistics 2013-02-11 04:21 . 2013-02-11 04:21 14456 —-a-w- c:\windows\system32\drivers\gfibto.sys 2013-02-11 04:20 . 2013-02-11 04:20 ——– d—–w- c:\programdata\Ad-Aware Browsing Protection 2013-02-11 04:20 . 2013-02-11 04:20 ——– d—–w- c:\program files (x86)\Toolbar Cleaner 2013-02-10 07:32 . 2013-02-10 07:38 ——– d—–w- c:\users\Scotty\AppData\Local\NPE 2013-02-10 05:18 . 2013-01-08 05:32 9161176 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{5D769319-A49C-46F2-999C-ADDB287B7434}\mpengine.dll 2013-02-05 12:24 . 2013-02-05 12:24 ——– d—–w- c:\program files (x86)\Code Laboratories 2013-02-05 05:22 . 2013-02-10 13:36 ——– d—–w- c:\users\Scotty\AppData\Roaming\Skype 2013-02-05 05:22 . 2013-02-10 13:36 ——– d—–w- c:\programdata\Skype 2013-02-02 15:34 . 2013-02-02 15:34 95648 —-a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-01-31 15:27 . 2013-01-31 15:27 ——– d–h–w- c:\program files (x86)\Common Files\EAInstaller 2013-01-27 09:58 . 2013-01-27 09:58 ——– d—–w- c:\users\Scotty\AppData\Roaming\Apple Computer 2013-01-26 02:16 . 2013-01-26 02:16 ——– d—–w- c:\program files (x86)\MSI Kombustor 2.5 2013-01-26 02:16 . 2013-01-26 02:16 ——– d—–w- c:\users\Scotty\AppData\Local\Programs 2013-01-26 00:29 . 2013-01-26 00:29 ——– d—–w- c:\users\Scotty\AppData\Roaming\iMobie 2013-01-26 00:29 . 2013-01-26 00:29 ——– d—–w- c:\users\Scotty\AppData\Local\iMobie_Inc 2013-01-25 00:40 . 2013-01-15 08:49 26432 —-a-w- c:\windows\system32\RegistryDefragBootTime.exe 2013-01-24 14:49 . 2013-01-24 14:49 ——– d—–w- c:\program files (x86)\IObit Apps Toolbar 2013-01-24 14:49 . 2013-01-24 14:49 ——– d—–w- c:\programdata\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A} 2013-01-24 14:49 . 2013-01-25 00:56 ——– d—–w- c:\programdata\IObit 2013-01-24 14:49 . 2013-02-10 04:03 ——– d—–w- c:\users\Scotty\AppData\Roaming\IObit 2013-01-24 14:49 . 2013-01-27 23:10 ——– d—–w- c:\program files (x86)\IObit 2013-01-21 07:42 . 2013-01-21 07:42 ——– d—–w- c:\users\Scotty\AppData\Local\Adobe 2013-01-21 04:56 . 2013-02-11 03:46 ——– d—–w- c:\users\Scotty\AppData\Roaming\QuickScan 2013-01-21 04:41 . 2013-01-21 04:41 ——– d—–w- c:\programdata\Futuremark 2013-01-21 04:40 . 2013-01-21 04:40 ——– d—–w- c:\program files (x86)\Common Files\Wise Installation Wizard 2013-01-21 04:39 . 2013-01-21 04:39 ——– d—–w- c:\program files (x86)\Futuremark 2013-01-20 23:56 . 2013-01-20 23:56 ——– d—–w- c:\programdata\ATI 2013-01-20 23:56 . 2013-01-20 23:56 ——– d—–w- c:\program files (x86)\AMD AVT 2013-01-20 23:56 . 2013-01-20 23:56 ——– d—–w- c:\program files (x86)\AMD APP 2013-01-20 12:05 . 2013-01-20 12:05 ——– d—–w- C:\.cache 2013-01-18 23:19 . 2013-01-18 23:19 ——– d—–w- c:\users\Scotty\AppData\Roaming\AccurateRip 2013-01-18 23:19 . 2013-01-18 23:18 7261256 —-a-w- c:\windows\SysWow64\SpoonUninstall.exe 2013-01-18 23:19 . 2013-01-18 23:19 ——– d—–w- c:\program files (x86)\Illustrate 2013-01-18 13:56 . 2013-01-18 13:56 ——– d—–w- c:\users\Scotty\AppData\Roaming\Auslogics 2013-01-16 08:18 . 2013-02-05 01:48 ——– d—–w- c:\program files (x86)\SlimCleaner 2013-01-15 06:07 . 2013-02-12 09:05 ——– d—–w- c:\program files (x86)\Antec CC . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-02-14 04:07 . 2012-11-16 16:00 15712 —-a-w- c:\windows\system32\drivers\SWDUMon.sys 2013-02-14 04:06 . 2012-10-10 04:15 34752 —-a-w- c:\windows\system32\drivers\WPRO_41_2001.sys 2013-02-13 00:32 . 2012-10-16 15:31 70004024 —-a-w- c:\windows\system32\MRT.exe 2013-02-11 07:33 . 2012-11-10 12:14 39768 —-a-w- c:\windows\system32\drivers\avgtpx64.sys 2013-02-08 05:50 . 2012-12-30 05:48 74096 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-02-08 05:50 . 2012-12-30 05:48 697712 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-02-02 15:34 . 2012-10-16 13:56 861088 —-a-w- c:\windows\SysWow64\npDeployJava1.dll 2013-02-02 15:34 . 2012-10-16 13:56 782240 —-a-w- c:\windows\SysWow64\deployJava1.dll 2013-01-16 15:28 . 2012-12-09 22:38 273840 ——w- c:\windows\system32\MpSigStub.exe 2013-01-07 06:19 . 2013-01-07 06:19 1831424 —-a-w- c:\windows\SysWow64\atiumdmv.dll 2013-01-07 06:18 . 2013-01-07 06:18 67584 —-a-w- c:\windows\atisamu32.dll 2013-01-07 06:18 . 2013-01-07 06:18 442368 —-a-w- c:\windows\system32\ATIDEMGX.dll 2013-01-07 06:18 . 2013-01-07 06:18 1120768 —-a-w- c:\windows\system32\atiumd6v.dll 2013-01-04 04:43 . 2013-02-13 00:29 44032 —-a-w- c:\windows\apppatch\acwow64.dll 2012-12-27 04:46 . 2012-12-27 04:46 2848312 —-a-r- c:\users\Scotty\AppData\Roaming\Microsoft\Installer\{EAB5AC2D-BDD5-4864-8380-904B3EB4B1E7}\Icon_2.exe 2012-12-27 04:46 . 2012-12-27 04:46 2848312 —-a-r- c:\users\Scotty\AppData\Roaming\Microsoft\Installer\{EAB5AC2D-BDD5-4864-8380-904B3EB4B1E7}\Icon_1.exe 2012-12-19 20:50 . 2012-12-19 20:50 5630200 —-a-w- c:\windows\SysWow64\atiumdag.dll 2012-12-19 20:48 . 2012-12-19 20:48 11278336 —-a-w- c:\windows\system32\drivers\atikmdag.sys 2012-12-19 20:29 . 2012-12-19 20:29 23461376 —-a-w- c:\windows\system32\atio6axx.dll 2012-12-19 20:22 . 2012-12-19 20:22 70144 —-a-w- c:\windows\system32\coinst_9.012.dll 2012-12-19 20:19 . 2012-12-19 20:19 163840 —-a-w- c:\windows\system32\atiapfxx.exe 2012-12-19 20:18 . 2012-12-19 20:18 51200 —-a-w- c:\windows\system32\aticalrt64.dll 2012-12-19 20:18 . 2012-12-19 20:18 46080 —-a-w- c:\windows\SysWow64\aticalrt.dll 2012-12-19 20:17 . 2012-12-19 20:17 44544 —-a-w- c:\windows\system32\aticalcl64.dll 2012-12-19 20:17 . 2012-12-19 20:17 44032 —-a-w- c:\windows\SysWow64\aticalcl.dll 2012-12-19 20:17 . 2012-12-19 20:17 16082944 —-a-w- c:\windows\system32\aticaldd64.dll 2012-12-19 20:13 . 2012-12-19 20:13 13703168 —-a-w- c:\windows\SysWow64\aticaldd.dll 2012-12-19 20:12 . 2012-12-19 20:12 18982400 —-a-w- c:\windows\SysWow64\atioglxx.dll 2012-12-19 20:09 . 2012-12-19 20:09 960512 —-a-w- c:\windows\SysWow64\aticfx32.dll 2012-12-19 20:08 . 2012-02-15 03:17 1151488 —-a-w- c:\windows\system32\aticfx64.dll 2012-12-19 20:06 . 2012-12-19 20:06 6681088 —-a-w- c:\windows\SysWow64\atidxx32.dll 2012-12-19 19:59 . 2012-12-19 19:59 5087744 —-a-w- c:\windows\system32\atiumd6a.dll 2012-12-19 19:57 . 2012-12-19 19:57 442368 —-a-w- c:\windows\system32\atidemgy.dll 2012-12-19 19:56 . 2012-12-19 19:56 550912 —-a-w- c:\windows\system32\atieclxx.exe 2012-12-19 19:56 . 2012-12-19 19:56 240640 —-a-w- c:\windows\system32\atiesrxx.exe 2012-12-19 19:54 . 2012-12-19 19:54 120320 —-a-w- c:\windows\system32\atitmm64.dll 2012-12-19 19:54 . 2012-12-19 19:54 21504 —-a-w- c:\windows\system32\atimuixx.dll 2012-12-19 19:54 . 2012-12-19 19:54 59392 —-a-w- c:\windows\system32\atiedu64.dll 2012-12-19 19:54 . 2012-12-19 19:54 43520 —-a-w- c:\windows\SysWow64\ati2edxx.dll 2012-12-19 19:49 . 2012-02-15 02:52 7370752 —-a-w- c:\windows\system32\atidxx64.dll 2012-12-19 19:44 . 2012-12-19 19:44 4162048 —-a-w- c:\windows\SysWow64\atiumdva.dll 2012-12-19 19:44 . 2012-12-19 19:44 6786560 —-a-w- c:\windows\system32\atiumd64.dll 2012-12-19 19:34 . 2012-12-19 19:34 79360 —-a-w- c:\windows\system32\amdave64.dll 2012-12-19 19:34 . 2012-12-19 19:34 78336 —-a-w- c:\windows\SysWow64\amdave32.dll 2012-12-19 19:34 . 2012-12-19 19:34 74240 —-a-w- c:\windows\system32\atisamu64.dll 2012-12-19 19:34 . 2012-12-19 19:34 71168 —-a-w- c:\windows\SysWow64\atisamu32.dll 2012-12-19 19:33 . 2012-12-19 19:33 56320 —-a-w- c:\windows\system32\atimpc64.dll 2012-12-19 19:33 . 2012-12-19 19:33 56320 —-a-w- c:\windows\system32\amdpcom64.dll 2012-12-19 19:33 . 2012-09-28 01:13 619008 —-a-w- c:\windows\system32\atiadlxx.dll 2012-12-19 19:33 . 2012-12-19 19:33 56832 —-a-w- c:\windows\SysWow64\atimpc32.dll 2012-12-19 19:33 . 2012-12-19 19:33 56832 —-a-w- c:\windows\SysWow64\amdpcom32.dll 2012-12-19 19:33 . 2012-09-28 01:13 421888 —-a-w- c:\windows\SysWow64\atiadlxy.dll 2012-12-19 19:33 . 2012-12-19 19:33 17920 —-a-w- c:\windows\system32\atig6pxx.dll 2012-12-19 19:33 . 2012-12-19 19:33 14848 —-a-w- c:\windows\SysWow64\atiglpxx.dll 2012-12-19 19:33 . 2012-12-19 19:33 14848 —-a-w- c:\windows\system32\atiglpxx.dll 2012-12-19 19:33 . 2012-12-19 19:33 41984 —-a-w- c:\windows\system32\atig6txx.dll 2012-12-19 19:33 . 2012-12-19 19:33 33280 —-a-w- c:\windows\SysWow64\atigktxx.dll 2012-12-19 19:32 . 2012-12-19 19:32 552960 —-a-w- c:\windows\system32\drivers\atikmpag.sys 2012-12-19 19:31 . 2012-09-28 01:11 130048 —-a-w- c:\windows\system32\atiuxp64.dll 2012-12-19 19:31 . 2012-12-19 19:31 109568 —-a-w- c:\windows\SysWow64\atiuxpag.dll 2012-12-19 19:31 . 2012-12-19 19:31 104448 —-a-w- c:\windows\system32\atiu9p64.dll 2012-12-19 19:30 . 2012-09-28 01:10 83968 —-a-w- c:\windows\SysWow64\atiu9pag.dll 2012-12-19 19:30 . 2012-12-19 19:30 53248 —-a-w- c:\windows\system32\drivers\ati2erec.dll 2012-12-19 05:45 . 2012-12-19 05:45 222720 —-a-w- c:\windows\system32\clinfo.exe 2012-12-19 05:44 . 2012-12-19 05:44 76288 —-a-w- c:\windows\system32\OpenVideo64.dll 2012-12-19 05:44 . 2012-12-19 05:44 65536 —-a-w- c:\windows\SysWow64\OpenVideo.dll 2012-12-19 05:44 . 2012-12-19 05:44 64000 —-a-w- c:\windows\system32\OVDecode64.dll 2012-12-19 05:44 . 2012-12-19 05:44 56320 —-a-w- c:\windows\SysWow64\OVDecode.dll 2012-12-19 05:44 . 2012-12-19 05:44 34518016 —-a-w- c:\windows\system32\amdocl64.dll 2012-12-19 05:38 . 2012-12-19 05:38 28732928 —-a-w- c:\windows\SysWow64\amdocl.dll 2012-12-19 05:34 . 2012-12-19 05:34 54784 —-a-w- c:\windows\system32\OpenCL.dll 2012-12-19 05:34 . 2012-12-19 05:34 50176 —-a-w- c:\windows\SysWow64\OpenCL.dll 2012-12-16 17:11 . 2012-12-21 22:28 46080 —-a-w- c:\windows\system32\atmlib.dll 2012-12-16 14:45 . 2012-12-21 22:28 367616 —-a-w- c:\windows\system32\atmfd.dll 2012-12-16 14:13 . 2012-12-21 22:28 295424 —-a-w- c:\windows\SysWow64\atmfd.dll 2012-12-16 14:13 . 2012-12-21 22:28 34304 —-a-w- c:\windows\SysWow64\atmlib.dll 2012-12-07 13:20 . 2013-01-09 02:33 441856 —-a-w- c:\windows\system32\Wpc.dll 2012-12-07 13:15 . 2013-01-09 02:33 2746368 —-a-w- c:\windows\system32\gameux.dll 2012-12-07 12:26 . 2013-01-09 02:33 308736 —-a-w- c:\windows\SysWow64\Wpc.dll 2012-12-07 12:20 . 2013-01-09 02:33 2576384 —-a-w- c:\windows\SysWow64\gameux.dll 2012-12-07 11:20 . 2013-01-09 02:33 30720 —-a-w- c:\windows\system32\usk.rs 2012-12-07 11:20 . 2013-01-09 02:33 43520 —-a-w- c:\windows\system32\csrr.rs 2012-12-07 11:20 . 2013-01-09 02:33 23552 —-a-w- c:\windows\system32\oflc.rs 2012-12-07 11:20 . 2013-01-09 02:33 45568 —-a-w- c:\windows\system32\oflc-nz.rs 2012-12-07 11:20 . 2013-01-09 02:33 44544 —-a-w- c:\windows\system32\pegibbfc.rs 2012-12-07 11:20 . 2013-01-09 02:33 20480 —-a-w- c:\windows\system32\pegi-fi.rs 2012-12-07 11:20 . 2013-01-09 02:33 20480 —-a-w- c:\windows\system32\pegi-pt.rs 2012-12-07 11:19 . 2013-01-09 02:33 20480 —-a-w- c:\windows\system32\pegi.rs 2012-12-07 11:19 . 2013-01-09 02:33 46592 —-a-w- c:\windows\system32\fpb.rs 2012-12-07 11:19 . 2013-01-09 02:33 40960 —-a-w- c:\windows\system32\cob-au.rs 2012-12-07 11:19 . 2013-01-09 02:33 21504 —-a-w- c:\windows\system32\grb.rs 2012-12-07 11:19 . 2013-01-09 02:33 15360 —-a-w- c:\windows\system32\djctq.rs 2012-12-07 11:19 . 2013-01-09 02:33 55296 —-a-w- c:\windows\system32\cero.rs 2012-12-07 11:19 . 2013-01-09 02:33 51712 —-a-w- c:\windows\system32\esrb.rs 2012-12-07 10:46 . 2013-01-09 02:33 43520 —-a-w- c:\windows\SysWow64\csrr.rs 2012-12-07 10:46 . 2013-01-09 02:33 30720 —-a-w- c:\windows\SysWow64\usk.rs 2012-12-07 10:46 . 2013-01-09 02:33 45568 —-a-w- c:\windows\SysWow64\oflc-nz.rs 2012-12-07 10:46 . 2013-01-09 02:33 44544 —-a-w- c:\windows\SysWow64\pegibbfc.rs 2012-12-07 10:46 . 2013-01-09 02:33 23552 —-a-w- c:\windows\SysWow64\oflc.rs 2012-12-07 10:46 . 2013-01-09 02:33 20480 —-a-w- c:\windows\SysWow64\pegi-pt.rs . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{03EB0E9C-7A91-4381-A220-9B52B641CDB1}"= "c:\program files (x86)\IObit Apps Toolbar\IE\6.7\iobitappsToolbarIE.dll" [2013-01-10 1348416] . [HKEY_CLASSES_ROOT\clsid\{03eb0e9c-7a91-4381-a220-9b52b641cdb1}] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{03EB0E9C-7A91-4381-A220-9B52B641CDB1}] 2013-01-10 06:54 1348416 —-a-w- c:\program files (x86)\IObit Apps Toolbar\IE\6.7\iobitappsToolbarIE.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{03EB0E9C-7A91-4381-A220-9B52B641CDB1}"= "c:\program files (x86)\IObit Apps Toolbar\IE\6.7\iobitappsToolbarIE.dll" [2013-01-10 1348416] . [HKEY_CLASSES_ROOT\clsid\{03eb0e9c-7a91-4381-a220-9b52b641cdb1}] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files (x86)\Windows Sidebar\sidebar.exe" [2010-11-20 1174016] "NETGEARGenie"="c:\program files (x86)\NETGEAR Genie\bin\NETGEARGenie.exe" [2012-10-16 1041736] "F3B86A9EB072ABC2F0F62B1D515F7C32AAE587FE._service_run"="c:\program files (x86)\Google\Chrome\Application\chrome.exe" [2013-01-26 1248208] "Steam"="c:\program files (x86)\Steam\steam.exe" [2013-01-23 1597864] "LCLC Control Panel"="c:\program files (x86)\Antec CC\ChillControl V.exe" [2011-08-08 692096] "AviraSpeedup"="c:\program files (x86)\Avira\AviraSpeedup\AviraSpeedup.exe" [2013-02-13 5827824] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2011-11-29 284440] "IMSS"="c:\program files (x86)\Intel\Intel® Management Engine Components\IMSS\PIconStartup.exe" [2012-02-07 133400] "USB3MON"="c:\program files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-01-26 291608] "THX TruStudio NB Settings"="c:\program files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe" [2011-05-19 909824] "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-10 90112] "Tt eSPORTS BLACK Gaming Mouse"="c:\program files (x86)\Thermaltake\Tt eSPORTS BLACK\Black.exe" [2011-01-06 13346600] "Live Update 5"="c:\program files (x86)\MSI\Live Update 5\LU5.exe" [2011-11-22 1935888] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-12-19 642808] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-18 946352] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-02 252848] "Trend Micro RUBotted V2.0 Beta"="c:\program files (x86)\Trend Micro\RUBotted\RUBottedGUI.exe" [2010-12-16 1103184] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-01-23 385248] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "Userinit"="userinit.exe" . R2 ADExchange;ArcSoft Exchange Service; [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 RUBotSrv;Trend Micro RUBotted Service;c:\program files (x86)\Trend Micro\RUBotted\RUBotSrv.exe [x] R3 AxtuDrv;AxtuDrv; [x] R3 BVRPMPR5a64;BVRPMPR5a64 NDIS Protocol Driver;c:\windows\system32\drivers\BVRPMPR5a64.SYS [x] R3 cpudrv64;cpudrv64;c:\program files (x86)\SystemRequirementsLab\cpudrv64.sys [x] R3 cpuz135;cpuz135; [x] R3 cpuz136;cpuz136; [x] R3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [x] R3 gfiark;gfiark;c:\windows\system32\drivers\gfiark.sys [x] R3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x] R3 MSICDSetup;MSICDSetup;D:\CDriver64.sys [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x] R3 Revoflt;Revoflt;c:\windows\system32\DRIVERS\revoflt.sys [x] R3 RoxMediaDBGame1X;RoxMediaDBGame1X;c:\program files (x86)\Common Files\Roxio Shared\Game1X\SharedCOM\RoxMediaDBGame1X.exe [x] R3 SWDUMon;SWDUMon;c:\windows\system32\DRIVERS\SWDUMon.sys [x] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x] R3 TurboBoost;Intel® Turbo Boost Technology Monitor 2.6;c:\program files\Intel\TurboBoost\TurboBoost.exe [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] S0 asahci64;asahci64;c:\windows\system32\DRIVERS\asahci64.sys [x] S0 AsrRamDisk;AsrRamDisk;c:\windows\system32\DRIVERS\AsrRamDisk.sys [x] S0 gfibto;gfibto;c:\windows\system32\drivers\gfibto.sys [x] S0 iusb3hcs;Intel® USB 3.0 Host Controller Switch Driver;c:\windows\system32\DRIVERS\iusb3hcs.sys [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x] S1 AsrAppCharger;AsrAppCharger;c:\windows\system32\DRIVERS\AsrAppCharger.sys [x] S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx64.sys [x] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x] S2 AntiVirMailService;Avira Mail Protection;c:\program files (x86)\Avira\AntiVir Desktop\avmailc.exe [x] S2 AntiVirSchedulerService;Avira Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x] S2 AntiVirWebService;Avira Web Protection;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [x] S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [x] S2 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe [x] S2 Intel® ME Service;Intel® ME Service;c:\program files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [x] S2 iocbios2;iocbios2;c:\program files (x86)\Intel\Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys [x] S2 ISCTAgent;ISCT Always Updated Agent;c:\program files\Intel\Intel® Smart Connect Technology Agent\iSCTAgent.exe [x] S2 jhi_service;Intel® Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [x] S2 NETGEARGenieDaemon;NETGEARGenieDaemon;c:\program files (x86)\NETGEAR Genie\bin\NETGEARGenieDaemon64.exe [x] S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [x] S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [x] S2 vToolbarUpdater14.1.7;vToolbarUpdater14.1.7;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.1.7\ToolbarUpdater.exe [x] S2 XTU3SERVICE;Intel® Extreme Tuning Utility Service;c:\program files (x86)\Intel\Extreme Tuning Utility\XtuService.exe [x] S3 ASEUSBCC;ASEUSBCC;c:\windows\system32\drivers\AseUSBCC.sys [x] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x] S3 ICCS;Intel® Integrated Clock Controller Service - Intel® ICCS;c:\program files (x86)\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe [x] S3 ICCWDT;Intel® Watchdog Timer Driver (Intel® WDT);c:\windows\system32\DRIVERS\ICCWDT.sys [x] S3 ikbevent;Intel Upper keyboard Class Filter Driver;c:\windows\system32\DRIVERS\ikbevent.sys [x] S3 imsevent;Intel Upper Mouse Class Filter Driver;c:\windows\system32\DRIVERS\imsevent.sys [x] S3 ISCT;Intel® Smart Connect Technology Device Driver;c:\windows\system32\DRIVERS\ISCTD64.sys [x] S3 iusb3hub;Intel® USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\iusb3hub.sys [x] S3 iusb3xhc;Intel® USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\DRIVERS\iusb3xhc.sys [x] S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys [x] S3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507;c:\program files (x86)\MSI\Live Update 5\msibios64_100507.sys [x] S3 NPF;WinPcap Packet Driver (NPF);c:\windows\system32\drivers\NPF.sys [x] S3 NTIOLib_1_0_4;NTIOLib_1_0_4;c:\program files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [x] S3 RTCore64;RTCore64;c:\program files (x86)\MSI Afterburner\RTCore64.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] S3 Thermnaltake MS1 Filter;Thermnaltake MS1 Filter;c:\windows\system32\Drivers\MS1Filter.sys [x] S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [x] S3 WinRing0_1_2_0;WinRing0_1_2_0;c:\users\Scotty\AppData\Local\Temp\tmpB192.tmp [x] S3 WPRO_41_2001;WinPcap Packet Driver (WPRO_41_2001);c:\windows\system32\drivers\WPRO_41_2001.sys [x] . . — Other Services/Drivers In Memory — . *NewlyCreated* - NPF *NewlyCreated* - WINRING0_1_2_0 *NewlyCreated* - WS2IFSL . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-02-01 02:22 1607120 —-a-w- c:\program files (x86)\Google\Chrome\Application\24.0.1312.57\Installer\chrmstp.exe . Contents of the 'Scheduled Tasks' folder . 2013-02-14 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-30 05:50] . 2013-02-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-16 05:57] . 2013-02-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-16 05:57] . 2013-02-14 c:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job - c:\program files (x86)\Intel\Intel® ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25 03:41] . 2013-02-13 c:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job - c:\program files (x86)\Intel\Intel® ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25 03:41] . 2013-02-14 c:\windows\Tasks\SlimDrivers Startup.job - c:\program files (x86)\SlimDrivers\SlimDrivers.exe [2012-12-16 02:04] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "XFast LAN"="c:\program files\ASRock\XFast LAN\cFosSpeed.exe" [2011-10-19 1441152] "THXCfg64"="c:\windows\system32\THXCfg64.dll" [2011-05-13 26624] "IntelTBRunOnce"="wscript.exe" [2009-07-14 168960] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2000-01-01 170304] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2000-01-01 398656] "Persistence"="c:\windows\system32\igfxpers.exe" [2000-01-01 441152] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2000-01-01 12503184] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = about:blank mStart Page = about:blank mLocal Page = c:\windows\SysWOW64\blank.htm LSP: c:\program files (x86)\Avira\AntiVir Desktop\avsda.dll TCP: DhcpNameServer = 192.168.1.1 . - - - - ORPHANS REMOVED - - - - . Wow6432Node-HKU-Default-Run-Norton Download Manager{N360202122-SHPD-FSD31014} - c:\program files (x86)\Norton Management\Engine\3.2.0.19\ccSvcHst.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRing0_1_2_0] "ImagePath"="\??\c:\users\Scotty\AppData\Local\Temp\tmpB192.tmp" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}] @Denied: (A 2) (Everyone) @="IFlashBroker3" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\MSI Afterburner\MSIAfterburner.exe c:\program files (x86)\MSI Afterburner\Bundle\OSDServer\RTSS.exe c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe c:\windows\SysWOW64\PnkBstrA.exe c:\program files (x86)\NETGEAR Genie\bin\genie2_tray.exe c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe . ************************************************************************** . Completion time: 2013-02-14 14:11:13 - machine was rebooted ComboFix-quarantined-files.txt 2013-02-14 04:11 . Pre-Run: 255,184,773,120 bytes free Post-Run: 254,462,242,816 bytes free . - - End Of File - - 9ED7D52C903DDFFEA0E5FBB8EBB45078
Hi Retchy82 ;)

Very good job ;)

I see you have Iobit installed, there was some controversy concerning this software a couple of years ago, take a read of this article then decide if you wish to keep this program:

http://dottech.org/13126/malwarebytes-vs-i…mes-to-a-close/

Next

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.

=============================== Next =======================================



ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

Note: If you are using Windows Vista/7, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as MyEsetScan. Alternatively, look for report in C:\Program Files\ESET\ESET Online Scanner\log.txt. Include the contents of this report in your next reply.
  • Push the Back button.
  • Select Uninstall application on close check box and push [external image: Posted Image]
On your next reply please post :
  • MBAM report
  • ESET Result

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
malwarebytes Malwarebytes Anti-Malware (Trial) 1.70.0.1100 www.malwarebytes.org Database version: v2013.02.16.07 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Scotty :: SCOTTY-PC [administrator] Protection: Enabled 17/02/2013 10:21:55 AM mbam-log-2013-02-17 (10-21-55).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 213453 Time elapsed: 2 minute(s), 29 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
i did the eset and it found 0 threats but when it finished i couldnt export a text file because it didnt have that option??? and i cannot uninstall combo fix look for combofix /uninstall nothing?
Hi Retchy82 ;)

and i cannot uninstall combo fix look for combofix /uninstall nothing?

IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

We will be uninstalling all the tools once your machine is clean

Now, Please re run OTL

  • Open OTL again and click the Quick Scan button (don't check the boxes beside LOP Check or Purity this time)
  • Post the OTL.txt log it produces in your next reply.

Please let me know how your machine is running and if there are any outstanding issues
ok i ran otl but when you said not to tick those boxes made sure they were not ticked but when i run quick scan they auto tick?

otl results:

OTL logfile created on: 2/20/2013 2:37:03 AM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Scotty\Downloads
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

15.95 Gb Total Physical Memory | 12.25 Gb Available Physical Memory | 76.82% Memory free
31.90 Gb Paging File | 27.82 Gb Available in Paging File | 87.20% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.66 Gb Total Space | 229.99 Gb Free Space | 49.39% Space Free | Partition Type: NTFS
Drive F: | 931.48 Gb Total Space | 563.46 Gb Free Space | 60.49% Space Free | Partition Type: NTFS
Drive G: | 100.00 Mb Total Space | 69.88 Mb Free Space | 69.89% Space Free | Partition Type: NTFS

Computer Name: SCOTTY-PC | User Name: Scotty | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Avira\AviraSpeedup\AviraSpeedup.exe (Avira)
PRC - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.1.7\ToolbarUpdater.exe ()
PRC - C:\Users\Scotty\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTSS.exe ()
PRC - C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe ()
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe (SlimWare Utilities, Inc.)
PRC - C:\Program Files (x86)\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\GRETECH\GomAudio\Goma.exe (Gretech Corporation)
PRC - C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenie.exe ()
PRC - C:\Program Files (x86)\NETGEAR Genie\bin\genie2_tray.exe ()
PRC - C:\Program Files (x86)\Intel\Extreme Tuning Utility\XtuService.exe (Intel® Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe ()
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\MSI\Live Update 5\LU5.exe (Micro-Star International)
PRC - C:\Program Files (x86)\Antec CC\ChillControl V.exe (Antec Inc.)
PRC - C:\Program Files (x86)\Thermaltake\Tt eSPORTS BLACK\Black.exe (Thermaltake)
PRC - C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Google\Google Talk\googletalk.exe (Google)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Steam\bin\chromehtml.dll ()
MOD - C:\Program Files (x86)\Steam\bin\audio.dll ()
MOD - C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\PepperFlash\11.6.602.167\pepflashplayer.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\7366a39c36523a084bc11c230929ff92\Microsoft.VisualBasic.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\cb562e2e4f74ae607f1186f6ec50cec7\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_149.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\ppgooglenaclpluginchrome.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\pdf.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\libglesv2.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\libegl.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\ffmpegsumo.dll ()
MOD - C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTSS.exe ()
MOD - C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe ()
MOD - C:\Users\Scotty\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.6.gadget\GetCoreTempInfoNET.dll ()
MOD - C:\Users\Scotty\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.6.gadget\SystemInfo.dll ()
MOD - C:\Users\Scotty\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.6.gadget\CoreTempReader.dll ()
MOD - C:\Program Files (x86)\Steam\bin\libcef.dll ()
MOD - C:\Program Files (x86)\Steam\bin\mssvoice.asi ()
MOD - C:\Program Files (x86)\MSI Afterburner\RTMUI.dll ()
MOD - C:\Program Files (x86)\MSI Afterburner\RTHAL.dll ()
MOD - C:\Program Files (x86)\MSI Afterburner\RTCore.dll ()
MOD - C:\Program Files (x86)\MSI Afterburner\RTUI.dll ()
MOD - C:\Program Files (x86)\MSI Afterburner\RTFC.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\302207b4fa3083899fd8ab4db98cecc5\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\7ffdaee3a54ffd1a5e3b008a5bde5ecf\IAStorUtil.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\389a1832a3da11e1b409cd6ae60cb9fa\IAStorCommon.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\90b89f6e8032310e9ac72a309fd49e83\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\dd20416f723ee13ffb4173ec1afc4ec4\System.Data.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\d908c91e24616e6b8d38c9da61038b25\Accessibility.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\cf827fe7bc99d9bcf0ba3621054ef527\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\195a77fcc6206f8bb35d419ff2cf0d72\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Steam\sdl.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avcodec-53.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avformat-53.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avutil-51.dll ()
MOD - C:\Program Files (x86)\Battlelog Web Plugins\launcher-106.dll ()
MOD - C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTMUI.dll ()
MOD - C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTSSHooks.dll ()
MOD - C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTUI.dll ()
MOD - C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTFC.dll ()
MOD - C:\Program Files (x86)\GRETECH\GomAudio\Plugins\mzin_cdda.dll ()
MOD - C:\Program Files (x86)\GRETECH\GomAudio\Plugins\mzin_ogg.dll ()
MOD - C:\Program Files (x86)\GRETECH\GomAudio\Plugins\mzin_mp3.dll ()
MOD - C:\Program Files (x86)\GRETECH\GomAudio\Plugins\mzin_m4a.dll ()
MOD - C:\Program Files (x86)\GRETECH\GomAudio\MultiLangEx.dll ()
MOD - C:\Program Files (x86)\GRETECH\GomAudio\Plugins\mzin_flac.dll ()
MOD - C:\Program Files (x86)\GRETECH\GomAudio\Plugins\mzin_midi.dll ()
MOD - C:\Program Files (x86)\GRETECH\GomAudio\Plugins\mzin_mpc.dll ()
MOD - C:\Program Files (x86)\GRETECH\GomAudio\Plugins\mzin_ape.dll ()
MOD - C:\Program Files (x86)\GRETECH\GomAudio\Plugins\mzin_wm.dll ()
MOD - C:\Program Files (x86)\GRETECH\GomAudio\Plugins\mzin_wav.dll ()
MOD - C:\Program Files (x86)\GRETECH\GomAudio\Plugins\mzout_ds.dll ()
MOD - C:\Program Files (x86)\GRETECH\GomAudio\Plugins\mzout_wave.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Map.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenie.exe ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Resource.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\SvtNetworkTool.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_RouterConfiguration.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_ParentalControl.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Internet.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Ui.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\InnerPlugin_Update.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Statistics.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\InnerPlugin_WirelessExport.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_NetworkProblem.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\Genie.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Wireless.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Airprint.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\DragonNetTool.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\DiagnoseDll.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\airprintdll.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\DiagnosePlugin.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\WSetupApiPlugin.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\QRCode.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\NetcardApi.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\SVTUtils.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\WSetupDll.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\genie2_tray.exe ()
MOD - C:\Program Files (x86)\Steam\bin\mssmp3.asi ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\QtGui4.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\QtCore4.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\QtNetwork4.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\QtXml4.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qjpeg4.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qico4.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qgif4.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\libgcc_s_dw2-1.dll ()
MOD - C:\Program Files (x86)\NETGEAR Genie\bin\mingwm10.dll ()
MOD - C:\Users\Scotty\AppData\Local\Temp\ShellHook.dll ()
MOD - C:\Program Files (x86)\MSI Afterburner\RTTSH.dll ()
MOD - C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTTSH.dll ()
MOD - C:\Program Files (x86)\Thermaltake\Tt eSPORTS BLACK\BlackHook.dll ()
MOD - C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (TurboBoost) – C:\Program Files\Intel\TurboBoost\TurboBoost.exe (Intel® Corporation)
SRV:64bit: - (ISCTAgent) – C:\Program Files\Intel\Intel® Smart Connect Technology Agent\iSCTAgent.exe ()
SRV:64bit: - (Intel® – C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel® Corporation)
SRV:64bit: - (cFosSpeedS) – C:\Program Files\ASRock\XFast LAN\spd.exe (cFos Software GmbH)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (vToolbarUpdater14.1.7) – C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.1.7\ToolbarUpdater.exe ()
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (Futuremark SystemInfo Service) – C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe (Futuremark Corporation)
SRV - (AVGIDSAgent) – C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (NETGEARGenieDaemon) – C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenieDaemon64.exe (NETGEAR)
SRV - (XTU3SERVICE) – C:\Program Files (x86)\Intel\Extreme Tuning Utility\XtuService.exe (Intel® Corporation)
SRV - (UNS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe ()
SRV - (jhi_service) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe (Intel Corporation)
SRV - (ICCS) – C:\Program Files (x86)\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe (Intel Corporation)
SRV - (IAStorDataMgrSvc) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (RoxMediaDBGame1X) – C:\Program Files (x86)\Common Files\Roxio Shared\Game1X\SharedCOM\RoxMediaDBGame1X.exe (Sonic Solutions)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (cphs) – C:\Windows\SysWOW64\IntelCpHeciSvc.exe (Intel Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (SWDUMon) – C:\Windows\SysNative\drivers\SWDUMon.sys ()
DRV:64bit: - (WPRO_41_2001) – C:\Windows\SysNative\drivers\WPRO_41_2001.sys ()
DRV:64bit: - (avgtp) – C:\Windows\SysNative\drivers\avgtpx64.sys (AVG Technologies)
DRV:64bit: - (gfibto) – C:\Windows\SysNative\drivers\gfibto.sys (GFI Software)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (gfiark) – C:\Windows\SysNative\drivers\gfiark.sys (GFI Software)
DRV:64bit: - (Avgmfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (NPF) – C:\Windows\SysNative\drivers\npf.sys (CACE Technologies, Inc.)
DRV:64bit: - (AVGIDSDriver) – C:\Windows\SysNative\drivers\avgidsdrivera.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSHA) – C:\Windows\SysNative\drivers\avgidsha.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (Avgldx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgtdia) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgloga) – C:\Windows\SysNative\drivers\avgloga.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgrkx64) – C:\Windows\SysNative\drivers\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (MEIx64) – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (ICCWDT) – C:\Windows\SysNative\drivers\ICCWDT.sys (Intel Corporation)
DRV:64bit: - (TurboB) – C:\Windows\SysNative\drivers\TurboB.sys (Intel® Corporation)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (ISCT) – C:\Windows\SysNative\drivers\ISCTD64.sys ()
DRV:64bit: - (imsevent) – C:\Windows\SysNative\drivers\imsevent.sys ()
DRV:64bit: - (ikbevent) – C:\Windows\SysNative\drivers\ikbevent.sys ()
DRV:64bit: - (iusb3xhc) – C:\Windows\SysNative\drivers\iusb3xhc.sys (Intel Corporation)
DRV:64bit: - (iusb3hub) – C:\Windows\SysNative\drivers\iusb3hub.sys (Intel Corporation)
DRV:64bit: - (iusb3hcs) – C:\Windows\SysNative\drivers\iusb3hcs.sys (Intel Corporation)
DRV:64bit: - (AsrRamDisk) – C:\Windows\SysNative\drivers\AsrRamDisk.sys (ASRock Inc.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (asahci64) – C:\Windows\SysNative\drivers\asahci64.sys (Asmedia Technology)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (cFosSpeed) – C:\Windows\SysNative\drivers\cfosspeed6.sys (cFos Software GmbH)
DRV:64bit: - (ASEUSBCC) – C:\Windows\SysNative\drivers\AseUSBCC.sys (Silicon Laboratories)
DRV:64bit: - (AsrAppCharger) – C:\Windows\SysNative\drivers\AsrAppCharger.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (Thermnaltake MS1 Filter) – C:\Windows\SysNative\drivers\MS1Filter.sys (Thermaltake)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (BVRPMPR5a64) – C:\Windows\SysNative\drivers\BVRPMPR5a64.SYS (Avanquest Software)
DRV:64bit: - (Revoflt) – C:\Windows\SysNative\drivers\revoflt.sys (VS Revo Group)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) – C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (WDC_SAM) – C:\Windows\SysNative\drivers\wdcsam64.sys (Western Digital Technologies)
DRV:64bit: - (IntcDAud) – C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (MBfilt) – C:\Windows\SysNative\drivers\MBfilt64.sys (Creative Technology Ltd.)
DRV - (RTCore64) – C:\Program Files (x86)\MSI Afterburner\RTCore64.sys ()
DRV - (iocbios2) – C:\Program Files (x86)\Intel\Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys (Intel Corporation)
DRV - (cpudrv64) – C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys ()
DRV - (Thermnaltake MS1 Filter) – C:\Windows\SysWOW64\drivers\MS1Filter.sys (Thermaltake)
DRV - (NTIOLib_1_0_4) – C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys (MSI)
DRV - (MSI_MSIBIOS_010507) – C:\Program Files (x86)\MSI\Live Update 5\msibios64_100507.sys (Your Corporation)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\..\SearchScopes,DefaultScope = {3F7BEE20-2911-4a67-9F67-EA9B652915AB}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://au.search.yahoo.com/search?p={searc…m&type=ASRK
IE - HKCU\..\SearchScopes\{3F7BEE20-2911-4a67-9F67-EA9B652915AB}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\..\SearchScopes\{8AD2049C-4EAA-43D8-8CE2-35AE14F796C3}: "URL" = http://websearch.ask.com/redirect?client=i…54-ADD5C8A467D3
IE - HKCU\..\SearchScopes\{C7EADF9A-79F4-4CE9-8835-FEA129ADAA22}: "URL" = http://au.search.yahoo.com/search?fr=chr-g…p={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_149.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_149.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.140.0: C:\Program Files (x86)\Battlelog Web Plugins\1.140.0\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=2.1.2: C:\Program Files (x86)\Battlelog Web Plugins\2.1.2\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.13.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.13.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@TrendMicro.com/FFExtension: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)



========== Chrome ==========

CHR - homepage:
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter},
CHR - homepage:
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\pdf.dll
CHR - plugin: Norton Confidential (Enabled) = C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.1.0.30_0\npcoplgn.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Intel\u00AE Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll
CHR - plugin: Intel\u00AE Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll
CHR - Extension: Turn Off the Lights = C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn\2.1.0.30_0\
CHR - Extension: Battlefield Heroes = C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehdakiococlfmjcbebbkjkfjhbieknh\5.0.199.0_0\
CHR - Extension: Adblock Plus = C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.3.4_0\
CHR - Extension: Better Battlelog (BBLog) = C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbnkmpcicaafjhmnhiblopefjfacnmem\3.3.0_0\
CHR - Extension: ImageBot Photo Editor = C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\gngdfkmfhlbimnaglgofeloikojnnaka\2.0.1_0\
CHR - Extension: Criminals In Action = C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\lodcgfknlnpepeiopmdkioopbnpghgme\1_0\
CHR - Extension: Need for Speed World = C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\mnnelgnkomjdakpkjpkfehdipjifjmbk\1.0.0.4_0\
CHR - Extension: Battlefield Play4Free = C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\oiokahphinmbmakkehgelkmpolmnbkdh\1.0.80.5_0\
CHR - Extension: Bitdefender QuickScan = C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdnkcidphdcakpkheohlhocaicfamjie\0.9.9.118_0\
CHR - Extension: Google Reader = C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjjhlfkghdhmijklfnahfkpgmhcmfgcm\4.4_0\

O1 HOSTS File: ([2013/02/17 14:15:27 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (SteadyVideoBHO Class) - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
O2 - BHO: (SteadyVideoBHO Class) - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" File not found
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [THXCfg64] C:\Windows\SysNative\THXCfg64.DLL (Creative Technology Ltd.)
O4:64bit: - HKLM..\Run: [XFast LAN] C:\Program Files\ASRock\XFast LAN\cfosspeed.exe (cFos Software GmbH)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files (x86)\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [googletalk] C:\Program Files (x86)\Google\Google Talk\googletalk.exe (Google)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [IMSS] C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PIconStartup.exe (Intel Corporation)
O4 - HKLM..\Run: [Live Update 5] C:\Program Files (x86)\MSI\Live Update 5\LU5.exe (Micro-Star International)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [THX TruStudio NB Settings] C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Tt eSPORTS BLACK Gaming Mouse] C:\Program Files (x86)\Thermaltake\Tt eSPORTS BLACK\Black.exe (Thermaltake)
O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
O4 - HKCU..\Run: [AviraSpeedup] C:\Program Files (x86)\Avira\AviraSpeedup\AviraSpeedup.exe (Avira)
O4 - HKCU..\Run: [F3B86A9EB072ABC2F0F62B1D515F7C32AAE587FE._service_run] C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
O4 - HKCU..\Run: [LCLC Control Panel] C:\Program Files (x86)\Antec CC\ChillControl V.exe (Antec Inc.)
O4 - HKCU..\Run: [NETGEARGenie] C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenie.exe ()
O4 - HKCU..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\sidebar.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe (PokerStars)
O13 - gopher Prefix: missing
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} http://ccfiles.creative.com/Web/softwareup…102/CTSUEng.cab (Creative Software AutoUpdate)
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwareup…13/CTPIDPDE.cab (Creative Software AutoUpdate Support Package 2)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareup…21022/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9039D649-4DA3-475A-849E-53C9DA5DF37D}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Filter\video/mp4 {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18:64bit: - Protocol\Filter\video/x-flv {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18 - Protocol\Filter\video/mp4 {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18 - Protocol\Filter\video/x-flv {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/02/19 14:46:24 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Talk
[2013/02/18 17:31:03 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Local\DayZCommander
[2013/02/18 17:23:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\Dotjosh Studios
[2013/02/17 16:36:38 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GamersFirst
[2013/02/17 16:36:36 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Local\GamersFirst
[2013/02/17 16:25:26 | 000,000,000 | —D | C] – C:\ProgramData\Package Cache
[2013/02/17 15:41:35 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Roaming\AVG
[2013/02/17 15:41:22 | 000,000,000 | —D | C] – C:\ProgramData\AVG
[2013/02/17 15:41:19 | 000,000,000 | -HSD | C] – C:\ProgramData\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F}
[2013/02/17 15:24:58 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Roaming\AVG2013
[2013/02/17 15:23:48 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Roaming\TuneUp Software
[2013/02/17 15:23:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013/02/17 15:23:30 | 000,000,000 | -H-D | C] – C:\$AVG
[2013/02/17 15:23:30 | 000,000,000 | —D | C] – C:\ProgramData\AVG2013
[2013/02/17 15:23:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVG
[2013/02/17 15:21:35 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Local\MFAData
[2013/02/17 15:21:35 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2013/02/17 15:21:35 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Local\Avg2013
[2013/02/17 14:16:59 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/02/17 14:11:51 | 000,000,000 | —D | C] – C:\Windows\temp
[2013/02/17 10:21:12 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Roaming\Malwarebytes
[2013/02/17 10:21:06 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/02/16 11:16:28 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Local\IsolatedStorage
[2013/02/14 13:57:48 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2013/02/14 13:57:48 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2013/02/14 13:57:48 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2013/02/14 13:57:44 | 000,000,000 | —D | C] – C:\Qoobox
[2013/02/14 13:57:34 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2013/02/14 13:54:18 | 005,032,798 | R— | C] (Swearware) – C:\Users\Scotty\Desktop\ComboFix.exe
[2013/02/13 12:03:05 | 000,000,000 | —D | C] – C:\ProgramData\Avira
[2013/02/13 11:42:07 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Local\AviraSpeedup
[2013/02/13 11:42:07 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviraSpeedup
[2013/02/13 11:42:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\Avira
[2013/02/13 10:25:30 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Local\adawarebp
[2013/02/12 18:36:18 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/02/12 18:35:49 | 000,000,000 | —D | C] – C:\JRT
[2013/02/12 11:25:52 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Local\Trend Micro
[2013/02/12 11:24:42 | 000,000,000 | —D | C] – C:\ProgramData\Trend Micro
[2013/02/11 19:48:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Symantec Shared
[2013/02/11 15:34:50 | 000,038,096 | —- | C] (GFI Software) – C:\Windows\SysNative\drivers\gfiark.sys
[2013/02/11 14:32:30 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Roaming\LavasoftStatistics
[2013/02/11 14:21:08 | 000,014,456 | —- | C] (GFI Software) – C:\Windows\SysNative\drivers\gfibto.sys
[2013/02/11 14:20:09 | 000,000,000 | —D | C] – C:\ProgramData\Ad-Aware Browsing Protection
[2013/02/11 14:20:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\Toolbar Cleaner
[2013/02/11 11:45:22 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2013/02/10 17:32:19 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Local\NPE
[2013/02/05 22:24:45 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CL-Eye Driver
[2013/02/05 22:24:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\Code Laboratories
[2013/02/05 15:22:29 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Roaming\Skype
[2013/02/05 15:22:09 | 000,000,000 | —D | C] – C:\ProgramData\Skype
[2013/02/01 01:27:52 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crysis 3 MP Open Beta
[2013/02/01 01:27:51 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\Common Files\EAInstaller
[2013/01/30 19:07:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
[2013/01/27 19:58:08 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Roaming\Apple Computer
[2013/01/26 12:16:54 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI Kombustor 2.5
[2013/01/26 12:16:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\MSI Kombustor 2.5
[2013/01/26 12:16:41 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Local\Programs
[2013/01/26 12:15:30 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner
[2013/01/26 10:29:58 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Roaming\iMobie
[2013/01/26 10:29:57 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Local\iMobie_Inc
[2013/01/25 10:40:29 | 000,026,432 | —- | C] (IObit) – C:\Windows\SysNative\RegistryDefragBootTime.exe
[2013/01/25 00:49:06 | 000,000,000 | —D | C] – C:\ProgramData\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}
[2013/01/25 00:49:05 | 000,000,000 | —D | C] – C:\ProgramData\IObit
[2013/01/25 00:49:04 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Roaming\IObit
[2013/01/25 00:49:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\IObit
[2013/01/21 17:42:47 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Local\Adobe
[2013/01/21 17:42:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\Adobe
[2013/01/21 14:56:12 | 000,000,000 | —D | C] – C:\Users\Scotty\AppData\Roaming\QuickScan
[2013/01/21 14:41:38 | 000,000,000 | —D | C] – C:\ProgramData\Futuremark
[2013/01/21 14:40:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2013/01/21 14:39:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\Futuremark
[2013/01/21 09:56:27 | 000,000,000 | —D | C] – C:\ProgramData\ATI
[2013/01/21 09:56:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\AMD AVT
[2013/01/21 09:56:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\AMD APP
[2013/01/21 09:56:03 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/02/20 02:27:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/02/20 02:00:00 | 000,006,067 | —- | M] () – C:\ProgramData\Network_Meter_Data.csv
[2013/02/20 01:50:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/02/19 18:08:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
[2013/02/19 16:27:00 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/02/19 14:48:01 | 000,002,279 | —- | M] () – C:\Users\Scotty\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/02/19 12:21:37 | 000,270,240 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.xtr
[2013/02/19 12:21:37 | 000,270,240 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.exe
[2013/02/19 11:30:11 | 000,025,008 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/02/19 11:30:11 | 000,025,008 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/02/19 11:23:22 | 000,000,412 | —- | M] () – C:\Windows\tasks\SlimDrivers Startup.job
[2013/02/19 11:23:12 | 000,005,614 | —- | M] () – C:\Windows\SysWow64\Utility.xml
[2013/02/19 11:23:11 | 000,015,712 | —- | M] () – C:\Windows\SysNative\drivers\SWDUMon.sys
[2013/02/19 11:22:22 | 000,000,828 | —- | M] () – C:\Windows\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
[2013/02/19 11:22:21 | 000,034,752 | —- | M] () – C:\Windows\SysNative\drivers\WPRO_41_2001.sys
[2013/02/19 11:22:18 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/02/19 11:22:17 | 4254,613,502 | -HS- | M] () – C:\hiberfil.sys
[2013/02/18 17:23:44 | 000,001,406 | —- | M] () – C:\Users\Scotty\Desktop\DayZ Commander.lnk
[2013/02/17 20:54:46 | 000,000,889 | —- | M] () – C:\Users\Scotty\AppData\Roaming\Network Meter_Settings.ini
[2013/02/17 20:54:44 | 000,000,578 | —- | M] () – C:\Users\Scotty\AppData\Roaming\All CPU MeterV3_Settings.ini
[2013/02/17 18:35:27 | 000,281,288 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.ex0
[2013/02/17 16:24:48 | 000,076,888 | —- | M] () – C:\Windows\SysWow64\PnkBstrA.exe
[2013/02/17 15:23:48 | 000,000,965 | —- | M] () – C:\Users\Public\Desktop\AVG 2013.lnk
[2013/02/17 14:15:27 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2013/02/16 22:04:22 | 000,000,222 | —- | M] () – C:\Users\Scotty\Desktop\APB Reloaded.url
[2013/02/14 13:55:07 | 005,032,798 | R— | M] (Swearware) – C:\Users\Scotty\Desktop\ComboFix.exe
[2013/02/13 14:24:47 | 000,335,646 | —- | M] () – C:\Users\Scotty\Desktop\AnalysisLog.sr0
[2013/02/13 11:42:07 | 000,001,163 | —- | M] () – C:\Users\Scotty\Desktop\Avira System Speedup.lnk
[2013/02/13 11:30:22 | 004,936,992 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/02/13 11:28:05 | 000,000,370 | RHS- | M] () – C:\ProgramData\ntuser.pol
[2013/02/13 10:31:35 | 000,731,650 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/02/13 10:31:35 | 000,615,810 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/02/13 10:31:35 | 000,106,190 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/02/12 18:24:13 | 000,000,121 | —- | M] () – C:\Windows\DeleteOnReboot.bat
[2013/02/12 18:15:39 | 000,000,559 | —- | M] () – C:\Users\Scotty\Desktop\MBR.zip
[2013/02/12 18:13:39 | 000,000,512 | —- | M] () – C:\Users\Scotty\Desktop\MBR.dat
[2013/02/12 13:21:48 | 000,234,544 | —- | M] () – C:\Windows\RegBootClean64.exe
[2013/02/12 11:24:03 | 000,000,036 | —- | M] () – C:\Users\Scotty\AppData\Local\housecall.guid.cache
[2013/02/11 17:33:43 | 000,039,768 | —- | M] (AVG Technologies) – C:\Windows\SysNative\drivers\avgtpx64.sys
[2013/02/11 14:21:08 | 000,014,456 | —- | M] (GFI Software) – C:\Windows\SysNative\drivers\gfibto.sys
[2013/02/11 12:18:44 | 000,000,095 | —- | M] () – C:\Users\Scotty\Documents\PCMeterV0.3.config
[2013/02/05 22:24:44 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_Kernel_WinUSB_01009.Wdf
[2013/02/02 13:54:02 | 000,000,222 | —- | M] () – C:\Users\Scotty\Desktop\Painkiller Hell & Damnation.url
[2013/02/02 11:24:00 | 000,002,656 | —- | M] () – C:\{9D7B1E24-71C4-4B4A-8704-6C23A9447E0D}
[2013/02/01 01:27:52 | 000,001,428 | —- | M] () – C:\Users\Public\Desktop\Crysis 3 MP Open Beta.lnk
[2013/01/31 19:14:20 | 000,007,596 | —- | M] () – C:\Users\Scotty\AppData\Local\Resmon.ResmonCfg
[2013/01/31 11:00:53 | 000,000,292 | —- | M] () – C:\Users\Scotty\AppData\Roaming\GPU MeterV2_Settings.ini
[2013/01/30 19:07:40 | 000,000,869 | —- | M] () – C:\Users\Public\Desktop\CPUID CPU-Z.lnk
[2013/01/28 12:18:22 | 000,000,222 | —- | M] () – C:\Users\Scotty\Desktop\Sleeping Dogs.url
[2013/01/28 09:00:41 | 000,002,384 | —- | M] () – C:\{4136D721-BA39-406F-813D-3FFDBF5A947B}
[2013/01/26 12:16:54 | 000,001,092 | —- | M] () – C:\Users\Scotty\Desktop\MSI Kombustor 2.5.lnk
[2013/01/26 12:15:34 | 000,001,086 | —- | M] () – C:\Users\Scotty\Desktop\MSI Afterburner.lnk
[2013/01/24 00:31:38 | 000,002,456 | —- | M] () – C:\{0C9C7502-7347-4854-9CC1-0130B71328CC}
[2013/01/21 14:37:08 | 000,000,222 | —- | M] () – C:\Users\Scotty\Desktop\3DMark Vantage Demo.url
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/02/19 14:48:01 | 000,002,279 | —- | C] () – C:\Users\Scotty\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/02/18 17:23:44 | 000,001,406 | —- | C] () – C:\Users\Scotty\Desktop\DayZ Commander.lnk
[2013/02/17 15:23:48 | 000,000,965 | —- | C] () – C:\Users\Public\Desktop\AVG 2013.lnk
[2013/02/16 22:04:22 | 000,000,222 | —- | C] () – C:\Users\Scotty\Desktop\APB Reloaded.url
[2013/02/14 13:57:48 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/02/14 13:57:48 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/02/14 13:57:48 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/02/14 13:57:48 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/02/14 13:57:48 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2013/02/13 14:24:40 | 000,335,646 | —- | C] () – C:\Users\Scotty\Desktop\AnalysisLog.sr0
[2013/02/13 11:42:07 | 000,001,163 | —- | C] () – C:\Users\Scotty\Desktop\Avira System Speedup.lnk
[2013/02/12 18:24:08 | 000,000,121 | —- | C] () – C:\Windows\DeleteOnReboot.bat
[2013/02/12 18:15:39 | 000,000,559 | —- | C] () – C:\Users\Scotty\Desktop\MBR.zip
[2013/02/12 18:13:39 | 000,000,512 | —- | C] () – C:\Users\Scotty\Desktop\MBR.dat
[2013/02/12 11:43:59 | 000,234,544 | —- | C] () – C:\Windows\RegBootClean64.exe
[2013/02/12 11:24:53 | 000,000,370 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2013/02/12 11:24:03 | 000,000,036 | —- | C] () – C:\Users\Scotty\AppData\Local\housecall.guid.cache
[2013/02/05 22:24:44 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_Kernel_WinUSB_01009.Wdf
[2013/02/05 12:00:00 | 000,006,067 | —- | C] () – C:\ProgramData\Network_Meter_Data.csv
[2013/02/02 13:54:02 | 000,000,222 | —- | C] () – C:\Users\Scotty\Desktop\Painkiller Hell & Damnation.url
[2013/02/02 11:24:00 | 000,002,656 | —- | C] () – C:\{9D7B1E24-71C4-4B4A-8704-6C23A9447E0D}
[2013/02/01 01:27:52 | 000,001,428 | —- | C] () – C:\Users\Public\Desktop\Crysis 3 MP Open Beta.lnk
[2013/01/30 19:07:40 | 000,000,869 | —- | C] () – C:\Users\Public\Desktop\CPUID CPU-Z.lnk
[2013/01/28 12:18:22 | 000,000,222 | —- | C] () – C:\Users\Scotty\Desktop\Sleeping Dogs.url
[2013/01/28 09:00:40 | 000,002,384 | —- | C] () – C:\{4136D721-BA39-406F-813D-3FFDBF5A947B}
[2013/01/26 12:16:54 | 000,001,092 | —- | C] () – C:\Users\Scotty\Desktop\MSI Kombustor 2.5.lnk
[2013/01/26 12:15:34 | 000,001,086 | —- | C] () – C:\Users\Scotty\Desktop\MSI Afterburner.lnk
[2013/01/24 00:31:38 | 000,002,456 | —- | C] () – C:\{0C9C7502-7347-4854-9CC1-0130B71328CC}
[2013/01/21 17:42:06 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
[2013/01/21 14:37:08 | 000,000,222 | —- | C] () – C:\Users\Scotty\Desktop\3DMark Vantage Demo.url
[2013/01/19 09:19:09 | 007,261,256 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall.exe
[2013/01/19 09:19:09 | 000,018,041 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp Music Converter.dat
[2013/01/07 17:34:21 | 000,000,292 | —- | C] () – C:\Users\Scotty\AppData\Roaming\GPU MeterV2_Settings.ini
[2012/12/10 09:30:57 | 000,000,706 | RHS- | C] () – C:\Users\Scotty\ntuser.pol
[2012/10/20 22:36:21 | 000,000,248 | —- | C] () – C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2012/10/17 09:59:52 | 000,270,240 | —- | C] () – C:\Windows\SysWow64\PnkBstrB.exe
[2012/10/17 09:59:43 | 000,076,888 | —- | C] () – C:\Windows\SysWow64\PnkBstrA.exe
[2012/10/16 18:22:30 | 000,000,889 | —- | C] () – C:\Users\Scotty\AppData\Roaming\Network Meter_Settings.ini
[2012/10/16 16:17:47 | 000,000,578 | —- | C] () – C:\Users\Scotty\AppData\Roaming\All CPU MeterV3_Settings.ini
[2012/10/13 23:12:21 | 000,007,596 | —- | C] () – C:\Users\Scotty\AppData\Local\Resmon.ResmonCfg
[2012/10/10 14:18:40 | 000,001,424 | —- | C] () – C:\Windows\THXCfg_SP_APOIM.ini
[2012/10/10 14:18:40 | 000,001,323 | —- | C] () – C:\Windows\THXCfg_HP_APOIM.ini
[2012/10/10 14:18:40 | 000,001,323 | —- | C] () – C:\Windows\THXCfg_APOIM.ini
[2012/10/10 14:18:38 | 000,190,464 | —- | C] () – C:\Windows\SysWow64\APOMngr.DLL
[2012/10/10 14:18:38 | 000,073,728 | —- | C] () – C:\Windows\SysWow64\CmdRtr.DLL
[2012/10/10 14:15:58 | 000,000,003 | —- | C] () – C:\Users\Scotty\AppData\Local\user_data.ini
[2012/10/10 02:22:34 | 000,064,512 | —- | C] () – C:\Windows\SysWow64\igdde32.dll
[2012/10/10 02:22:32 | 000,598,780 | —- | C] () – C:\Windows\SysWow64\igvpkrng700.bin
[2012/10/10 02:22:16 | 000,755,048 | —- | C] () – C:\Windows\SysWow64\igcodeckrng700.bin
[2012/09/29 05:45:06 | 000,247,296 | —- | C] () – C:\Windows\SysWow64\rtvcvfw32.dll
[2012/05/11 00:37:24 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2012/05/11 00:34:44 | 000,204,952 | —- | C] () – C:\Windows\SysWow64\ativvsvl.dat
[2012/05/11 00:34:44 | 000,157,144 | —- | C] () – C:\Windows\SysWow64\ativvsva.dat
[2012/05/11 00:34:44 | 000,003,917 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2012/05/02 13:58:10 | 000,029,184 | —- | C] () – C:\Windows\SysWow64\kdbsdk32.dll
[2012/03/19 23:37:12 | 000,755,188 | —- | C] () – C:\Windows\SysWow64\igkrng700.bin
[2012/03/19 23:37:12 | 000,561,508 | —- | C] () – C:\Windows\SysWow64\igfcg700m.bin
[2012/02/02 22:08:26 | 000,001,536 | —- | C] () – C:\Windows\SysWow64\IusEventLog.dll

========== ZeroAccess Check ==========

[2009/07/14 14:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/09 15:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/09 14:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/14 11:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 22:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/14 11:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013/01/18 23:56:34 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\Auslogics
[2013/02/17 15:41:35 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\AVG
[2013/02/17 15:24:58 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\AVG2013
[2013/02/17 14:14:19 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\Azureus
[2012/10/10 14:57:52 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\DeviceVm
[2013/01/26 10:29:58 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\iMobie
[2013/02/10 14:03:36 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\IObit
[2012/12/03 10:49:24 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\MAGIX
[2012/11/11 09:52:12 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\Need for Speed World
[2013/01/01 21:55:17 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\Origin
[2012/11/10 22:33:46 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\PDAppFlex
[2013/02/11 13:46:49 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\QuickScan
[2012/12/19 00:40:34 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2012/10/17 22:41:26 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\SystemRequirementsLab
[2013/02/17 15:23:48 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\TuneUp Software
[2012/10/13 23:07:09 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\Uniblue
[2013/01/05 12:40:41 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\Vuze Turbo Booster
[2012/10/21 14:37:40 | 000,000,000 | —D | M] – C:\Users\Scotty\AppData\Roaming\wargaming.net

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:07BF512B
@Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:D1B5B4F1

< End of report >
it is abit sluggish to start but i think that i have alot of start ups running that causes it avira speedup says it takes 135sec usually to start up to windows my cpu is 3570k 3.4ghz turbo 3.8ghz

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI