This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Another Win32/Small.CA Virus Problem

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, After a lot searching I've been unable to find a solution I can implement. A couple of days ago my internet became extremely slow and I assumed it was related to my newly installed wireless PCIe adapter. However, today Windows asked me to remove Win32/Small.CA virus. I have run scans with both McAfee Virus Scan and Malwarebytes but they found nothing. I then went to do a System Restore only to be told system protection has been turned off putting to bed my theories of a false positive. That led to my internet trawl and whilst the consensus is that some system files need deleting, no one seems to have exactly the same list and they include some I couldn't find. In the end every search seems to end up here, which is the only good thing to come out of it so far. Any help would be much appreciated. Regards, Rodney. —————————————————– My DDS log… . DDS (Ver_11-03-05.01) - NTFS_AMD64 Run by [removed] at 23:14:02.24 on 18/02/2013 Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 10.13.2 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.8136.5296 [GMT 0:00] . AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {ADA629C7-7F48-5689-624A-3B76997E0892} SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {16C7C823-5972-5907-58FA-0004E2F9422F} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: McAfee Firewall *Enabled* {959DA8E2-3527-57D1-4915-924367AD4FE9} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe C:\Windows\system32\nvvsvc.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Intel\WiFi\bin\EvtEng.exe C:\Program Files\Intel\iCLS Client\HeciServer.exe C:\Windows\system32\IProsetMonitor.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe C:\Windows\runservice.exe C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe C:\Windows\system32\mfevtps.exe C:\Program Files (x86)\PDF Architect\HelperService.exe C:\Windows\system32\rundll32.exe C:\Windows\system32\rundll32.exe C:\Windows\SysWOW64\rundll32.exe C:\Program Files (x86)\PDF Architect\ConversionService.exe C:\Program Files\Macrium\Reflect\ReflectService.exe C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe C:\Program Files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\WLANExt.exe C:\Windows\system32\conhost.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files\Core Temp\Core Temp.exe C:\Program Files\pia_manager\pia_manager.exe C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe C:\Windows\System32\rundll32.exe C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\system\CMGxMon.exe C:\Program Files (x86)\Thunder Master\THPanel.exe C:\Program Files (x86)\Internet Download Manager\IDMan.exe C:\Users\Rod\AppData\Local\Akamai\netsession_win.exe C:\Users\Rod\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe C:\Program Files (x86)\Thermaltake\Fan Control Software\Fan Control Software.exe C:\Users\Rod\AppData\Local\Akamai\netsession_win.exe C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe C:\Program Files\NVIDIA Corporation\Display\nvtray.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe C:\Program Files\McAfee.com\Agent\mcagent.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\iPod\bin\iPodService.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe F:\Program Files (x86) SSD\AutoRip\Extender Rip Monitor.exe C:\Program Files (x86)\NETGEAR\WNDA3100v2\WNDA3100v2.exe C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe C:\Users\Rod\AppData\Local\Temp\ocr71F4.tmp\bin\rubyw.exe C:\Program Files\pia_manager\pia_manager.exe C:\Users\Rod\AppData\Local\Temp\ocrA092.tmp\bin\rubyw.exe C:\Program Files\pia_manager\pia_tray\pia_tray.exe F:\Program Files (x86) SSD\steam.exe C:\Program Files (x86)\Common Files\Steam\SteamService.exe C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe C:\PROGRA~1\McAfee\MSC\McAPExe.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe C:\Windows\system32\svchost.exe -k SDRSVC C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe c:\PROGRA~2\mcafee\SITEAD~1\saui.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Rod\Desktop\dds.scr C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uSearch Page = uStart Page = hxxp://www.bigseekpro.com/dvdshrink2/{ACBE0245-95A0-45DD-9BD3-2616F2AF5660} uSearch Bar = mStart Page = hxxp://www.bigseekpro.com/dvdshrink2/{ACBE0245-95A0-45DD-9BD3-2616F2AF5660} uInternet Settings,ProxyOverride = *.local; mWinlogon: Userinit=userinit.exe, BHO: IDM integration (IDMIEHlprObj Class): {0055c089-8582-441b-a0bf-17b458c2a3a8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: PDF Architect Helper: {3a2d5eba-f86d-4bd3-a177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll TB: PDF Architect Toolbar: {25a3a431-30bb-47c8-ad6a-e1063801134f} - C:\Program Files (x86)\PDF Architect\PDFIEPlugin.dll TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File uRun: [THPanel] "C:\Program Files (x86)\Thunder Master\THPanel.exe" /A uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun uRun: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot uRun: [AdobeBridge] uRun: [Akamai NetSession Interface] "C:\Users\Rod\AppData\Local\Akamai\netsession_win.exe" uRun: [Spotify Web Helper] "C:\Users\Rod\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" uRun: [LCLC Control Panel] C:\Program Files (x86)\Thermaltake\Fan Control Software\Fan Control Software.exe uRun: [Steam] "F:\Program Files (x86) SSD\steam.exe" -silent uRun: [uTorrent] "C:\Program Files (x86)\uTorrent.exe" /MINIMIZED mRun: [THX Audio Control Panel] "C:\Program Files (x86)\Creative\Sound Blaster X-Fi MB 2\THXAudioCP\THXAudio.exe" /r mRun: [UpdReg] C:\Windows\UpdReg.EXE mRun: [USB3MON] "C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" 60 mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe mRun: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin mRun: [mcpltui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\AUTORI~1.LNK - F:\Program Files (x86) SSD\AutoRip\Extender Rip Monitor.exe StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\NETGEA~1.LNK - C:\Program Files (x86)\NETGEAR\WNDA3100v2\WNDA3100v2.exe mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: PromptOnSecureDesktop = 0 (0x0) IE: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm IE: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000 IE: Free YouTube to MP3 Converter - C:\Users\Rod\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105 IE: Send to Bluetooth - C:\Program Files (x86)\Intel\Bluetooth\btSendToObject.htm IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\McAfee\MSC\McSnIePl.dll Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\McAfee\SITEAD~1\McIEPlg.dll Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\McAfee\SITEAD~1\McIEPlg.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\Installer\chrmstp.exe" –configure-user-settings –verbose-logging –system-level –multi-install –chrome BHO-X64: IDM integration (IDMIEHlprObj Class): {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll BHO-X64: IDM Helper - No File BHO-X64: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll BHO-X64: McAfee SiteAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL BHO-X64: URLRedirectionBHO - No File BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll TB-X64: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll TB-X64: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File mRun-x64: [BLEServicesCtrl] C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe mRun-x64: [BTMTrayAgent] rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp mRun-x64: [IntelPAN] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PAN Tray mRun-x64: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s mRun-x64: [THXCfg64] C:\Windows\system32\RunDLL32.exe C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64 mRun-x64: [RunDLLEntry] C:\Windows\system32\RunDLL32.exe C:\Windows\system32\AmbRunE.dll,RunDLLEntry mRun-x64: [Cmaudio8788] C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cmicnfgp.cpl,CMICtrlWnd mRun-x64: [Cmaudio8788GX] C:\Windows\system\CmGxMon.exe Envoke mRun-x64: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" IE-X64: {2F56DCAA-153B-4479-B4E2-547405B34FB9} - C:\Program Files (x86)\Intel\Bluetooth\btSendToPage.htm . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\Rod\AppData\Roaming\Mozilla\Firefox\Profiles\863j7af2.default\ FF - plugin: c:\progra~2\mcafee\msc\npMcSnFFPl.dll FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll FF - plugin: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll FF - plugin: C:\Program Files (x86)\McAfee\SiteAdvisor\NPMcFFPlg32.dll FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll FF - plugin: C:\Windows\SysWOW64\npmproxy.dll . ============= SERVICES / DRIVERS =============== . R0 asahci64;asahci64;C:\Windows\System32\drivers\asahci64.sys [2012-1-6 49760] R0 iusb3hcs;Intel® USB 3.0 Host Controller Switch Driver;C:\Windows\System32\drivers\iusb3hcs.sys [2012-3-11 16152] R0 mfehidk;McAfee Inc. mfehidk;C:\Windows\System32\drivers\mfehidk.sys [2012-7-17 771096] R0 mfewfpk;McAfee Inc. mfewfpk;C:\Windows\System32\drivers\mfewfpk.sys [2012-7-17 339776] R0 SCMNdisP;General NDIS Protocol Driver;C:\Windows\System32\drivers\SCMNdisP.sys [2012-11-3 25312] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-14 59904] R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-12-18 65192] R2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-12-12 661504] R2 Bluetooth Device Monitor;Bluetooth Device Monitor;C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [2012-6-18 1095616] R2 Bluetooth Media Service;Bluetooth Media Service;C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe [2012-6-18 1333184] R2 Bluetooth OBEX Service;Bluetooth OBEX Service;C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [2012-6-18 1124288] R2 BTHSSecurityMgr;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Security Service;C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2012-1-13 135952] R2 HomeNetSvc;McAfee Home Network;"C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [2012-12-15 220856] R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-3-11 13592] R2 IDMWFP;IDMWFP;C:\Windows\System32\drivers\idmwfp.sys [2013-1-29 165112] R2 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-2-2 628448] R2 Intel® PROSet Monitoring Service;Intel® PROSet Monitoring Service;C:\Windows\System32\IPROSetMonitor.exe [2012-3-11 178344] R2 jhi_service;Intel® Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe [2012-3-11 161560] R2 LicCtrlService;LicCtrl Service;C:\Windows\Runservice.exe [2012-12-20 2560] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;"C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [2012-11-3 201304] R2 McMPFSvc;McAfee Personal Firewall Service;"C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [2012-12-15 220856] R2 McNaiAnn;McAfee VirusScan Announcer;"C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [2012-12-15 220856] R2 mcpltsvc;McAfee Platform Services;"C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [2012-12-15 220856] R2 McProxy;McAfee Proxy Service;"C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [2012-12-15 220856] R2 mfecore;McAfee Anti-Malware Core;C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [2012-12-15 1007288] R2 mfefire;McAfee Firewall Core Service;C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe [2012-11-3 218320] R2 mfevtp;McAfee Validation Trust Protection Service;C:\Windows\System32\mfevtps.exe [2012-11-3 177680] R2 PDF Architect Helper Service;PDF Architect Helper Service;C:\Program Files (x86)\PDF Architect\HelperService.exe [2012-11-22 1522312] R2 PDF Architect Service;PDF Architect Service;C:\Program Files (x86)\PDF Architect\ConversionService.exe [2012-11-22 905864] R2 ReflectService.exe;Macrium Reflect Image Mounting Service;C:\Program Files\Macrium\Reflect\ReflectService.exe [2013-1-31 302200] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-12-29 383416] R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2012-3-11 363800] R2 WSWNDA3100;WSWNDA3100;C:\Program Files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe [2012-11-3 272864] R3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Virtual Adapter;C:\Windows\System32\drivers\AmpPal.sys [2011-12-12 195072] R3 ASEUSBCC;ASEUSBCC;C:\Windows\System32\drivers\AseUSBCC.sys [2011-12-13 16384] R3 asmthub3;ASMedia USB3 Hub Service;C:\Windows\System32\drivers\asmthub3.sys [2011-11-3 130536] R3 asmtxhci;ASMEDIA XHCI Service;C:\Windows\System32\drivers\asmtxhci.sys [2011-11-3 395752] R3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;C:\Windows\System32\drivers\bcmwlhigh664.sys [2012-11-3 1244224] R3 cfwids;McAfee Inc. cfwids;C:\Windows\System32\drivers\cfwids.sys [2012-11-3 69672] R3 e1cexpress;Intel® PRO/1000 PCI Express Network Connection Driver C;C:\Windows\System32\drivers\e1c62x64.sys [2012-3-11 342704] R3 iusb3hub;Intel® USB 3.0 Hub Driver;C:\Windows\System32\drivers\iusb3hub.sys [2012-3-11 355096] R3 iusb3xhc;Intel® USB 3.0 eXtensible Host Controller Driver;C:\Windows\System32\drivers\iusb3xhc.sys [2012-3-11 786200] R3 MEIx64;Intel® Management Engine Interface ;C:\Windows\System32\drivers\HECIx64.sys [2012-3-11 60184] R3 mfeavfk;McAfee Inc. mfeavfk;C:\Windows\System32\drivers\mfeavfk.sys [2012-11-3 309400] R3 mfefirek;McAfee Inc. mfefirek;C:\Windows\System32\drivers\mfefirek.sys [2012-11-3 515528] R3 mfencbdc;McAfee Inc. mfencbdc;C:\Windows\System32\drivers\mfencbdc.sys [2012-11-2 328976] R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\System32\drivers\nvhda64v.sys [2012-12-4 189288] R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\System32\drivers\vwifimp.sys [2009-7-14 17920] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-3-11 136176] S2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-3-11 1260472] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-3 251248] S3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protocol;C:\Windows\System32\drivers\AmpPal.sys [2011-12-12 195072] S3 btmaux;Intel Bluetooth Auxiliary Service;C:\Windows\System32\drivers\btmaux.sys [2012-5-21 111104] S3 btmhsf;btmhsf;C:\Windows\System32\drivers\btmhsf.sys [2012-6-9 849408] S3 cmudaxp;ASUS Xonar DX Audio Interface;C:\Windows\System32\drivers\cmudaxp.sys [2012-11-10 1197568] S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2012-3-11 79360] S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2012-3-11 79360] S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-3-11 136176] S3 HipShieldK;McAfee Inc. HipShieldK;C:\Windows\System32\drivers\HipShieldK.sys [2012-12-15 197264] S3 ibtfltcoex;ibtfltcoex;C:\Windows\System32\drivers\iBtFltCoex.sys [2012-7-9 60928] S3 mfencrk;McAfee Inc. mfencrk;C:\Windows\System32\drivers\mfencrk.sys [2012-11-2 97208] S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-11-3 115168] S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2012-1-4 340240] S3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\System32\drivers\NETwNs64.sys [2012-3-5 8616448] S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184] S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096] S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-21 59392] S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-21 31232] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-11-3 1255736] . =============== Created Last 30 ================ . 2013-02-18 20:05:28 ——– d—–w- C:\Users\Rod\AppData\Roaming\Malwarebytes 2013-02-18 20:04:58 ——– d—–w- C:\PROGRA~3\Malwarebytes 2013-02-18 20:04:44 24176 —-a-w- C:\Windows\System32\drivers\mbam.sys 2013-02-18 20:04:44 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-02-17 21:25:05 2736640 —-a-w- C:\Windows\System32\drivers\athrx.sys 2013-02-17 21:25:05 2736640 —-a-w- C:\Windows\System32\athrx.sys 2013-02-17 21:25:05 ——– d—–w- C:\Windows\Options 2013-02-17 21:24:51 ——– d—–w- C:\PROGRA~3\TP-LINK 2013-02-15 20:37:54 969104 —-a-w- C:\Program Files (x86)\uTorrent.exe 2013-02-15 20:26:22 ——– d—–w- C:\Users\Rod\AppData\Local\Shareaza 2013-02-15 20:26:17 ——– d—–w- C:\Users\Rod\AppData\Roaming\Shareaza 2013-02-14 08:19:07 ——– d—–w- C:\PROGRA~3\IDM 2013-02-10 00:43:25 ——– d—–w- C:\Users\Rod\AppData\Local\Sidhe 2013-02-09 18:06:00 ——– d—–w- C:\Program Files (x86)\Thermaltake 2013-02-09 16:22:47 ——– d—–w- C:\PROGRA~3\Macrium 2013-02-09 16:22:32 ——– d—–w- C:\Program Files\Macrium 2013-02-09 16:22:32 ——– d—–w- C:\boot 2013-02-08 20:31:12 95648 —-a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll 2013-01-31 13:42:38 13944 —-a-w- C:\Windows\System32\drivers\PSVolAcc.sys 2013-01-31 13:42:16 57976 —-a-w- C:\Windows\System32\drivers\psmounterex.sys 2013-01-30 23:36:08 ——– d—–w- C:\Users\Rod\AppData\Roaming\JAM Software 2013-01-30 23:18:13 ——– d—–w- C:\Program Files\Core Temp 2013-01-30 23:18:07 ——– d—–w- C:\PROGRA~3\Tarma Installer 2013-01-29 12:03:10 165112 —-a-w- C:\Windows\System32\drivers\idmwfp.sys 2013-01-21 21:57:26 ——– d—–w- C:\PROGRA~3\APN 2013-01-20 16:24:55 ——– d—–w- C:\Users\Rod\AppData\Roaming\Titanium 2013-01-20 16:24:20 31232 —-a-w- C:\Windows\System32\drivers\tap0901.sys 2013-01-20 16:24:14 ——– d—–w- C:\Program Files\pia_manager . ==================== Find3M ==================== . 2013-02-18 22:45:02 1729 –sha-w- C:\Windows\SysWow64\mmf.sys 2013-02-09 19:56:34 74096 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2013-02-09 19:56:34 697712 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2013-02-08 20:31:09 861088 —-a-w- C:\Windows\SysWow64\npDeployJava1.dll 2013-02-08 20:31:09 782240 —-a-w- C:\Windows\SysWow64\deployJava1.dll 2013-01-05 05:53:43 5553512 —-a-w- C:\Windows\System32\ntoskrnl.exe 2013-01-05 05:00:15 3967848 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe 2013-01-05 05:00:11 3913064 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe 2013-01-04 05:46:09 215040 —-a-w- C:\Windows\System32\winsrv.dll 2013-01-04 04:51:16 5120 —-a-w- C:\Windows\SysWow64\wow32.dll 2013-01-04 04:43:21 44032 —-a-w- C:\Windows\apppatch\acwow64.dll 2013-01-04 03:26:48 3153408 —-a-w- C:\Windows\System32\win32k.sys 2013-01-04 02:47:35 25600 —-a-w- C:\Windows\SysWow64\setup16.exe 2013-01-04 02:47:34 7680 —-a-w- C:\Windows\SysWow64\instnm.exe 2013-01-04 02:47:34 2048 —-a-w- C:\Windows\SysWow64\user.exe 2013-01-04 02:47:33 14336 —-a-w- C:\Windows\SysWow64\ntvdm64.dll 2013-01-03 06:00:54 1913192 —-a-w- C:\Windows\System32\drivers\tcpip.sys 2013-01-03 06:00:42 288088 —-a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS 2012-12-29 08:40:27 6382008 —-a-w- C:\Windows\System32\nvcpl.dll 2012-12-29 08:40:27 3455416 —-a-w- C:\Windows\System32\nvsvc64.dll 2012-12-29 08:40:11 2923201 —-a-w- C:\Windows\System32\nvcoproc.bin 2012-12-29 08:40:09 884152 —-a-w- C:\Windows\System32\nvvsvc.exe 2012-12-29 08:40:09 63928 —-a-w- C:\Windows\System32\nvshext.dll 2012-12-29 08:40:09 118712 —-a-w- C:\Windows\System32\nvmctray.dll 2012-12-29 02:54:24 550328 —-a-w- C:\Windows\SysWow64\nvStreaming.exe 2012-12-20 13:59:36 1188864 —-a-w- C:\Windows\System32\wininet.dll 2012-12-20 12:53:51 981504 —-a-w- C:\Windows\SysWow64\wininet.dll 2012-12-20 12:02:26 1638912 —-a-w- C:\Windows\System32\mshtml.tlb 2012-12-20 11:20:29 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2012-12-20 01:52:10 126976 —-a-w- C:\Windows\lcmmfu.cpl 2012-12-20 01:52:09 48640 —-a-w- C:\Windows\mmfs.dll 2012-12-20 01:52:09 2560 —-a-w- C:\Windows\Runservice.exe 2012-12-16 17:11:22 46080 —-a-w- C:\Windows\System32\atmlib.dll 2012-12-16 14:45:03 367616 —-a-w- C:\Windows\System32\atmfd.dll 2012-12-16 14:13:28 295424 —-a-w- C:\Windows\SysWow64\atmfd.dll 2012-12-16 14:13:20 34304 —-a-w- C:\Windows\SysWow64\atmlib.dll 2012-12-07 13:20:16 441856 —-a-w- C:\Windows\System32\Wpc.dll 2012-12-07 13:15:31 2746368 —-a-w- C:\Windows\System32\gameux.dll 2012-12-07 12:26:17 308736 —-a-w- C:\Windows\SysWow64\Wpc.dll 2012-12-07 12:20:43 2576384 —-a-w- C:\Windows\SysWow64\gameux.dll 2012-12-07 11:20:04 30720 —-a-w- C:\Windows\System32\usk.rs 2012-12-07 11:20:03 43520 —-a-w- C:\Windows\System32\csrr.rs 2012-12-07 11:20:03 23552 —-a-w- C:\Windows\System32\oflc.rs 2012-12-07 11:20:01 45568 —-a-w- C:\Windows\System32\oflc-nz.rs 2012-12-07 11:20:01 44544 —-a-w- C:\Windows\System32\pegibbfc.rs 2012-12-07 11:20:01 20480 —-a-w- C:\Windows\System32\pegi-fi.rs 2012-12-07 11:20:00 20480 —-a-w- C:\Windows\System32\pegi-pt.rs 2012-12-07 11:19:59 20480 —-a-w- C:\Windows\System32\pegi.rs 2012-12-07 11:19:58 46592 —-a-w- C:\Windows\System32\fpb.rs 2012-12-07 11:19:57 40960 —-a-w- C:\Windows\System32\cob-au.rs 2012-12-07 11:19:57 21504 —-a-w- C:\Windows\System32\grb.rs 2012-12-07 11:19:57 15360 —-a-w- C:\Windows\System32\djctq.rs 2012-12-07 11:19:56 55296 —-a-w- C:\Windows\System32\cero.rs 2012-12-07 11:19:55 51712 —-a-w- C:\Windows\System32\esrb.rs 2012-12-01 05:49:26 2557800 —-a-w- C:\Windows\System32\nvsvcr.dll 2012-11-30 05:45:35 362496 —-a-w- C:\Windows\System32\wow64win.dll 2012-11-30 05:45:35 243200 —-a-w- C:\Windows\System32\wow64.dll 2012-11-30 05:45:35 13312 —-a-w- C:\Windows\System32\wow64cpu.dll 2012-11-30 05:43:12 16384 —-a-w- C:\Windows\System32\ntvdm64.dll 2012-11-30 05:41:07 424448 —-a-w- C:\Windows\System32\KernelBase.dll 2012-11-30 04:53:59 274944 —-a-w- C:\Windows\SysWow64\KernelBase.dll 2012-11-30 03:23:48 338432 —-a-w- C:\Windows\System32\conhost.exe 2012-11-30 02:38:59 6144 —ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll 2012-11-30 02:38:59 4608 —ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll 2012-11-30 02:38:59 3584 —ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll 2012-11-30 02:38:59 3072 —ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll 2012-11-23 03:13:57 68608 —-a-w- C:\Windows\System32\taskhost.exe 2012-11-22 05:44:23 800768 —-a-w- C:\Windows\System32\usp10.dll 2012-11-22 04:45:03 626688 —-a-w- C:\Windows\SysWow64\usp10.dll . ============= FINISH: 23:14:31.28 ===============
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post







Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error
Thank you Mowman. My Combofix report. ComboFix 13-02-18.02 - Rod 19/02/2013 13:22:07.1.8 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.8136.6293 [GMT 0:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {ADA629C7-7F48-5689-624A-3B76997E0892} FW: McAfee Firewall *Enabled* {959DA8E2-3527-57D1-4915-924367AD4FE9} SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {16C7C823-5972-5907-58FA-0004E2F9422F} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\Roaming c:\windows\SysWow64\Packet.dll c:\windows\SysWow64\pthreadVC.dll c:\windows\SysWow64\tmp2319.tmp c:\windows\SysWow64\tmp231A.tmp c:\windows\SysWow64\tmp32C2.tmp c:\windows\SysWow64\tmp3350.tmp c:\windows\SysWow64\wpcap.dll . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . ——-\Service_NPF . . ((((((((((((((((((((((((( Files Created from 2013-01-19 to 2013-02-19 ))))))))))))))))))))))))))))))) . . 2013-02-18 20:05 . 2013-02-18 20:05 ——– d—–w- c:\users\Rod\AppData\Roaming\Malwarebytes 2013-02-18 20:04 . 2013-02-18 20:04 ——– d—–w- c:\programdata\Malwarebytes 2013-02-18 20:04 . 2013-02-18 20:05 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2013-02-18 20:04 . 2012-12-14 16:49 24176 —-a-w- c:\windows\system32\drivers\mbam.sys 2013-02-17 21:25 . 2013-02-17 21:25 ——– d—–w- c:\windows\Options 2013-02-17 21:25 . 2011-08-31 13:55 2736640 —-a-w- c:\windows\system32\drivers\athrx.sys 2013-02-17 21:25 . 2011-08-31 13:55 2736640 —-a-w- c:\windows\system32\athrx.sys 2013-02-17 21:24 . 2013-02-17 21:25 ——– d—–w- c:\programdata\TP-LINK 2013-02-15 20:37 . 2013-02-17 21:23 969104 —-a-w- c:\program files (x86)\uTorrent.exe 2013-02-15 20:26 . 2013-02-15 20:26 ——– d—–w- c:\users\Rod\AppData\Local\Shareaza 2013-02-15 20:26 . 2013-02-15 20:31 ——– d—–w- c:\users\Rod\AppData\Roaming\Shareaza 2013-02-14 08:19 . 2013-02-14 08:19 ——– d—–w- c:\programdata\IDM 2013-02-10 00:43 . 2013-02-10 00:43 ——– d—–w- c:\users\Rod\AppData\Local\Sidhe 2013-02-09 18:06 . 2013-02-09 18:06 ——– d—–w- c:\program files (x86)\Thermaltake 2013-02-09 16:22 . 2013-02-09 16:22 ——– d—–w- c:\programdata\Macrium 2013-02-09 16:22 . 2013-02-09 16:22 ——– d—–w- c:\program files\Macrium 2013-02-09 16:22 . 2013-02-09 16:22 ——– d—–w- C:\boot 2013-02-08 20:31 . 2013-02-08 20:31 95648 —-a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-01-31 13:42 . 2013-01-31 13:42 13944 —-a-w- c:\windows\system32\drivers\PSVolAcc.sys 2013-01-31 13:42 . 2013-01-31 13:42 57976 —-a-w- c:\windows\system32\drivers\psmounterex.sys 2013-01-30 23:36 . 2013-02-09 18:45 ——– d—–w- c:\users\Rod\AppData\Roaming\JAM Software 2013-01-30 23:18 . 2013-02-19 13:26 ——– d—–w- c:\program files\Core Temp 2013-01-30 23:18 . 2013-02-09 22:16 ——– d—–w- c:\programdata\Tarma Installer 2013-01-29 12:03 . 2012-11-22 00:43 165112 —-a-w- c:\windows\system32\drivers\idmwfp.sys 2013-01-21 21:57 . 2013-01-21 21:57 ——– d—–w- c:\programdata\APN 2013-01-20 16:24 . 2013-01-20 16:24 ——– d—–w- c:\users\Rod\AppData\Roaming\Titanium 2013-01-20 16:24 . 2013-01-20 16:24 31232 —-a-w- c:\windows\system32\drivers\tap0901.sys 2013-01-20 16:24 . 2013-01-20 16:27 ——– d—–w- c:\program files\pia_manager . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-02-13 13:18 . 2012-11-03 23:07 70004024 —-a-w- c:\windows\system32\MRT.exe 2013-02-09 19:56 . 2012-11-03 14:43 74096 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-02-09 19:56 . 2012-11-03 14:43 697712 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-02-08 20:31 . 2012-11-03 14:49 861088 —-a-w- c:\windows\SysWow64\npDeployJava1.dll 2013-02-08 20:31 . 2012-11-03 14:49 782240 —-a-w- c:\windows\SysWow64\deployJava1.dll 2013-02-07 00:57 . 2012-12-16 00:35 895088 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll 2013-02-07 00:56 . 2012-12-16 00:35 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll 2013-01-19 01:01 . 2013-01-05 00:59 895088 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll 2013-01-19 01:00 . 2013-01-05 00:59 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll 2013-01-15 01:44 . 2012-12-16 00:35 710992 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2013-01-05 00:59 . 2013-01-05 00:59 710992 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll 2013-01-04 04:43 . 2013-02-13 12:43 44032 —-a-w- c:\windows\apppatch\acwow64.dll 2012-12-29 10:34 . 2013-01-06 18:21 958272 —-a-w- c:\windows\SysWow64\nvumdshim.dll 2012-12-29 10:34 . 2013-01-06 18:21 7565240 —-a-w- c:\windows\system32\nvopencl.dll 2012-12-29 10:34 . 2013-01-06 18:21 6263784 —-a-w- c:\windows\SysWow64\nvopencl.dll 2012-12-29 10:34 . 2013-01-06 18:21 26931128 —-a-w- c:\windows\system32\nvoglv64.dll 2012-12-29 10:34 . 2013-01-06 18:21 12641120 —-a-w- c:\windows\SysWow64\nvwgf2um.dll 2012-12-29 10:34 . 2013-01-06 18:21 9389888 —-a-w- c:\windows\system32\nvcuda.dll 2012-12-29 10:34 . 2013-01-06 18:21 7931896 —-a-w- c:\windows\SysWow64\nvcuda.dll 2012-12-29 10:34 . 2013-01-06 18:21 246024 —-a-w- c:\windows\system32\nvinitx.dll 2012-12-29 10:34 . 2013-01-06 18:21 20450232 —-a-w- c:\windows\SysWow64\nvoglv32.dll 2012-12-29 10:34 . 2013-01-06 18:21 201728 —-a-w- c:\windows\SysWow64\nvinit.dll 2012-12-29 10:34 . 2013-01-06 18:21 18054312 —-a-w- c:\windows\system32\nvd3dumx.dll 2012-12-29 10:34 . 2013-01-06 18:21 10997176 —-a-w- c:\windows\system32\drivers\nvlddmkm.sys 2012-12-29 10:34 . 2013-01-06 18:21 420280 —-a-w- c:\windows\system32\nvEncodeAPI64.dll 2012-12-29 10:34 . 2013-01-06 18:21 364984 —-a-w- c:\windows\SysWow64\nvEncodeAPI.dll 2012-12-29 10:34 . 2013-01-06 18:21 2904504 —-a-w- c:\windows\system32\nvcuvid.dll 2012-12-29 10:34 . 2013-01-06 18:21 2720696 —-a-w- c:\windows\SysWow64\nvcuvid.dll 2012-12-29 10:34 . 2013-01-06 18:21 2344888 —-a-w- c:\windows\system32\nvcuvenc.dll 2012-12-29 10:34 . 2013-01-06 18:21 1985976 —-a-w- c:\windows\SysWow64\nvcuvenc.dll 2012-12-29 10:34 . 2013-01-06 18:21 17560504 —-a-w- c:\windows\SysWow64\nvcompiler.dll 2012-12-29 10:34 . 2013-01-06 18:21 25256376 —-a-w- c:\windows\system32\nvcompiler.dll 2012-12-29 10:34 . 2012-10-10 21:23 1504696 —-a-w- c:\windows\system32\nvdispgenco64.dll 2012-12-29 10:34 . 2012-10-10 21:23 2824656 —-a-w- c:\windows\system32\nvapi64.dll 2012-12-29 10:34 . 2012-10-10 21:23 1107592 —-a-w- c:\windows\system32\nvumdshimx.dll 2012-12-29 10:34 . 2012-10-10 21:23 15052368 —-a-w- c:\windows\system32\nvwgf2umx.dll 2012-12-29 10:34 . 2012-10-10 21:22 2504248 —-a-w- c:\windows\SysWow64\nvapi.dll 2012-12-29 10:34 . 2012-10-10 21:22 15129064 —-a-w- c:\windows\SysWow64\nvd3dum.dll 2012-12-29 10:34 . 2012-03-11 19:54 1813432 —-a-w- c:\windows\system32\nvdispco64.dll 2012-12-29 08:40 . 2012-03-11 19:55 6382008 —-a-w- c:\windows\system32\nvcpl.dll 2012-12-29 08:40 . 2012-03-11 19:55 3455416 —-a-w- c:\windows\system32\nvsvc64.dll 2012-12-29 08:40 . 2012-03-11 19:55 2923201 —-a-w- c:\windows\system32\nvcoproc.bin 2012-12-29 08:40 . 2012-03-11 19:55 884152 —-a-w- c:\windows\system32\nvvsvc.exe 2012-12-29 08:40 . 2012-03-11 19:55 63928 —-a-w- c:\windows\system32\nvshext.dll 2012-12-29 08:40 . 2012-03-11 19:55 118712 —-a-w- c:\windows\system32\nvmctray.dll 2012-12-29 02:54 . 2012-12-29 02:54 550328 —-a-w- c:\windows\SysWow64\nvStreaming.exe 2012-12-20 01:52 . 2012-12-20 01:52 126976 —-a-w- c:\windows\lcmmfu.cpl 2012-12-20 01:52 . 2012-12-20 01:52 48640 —-a-w- c:\windows\mmfs.dll 2012-12-20 01:52 . 2012-12-20 01:52 2560 —-a-w- c:\windows\Runservice.exe 2012-12-16 17:11 . 2012-12-21 03:00 46080 —-a-w- c:\windows\system32\atmlib.dll 2012-12-16 14:45 . 2012-12-21 03:00 367616 —-a-w- c:\windows\system32\atmfd.dll 2012-12-16 14:13 . 2012-12-21 03:00 295424 —-a-w- c:\windows\SysWow64\atmfd.dll 2012-12-16 14:13 . 2012-12-21 03:00 34304 —-a-w- c:\windows\SysWow64\atmlib.dll 2012-12-07 13:20 . 2013-01-09 08:25 441856 —-a-w- c:\windows\system32\Wpc.dll 2012-12-07 13:15 . 2013-01-09 08:25 2746368 —-a-w- c:\windows\system32\gameux.dll 2012-12-07 12:26 . 2013-01-09 08:25 308736 —-a-w- c:\windows\SysWow64\Wpc.dll 2012-12-07 12:20 . 2013-01-09 08:25 2576384 —-a-w- c:\windows\SysWow64\gameux.dll 2012-12-07 11:20 . 2013-01-09 08:25 30720 —-a-w- c:\windows\system32\usk.rs 2012-12-07 11:20 . 2013-01-09 08:25 43520 —-a-w- c:\windows\system32\csrr.rs 2012-12-07 11:20 . 2013-01-09 08:24 23552 —-a-w- c:\windows\system32\oflc.rs 2012-12-07 11:20 . 2013-01-09 08:25 45568 —-a-w- c:\windows\system32\oflc-nz.rs 2012-12-07 11:20 . 2013-01-09 08:25 44544 —-a-w- c:\windows\system32\pegibbfc.rs 2012-12-07 11:20 . 2013-01-09 08:24 20480 —-a-w- c:\windows\system32\pegi-fi.rs 2012-12-07 11:20 . 2013-01-09 08:25 20480 —-a-w- c:\windows\system32\pegi-pt.rs 2012-12-07 11:19 . 2013-01-09 08:25 20480 —-a-w- c:\windows\system32\pegi.rs 2012-12-07 11:19 . 2013-01-09 08:25 46592 —-a-w- c:\windows\system32\fpb.rs 2012-12-07 11:19 . 2013-01-09 08:25 40960 —-a-w- c:\windows\system32\cob-au.rs 2012-12-07 11:19 . 2013-01-09 08:25 21504 —-a-w- c:\windows\system32\grb.rs 2012-12-07 11:19 . 2013-01-09 08:25 15360 —-a-w- c:\windows\system32\djctq.rs 2012-12-07 11:19 . 2013-01-09 08:24 55296 —-a-w- c:\windows\system32\cero.rs 2012-12-07 11:19 . 2013-01-09 08:24 51712 —-a-w- c:\windows\system32\esrb.rs 2012-12-07 10:46 . 2013-01-09 08:25 43520 —-a-w- c:\windows\SysWow64\csrr.rs 2012-12-07 10:46 . 2013-01-09 08:25 30720 —-a-w- c:\windows\SysWow64\usk.rs 2012-12-07 10:46 . 2013-01-09 08:25 45568 —-a-w- c:\windows\SysWow64\oflc-nz.rs 2012-12-07 10:46 . 2013-01-09 08:25 44544 —-a-w- c:\windows\SysWow64\pegibbfc.rs 2012-12-07 10:46 . 2013-01-09 08:25 20480 —-a-w- c:\windows\SysWow64\pegi-pt.rs 2012-12-07 10:46 . 2013-01-09 08:24 23552 —-a-w- c:\windows\SysWow64\oflc.rs 2012-12-07 10:46 . 2013-01-09 08:24 20480 —-a-w- c:\windows\SysWow64\pegi-fi.rs 2012-12-07 10:46 . 2013-01-09 08:25 46592 —-a-w- c:\windows\SysWow64\fpb.rs 2012-12-07 10:46 . 2013-01-09 08:25 20480 —-a-w- c:\windows\SysWow64\pegi.rs 2012-12-07 10:46 . 2013-01-09 08:25 21504 —-a-w- c:\windows\SysWow64\grb.rs 2012-12-07 10:46 . 2013-01-09 08:25 40960 —-a-w- c:\windows\SysWow64\cob-au.rs 2012-12-07 10:46 . 2013-01-09 08:25 15360 —-a-w- c:\windows\SysWow64\djctq.rs 2012-12-07 10:46 . 2013-01-09 08:24 51712 —-a-w- c:\windows\SysWow64\esrb.rs 2012-12-07 10:46 . 2013-01-09 08:24 55296 —-a-w- c:\windows\SysWow64\cero.rs 2012-12-01 05:49 . 2012-03-11 19:55 2557800 —-a-w- c:\windows\system32\nvsvcr.dll 2012-11-30 05:45 . 2013-01-09 08:24 362496 —-a-w- c:\windows\system32\wow64win.dll 2012-11-30 05:45 . 2013-01-09 08:24 243200 —-a-w- c:\windows\system32\wow64.dll 2012-11-30 05:45 . 2013-01-09 08:24 13312 —-a-w- c:\windows\system32\wow64cpu.dll 2012-11-30 05:43 . 2013-01-09 08:24 16384 —-a-w- c:\windows\system32\ntvdm64.dll 2012-11-30 05:41 . 2013-01-09 08:24 424448 —-a-w- c:\windows\system32\KernelBase.dll 2012-11-30 05:41 . 2013-01-09 08:24 1161216 —-a-w- c:\windows\system32\kernel32.dll 2012-11-30 05:38 . 2013-01-09 08:24 3072 —ha-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll 2012-11-30 05:38 . 2013-01-09 08:24 6144 —ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll 2012-11-30 05:38 . 2013-01-09 08:24 4608 —ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2012-11-30 05:38 . 2013-01-09 08:24 4096 —ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2012-11-30 05:38 . 2013-01-09 08:24 3072 —ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2012-11-30 05:38 . 2013-01-09 08:24 3072 —ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll 2012-11-30 05:38 . 2013-01-09 08:24 4608 —ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2012-11-30 05:38 . 2013-01-09 08:24 4096 —ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "THPanel"="c:\program files (x86)\Thunder Master\THPanel.exe" [2012-05-24 2047344] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2012-10-19 17875120] "IDMan"="c:\program files (x86)\Internet Download Manager\IDMan.exe" [2013-01-29 3565432] "Akamai NetSession Interface"="c:\users\Rod\AppData\Local\Akamai\netsession_win.exe" [2012-10-09 4441920] "Spotify Web Helper"="c:\users\Rod\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2012-12-02 1199576] "LCLC Control Panel"="c:\program files (x86)\Thermaltake\Fan Control Software\Fan Control Software.exe" [2012-03-29 870400] "Steam"="f:\program files (x86) ssd\steam.exe" [2013-02-15 1597864] "uTorrent"="c:\program files (x86)\uTorrent.exe" [2013-02-17 969104] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "THX Audio Control Panel"="c:\program files (x86)\Creative\Sound Blaster X-Fi MB 2\THXAudioCP\THXAudio.exe" [2010-06-11 1349632] "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112] "USB3MON"="c:\program files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-01-04 291608] "IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIconLaunch.exe" [2012-02-29 56088] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352] "mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2012-09-12 1535112] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS6ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-03-09 1073312] "mcpltui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2012-09-12 1535112] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-12-12 152544] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Auto Rip n Compress - Extender Monitor.lnk - f:\program files (x86) ssd\AutoRip\Extender Rip Monitor.exe [2010-6-15 212376] NETGEAR WNDA3100v2 Smart Wizard.lnk - c:\program files (x86)\NETGEAR\WNDA3100v2\WNDA3100v2.exe [2012-11-3 4559840] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc] @="" . R2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-12-12 661504] R2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [2012-06-18 1095616] R2 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [2012-06-18 1333184] R2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [2012-06-18 1124288] R2 BTHSSecurityMgr;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2012-01-13 135952] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 HomeNetSvc;McAfee Home Network;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [2012-10-07 220856] R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-02-01 13592] R2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [2012-10-07 220856] R2 mcpltsvc;McAfee Platform Services;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [2012-10-07 220856] R2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2012-02-07 363800] R2 WSWNDA3100;WSWNDA3100;c:\program files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe [2010-08-19 272864] R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys [2011-12-12 195072] R3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys [2012-05-21 111104] R3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys [2012-06-09 849408] R3 cmudaxp;ASUS Xonar DX Audio Interface;c:\windows\system32\drivers\cmudaxp.sys [2008-01-18 1197568] R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2012-03-11 79360] R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2012-03-11 79360] R3 HipShieldK;McAfee Inc. HipShieldK;c:\windows\system32\drivers\HipShieldK.sys [2012-05-28 197264] R3 ibtfltcoex;ibtfltcoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys [2012-07-09 60928] R3 mfencrk;McAfee Inc. mfencrk;c:\windows\system32\DRIVERS\mfencrk.sys [2012-11-02 97208] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2012-01-04 340240] R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-11-03 1255736] S0 asahci64;asahci64;c:\windows\system32\DRIVERS\asahci64.sys [2012-01-06 49760] S0 iusb3hcs;Intel® USB 3.0 Host Controller Switch Driver;c:\windows\system32\DRIVERS\iusb3hcs.sys [2012-01-04 16152] S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2012-11-09 339776] S0 SCMNdisP;General NDIS Protocol Driver;c:\windows\system32\DRIVERS\scmndisp.sys [2007-01-19 25312] S2 IDMWFP;IDMWFP;c:\windows\system32\DRIVERS\idmwfp.sys [2012-11-22 165112] S2 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe [2012-02-02 628448] S2 Intel® PROSet Monitoring Service;Intel® PROSet Monitoring Service;c:\windows\system32\IProsetMonitor.exe [2011-08-15 178344] S2 jhi_service;Intel® Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [2012-02-07 161560] S2 LicCtrlService;LicCtrl Service;c:\windows\runservice.exe [2012-12-20 2560] S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2012-08-31 201304] S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [2012-10-07 220856] S2 mfecore;McAfee Anti-Malware Core;c:\program files\Common Files\McAfee\AMCore\mcshield.exe [2012-10-06 1007288] S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2012-11-09 218320] S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2012-11-09 177680] S2 PDF Architect Helper Service;PDF Architect Helper Service;c:\program files (x86)\PDF Architect\HelperService.exe [2012-11-22 1522312] S2 PDF Architect Service;PDF Architect Service;c:\program files (x86)\PDF Architect\ConversionService.exe [2012-11-22 905864] S2 ReflectService.exe;Macrium Reflect Image Mounting Service;c:\program files\Macrium\Reflect\ReflectService.exe [2013-01-31 302200] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-12-29 383416] S3 ALSysIO;ALSysIO;c:\users\Rod\AppData\Local\Temp\ALSysIO64.sys [x] S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Virtual Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys [2011-12-12 195072] S3 ASEUSBCC;ASEUSBCC;c:\windows\system32\drivers\AseUSBCC.sys [2011-12-13 16384] S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys [2011-11-03 130536] S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys [2011-11-03 395752] S3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;c:\windows\system32\DRIVERS\bcmwlhigh664.sys [2010-10-13 1244224] S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2012-11-09 69672] S3 iusb3hub;Intel® USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\iusb3hub.sys [2012-01-04 355096] S3 iusb3xhc;Intel® USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\DRIVERS\iusb3xhc.sys [2012-01-04 786200] S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2012-11-09 515528] S3 mfencbdc;McAfee Inc. mfencbdc;c:\windows\system32\DRIVERS\mfencbdc.sys [2012-11-02 328976] . . — Other Services/Drivers In Memory — . *NewlyCreated* - WS2IFSL *Deregistered* - mfeavfk01 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-02-01 08:27 1607120 —-a-w- c:\program files (x86)\Google\Chrome\Application\24.0.1312.57\Installer\chrmstp.exe . Contents of the 'Scheduled Tasks' folder . 2013-02-19 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-03 19:56] . 2013-02-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-11 21:24] . 2013-02-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-11 21:24] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension] @="{CDC95B92-E27C-4745-A8C5-64A52A78855D}" [HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}] 2012-11-15 23:07 23496 —-a-w- c:\program files (x86)\Internet Download Manager\IDMShellExt64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BLEServicesCtrl"="c:\program files (x86)\Intel\Bluetooth\BleServicesCtrl.exe" [2012-05-31 184112] "BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshell.dll" [2012-06-18 11586944] "IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2012-01-04 1935120] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2012-02-10 6463592] "THXCfg64"="c:\windows\system32\THXCfg64.dll" [2009-10-15 17920] "RunDLLEntry"="c:\windows\system32\AmbRunE.dll" [2009-02-26 17920] "Cmaudio8788"="c:\windows\Syswow64\cmicnfgp.cpl" [2008-01-10 6475776] "Cmaudio8788GX"="c:\windows\system\CmGxMon.exe" [2007-12-19 20480] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-09-20 444904] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.bigseekpro.com/dvdshrink2/{ACBE0245-95A0-45DD-9BD3-2616F2AF5660} mStart Page = hxxp://www.bigseekpro.com/dvdshrink2/{ACBE0245-95A0-45DD-9BD3-2616F2AF5660} mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local; IE: Download all links with IDM - c:\program files (x86)\Internet Download Manager\IEGetAll.htm IE: Download with IDM - c:\program files (x86)\Internet Download Manager\IEExt.htm IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000 IE: Free YouTube to MP3 Converter - c:\users\Rod\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105 IE: Send to Bluetooth - c:\program files (x86)\Intel\Bluetooth\btSendToObject.htm TCP: DhcpNameServer = [removed] [removed] FF - ProfilePath - c:\users\Rod\AppData\Roaming\Mozilla\Firefox\Profiles\863j7af2.default\ FF - ExtSQL: 2013-02-09 16:18; [removed]; c:\program files (x86)\Iminent\[removed] . - - - - ORPHANS REMOVED - - - - . Wow6432Node-HKCU-Run-AdobeBridge - (no file) . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-2558175178-271460453-2730271903-1000_Classes\Wow6432Node\CLSID\{064dc71f-b8a4-4cb2-a69a-09988967c73a}] @Denied: (Full) (Everyone) @Allowed: (Read) (RestrictedCode) "Model"=dword:0000015e "Therad"=dword:0000001e . [HKEY_USERS\S-1-5-21-2558175178-271460453-2730271903-1000_Classes\Wow6432Node\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}] @Denied: (Full) (Everyone) @Allowed: (Read) (RestrictedCode) "scansk"=hex(0):52,08,f6,32,9f,8e,c3,79,5b,5e,cb,b1,c6,82,74,e7,18,4b,c2,57,77, de,be,00,a7,73,3f,59,23,03,c3,1c,17,1e,2e,46,e0,ea,e8,6c,00,00,00,00,00,00,\ . [HKEY_USERS\S-1-5-21-2558175178-271460453-2730271903-1000_Classes\Wow6432Node\CLSID\{78ba9262-e1d0-4037-abdd-1a541727129f}] @Denied: (Full) (Everyone) @Allowed: (Read) (RestrictedCode) "Model"=dword:0000002f "Therad"=dword:00000015 "SpecVersion"=dword:0000002f "MData"=hex(0):2c,de,ec,a8,de,34,d5,35,f9,05,e7,63,2b,e0,d4,20,1f,d9,76,af,31, 38,90,f7,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\ . [HKEY_USERS\S-1-5-21-2558175178-271460453-2730271903-1000_Classes\Wow6432Node\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}] @Denied: (Full) (Everyone) "scansk"=hex(0):b3,2b,35,45,03,50,96,5c,4d,0d,e8,33,67,4e,28,48,23,c7,b4,89,24, 11,6d,55,b8,a2,40,2f,d9,e5,2c,2d,48,39,d8,49,a4,c7,21,7f,00,00,00,00,00,00,\ . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_149_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_149_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_149_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_149_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_149.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_149.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_149.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_149.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*] @="?????????????????? v1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID] @="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*] @="?????????????????? v2" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID] @="{9BE31822-FDAD-461B-AD51-BE1D1C159921}" . [HKEY_LOCAL_MACHINE\SOFTWARE\McAfee] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Environment*] "v5Licence0"="15-S52A-CNWN-R755-KYQZ-WYDU-1KXVXJ9" "Activated"="Y" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Creative\Shared Files\CTAudSvc.exe c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\windows\SysWOW64\rundll32.exe . ************************************************************************** . Completion time: 2013-02-19 13:27:58 - machine was rebooted ComboFix-quarantined-files.txt 2013-02-19 13:27 . Pre-Run: 81,035,833,344 bytes free Post-Run: 81,071,292,416 bytes free . - - End Of File - - 8775DC3A0A75CDE0A4E726BFE9E8DC99
Please download AdwCleaner from here and save it to your desktop.
  • Right click on AdwCleaner.exe and click "Run as Administrator" to run the tool.
  • Click on Delete.
A logfile will automatically open after the scan has finished.

Please post the content of that logfile in your reply.

You can find the logfile at C:\AdwCleaner[Rn].txt as well - (n is the scan number.)








  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.







Next

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is not checked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the Back button.
  • Push Finish
http://www.eset.com/onlinescan/





Also tell me how the computer is running now.
HI, My computer seems to be running fine but I never really had an issue with it other than my internet was unusually slow for a unusually long time whilst my laptop wasn't having any issues. That was when I discovered the virus and my inability to do a system restore. The speed of my internet connection has improved since yesterday but isn't back to normal. My Adwcleaner log. # AdwCleaner v2.112 - Logfile created 02/19/2013 at 18:01:36 # Updated 10/02/2013 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : Rod - ROD-PC # Boot Mode : Normal # Running from : E:\Downloads\Programs\adwcleaner0.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** Folder Deleted : C:\ProgramData\APN Folder Deleted : C:\ProgramData\Tarma Installer Folder Deleted : C:\Users\Rod\AppData\LocalLow\Toolbar4 Folder Deleted : C:\Users\Rod\AppData\Roaming\pdfforge ***** [Registry] ***** Key Deleted : HKCU\Software\Iminent Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FCBCCB87-9224-4B8D-B117-F56D924BEB18} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FCBCCB87-9224-4B8D-B117-F56D924BEB18} Key Deleted : HKCU\Software\Softonic Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{96BD48DD-741B-41AE-AC4A-AFF96BA00F7E} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF} Key Deleted : HKLM\Software\Iminent Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASMANCS Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP Key Deleted : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7} ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.7601.17514 Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://www.bigseekpro.com/dvdshrink2/{ACBE0245-95A0-45DD-9BD3-2616F2AF5660} –> hxxp://www.google.com Replaced : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Start Page] = hxxp://www.bigseekpro.com/dvdshrink2/{ACBE0245-95A0-45DD-9BD3-2616F2AF5660} –> hxxp://www.google.com -\\ Mozilla Firefox v16.0.2 (en-US) File : C:\Users\Rod\AppData\Roaming\Mozilla\Firefox\Profiles\863j7af2.default\prefs.js C:\Users\Rod\AppData\Roaming\Mozilla\Firefox\Profiles\863j7af2.default\user.js … Deleted ! [OK] File is clean. -\\ Google Chrome v24.0.1312.57 File : C:\Users\Rod\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[S1].txt - [11379 octets] - [19/02/2013 18:01:36] ########## EOF - C:\AdwCleaner[S1].txt - [11440 octets] ########## ————————————————————————————————– I didn't have/didn't see a show results button after the Malwarebytes scan finished but I do have a log. I also ran a scan before seeking help without the latest update because I couldn't download it. I've included that log as well. Malwarebytes Anti-Malware 1.70.0.1100 www.malwarebytes.org Database version: v2013.02.19.05 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 8.0.7601.17514 Rod :: ROD-PC [administrator] 19/02/2013 18:07:05 mbam-log-2013-02-19 (18-07-05).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 230228 Time elapsed: 2 minute(s), 16 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) ——————————————————- First scan without update. Malwarebytes Anti-Malware 1.70.0.1100 www.malwarebytes.org Database version: v2012.12.14.11 Windows 7 Service Pack 1 x64 NTFS (Safe Mode/Networking) Internet Explorer 8.0.7601.17514 Rod :: ROD-PC [administrator] 18/02/2013 20:31:21 mbam-log-2013-02-18 (20-31-21).txt Scan type: Full scan (C:\|E:\|F:\|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 624466 Time elapsed: 18 minute(s), 39 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 1 E:\Progam Files (x86) HDD\Adobe Photoshop CS6 (64 Bit)\amtlib.dll (PUP.RiskwareTool.CK) -> Quarantined and deleted successfully. (end) ————————————————————— The ESET scan log. E:\ROD-PC\Backup Set 2013-01-29 213312\Backup Files 2013-02-01 082717\Backup files 1.zip Win32/Adware.Yontoo application —————————————————————– Thanks.
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    C:\Windows\assembly\tmp\U\*.* /s
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
OTL results

OTL logfile created on: 20/02/2013 19:10:34 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Rod\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

7.95 Gb Total Physical Memory | 6.51 Gb Available Physical Memory | 81.88% Memory free
15.89 Gb Paging File | 12.97 Gb Available in Paging File | 81.65% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 119.14 Gb Total Space | 75.40 Gb Free Space | 63.29% Space Free | Partition Type: NTFS
Drive E: | 1862.89 Gb Total Space | 974.81 Gb Free Space | 52.33% Space Free | Partition Type: NTFS
Drive F: | 476.94 Gb Total Space | 416.01 Gb Free Space | 87.23% Space Free | Partition Type: NTFS

Computer Name: ROD-PC | User Name: Rod | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Rod\AppData\Local\Temp\ocr84C8.tmp\bin\rubyw.exe (http://www.ruby-lang.org/)
PRC - C:\Users\Rod\AppData\Local\Temp\ocr6631.tmp\bin\rubyw.exe (http://www.ruby-lang.org/)
PRC - C:\Users\Rod\Desktop\OTL.exe (OldTimer Tools)
PRC - F:\Program Files (x86) SSD\steam.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.)
PRC - C:\Program Files\pia_manager\pia_manager.exe ()
PRC - C:\Program Files\pia_manager\pia_tray\pia_tray.exe ()
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Windows\Runservice.exe ()
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe (Tonec Inc.)
PRC - C:\Users\Rod\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
PRC - C:\Program Files (x86)\PDF Architect\HelperService.exe (pdfforge GbR)
PRC - C:\Program Files (x86)\PDF Architect\ConversionService.exe (pdfforge GbR)
PRC - C:\Users\Rod\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Motorola Solutions, Inc.)
PRC - C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Motorola Solutions, Inc.)
PRC - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Motorola Solutions, Inc.)
PRC - C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe (Motorola Solutions, Inc.)
PRC - C:\Program Files (x86)\Thunder Master\THPanel.exe (Palit Microsystems Ltd.)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\NETGEAR\WNDA3100v2\WNDA3100v2.exe ()
PRC - F:\Program Files (x86) SSD\AutoRip\Extender Rip Monitor.exe ()
PRC - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
PRC - C:\Windows\system\CMGxMon.exe ()


========== Modules (No Company Name) ==========

MOD - C:\Users\Rod\AppData\Local\Temp\ocr84C8.tmp\lib\ruby\1.9.1\i386-mingw32\openssl.so ()
MOD - C:\Users\Rod\AppData\Local\Temp\ocr84C8.tmp\lib\ruby\1.9.1\i386-mingw32\win32ole.so ()
MOD - C:\Users\Rod\AppData\Local\Temp\ocr84C8.tmp\lib\ruby\1.9.1\i386-mingw32\zlib.so ()
MOD - C:\Users\Rod\AppData\Local\Temp\ocr84C8.tmp\lib\ruby\1.9.1\i386-mingw32\dl.so ()
MOD - C:\Users\Rod\AppData\Local\Temp\ocr84C8.tmp\lib\ruby\1.9.1\i386-mingw32\json\ext\generator.so ()
MOD - C:\Users\Rod\AppData\Local\Temp\ocr84C8.tmp\lib\ruby\1.9.1\i386-mingw32\fiddle.so ()
MOD - C:\Users\Rod\AppData\Local\Temp\ocr84C8.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.4.8-x86-mingw32\lib\win32\ruby19\win32\api.so ()
MOD - C:\Users\Rod\AppData\Local\Temp\ocr84C8.tmp\lib\ruby\1.9.1\i386-mingw32\stringio.so ()
MOD - C:\Users\Rod\AppData\Local\Temp\ocr84C8.tmp\lib\ruby\1.9.1\i386-mingw32\json\ext\parser.so ()
MOD - C:\Users\Rod\AppData\Local\Temp\ocr84C8.tmp\lib\ruby\1.9.1\i386-mingw32\digest.so ()
MOD - C:\Users\Rod\AppData\Local\Temp\ocr84C8.tmp\lib\ruby\1.9.1\i386-mingw32\etc.so ()
MOD - C:\Users\Rod\AppData\Local\Temp\ocr84C8.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_32le.so ()
MOD - C:\Users\Rod\AppData\Local\Temp\ocr84C8.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_32be.so ()
MOD - C:\Users\Rod\AppData\Local\Temp\ocr84C8.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_16be.so ()
MOD - C:\Users\Rod\AppData\Local\Temp\ocr84C8.tmp\lib\ruby\1.9.1\i386-mingw32\fcntl.so ()
MOD - C:\Users\Rod\AppData\Local\Temp\ocr84C8.tmp\bin\libeay32-1.0.0-msvcrt.dll ()
MOD - C:\Users\Rod\AppData\Local\Temp\ocr84C8.tmp\bin\ssleay32-1.0.0-msvcrt.dll ()
MOD - C:\Users\Rod\AppData\Local\Temp\ocr84C8.tmp\lib\ruby\1.9.1\i386-mingw32\socket.so ()
MOD - C:\Users\Rod\AppData\Local\Temp\ocr84C8.tmp\bin\ZLIB1.dll ()
MOD - C:\Users\Rod\AppData\Local\Temp\ocr84C8.tmp\src\rgloader\rgloader193.mswin.so ()
MOD - C:\Users\Rod\AppData\Local\Temp\ocr84C8.tmp\lib\ruby\site_ruby\1.9.1\rgloader\rgloader193.mswin.so ()
MOD - C:\Users\Rod\AppData\Local\Temp\ocr84C8.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\transdb.so ()
MOD - C:\Users\Rod\AppData\Local\Temp\ocr84C8.tmp\lib\ruby\1.9.1\i386-mingw32\enc\encdb.so ()
MOD - C:\Users\Rod\AppData\Local\Temp\ocr84C8.tmp\lib\ruby\1.9.1\i386-mingw32\enc\iso_8859_1.so ()
MOD - C:\Users\Rod\AppData\Local\Temp\ocr84C8.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_16le.so ()
MOD - C:\Users\Rod\AppData\Local\Temp\ocr6631.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.4.8-x86-mingw32\lib\win32\ruby19\win32\api.so ()
MOD - C:\Users\Rod\AppData\Local\Temp\ocr6631.tmp\lib\ruby\1.9.1\i386-mingw32\win32ole.so ()
MOD - C:\Users\Rod\AppData\Local\Temp\ocr6631.tmp\lib\ruby\1.9.1\i386-mingw32\dl.so ()
MOD - C:\Users\Rod\AppData\Local\Temp\ocr6631.tmp\lib\ruby\1.9.1\i386-mingw32\fiddle.so ()
MOD - C:\Users\Rod\AppData\Local\Temp\ocr6631.tmp\lib\ruby\1.9.1\i386-mingw32\etc.so ()
MOD - C:\Users\Rod\AppData\Local\Temp\ocr6631.tmp\lib\ruby\site_ruby\1.9.1\rgloader\rgloader193.mswin.so ()
MOD - C:\Users\Rod\AppData\Local\Temp\ocr6631.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\transdb.so ()
MOD - C:\Users\Rod\AppData\Local\Temp\ocr6631.tmp\lib\ruby\1.9.1\i386-mingw32\enc\encdb.so ()
MOD - C:\Users\Rod\AppData\Local\Temp\ocr6631.tmp\lib\ruby\1.9.1\i386-mingw32\enc\iso_8859_1.so ()
MOD - C:\Users\Rod\AppData\Local\Temp\ocr6631.tmp\src\rgloader\rgloader193.mswin.so ()
MOD - F:\Program Files (x86) SSD\bin\chromehtml.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\cb562e2e4f74ae607f1186f6ec50cec7\System.Windows.Forms.ni.dll ()
MOD - F:\Program Files (x86) SSD\bin\libcef.dll ()
MOD - C:\Program Files\pia_manager\pia_tray\runtime\1.2.0.RC6d\zlib1.dll ()
MOD - C:\Program Files\pia_manager\pia_tray\runtime\1.2.0.RC6d\PocoNet.dll ()
MOD - C:\Program Files\pia_manager\pia_tray\runtime\1.2.0.RC6d\PocoXML.dll ()
MOD - C:\Program Files\pia_manager\pia_tray\runtime\1.2.0.RC6d\PocoUtil.dll ()
MOD - C:\Program Files\pia_manager\pia_tray\runtime\1.2.0.RC6d\libxml2.dll ()
MOD - C:\Program Files\pia_manager\pia_tray\runtime\1.2.0.RC6d\PocoFoundation.dll ()
MOD - C:\Program Files\pia_manager\pia_tray\runtime\1.2.0.RC6d\khost.dll ()
MOD - C:\Program Files\pia_manager\pia_tray\runtime\1.2.0.RC6d\CFLite.dll ()
MOD - C:\Program Files\pia_manager\pia_manager.exe ()
MOD - C:\Program Files\pia_manager\pia_tray\modules\tinetwork\1.2.0.RC6d\tinetworkmodule.dll ()
MOD - C:\Program Files\pia_manager\pia_tray\modules\tiui\1.2.0.RC6d\tiuimodule.dll ()
MOD - C:\Program Files\pia_manager\pia_tray\modules\tiprocess\1.2.0.RC6d\tiprocessmodule.dll ()
MOD - C:\Program Files\pia_manager\pia_tray\modules\tiapp\1.2.0.RC6d\tiappmodule.dll ()
MOD - C:\Program Files\pia_manager\pia_tray\modules\tifilesystem\1.2.0.RC6d\tifilesystemmodule.dll ()
MOD - C:\Program Files\pia_manager\pia_tray\pia_tray.exe ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\8c78244854f84b69701fcee19b543645\IAStorUtil.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\1c402ca365b68a2616ea3a5194d38310\IAStorCommon.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\90b89f6e8032310e9ac72a309fd49e83\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\cf827fe7bc99d9bcf0ba3621054ef527\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\571b85634abf2fba6bab80c21a347081\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\195a77fcc6206f8bb35d419ff2cf0d72\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll ()
MOD - F:\Program Files (x86) SSD\sdl.dll ()
MOD - F:\Program Files (x86) SSD\bin\avcodec-53.dll ()
MOD - F:\Program Files (x86) SSD\bin\avformat-53.dll ()
MOD - F:\Program Files (x86) SSD\bin\avutil-51.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\NETGEAR\WNDA3100v2\WNDA3100v2.exe ()
MOD - C:\Program Files (x86)\NETGEAR\WNDA3100v2\WifiSvcLib.dll ()
MOD - F:\Program Files (x86) SSD\AutoRip\Extender Rip Monitor.exe ()
MOD - C:\Windows\system\CMGxMon.exe ()


========== Services (SafeList) ==========

SRV:64bit: - (ReflectService.exe) – C:\Program Files\Macrium\Reflect\ReflectService.exe ()
SRV:64bit: - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV:64bit: - (mfevtp) – C:\Windows\SysNative\mfevtps.exe (McAfee, Inc.)
SRV:64bit: - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
SRV:64bit: - (McProxy) – C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (mcpltsvc) – C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McNaiAnn) – C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McMPFSvc) – C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (HomeNetSvc) – C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (mfecore) – C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe (McAfee, Inc.)
SRV:64bit: - (McAfee SiteAdvisor Service) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (Intel® – C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel® Corporation)
SRV:64bit: - (BTHSSecurityMgr) – C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Intel® Corporation)
SRV:64bit: - (EvtEng) – C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV:64bit: - (MyWiFiDHCPDNS) – C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe ()
SRV:64bit: - (RegSrvc) – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV:64bit: - (AMPPALR3) – C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel Corporation)
SRV:64bit: - (Intel® – C:\Windows\SysNative\IPROSetMonitor.exe (Intel Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (LicCtrlService) – C:\Windows\Runservice.exe ()
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (PDF Architect Helper Service) – C:\Program Files (x86)\PDF Architect\HelperService.exe (pdfforge GbR)
SRV - (PDF Architect Service) – C:\Program Files (x86)\PDF Architect\ConversionService.exe (pdfforge GbR)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (Bluetooth OBEX Service) – C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Motorola Solutions, Inc.)
SRV - (Bluetooth Media Service) – C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Motorola Solutions, Inc.)
SRV - (Bluetooth Device Monitor) – C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Motorola Solutions, Inc.)
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (Creative ALchemy AL6 Licensing Service) – C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe (Creative Labs)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (UNS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (jhi_service) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe (Intel Corporation)
SRV - (IAStorDataMgrSvc) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (WSWNDA3100) – C:\Program Files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe ()
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SwitchBoard) – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (CTAudSvcService) – C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (tap0901) – C:\Windows\SysNative\drivers\tap0901.sys (The OpenVPN Project)
DRV:64bit: - (IDMWFP) – C:\Windows\SysNative\drivers\idmwfp.sys (Tonec Inc.)
DRV:64bit: - (cfwids) – C:\Windows\SysNative\drivers\cfwids.sys (McAfee, Inc.)
DRV:64bit: - (mfewfpk) – C:\Windows\SysNative\drivers\mfewfpk.sys (McAfee, Inc.)
DRV:64bit: - (mfehidk) – C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.)
DRV:64bit: - (mfefirek) – C:\Windows\SysNative\drivers\mfefirek.sys (McAfee, Inc.)
DRV:64bit: - (mfeavfk) – C:\Windows\SysNative\drivers\mfeavfk.sys (McAfee, Inc.)
DRV:64bit: - (mfeapfk) – C:\Windows\SysNative\drivers\mfeapfk.sys (McAfee, Inc.)
DRV:64bit: - (mfencbdc) – C:\Windows\SysNative\drivers\mfencbdc.sys (McAfee, Inc.)
DRV:64bit: - (mfencrk) – C:\Windows\SysNative\drivers\mfencrk.sys (McAfee, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (ibtfltcoex) – C:\Windows\SysNative\drivers\iBtFltCoex.sys (Intel Corporation)
DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (btmhsf) – C:\Windows\SysNative\drivers\btmhsf.sys (Motorola Solutions, Inc.)
DRV:64bit: - (HipShieldK) – C:\Windows\SysNative\drivers\HipShieldK.sys (McAfee, Inc.)
DRV:64bit: - (btmaux) – C:\Windows\SysNative\drivers\btmaux.sys (Motorola Solutions, Inc.)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (asahci64) – C:\Windows\SysNative\drivers\asahci64.sys (Asmedia Technology)
DRV:64bit: - (iusb3xhc) – C:\Windows\SysNative\drivers\iusb3xhc.sys (Intel Corporation)
DRV:64bit: - (iusb3hub) – C:\Windows\SysNative\drivers\iusb3hub.sys (Intel Corporation)
DRV:64bit: - (iusb3hcs) – C:\Windows\SysNative\drivers\iusb3hcs.sys (Intel Corporation)
DRV:64bit: - (ASEUSBCC) – C:\Windows\SysNative\drivers\AseUSBCC.sys (Silicon Laboratories)
DRV:64bit: - (NETwNs64) – C:\Windows\SysNative\drivers\NETwNs64.sys (Intel Corporation)
DRV:64bit: - (AMPPALP) – C:\Windows\SysNative\drivers\AmpPal.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (AMPPAL) – C:\Windows\SysNative\drivers\AmpPal.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (MEIx64) – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (asmtxhci) – C:\Windows\SysNative\drivers\asmtxhci.sys (ASMedia Technology Inc)
DRV:64bit: - (asmthub3) – C:\Windows\SysNative\drivers\asmthub3.sys (ASMedia Technology Inc)
DRV:64bit: - (athr) – C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (e1cexpress) – C:\Windows\SysNative\drivers\e1c62x64.sys (Intel Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) – C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (BCMH43XX) – C:\Windows\SysNative\drivers\bcmwlhigh664.sys (Broadcom Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (cmudaxp) – C:\Windows\SysNative\drivers\cmudaxp.sys (C-Media Inc)
DRV:64bit: - (SCMNdisP) – C:\Windows\SysNative\drivers\SCMNdisP.sys (Windows ® Codename Longhorn DDK provider)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;

========== FireFox ==========

FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_149.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF:64bit: - HKLM\Software\MozillaPlugins\adobe.com/AdobeExManDetect: E:\Progam Files (x86) HDD\Adobe Extension Manager CS6\npAdobeExManDetectX64.dll (Adobe Systems)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_149.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.13.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.13.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: F:\Program Files (x86) SSD\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeExManDetect: E:\Progam Files (x86) HDD\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll (Adobe Systems)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Rod\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor [2012/12/17 08:25:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2012/12/06 19:41:59 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}: C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ [2012/12/10 18:35:25 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/11/07 19:46:01 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Users\Rod\AppData\Roaming\IDM\idmmzcc5 [2013/01/23 18:47:03 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\[removed]: C:\Users\Rod\AppData\Roaming\IDM\idmmzcc5 [2013/01/23 18:47:03 | 000,000,000 | —D | M]

[2012/11/07 21:03:06 | 000,000,000 | —D | M] (No name found) – C:\Users\Rod\AppData\Roaming\Mozilla\Extensions
[2013/02/09 22:16:27 | 000,000,000 | —D | M] (No name found) – C:\Users\Rod\AppData\Roaming\Mozilla\Firefox\Profiles\863j7af2.default\extensions
[2012/11/03 19:01:14 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/10/24 17:50:58 | 000,261,600 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/10/24 17:50:17 | 000,002,465 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/10/24 17:50:17 | 000,002,058 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: http://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}&sugkey;={google:suggestAPIKeyParameter},
CHR - homepage: http://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\pdf.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Users\Rod\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\McChPlg.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Intel\u00AE Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll
CHR - plugin: Intel\u00AE Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\progra~2\mcafee\msc\npmcsn~1.dll
CHR - Extension: SiteAdvisor = C:\Users\Rod\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.50.146.2_0\
CHR - Extension: AdBlock = C:\Users\Rod\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.60_0\
CHR - Extension: IDM Integration = C:\Users\Rod\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmolcgpienlcieaajfkkdamlngancncm\6.15.2.2_0\
CHR - Extension: Google Mail Checker = C:\Users\Rod\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff\4.4.0_0\
CHR - Extension: Ghostery = C:\Users\Rod\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij\4.1.0_0\

O1 HOSTS File: ([2013/02/19 13:26:02 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll (Internet Download Manager, Tonec Inc.)
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)
O2 - BHO: (PDF Architect Helper) - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GbR)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (PDF Architect Toolbar) - {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files (x86)\PDF Architect\PDFIEPlugin.dll (pdfforge GbR)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [BLEServicesCtrl] C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [BTMTrayAgent] C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll (Motorola Solutions, Inc.)
O4:64bit: - HKLM..\Run: [Cmaudio8788] C:\Windows\Syswow64\cmicnfgp.cpl (C-Media Corporation)
O4:64bit: - HKLM..\Run: [Cmaudio8788GX] C:\Windows\system\CmGxMon.exe ()
O4:64bit: - HKLM..\Run: [IntelPAN] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RunDLLEntry] C:\Windows\SysNative\AmbRunE.DLL (Creative Technology Ltd.)
O4:64bit: - HKLM..\Run: [THXCfg64] C:\Windows\SysNative\THXCfg64.DLL (Creative Technology Ltd.)
O4 - HKLM..\Run: [AdobeCS6ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIconLaunch.exe (Intel Corporation)
O4 - HKLM..\Run: [mcpltui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [THX Audio Control Panel] C:\Program Files (x86)\Creative\Sound Blaster X-Fi MB 2\THXAudioCP\THXAudio.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\Rod\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
O4 - HKCU..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.)
O4 - HKCU..\Run: [LCLC Control Panel] C:\Program Files (x86)\Thermaltake\Fan Control Software\Fan Control Software.exe (Thermaltake)
O4 - HKCU..\Run: [Spotify Web Helper] C:\Users\Rod\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
O4 - HKCU..\Run: [Steam] F:\Program Files (x86) SSD\steam.exe (Valve Corporation)
O4 - HKCU..\Run: [THPanel] C:\Program Files (x86)\Thunder Master\THPanel.exe (Palit Microsystems Ltd.)
O4 - HKCU..\Run: [uTorrent] C:\Program Files (x86)\uTorrent.exe (BitTorrent, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8:64bit: - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Rod\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8:64bit: - Extra context menu item: Send to Bluetooth - C:\Program Files (x86)\Intel\Bluetooth\btSendToObject.htm ()
O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Rod\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Send to Bluetooth - C:\Program Files (x86)\Intel\Bluetooth\btSendToObject.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5061F7A1-BA9C-4C3D-87FD-BA07139AE9F2}: DhcpNameServer = 8.8.8.8 8.8.4.4
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9FEAF9FC-A8F7-4631-8442-A4FB26678DF6}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E23F2CFA-033A-4EBA-A059-DF7FFE434206}: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18:64bit: - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll (McAfee, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/02/20 19:07:48 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Rod\Desktop\OTL.exe
[2013/02/19 18:12:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2013/02/19 18:12:16 | 002,347,384 | —- | C] (ESET) – C:\Users\Rod\Desktop\esetsmartinstaller_enu.exe
[2013/02/19 13:28:00 | 000,000,000 | —D | C] – C:\Windows\temp
[2013/02/19 13:26:03 | 000,000,000 | —D | C] – C:\$RECYCLE.BIN
[2013/02/19 13:21:32 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2013/02/19 13:21:32 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2013/02/19 13:21:32 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2013/02/19 13:21:28 | 000,000,000 | —D | C] – C:\Qoobox
[2013/02/19 13:21:23 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2013/02/19 08:44:03 | 005,034,457 | R— | C] (Swearware) – C:\Users\Rod\Desktop\ComboFix.exe
[2013/02/18 20:05:28 | 000,000,000 | —D | C] – C:\Users\Rod\AppData\Roaming\Malwarebytes
[2013/02/18 20:05:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/02/18 20:04:58 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/02/18 20:04:44 | 000,024,176 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2013/02/18 20:04:44 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/02/17 21:25:05 | 002,736,640 | —- | C] (Atheros Communications, Inc.) – C:\Windows\SysNative\drivers\athrx.sys
[2013/02/17 21:25:05 | 002,736,640 | —- | C] (Atheros Communications, Inc.) – C:\Windows\SysNative\athrx.sys
[2013/02/17 21:25:05 | 000,000,000 | —D | C] – C:\Windows\Options
[2013/02/17 21:24:51 | 000,000,000 | —D | C] – C:\ProgramData\TP-LINK
[2013/02/15 20:37:54 | 000,969,104 | —- | C] (BitTorrent, Inc.) – C:\Program Files (x86)\uTorrent.exe
[2013/02/15 20:26:22 | 000,000,000 | —D | C] – C:\Users\Rod\AppData\Local\Shareaza
[2013/02/15 20:26:17 | 000,000,000 | —D | C] – C:\Users\Rod\AppData\Roaming\Shareaza
[2013/02/15 02:05:05 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2013/02/14 08:19:07 | 000,000,000 | —D | C] – C:\ProgramData\IDM
[2013/02/13 12:43:37 | 005,553,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2013/02/13 12:43:36 | 003,967,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2013/02/13 12:43:36 | 003,913,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2013/02/13 12:43:21 | 000,735,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/02/13 12:43:20 | 000,097,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/02/13 12:43:20 | 000,067,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/02/13 12:43:19 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/02/13 12:43:19 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/02/13 12:43:19 | 000,134,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/02/13 12:43:19 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/02/13 12:43:12 | 000,215,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2013/02/13 12:43:12 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2013/02/13 12:43:11 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2013/02/13 12:43:11 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2013/02/13 12:43:11 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2013/02/13 12:43:09 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2013/02/13 12:43:07 | 000,288,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\FWPKCLNT.SYS
[2013/02/11 20:38:22 | 000,000,000 | —D | C] – F:\My Documents SSD\Reflect
[2013/02/10 00:43:25 | 000,000,000 | —D | C] – C:\Users\Rod\AppData\Local\Sidhe
[2013/02/09 18:06:04 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thermaltake Technology Inc
[2013/02/09 18:06:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Thermaltake
[2013/02/09 16:22:47 | 000,000,000 | —D | C] – C:\ProgramData\Macrium
[2013/02/09 16:22:33 | 000,000,000 | —D | C] – C:\Users\Rod\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Macrium
[2013/02/09 16:22:32 | 000,000,000 | —D | C] – C:\Program Files\Macrium
[2013/02/09 16:22:32 | 000,000,000 | —D | C] – C:\boot
[2013/02/09 16:18:24 | 000,000,000 | —D | C] – C:\Users\Rod\Downloads
[2013/02/08 20:31:14 | 000,262,560 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013/02/08 20:31:12 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/02/08 20:31:12 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013/02/08 20:31:12 | 000,095,648 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/01/31 13:42:38 | 000,013,944 | —- | C] (Paramount Software UK Ltd) – C:\Windows\SysNative\drivers\PSVolAcc.sys
[2013/01/30 23:36:08 | 000,000,000 | —D | C] – C:\Users\Rod\AppData\Roaming\JAM Software
[2013/01/30 23:18:13 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Core Temp
[2013/01/30 23:18:13 | 000,000,000 | —D | C] – C:\Program Files\Core Temp
[2013/01/29 12:03:10 | 000,165,112 | —- | C] (Tonec Inc.) – C:\Windows\SysNative\drivers\idmwfp.sys
[2013/01/21 22:26:49 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cyanide

========== Files - Modified Within 30 Days ==========

[2013/02/20 19:11:07 | 000,000,888 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/02/20 18:58:01 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/02/20 18:58:01 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/02/20 18:57:59 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/02/19 18:11:58 | 002,347,384 | —- | M] (ESET) – C:\Users\Rod\Desktop\esetsmartinstaller_enu.exe
[2013/02/19 18:10:15 | 000,022,080 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/02/19 18:10:15 | 000,022,080 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/02/19 18:09:01 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/02/19 18:09:01 | 000,628,024 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/02/19 18:09:01 | 000,110,208 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/02/19 18:03:10 | 000,001,729 | -HS- | M] () – C:\Windows\SysWow64\mmf.sys
[2013/02/19 18:03:06 | 2103,717,887 | -HS- | M] () – C:\hiberfil.sys
[2013/02/19 13:26:02 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2013/02/19 08:43:39 | 005,034,457 | R— | M] (Swearware) – C:\Users\Rod\Desktop\ComboFix.exe
[2013/02/18 21:37:07 | 000,625,664 | —- | M] () – C:\Users\Rod\Desktop\dds.scr
[2013/02/18 21:18:21 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Rod\Desktop\OTL.exe
[2013/02/18 20:05:15 | 000,001,109 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/02/17 21:23:11 | 000,969,104 | —- | M] (BitTorrent, Inc.) – C:\Program Files (x86)\uTorrent.exe
[2013/02/15 20:37:54 | 000,000,854 | —- | M] () – C:\Users\Rod\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2013/02/15 20:36:32 | 000,020,535 | —- | M] () – C:\Users\Rod\AppData\Local\soulseek-client.dat.1360960592054
[2013/02/13 18:37:51 | 004,967,192 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/02/09 19:56:34 | 000,697,712 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/02/09 19:56:34 | 000,074,096 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/02/09 18:44:31 | 000,000,866 | —- | M] () – C:\Windows\SysWow64\InstallUtil.InstallLog
[2013/02/09 18:06:04 | 000,002,795 | —- | M] () – C:\Users\Public\Desktop\Fan Control Software.lnk
[2013/02/09 16:22:33 | 000,002,919 | —- | M] () – C:\Users\Rod\Desktop\Reflect.lnk
[2013/02/08 20:31:10 | 000,262,560 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013/02/08 20:31:10 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/02/08 20:31:10 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013/02/08 20:31:10 | 000,095,648 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/02/08 20:31:09 | 000,861,088 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\npDeployJava1.dll
[2013/02/08 20:31:09 | 000,782,240 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\deployJava1.dll
[2013/02/06 19:05:42 | 000,025,813 | —- | M] () – F:\My Documents SSD\CT-Log 2013-02-05 22-32-10_Updated.csv
[2013/01/31 13:42:38 | 000,013,944 | —- | M] (Paramount Software UK Ltd) – C:\Windows\SysNative\drivers\PSVolAcc.sys
[2013/01/31 13:42:16 | 000,057,976 | —- | M] () – C:\Windows\SysNative\drivers\psmounterex.sys
[2013/01/30 23:18:13 | 000,000,948 | —- | M] () – C:\Users\Rod\Desktop\Core Temp.lnk
[2013/01/21 22:26:49 | 000,001,224 | —- | M] () – C:\Users\Public\Desktop\PCM12.lnk

========== Files Created - No Company Name ==========

[2013/02/19 13:21:32 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/02/19 13:21:32 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/02/19 13:21:32 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/02/19 13:21:32 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/02/19 13:21:32 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2013/02/18 23:13:52 | 000,625,664 | —- | C] () – C:\Users\Rod\Desktop\dds.scr
[2013/02/18 20:05:15 | 000,001,109 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/02/17 21:25:05 | 000,068,879 | —- | C] () – C:\Windows\SysNative\netathrx.inf
[2013/02/17 21:25:05 | 000,007,944 | —- | C] () – C:\Windows\SysNative\athrextx.cat
[2013/02/15 20:36:32 | 000,020,535 | —- | C] () – C:\Users\Rod\AppData\Local\soulseek-client.dat.1360960592054
[2013/02/09 18:06:04 | 000,002,795 | —- | C] () – C:\Users\Public\Desktop\Fan Control Software.lnk
[2013/02/09 16:22:33 | 000,002,919 | —- | C] () – C:\Users\Rod\Desktop\Reflect.lnk
[2013/02/09 16:18:06 | 000,000,866 | —- | C] () – C:\Windows\SysWow64\InstallUtil.InstallLog
[2013/02/06 19:05:42 | 000,025,813 | —- | C] () – F:\My Documents SSD\CT-Log 2013-02-05 22-32-10_Updated.csv
[2013/01/31 13:42:16 | 000,057,976 | —- | C] () – C:\Windows\SysNative\drivers\psmounterex.sys
[2013/01/30 23:18:13 | 000,000,948 | —- | C] () – C:\Users\Rod\Desktop\Core Temp.lnk
[2013/01/21 22:26:49 | 000,001,224 | —- | C] () – C:\Users\Public\Desktop\PCM12.lnk
[2012/12/20 01:52:09 | 000,048,640 | —- | C] () – C:\Windows\mmfs.dll
[2012/12/20 01:52:09 | 000,002,560 | —- | C] () – C:\Windows\Runservice.exe
[2012/12/20 01:52:09 | 000,001,729 | -HS- | C] () – C:\Windows\SysWow64\mmf.sys
[2012/11/18 23:17:30 | 000,001,456 | —- | C] () – C:\Users\Rod\AppData\Local\Adobe Save for Web 13.0 Prefs
[2012/11/10 15:57:23 | 000,139,264 | R— | C] () – C:\Windows\SysWow64\VmixP8.dll
[2012/11/10 15:57:16 | 000,036,425 | —- | C] () – C:\Windows\Cmicnfgp.ini.cfl
[2012/11/10 15:57:09 | 000,004,967 | —- | C] () – C:\Windows\Cmicnfgp.ini.cfg
[2012/11/10 15:57:09 | 000,000,793 | —- | C] () – C:\Windows\Cmicnfgp.ini.imi
[2012/03/11 22:32:32 | 000,000,000 | —- | C] () – C:\Users\Rod\AppData\Local\{7E0AAE5A-0FD1-411D-9B59-4F2349C50368}
[2012/03/11 22:29:27 | 000,007,594 | —- | C] () – C:\Windows\SysWow64\xFiMB2CfgUninstall32.ini
[2012/03/11 22:29:27 | 000,005,135 | —- | C] () – C:\Windows\SysWow64\cfgfx.ini
[2012/03/11 22:29:27 | 000,002,775 | —- | C] () – C:\Windows\FF08_Render_Spk.ini
[2012/03/11 22:29:27 | 000,002,411 | —- | C] () – C:\Windows\FF08_Render_Hp.ini
[2012/03/11 22:29:27 | 000,002,267 | —- | C] () – C:\Windows\FF08_Capture.ini
[2012/03/11 22:29:27 | 000,001,542 | —- | C] () – C:\Windows\FF08_Render.ini
[2012/03/11 22:29:25 | 000,001,200 | —- | C] () – C:\Windows\THXCfg_SP_APOIM.ini
[2012/03/11 22:29:25 | 000,001,099 | —- | C] () – C:\Windows\THXCfg_HP_APOIM.ini
[2012/03/11 22:29:25 | 000,001,099 | —- | C] () – C:\Windows\THXCfg_APOIM.ini
[2012/03/11 22:29:23 | 000,181,760 | —- | C] () – C:\Windows\SysWow64\APOMngr.DLL
[2012/03/11 22:29:23 | 000,073,728 | —- | C] () – C:\Windows\SysWow64\CmdRtr.DLL
[2012/03/11 21:24:39 | 000,066,887 | —- | C] () – C:\Windows\Ascd_log.ini
[2012/03/11 21:23:14 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2012/03/11 21:23:10 | 000,051,145 | —- | C] () – C:\Windows\Ascd_tmp.ini
[2012/02/02 22:08:26 | 000,001,536 | —- | C] () – C:\Windows\SysWow64\IusEventLog.dll

========== ZeroAccess Check ==========

[2009/07/14 04:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/09 05:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/09 04:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/14 01:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/21 03:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/14 01:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2012/12/06 19:42:01 | 000,000,000 | —D | M] – C:\Users\Rod\AppData\Roaming\APP_NAME_NON_STRING
[2012/11/10 15:57:34 | 000,000,000 | —D | M] – C:\Users\Rod\AppData\Roaming\ASUS
[2012/11/18 23:52:24 | 000,000,000 | —D | M] – C:\Users\Rod\AppData\Roaming\Atari
[2012/11/17 14:22:27 | 000,000,000 | —D | M] – C:\Users\Rod\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2013/02/19 13:25:23 | 000,000,000 | —D | M] – C:\Users\Rod\AppData\Roaming\DMCache
[2012/12/10 18:35:29 | 000,000,000 | —D | M] – C:\Users\Rod\AppData\Roaming\DVDVideoSoft
[2012/12/10 18:35:29 | 000,000,000 | —D | M] – C:\Users\Rod\AppData\Roaming\DVDVideoSoftIEHelpers
[2013/02/06 18:52:25 | 000,000,000 | —D | M] – C:\Users\Rod\AppData\Roaming\HandBrake
[2013/02/14 08:18:18 | 000,000,000 | —D | M] – C:\Users\Rod\AppData\Roaming\IDM
[2013/02/09 18:45:07 | 000,000,000 | —D | M] – C:\Users\Rod\AppData\Roaming\JAM Software
[2012/12/03 01:20:20 | 000,000,000 | —D | M] – C:\Users\Rod\AppData\Roaming\MediaMonkey
[2012/12/29 23:31:31 | 000,000,000 | —D | M] – C:\Users\Rod\AppData\Roaming\mkvtoolnix
[2012/11/17 15:36:00 | 000,000,000 | —D | M] – C:\Users\Rod\AppData\Roaming\PDAppFlex
[2013/02/09 22:34:31 | 000,000,000 | —D | M] – C:\Users\Rod\AppData\Roaming\Pro Cycling Manager 2012
[2013/02/15 20:31:54 | 000,000,000 | —D | M] – C:\Users\Rod\AppData\Roaming\Shareaza
[2012/11/03 21:19:40 | 000,000,000 | —D | M] – C:\Users\Rod\AppData\Roaming\Sports Interactive
[2012/12/05 03:12:53 | 000,000,000 | —D | M] – C:\Users\Rod\AppData\Roaming\Spotify
[2012/11/03 20:04:37 | 000,000,000 | —D | M] – C:\Users\Rod\AppData\Roaming\TeraCopy
[2013/01/20 16:24:55 | 000,000,000 | —D | M] – C:\Users\Rod\AppData\Roaming\Titanium
[2013/02/19 18:05:33 | 000,000,000 | —D | M] – C:\Users\Rod\AppData\Roaming\uTorrent

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2011/02/26 05:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011/02/25 06:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\erdnt\cache86\explorer.exe
[2011/02/25 06:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 06:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 06:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/21 03:24:25 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/02/25 05:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 05:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/11/21 03:24:11 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

< MD5 for: SVCHOST.EXE >
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009/07/14 01:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\erdnt\cache86\svchost.exe
[2009/07/14 01:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\SysWOW64\svchost.exe
[2009/07/14 01:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009/07/14 01:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\erdnt\cache64\svchost.exe
[2009/07/14 01:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\SysNative\svchost.exe
[2009/07/14 01:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/21 03:23:55 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\erdnt\cache86\userinit.exe
[2010/11/21 03:23:55 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\SysWOW64\userinit.exe
[2010/11/21 03:23:55 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010/11/21 03:24:28 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\erdnt\cache64\userinit.exe
[2010/11/21 03:24:28 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\SysNative\userinit.exe
[2010/11/21 03:24:28 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010/11/21 03:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\erdnt\cache64\winlogon.exe
[2010/11/21 03:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/21 03:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe

< C:\Windows\assembly\tmp\U\*.* /s >
[2009/07/14 05:08:49 | 000,000,006 | -H– | C] () – C:\Windows\Tasks\SA.DAT
[2009/07/14 05:08:49 | 000,032,636 | —- | C] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2012/03/11 21:24:58 | 000,000,888 | —- | C] () – C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2012/03/11 21:24:58 | 000,000,892 | —- | C] () – C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2012/11/03 14:43:12 | 000,000,830 | —- | C] () – C:\Windows\Tasks\Adobe Flash Player Updater.job

< End of report >

OTL Extras logfile created on: 20/02/2013 19:10:34 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Rod\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

7.95 Gb Total Physical Memory | 6.51 Gb Available Physical Memory | 81.88% Memory free
15.89 Gb Paging File | 12.97 Gb Available in Paging File | 81.65% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 119.14 Gb Total Space | 75.40 Gb Free Space | 63.29% Space Free | Partition Type: NTFS
Drive E: | 1862.89 Gb Total Space | 974.81 Gb Free Space | 52.33% Space Free | Partition Type: NTFS
Drive F: | 476.94 Gb Total Space | 416.01 Gb Free Space | 87.23% Space Free | Partition Type: NTFS

Computer Name: ROD-PC | User Name: Rod | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "F:\Program Files (x86) SSD\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" (VideoLAN)
Directory [Bridge] – E:\Progam Files (x86) HDD\Adobe Bridge CS6 (64 Bit)\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "F:\Program Files (x86) SSD\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" (VideoLAN)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "F:\Program Files (x86) SSD\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" (VideoLAN)
Directory [Bridge] – E:\Progam Files (x86) HDD\Adobe Bridge CS6 (64 Bit)\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "F:\Program Files (x86) SSD\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" (VideoLAN)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{03EB2132-7D76-40B9-9056-691EB3A4B787}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{03FBA484-5C4F-4F6D-A306-EFD8C85517AC}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{091A9614-4453-4C57-A236-684677E2A49B}" = rport=445 | protocol=6 | dir=out | app=system |
"{1C430C6F-5647-42E9-9C8B-BF0FCBD6B0F0}" = lport=137 | protocol=17 | dir=in | app=system |
"{2B3D84B0-C6D9-406D-84B8-672ECAADEB87}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{35F4718B-C3C2-4555-9DD3-E24954BCB798}" = lport=138 | protocol=17 | dir=in | app=system |
"{46DF1E55-C240-497D-AC52-7E8BA6FB35C6}" = lport=10243 | protocol=6 | dir=in | app=system |
"{591F8EE1-89DA-4C9C-93CC-8CD3F6A4A568}" = rport=10243 | protocol=6 | dir=out | app=system |
"{5EE3C51A-8ACF-4301-8DEC-BE8C30DA5C0F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{670DB348-CE46-4575-A645-2F9F1CF14C0B}" = rport=138 | protocol=17 | dir=out | app=system |
"{7B0F7DA5-FB55-4B1D-B998-FD8791128EDB}" = rport=137 | protocol=17 | dir=out | app=system |
"{86E88B2D-A389-49D7-9FC6-40357299F5F1}" = lport=2869 | protocol=6 | dir=in | app=system |
"{8BE2FF42-559A-4C2F-A22D-7636B3DFB6A7}" = lport=139 | protocol=6 | dir=in | app=system |
"{BCB0C6EB-45AB-45DA-A420-A7916C739F4C}" = rport=139 | protocol=6 | dir=out | app=system |
"{C267D2E9-04D3-4327-97BC-875BDD89C762}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{D40A6838-BFA3-4F34-B6C3-E5E84BC3CC43}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{DC907B2C-B9BB-40BD-A2F0-5C01716B19FF}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{DE412512-8240-446D-847B-67D988AA1C6C}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F01895AD-D331-4C45-A62D-27918845E833}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{FCD8E52F-D039-451A-860F-2F616AD7DCA0}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{FF132DA6-06DB-4DB1-A598-D575E272088B}" = lport=445 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0029D2DE-B374-4347-B1EE-00B93007C00A}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{008860B6-6296-4FC7-BD73-5FAE493C2D35}" = protocol=17 | dir=in | app=f:\program files (x86)\cyanide\pro cycling manager - season 2012\autorun\exe\autorun.exe |
"{02393AC8-98BF-4794-848F-EA920FF09A80}" = protocol=6 | dir=in | app=f:\program files (x86) ssd\steamapps\common\sid meier's civilization v\launcher.exe |
"{039A1B7D-21FF-4728-A686-6EC1760DB54D}" = protocol=17 | dir=in | app=f:\program files (x86)\cyanide\pro cycling manager - season 2012\pcm.exe |
"{0573684B-F7CA-4AAB-9A25-E0D84A01391E}" = protocol=6 | dir=in | app=f:\program files (x86) ssd\steamapps\common\xcom-enemy-unknown\binaries\win32\xcomgame.exe |
"{0C172531-AAA7-48F7-AC7B-0FF3D1ECCE6B}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{0D1FA9ED-55A4-4BD7-8621-4EF52EF02C8C}" = protocol=17 | dir=in | app=f:\program files (x86) ssd\steamapps\common\rugbychallenge\rugbychallenge.exe |
"{0FC43399-BEDF-475B-83E1-50BC7F18B550}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{0FEE4122-582E-4637-92C2-19B3B1F9965F}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{114180CB-9015-4406-B78A-0C168C9EB17C}" = protocol=6 | dir=in | app=f:\program files (x86) ssd\pro cycling manager - season 2012\pcm.exe |
"{1DDA765F-C08E-46DF-9380-9215EF6F99CB}" = protocol=17 | dir=in | app=f:\program files (x86) ssd\steamapps\common\rollercoaster tycoon 3 gold\rct3plus.exe |
"{2152EB24-8B30-4355-8FC7-4262C0F3A0F5}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\platform\mcsvchost\mcsvhost.exe |
"{24C62733-2753-42A5-ABED-0BA0C642E4C6}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{30AF59BA-A367-4755-A624-BE957E5FEADB}" = protocol=17 | dir=in | app=f:\program files (x86) ssd\pro cycling manager - season 2012\autorun\exe\autorun.exe |
"{35A366F4-4EFC-4E74-8674-918F76EC2FF8}" = protocol=17 | dir=in | app=f:\program files (x86) ssd\steamapps\common\rugbychallenge\tools\rugbychallengesettingseditor.exe |
"{36A020BD-5375-49AE-A7F3-B5EA63A43D74}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\platform\mcsvchost\mcsvhost.exe |
"{41329FFD-B9EB-44EE-A89C-795CE41FE8CE}" = protocol=17 | dir=in | app=f:\program files (x86) ssd\steamapps\common\simcity 4 deluxe\support\ea help\electronic_arts_technical_support.htm |
"{46A3EC52-409D-421C-B982-A96BA9A02569}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{48DB29F6-6CC7-48C2-99BD-7841343A43C7}" = protocol=6 | dir=in | app=f:\program files (x86) ssd\steamapps\common\rollercoaster tycoon 3 gold\rct3plus.exe |
"{4FCD7971-4ACA-4FE6-A43C-731CC12E0054}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{528D360C-1368-460D-97BB-7E72E980A8F4}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{5341A1BE-8DD9-4DA0-8DF6-D953544ECCB0}" = protocol=6 | dir=in | app=f:\program files (x86) ssd\steamapps\common\rugbychallenge\tools\rugbychallengesettingseditor.exe |
"{58F270AF-29BF-403E-824D-D4060557A438}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{6607850F-3B8B-4608-9E74-A88C64F5CC2C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{68D85AED-92D2-4F11-89E6-EF4CBCC0B435}" = protocol=6 | dir=in | app=f:\program files (x86) ssd\steamapps\common\football manager 2013\fm.exe |
"{68E6A1D0-DBDB-48F6-BF76-10CE53DA76E9}" = dir=in | app=c:\program files\intel\wifi\bin\pandhcpdns.exe |
"{692BF6F8-9BF3-454D-AAF9-7234CD4C558A}" = protocol=6 | dir=in | app=f:\program files (x86) ssd\steamapps\common\rollercoaster tycoon 3 gold\rct3plus.exe |
"{6CDB8F8C-AAB0-4F8F-8932-107D5E30748A}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent.exe |
"{6E434481-CC25-469B-862F-9DE08716D971}" = protocol=6 | dir=in | app=f:\program files (x86)\cyanide\pro cycling manager - season 2012\autorun\exe\autorun.exe |
"{6F79B034-EC9C-4E0B-8D33-9706E6FCD743}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{742DFD53-679C-451F-99D4-8A1C6EF07477}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{7B415648-C718-417D-B746-013A1B7B8888}" = protocol=17 | dir=in | app=f:\program files (x86) ssd\steamapps\common\football manager 2013 editor\editor.exe |
"{7CAA124F-EE81-448E-A701-51CAABB744CA}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{7E27C05D-8CDE-467D-93B8-A568EBC4047A}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{8174895D-6A1D-4ADB-93E3-10C00BB1BAC1}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{85F2D1E3-97CD-4D90-BB3B-0E252AB4B9D2}" = protocol=17 | dir=in | app=f:\program files (x86) ssd\steam.exe |
"{875712BB-EDCD-4C2E-88EE-513A38B90F3A}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{8CE538BE-33B3-4005-8229-61CEFC3AD77C}" = protocol=17 | dir=in | app=f:\program files (x86) ssd\steamapps\common\xcom-enemy-unknown\binaries\win32\xcomgame.exe |
"{8D140282-79D3-4DA7-BAEF-23877A9D3253}" = protocol=6 | dir=in | app=f:\program files (x86) ssd\steamapps\common\rugbychallenge\rugbychallenge.exe |
"{8E134CA8-20D3-4607-9198-6D4AB6E2036A}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{92B1E61D-0B7D-43E2-8811-FBFD390528BC}" = protocol=6 | dir=in | app=f:\program files (x86) ssd\steamapps\common\simcity 4 deluxe\apps\simcity 4.exe |
"{95208950-F157-4D0E-9DDD-593AEAB9652E}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{96BAA0F3-2BF6-4F47-A731-AD767CF9D5C3}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{9D5E468D-CACA-4BA4-AB0C-C3BB4532701B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{A36E1C89-F98C-44FF-960D-9B1ECA56209C}" = protocol=17 | dir=in | app=f:\program files (x86) ssd\steamapps\common\simcity 4 deluxe\apps\simcity 4.exe |
"{A8918683-E4AE-4A90-8B80-24184CACE97C}" = protocol=17 | dir=in | app=f:\program files (x86) ssd\pro cycling manager - season 2012\pcm.exe |
"{A8EAC731-B3D4-48FF-842B-A89AFA62B694}" = protocol=17 | dir=in | app=f:\program files (x86) ssd\steamapps\common\f1 2012\f1_2012.exe |
"{AF8DEC69-3279-4619-91E4-CF89917318B2}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{B64CAA04-4BE9-4E2E-B549-ACAD0A0DD8EA}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent.exe |
"{C28CAFAC-B610-4297-9967-5339C77ED9F7}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{C2FB40D1-D9A8-45C6-A630-9EA90AEA2C41}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{C7438A5A-B12B-49AC-89CB-36F9600841F9}" = protocol=6 | dir=in | app=f:\program files (x86) ssd\steamapps\common\f1 2012\f1_2012.exe |
"{C79BEB8A-2C66-4AA9-81AA-CF40948CF392}" = protocol=6 | dir=in | app=f:\program files (x86) ssd\steamapps\common\simcity 4 deluxe\support\ea help\electronic_arts_technical_support.htm |
"{D04E3323-9E2A-4F0E-B47D-C2155951F4D9}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{D17A4A14-3A06-4457-983B-7467C2D3E2B0}" = protocol=6 | dir=in | app=f:\program files (x86)\cyanide\pro cycling manager - season 2012\pcm.exe |
"{D7AC8DBF-6E43-4BBC-B7AD-B8700CE6E299}" = protocol=6 | dir=out | app=system |
"{DD52934D-0D62-4577-BF61-34B604857A62}" = protocol=6 | dir=in | app=f:\program files (x86) ssd\steamapps\common\rollercoaster tycoon 3 gold\rct3plus.exe |
"{DED09F16-F34C-4916-B41C-9C752D384945}" = protocol=17 | dir=in | app=f:\program files (x86) ssd\steamapps\common\sid meier's civilization v\launcher.exe |
"{E0BA7597-9CC4-4C41-A188-336859D472E2}" = protocol=6 | dir=in | app=f:\program files (x86) ssd\steam.exe |
"{E6232410-9D2D-411E-9520-2CC1DE1788C0}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{E6850631-1CF1-4418-B0AB-1691F8C94E01}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{EBF9C8E5-D16D-45F0-A15B-2CF42145C4F5}" = protocol=6 | dir=in | app=f:\program files (x86) ssd\steamapps\common\rollercoaster tycoon 3 gold\rct3plus.exe |
"{F00BDD52-4DAF-439A-AE3E-47AF87C26DBD}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{F255DDA6-70A0-47B9-AE7A-E3F1C1DB8049}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F4433B22-90B0-4827-B32D-63F294891874}" = protocol=6 | dir=in | app=f:\program files (x86) ssd\pro cycling manager - season 2012\autorun\exe\autorun.exe |
"{F5AC3B17-A4A2-42C0-881F-8F861B547C17}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{F62C346D-0D7E-4525-B9EE-64F5D478A4C4}" = protocol=17 | dir=in | app=f:\program files (x86) ssd\steamapps\common\football manager 2013\fm.exe |
"{F8990DAB-4C5C-402A-BDA7-BF6CEA8F1ED0}" = protocol=6 | dir=in | app=f:\program files (x86) ssd\steamapps\common\football manager 2013 editor\editor.exe |
"{FC7BE424-CC3C-4B4A-A9B6-FCEDBF9D9F9E}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{FF6B69E7-4C44-41C8-B59E-106638DC2341}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1" = Core Temp 1.0 RC4
"{09536BA1-E498-4CC3-B834-D884A67D7E34}" = Intel® Trusted Connect Service Client
"{0E5D76AD-A3FB-48D5-8400-8903B10317D3}" = iTunes
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{26A24AE4-039D-4CA4-87B4-2F86417009FF}" = Java 7 Update 9 (64-bit)
"{357A82F9-B5FF-46C8-ABA2-104695E0F1D1}" = Intel® Network Connections [removed]
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}" = Paint.NET v3.5.10
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{A10B1524-63B5-40F2-B272-D841CF671C16}" = Intel® PROSet/Wireless Software for Bluetooth® Technology
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 310.90
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 310.90
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 310.90
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 310.90
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.12.1031
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.11.3
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver 1.3.18.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{D70884EA-E2CE-4539-91DB-4766CC1E5F5F}" = Apple Mobile Device Support
"{E7DC06A3-8516-4929-B712-80987AFFFB57}" = Intel® PROSet/Wireless WiFi Software
"{E9220B1F-33C4-4A89-B34D-38374CFBE2CF}" = Macrium Reflect Free Edition
"{EF79C448-6946-4D71-8134-03407888C054}" = Shared C Run-time for x64
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"C-Media Oxygen HD Audio Driver" = ASUS Xonar DX Audio Driver
"CPUID HWMonitor_is1" = CPUID HWMonitor 1.20
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"ProInst" = Intel PROSet Wireless
"PROSetDX" = Intel® Network Connections 16.6.126.0
"TeraCopy_is1" = TeraCopy 2.27

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{14DC0059-00F1-4F62-BD1A-AB23CD51A95E}" = Adobe AIR
"{1845470B-EB14-4ABC-835B-E36C693DC07D}" = Skype™ 6.0
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2397CAD4-2263-4CD0-96BE-E43A980B9C9A}_is1" = Geeks3D.com FurMark 1.10.3
"{240C3DDD-C5E9-4029-9DF7-95650D040CF2}" = Intel® USB 3.0 eXtensible Host Controller Driver
"{26A24AE4-039D-4CA4-87B4-2F83217013FF}" = Java 7 Update 13
"{30B41B7A-3C9D-44DE-A7A1-949011F33CC3}" = PDF Architect
"{385C8E5A-0B4F-4DCD-BBBD-2A8AE0400A76}" = TP-LINK Wireless Client Utility
"{3C7839E7-21F4-49E0-B4D5-AC8ED818CCB0}" = NETGEAR WNDA3100v2 wireless USB 2.0 adapter
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{43181C5F-23EF-4B5C-9AB4-11DD7F979768}" = AutoRipNCompress
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{61942EF5-2CD8-47D4-869C-2E9A8BB085F1}" = Asmedia ASM106x SATA Host Controller Driver
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}" = Adobe Photoshop CS6
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7D72DAFF-DCB2-437B-BC22-4B2ABF21462B}" = Private Internet Access Support Files
"{89F922D6-E3E0-4303-AF8E-CE18412E3A18}" = Sound Blaster X-Fi MB 2
"{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}" = NVIDIA PhysX
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0409-1000-0000000FF1CE}_Office14.SingleImage_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.SingleImage_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0116-0409-1000-0000000FF1CE}_Office14.SingleImage_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{944B1F23-53F4-48C6-80A6-8D764DFFB8F3}" = Fan Control Software
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.01)
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}" = PDF Settings CS6
"{C779648B-410E-4BBA-B75B-5815BCEFE71D}" = Safari
"{CCE825DB-347A-4004-A186-5F4A6FDD8547}" = Apple Application Support
"{DFAEC123-FE78-4305-879C-4994BC4C56F8}" = Fan Control Driver x64
"{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}" = Asmedia ASM104x USB 3.0 Host Controller Driver
"{EE04522C-0814-4B63-AE57-0B63E5A355BB}_is1" = Thunder Master v1.3
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Cycledog Tree Mod" = Cycledog Tree Mod 1.0 english
"DVD Shrink_is1" = DVD Shrink 3.2
"DVDFab 8 Qt_is1" = DVDFab 8.2.2.5 (14/12/2012) Qt
"ESET Online Scanner" = ESET Online Scanner v3
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.11.36.1201
"Google Chrome" = Google Chrome
"HaaliMkx" = Haali Media Splitter
"HandBrake" = HandBrake 0.9.8
"Internet Download Manager" = Internet Download Manager
"MakeMKV" = MakeMKV v1.7.10
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100
"MKVToolNix" = MKVToolNix 5.9.0
"Mozilla Firefox 16.0.2 (x86 en-US)" = Mozilla Firefox 16.0.2 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MSC" = McAfee AntiVirus Plus
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Office14.SingleImage" = Microsoft Office Home and Student 2010
"OpenAL" = OpenAL
"Pro Cycling Manager 2012_is1" = Pro Cycling Manager - Season 2012 version 1.4.0.0
"ProInst" = Intel PROSet Wireless
"Revo Uninstaller" = Revo Uninstaller 1.94
"Steam App 200510" = XCOM: Enemy Unknown
"Steam App 207890" = Football Manager 2013
"Steam App 20840" = Rugby Challenge
"Steam App 208500" = F1 2012
"Steam App 220600" = Football Manager 2013 Editor
"Steam App 24780" = SimCity 4 Deluxe
"Steam App 2700" = RollerCoaster Tycoon 3: Platinum!
"Steam App 8930" = Sid Meier's Civilization V
"TEW2013" = TEW2013
"uTorrent" = µTorrent
"VLC media player" = VLC media player 2.0.5
"Windows Essentials Media Codec Pack" = Windows Essentials Media Codec Pack 4.0 [64-Bit]

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"543994425.go.sky.com" = Sky Go Desktop
"Akamai" = Akamai NetSession Interface
"Network Addon Mod" = Network Addon Mod Version 30 with Essentials r132
"RealHighway Mod" = RealHighway Mod Version 5.0.0
"Spotify" = Spotify
"UnityWebPlayer" = Unity Web Player

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 20/02/2013 04:51:43 | Computer Name = Rod-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 3994

Error - 20/02/2013 04:51:44 | Computer Name = Rod-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 20/02/2013 04:51:44 | Computer Name = Rod-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 5024

Error - 20/02/2013 04:51:44 | Computer Name = Rod-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 5024

Error - 20/02/2013 04:51:45 | Computer Name = Rod-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 20/02/2013 04:51:45 | Computer Name = Rod-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 6022

Error - 20/02/2013 04:51:45 | Computer Name = Rod-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 6022

Error - 20/02/2013 14:57:57 | Computer Name = Rod-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 20/02/2013 14:57:57 | Computer Name = Rod-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 36377967

Error - 20/02/2013 14:57:57 | Computer Name = Rod-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 36377967

Error - 20/02/2013 15:07:47 | Computer Name = Rod-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "E:\Downloads\Programs\esetsmartinstaller_enu.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

[ Media Center Events ]
Error - 14/01/2013 20:43:55 | Computer Name = Rod-PC | Source = MCUpdate | ID = 0
Description = 00:43:52 - Error connecting to the internet. 00:43:52 - Unable
to contact server..

Error - 18/01/2013 20:00:30 | Computer Name = Rod-PC | Source = MCUpdate | ID = 0
Description = 00:00:29 - Failed to retrieve MCEClientUX (Error: Unable to connect
to the remote server)

Error - 05/02/2013 20:22:06 | Computer Name = Rod-PC | Source = MCUpdate | ID = 0
Description = 00:22:06 - Error connecting to the internet. 00:22:06 - Unable
to contact server..

Error - 05/02/2013 20:22:14 | Computer Name = Rod-PC | Source = MCUpdate | ID = 0
Description = 00:22:11 - Error connecting to the internet. 00:22:11 - Unable
to contact server..

Error - 05/02/2013 21:22:29 | Computer Name = Rod-PC | Source = MCUpdate | ID = 0
Description = 01:22:29 - Error connecting to the internet. 01:22:29 - Unable
to contact server..

Error - 05/02/2013 21:22:44 | Computer Name = Rod-PC | Source = MCUpdate | ID = 0
Description = 01:22:34 - Error connecting to the internet. 01:22:34 - Unable
to contact server..

Error - 05/02/2013 22:22:59 | Computer Name = Rod-PC | Source = MCUpdate | ID = 0
Description = 02:22:59 - Error connecting to the internet. 02:22:59 - Unable
to contact server..

Error - 05/02/2013 22:23:14 | Computer Name = Rod-PC | Source = MCUpdate | ID = 0
Description = 02:23:04 - Error connecting to the internet. 02:23:04 - Unable
to contact server..

Error - 05/02/2013 23:23:29 | Computer Name = Rod-PC | Source = MCUpdate | ID = 0
Description = 03:23:29 - Error connecting to the internet. 03:23:29 - Unable
to contact server..

Error - 05/02/2013 23:23:44 | Computer Name = Rod-PC | Source = MCUpdate | ID = 0
Description = 03:23:34 - Error connecting to the internet. 03:23:34 - Unable
to contact server..

[ System Events ]
Error - 19/02/2013 09:23:27 | Computer Name = Rod-PC | Source = Service Control Manager | ID = 7030
Description = The PEVSystemStart service is marked as an interactive service. However,
the system is configured to not allow interactive services. This service may not
function properly.

Error - 19/02/2013 09:25:01 | Computer Name = Rod-PC | Source = Application Popup | ID = 1060
Description = \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility
with this system. Please contact your software vendor for a compatible version
of the driver.

Error - 19/02/2013 09:25:17 | Computer Name = Rod-PC | Source = Service Control Manager | ID = 7030
Description = The PEVSystemStart service is marked as an interactive service. However,
the system is configured to not allow interactive services. This service may not
function properly.

Error - 19/02/2013 09:25:20 | Computer Name = Rod-PC | Source = Service Control Manager | ID = 7030
Description = The PEVSystemStart service is marked as an interactive service. However,
the system is configured to not allow interactive services. This service may not
function properly.

Error - 19/02/2013 09:28:03 | Computer Name = Rod-PC | Source = Service Control Manager | ID = 7038
Description = The nvUpdatusService service was unable to log on as .\UpdatusUser
with the currently configured password due to the following error: %%1330 To ensure
that the service is configured properly, use the Services snap-in in Microsoft
Management Console (MMC).

Error - 19/02/2013 09:28:03 | Computer Name = Rod-PC | Source = Service Control Manager | ID = 7000
Description = The NVIDIA Update Service Daemon service failed to start due to the
following error: %%1069

Error - 19/02/2013 09:31:37 | Computer Name = Rod-PC | Source = Service Control Manager | ID = 7038
Description = The nvUpdatusService service was unable to log on as .\UpdatusUser
with the currently configured password due to the following error: %%1330 To ensure
that the service is configured properly, use the Services snap-in in Microsoft
Management Console (MMC).

Error - 19/02/2013 09:31:37 | Computer Name = Rod-PC | Source = Service Control Manager | ID = 7000
Description = The NVIDIA Update Service Daemon service failed to start due to the
following error: %%1069

Error - 19/02/2013 14:05:13 | Computer Name = Rod-PC | Source = Service Control Manager | ID = 7038
Description = The nvUpdatusService service was unable to log on as .\UpdatusUser
with the currently configured password due to the following error: %%1330 To ensure
that the service is configured properly, use the Services snap-in in Microsoft
Management Console (MMC).

Error - 19/02/2013 14:05:13 | Computer Name = Rod-PC | Source = Service Control Manager | ID = 7000
Description = The NVIDIA Update Service Daemon service failed to start due to the
following error: %%1069


< End of report >
You appear clean of infections,please do the following.



ComboFix - Cleanup
Time for some housekeeping
  • Click Start…select Run from the menu.
  • Copy and paste the following into the text entry box:
    Combofix /Uninstall
  • Click the OK button. (See image below as reference.)
🖼Click to load external image (Posted Image)









Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.








Here are some recommendations to help you stay clean.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Visit Microsoft often to get the latest updates for your computer.
http://www.update.microsoft.com/



Make sure you are running a FIREWALL.The windows firewall is not sufficient to protect your system. It doesn't monitor outgoing traffic and this is a must.
Please read this article 'Safe Computing Practices'.
So how did I get infected in the first place.

please take a moment to read quietman7's excellent prevention tips in post 3 here
Click >>>> Tips to protect yourself against malware and reduce the potential for re-infection:

Preventing Infections in the Future

Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

  • Avoid gaming sites, underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users. The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications. Read P2P Software User Advisories and Risks of File-Sharing Technology.

Update Non-Microsoft Programs

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.


Thats it you are good to go.Safe surfing

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI