This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Yet another Win32/Small.CA virus [Solved]

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Good day, just want to thank you for reading this over in advance - and thank you for all the help you're providing to people.

Anyway, the other day my action center notifies me that I need to remove Win32/small.CA: " This problem was caused by Win32/Small.CA, a known computer virus." and didn't really give any advice in how to go about that.

I sort of panic and make my Microsoft Security Essentials run all night at full scan - trying to find it. No results. So googled it; and alas and alack no real help there either.

So here I am.


I've used the OTL.exe, and here are the results of that scan:

OTL logfile created on: 21.2.2013 01:27:15 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Ásdis\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 0000040f | Country: Ísland | Language: ISL | Date Format: d.M.yyyy

7,96 Gb Total Physical Memory | 6,48 Gb Available Physical Memory | 81,39% Memory free
15,92 Gb Paging File | 13,89 Gb Available in Paging File | 87,21% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931,41 Gb Total Space | 230,41 Gb Free Space | 24,74% Space Free | Partition Type: NTFS
Drive D: | 3,90 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Drive E: | 931,51 Gb Total Space | 593,88 Gb Free Space | 63,75% Space Free | Partition Type: NTFS
Drive F: | 1863,01 Gb Total Space | 1208,89 Gb Free Space | 64,89% Space Free | Partition Type: NTFS

Computer Name: ASDIS-PC | User Name: Ásdis | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Ásdis\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Bamboo Dock\BambooCore.exe ()
PRC - C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\5ecf01964c70e453d71e5d7653912ff9\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\cb562e2e4f74ae607f1186f6ec50cec7\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\521a6a2a0bdc82ad5f0ec5aecb6b8c82\IAStorCommon.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\c4fa75aed82f50d4a7831755a0c4f7b2\IAStorUtil.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\90b89f6e8032310e9ac72a309fd49e83\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\cf827fe7bc99d9bcf0ba3621054ef527\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\195a77fcc6206f8bb35d419ff2cf0d72\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\Bamboo Dock\BambooCore.exe ()


========== Services (SafeList) ==========

SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (NisSrv) – C:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
SRV:64bit: - (MsMpSvc) – C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (TabletServicePen) – C:\Program Files\Tablet\Pen\Pen_Tablet.exe (Wacom Technology, Corp.)
SRV:64bit: - (TouchServicePen) – C:\Program Files\Tablet\Pen\Pen_TouchService.exe (Wacom Technology, Corp.)
SRV:64bit: - (cFosSpeedS) – C:\Program Files\ASRock\XFast LAN\spd.exe (cFos Software GmbH)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (Hamachi2Svc) – C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (Desura Install Service) – C:\Program Files (x86)\Common Files\Desura\desura_service.exe (Desura Pty Ltd)
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (UMVPFSrv) – C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
SRV - (IAStorDataMgrSvc) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (DAUpdaterSvc) – c:\Program Files (x86)\Steam\steamapps\common\dragon age origins\bin_ship\daupdatersvc.service.exe (BioWare)
SRV - (tbbLoaderService) – C:\Program Files (x86)\thinkbroadband.com\tbbMeter\tbbLoaderService.exe (thinkbroadband.com)
SRV - (rpcapd) – C:\Program Files (x86)\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SwitchBoard) – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (PSSDKLBF) – C:\Windows\SysNative\drivers\pssdklbf.sys (microOLAP Technologies LTD)
DRV:64bit: - (PSSDK42) – C:\Windows\SysNative\drivers\pssdk42.sys (microOLAP Technologies LTD)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (dg_ssudbus) – C:\Windows\SysNative\drivers\ssudbus.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:64bit: - (ssudmdm) – C:\Windows\SysNative\drivers\ssudmdm.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:64bit: - (NisDrv) – C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbGD) – C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (LVUVC64) – C:\Windows\SysNative\drivers\lvuvc64.sys (Logitech Inc.)
DRV:64bit: - (LVRS64) – C:\Windows\SysNative\drivers\lvrs64.sys (Logitech Inc.)
DRV:64bit: - (dtsoftbus01) – C:\Windows\SysNative\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (MEIx64) – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (wacmoumonitor) – C:\Windows\SysNative\drivers\wacmoumonitor.sys (Wacom Technology)
DRV:64bit: - (wacomvhid) – C:\Windows\SysNative\drivers\wacomvhid.sys (Wacom Technology)
DRV:64bit: - (nmwcdnsux64) – C:\Windows\SysNative\drivers\nmwcdnsux64.sys (Nokia)
DRV:64bit: - (nmwcdnsucx64) – C:\Windows\SysNative\drivers\nmwcdnsucx64.sys (Nokia)
DRV:64bit: - (EtronHub3) – C:\Windows\SysNative\drivers\EtronHub3.sys (Etron Technology Inc)
DRV:64bit: - (EtronXHCI) – C:\Windows\SysNative\drivers\EtronXHCI.sys (Etron Technology Inc)
DRV:64bit: - (cFosSpeed) – C:\Windows\SysNative\drivers\cfosspeed6.sys (cFos Software GmbH)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (RTL8169) – C:\Windows\SysNative\drivers\Rtlh64.sys (Realtek )
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (NPF) – C:\Windows\SysNative\drivers\npf.sys (CACE Technologies, Inc.)
DRV:64bit: - (LGVirHid) – C:\Windows\SysNative\drivers\LGVirHid.sys (Logitech Inc.)
DRV:64bit: - (LGBusEnum) – C:\Windows\SysNative\drivers\LGBusEnum.sys (Logitech Inc.)
DRV:64bit: - (MBfilt) – C:\Windows\SysNative\drivers\MBfilt64.sys (Creative Technology Ltd.)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (LGPBTDD) – C:\Windows\SysNative\drivers\LGPBTDD.sys (Logitech Inc.)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (hamachi) – C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV:64bit: - (WDC_SAM) – C:\Windows\SysNative\drivers\wdcsam64.sys (Western Digital Technologies)
DRV:64bit: - (wacommousefilter) – C:\Windows\SysNative\drivers\wacommousefilter.sys (Wacom Technology)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = is-IS
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = E1 5E 70 87 A1 99 CD 01 [binary data]
IE - HKCU\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_149.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_149.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.110.0: File not found
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.122.0: C:\Program Files (x86)\Battlelog Web Plugins\1.122.0\npesnlaunch.dll File not found
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.140.0: C:\Program Files (x86)\Battlelog Web Plugins\1.140.0\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=2.1.2: C:\Program Files (x86)\Battlelog Web Plugins\2.1.2\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.13.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.13.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.10: C:\Program Files (x86)\TabletPlugins\npwacom.dll (Wacom, Inc.)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wtPlugin,version=2.0.0.1: C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Ásdis\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Ásdis\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Ásdis\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKCU\Software\MozillaPlugins\wacom.com/WacomTabletPlugin: C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.07.29 16:16:12 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.05.27 03:00:05 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.07.29 16:16:12 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.05.27 03:00:05 | 000,000,000 | —D | M]

[2012.01.04 19:45:28 | 000,000,000 | —D | M] (No name found) – C:\Users\Ásdis\AppData\Roaming\Mozilla\Extensions
[2012.11.08 01:20:08 | 000,000,000 | —D | M] (No name found) – C:\Users\Ásdis\AppData\Roaming\Mozilla\Firefox\Profiles\wmczw61l.default\extensions
[2012.09.12 19:35:47 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012.09.12 19:35:47 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
[2012.07.29 16:16:12 | 000,136,672 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.06.19 14:45:02 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.06.19 14:45:02 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage:
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter},
CHR - homepage:
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\\u00C1sdis\AppData\Local\Google\Chrome\Application\21.0.1180.75\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\\u00C1sdis\AppData\Local\Google\Chrome\Application\24.0.1312.57\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_270.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\\u00C1sdis\AppData\Local\Google\Chrome\Application\24.0.1312.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\\u00C1sdis\AppData\Local\Google\Chrome\Application\24.0.1312.57\pdf.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: ESN Launch Mozilla Plugin (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\1.122.0\npesnlaunch.dll
CHR - plugin: ESN Sonar API (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll
CHR - plugin: Foxit Reader Plugin for Mozilla (Enabled) = C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Java™ Platform SE 7 U5 (Enabled) = C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 7.0.50.255 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: WacomTabletPlugin (Enabled) = C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll
CHR - plugin: Wacom Dynamic Link Library (Enabled) = C:\Program Files (x86)\TabletPlugins\npwacom.dll
CHR - plugin: Uplay PC (Enabled) = C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - Extension: YouTube = C:\Users\Ásdis\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: Google Search = C:\Users\Ásdis\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: Gmail = C:\Users\Ásdis\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2012.05.30 22:55:41 | 000,001,805 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 3dns.adobe.com 3dns-1.adobe.com 3dns-2.adobe.com 3dns-3.adobe.com 3dns-4.adobe.com activate.adobe.com activate-sea.adobe.com activate-sjc0.adobe.com activate.wip.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip1.adobe.com activate.wip2.adobe.com activate.wip3.adobe.com activate.wip4.adobe.com adobe-dns.adobe.com adobe-dns-1.adobe.com adobe-dns-2.adobe.com adobe-dns-3.adobe.com adobe-dns-4.adobe.com
O1 - Hosts: 127.0.0.1 adobeereg.com practivate.adobe practivate.adobe.com practivate.adobe.newoa practivate.adobe.ntp practivate.adobe.ipp ereg.adobe.com ereg.wip.adobe.com ereg.wip1.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip2.adobe.com ereg.wip3.adobe.com ereg.wip4.adobe.com hl2rcv.adobe.com wip.adobe.com wip1.adobe.com wip2.adobe.com wip3.adobe.com wip4.adobe.com
O1 - Hosts: 127.0.0.1 www.adobeereg.com wwis-dubc1-vip60.adobe.com www.wip.adobe.com www.wip1.adobe.com
O1 - Hosts: 127.0.0.1 www.wip2.adobe.com www.wip3.adobe.com www.wip4.adobe.com wwis-dubc1-vip60.adobe.com crl.verisign.net CRL.VERISIGN.NET ood.opsource.net
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [Launch LCDMon] C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [Launch LCore] C:\Program Files\Logitech Gaming Software\LCore.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [Launch LGDCore] C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [Launch LgDeviceAgent] C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [XFast LAN] C:\Program Files\ASRock\XFast LAN\cfosspeed.exe (cFos Software GmbH)
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BambooCore] C:\Program Files (x86)\Bamboo Dock\BambooCore.exe ()
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O4 - HKCU..\Run: [whatpulse] "C:\Program Files (x86)\WhatPulse2\whatpulse.exe" File not found
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_5_502_149_Plugin.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Users\Ásdis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Ásdis\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 10.13.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{430D8F12-8B3A-49D1-8A14-0C8895306599}: DhcpNameServer = 192.168.1.254
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012.09.28 13:30:38 | 000,055,176 | R— | M] (Electronic Arts) - D:\Autorun.exe – [ UDF ]
O32 - AutoRun File - [2012.09.28 09:48:28 | 000,000,049 | R— | M] () - D:\Autorun.inf – [ UDF ]
O32 - AutoRun File - [2009.06.10 21:42:20 | 000,000,024 | —- | M] () - E:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{130a1848-370c-11e1-976f-002522fb47a3}\Shell - "" = AutoRun
O33 - MountPoints2\{130a1848-370c-11e1-976f-002522fb47a3}\Shell\AutoRun\command - "" = G:\Autorun.exe
O33 - MountPoints2\{488af93b-36ea-11e1-87a1-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{488af93b-36ea-11e1-87a1-806e6f6e6963}\Shell\AutoRun\command - "" = D:\Autorun.exe – [2012.09.28 13:30:38 | 000,055,176 | R— | M] (Electronic Arts)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: vidc.i420 - lvcod64.dll (Logitech Inc.)
Drivers32:64bit: VIDC.XFR1 - xfcodec64.dll ()
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - C:\Windows\SysWow64\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.VP60 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
Drivers32: VIDC.XFR1 - C:\Windows\SysWow64\xfcodec.dll ()
Drivers32: vidc.XVID - C:\Windows\SysWow64\xvidvfw.dll ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013.02.20 04:06:44 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Ásdis\Desktop\OTL.exe
[2013.02.20 03:18:53 | 000,000,000 | —D | C] – C:\Users\Ásdis\AppData\Local\{45DB5212-9856-40FE-8C51-6BD4AAC434CB}
[2013.02.20 03:01:03 | 000,000,000 | —D | C] – C:\Windows\Temp5E742C12-6AE7-1086-0CF5-2F558042F9F7-Signatures
[2013.02.18 22:39:07 | 000,000,000 | —D | C] – C:\Users\Ásdis\AppData\Roaming\.minecraft
[2013.02.18 16:42:36 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader
[2013.02.18 16:42:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\FOXIT SOFTWARE
[2013.02.18 16:41:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013.02.18 16:40:55 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2013.02.18 16:40:54 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2013.02.18 16:40:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2013.02.18 16:40:54 | 000,000,000 | —D | C] – C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2013.02.18 16:38:30 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2013.02.18 16:31:44 | 000,000,000 | —D | C] – C:\Users\Ásdis\AppData\Local\{AD03C02F-E385-4CE6-B378-90B8FE9E412D}
[2013.02.16 01:21:50 | 000,000,000 | —D | C] – C:\Users\Ásdis\AppData\Local\{3731C1EF-077A-491F-9CB8-D2B7BAE26D72}
[2013.02.15 13:21:17 | 000,000,000 | —D | C] – C:\Users\Ásdis\AppData\Local\{9DED4E34-6959-403F-A2C4-2C7E3D52AFDC}
[2013.02.14 13:39:22 | 000,000,000 | —D | C] – C:\Users\Ásdis\AppData\Local\{2912856D-AA71-4A9B-96A4-EC1E7A0FBD1E}
[2013.02.13 11:18:57 | 000,000,000 | —D | C] – C:\Users\Ásdis\AppData\Local\{4E3EED8A-BF97-4744-A672-3C90274EAA45}
[2013.02.13 03:00:36 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013.02.13 03:00:36 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013.02.13 03:00:35 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013.02.13 03:00:35 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013.02.13 03:00:35 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013.02.13 03:00:35 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013.02.13 03:00:34 | 002,312,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013.02.13 03:00:34 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013.02.13 03:00:34 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013.02.13 03:00:34 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013.02.13 03:00:34 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013.02.13 03:00:33 | 000,729,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013.02.13 03:00:32 | 000,816,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013.02.13 03:00:32 | 000,717,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013.02.13 03:00:32 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2013.02.13 00:14:11 | 005,553,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2013.02.13 00:14:11 | 003,967,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2013.02.13 00:14:11 | 003,913,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2013.02.13 00:14:08 | 000,215,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2013.02.13 00:14:08 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2013.02.13 00:14:08 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2013.02.13 00:14:07 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2013.02.13 00:14:07 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2013.02.13 00:14:06 | 000,288,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\FWPKCLNT.SYS
[2013.02.13 00:14:06 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2013.02.12 23:18:32 | 000,000,000 | —D | C] – C:\Users\Ásdis\AppData\Local\{E87C5239-38FB-4295-80E8-E2E228282342}
[2013.02.12 22:54:15 | 000,000,000 | —D | C] – C:\Users\Ásdis\AppData\Local\WhatPulse
[2013.02.12 22:53:56 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPcap
[2013.02.12 22:53:55 | 000,000,000 | —D | C] – C:\Program Files (x86)\WinPcap
[2013.02.11 15:24:51 | 000,000,000 | —D | C] – C:\Users\Ásdis\AppData\Roaming\Tropico 4
[2013.02.11 15:23:30 | 000,000,000 | —D | C] – C:\Users\Ásdis\AppData\Roaming\Kalypso Media
[2013.02.11 15:12:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\Kalypso Media
[2013.02.10 22:50:47 | 000,000,000 | —D | C] – C:\Users\Ásdis\AppData\Local\{C14A905E-9CC0-4D90-BA1D-83C625C14176}
[2013.02.10 12:36:49 | 000,000,000 | —D | C] – C:\Users\Ásdis\Desktop\Scripts
[2013.02.10 12:36:47 | 000,000,000 | —D | C] – C:\Users\Ásdis\Desktop\DB
[2013.02.09 22:49:50 | 000,000,000 | —D | C] – C:\Users\Ásdis\AppData\Local\{D9A12431-A61D-4F7E-8068-AFD695653843}
[2013.02.09 10:49:23 | 000,000,000 | —D | C] – C:\Users\Ásdis\AppData\Local\{086D3566-759C-4A18-9435-C83A7FD6AB5A}
[2013.02.08 13:13:06 | 016,365,936 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerInstaller.exe
[2013.02.08 10:29:17 | 000,000,000 | —D | C] – C:\Users\Ásdis\AppData\Local\{EDB8EBBB-1DFB-4847-BF58-B3EA419D96FE}
[2013.02.05 20:16:49 | 000,000,000 | —D | C] – C:\ProgramData\Orbit
[2013.02.03 10:54:10 | 000,095,648 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013.02.03 10:53:53 | 000,262,560 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013.02.02 07:36:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\logishrd
[2013.02.02 07:36:06 | 000,000,000 | —D | C] – C:\Program Files\Common Files\logishrd
[2013.02.02 04:01:23 | 000,000,000 | —D | C] – C:\Users\Ásdis\AppData\Roaming\Unity
[2013.02.02 03:51:30 | 000,000,000 | —D | C] – C:\Users\Ásdis\AppData\Local\Unity
[2013.02.01 22:56:37 | 000,000,000 | —D | C] – C:\Users\Ásdis\Documents\Amnesia
[2013.02.01 22:48:33 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Amnesia - The Dark Descent
[2013.02.01 22:43:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Amnesia - The Dark Descent
[2013.02.01 09:23:07 | 000,000,000 | —D | C] – C:\Users\Ásdis\Documents\Klei
[2013.02.01 07:49:09 | 000,000,000 | —D | C] – C:\Users\Ásdis\AppData\Local\{FE43476C-6E55-414D-9E8C-1DE50A5B15B4}
[2013.01.31 06:23:51 | 000,000,000 | —D | C] – C:\Users\Ásdis\AppData\Local\{D59309F8-B9D7-42C0-A7AF-B053E4237AF7}
[2013.01.27 17:55:32 | 000,000,000 | —D | C] – C:\Users\Ásdis\AppData\Local\{AE314217-0B89-4D9D-BE8C-DC07C117DDBF}
[2013.01.26 14:12:30 | 000,000,000 | —D | C] – C:\Users\Ásdis\AppData\Local\{DBE091DB-E026-4ABE-95B9-B414C8E2BCA9}
[2013.01.26 02:11:54 | 000,000,000 | —D | C] – C:\Users\Ásdis\AppData\Local\{C893FA33-A608-4177-82F0-0B4A97E42DFD}
[2013.01.25 14:11:35 | 000,000,000 | —D | C] – C:\Users\Ásdis\AppData\Local\{5E835777-D33F-4C8B-9FCE-ED0AD918A2E4}
[2013.01.25 00:29:51 | 000,000,000 | —D | C] – C:\Users\Ásdis\AppData\Local\{4B177BBE-1D33-4C0D-AA7A-B49D4AD1EB5F}
[2013.01.24 19:40:29 | 000,000,000 | —D | C] – C:\Users\Ásdis\Desktop\Orbit
[2013.01.24 19:38:59 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FarCry 3
[2013.01.24 19:30:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\FarCry 3
[2013.01.24 15:06:36 | 000,000,000 | —D | C] – C:\Users\Ásdis\Desktop\saves
[2013.01.24 12:29:16 | 000,000,000 | —D | C] – C:\Users\Ásdis\AppData\Local\{957189D4-8E3C-490E-93B2-0DDD2D7589D4}
[2 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013.02.21 01:13:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.02.21 00:49:00 | 000,001,006 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2006369733-2391191245-1076361487-1000UA.job
[2013.02.21 00:49:00 | 000,000,994 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.02.20 20:49:00 | 000,000,990 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.02.20 17:16:48 | 000,000,436 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts.ics
[2013.02.20 17:16:47 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013.02.20 08:49:33 | 000,000,954 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2006369733-2391191245-1076361487-1000Core.job
[2013.02.20 04:06:47 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Ásdis\Desktop\OTL.exe
[2013.02.20 03:26:35 | 000,022,080 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.02.20 03:26:35 | 000,022,080 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.02.20 03:17:35 | 2117,378,047 | -HS- | M] () – C:\hiberfil.sys
[2013.02.20 03:08:48 | 000,002,113 | —- | M] () – C:\Windows\epplauncher.mif
[2013.02.18 16:42:38 | 000,001,054 | —- | M] () – C:\Users\Public\Desktop\Foxit Reader.lnk
[2013.02.18 16:41:44 | 000,001,783 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2013.02.16 22:39:44 | 000,793,234 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013.02.16 22:39:44 | 000,661,302 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013.02.16 22:39:44 | 000,125,388 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013.02.13 03:24:39 | 004,996,336 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013.02.10 12:37:57 | 000,803,692 | —- | M] () – C:\Users\Ásdis\Desktop\AsdisBeingABotherForTheGuildII.7z
[2013.02.08 13:13:12 | 000,697,712 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013.02.08 13:13:12 | 000,074,096 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013.02.08 13:13:06 | 016,365,936 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerInstaller.exe
[2013.02.05 20:26:46 | 000,281,688 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.xtr
[2013.02.05 20:26:46 | 000,281,688 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.exe
[2013.02.05 20:19:19 | 000,022,785 | —- | M] () – C:\Users\Ásdis\Desktop\Save007.sav
[2013.02.05 20:19:19 | 000,000,037 | —- | M] () – C:\Users\Ásdis\Desktop\saves.ini
[2013.02.05 20:18:09 | 000,281,688 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.ex0
[2013.02.03 10:54:08 | 000,095,648 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013.02.03 10:54:07 | 000,262,560 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013.02.03 10:54:06 | 000,861,088 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\npdeployJava1.dll
[2013.02.03 10:54:06 | 000,782,240 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\deployJava1.dll
[2013.02.03 10:54:06 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013.02.03 10:54:06 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013.02.01 04:01:47 | 000,001,994 | —- | M] () – C:\Users\Public\Desktop\Project Zomboid.lnk
[2013.01.25 15:43:01 | 000,001,049 | —- | M] () – C:\Users\Ásdis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013.01.25 15:42:56 | 000,001,017 | —- | M] () – C:\Users\Ásdis\Desktop\Dropbox.lnk
[2013.01.25 15:39:45 | 661,716,093 | —- | M] () – C:\Windows\MEMORY.DMP
[2 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013.02.18 16:42:38 | 000,001,054 | —- | C] () – C:\Users\Public\Desktop\Foxit Reader.lnk
[2013.02.18 16:41:44 | 000,001,783 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2013.02.10 12:37:55 | 000,803,692 | —- | C] () – C:\Users\Ásdis\Desktop\AsdisBeingABotherForTheGuildII.7z
[2013.02.05 20:19:19 | 000,022,785 | —- | C] () – C:\Users\Ásdis\Desktop\Save007.sav
[2013.02.05 20:19:19 | 000,000,037 | —- | C] () – C:\Users\Ásdis\Desktop\saves.ini
[2013.02.03 11:50:07 | 000,005,763 | —- | C] () – C:\Users\Ásdis\Desktop\ms_CityControl.lua
[2013.01.25 15:39:45 | 661,716,093 | —- | C] () – C:\Windows\MEMORY.DMP
[2012.10.27 09:12:28 | 000,042,440 | —- | C] () – C:\Windows\SysWow64\xfcodec.dll
[2012.07.08 20:50:25 | 000,000,093 | —- | C] () – C:\Users\Ásdis\AppData\Local\fusioncache.dat
[2012.07.04 02:15:02 | 000,000,032 | R— | C] () – C:\ProgramData\hash.dat
[2012.05.31 01:23:43 | 000,000,132 | —- | C] () – C:\Users\Ásdis\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2012.05.27 22:07:14 | 000,000,044 | —- | C] () – C:\Users\Ásdis\jagex_cl_runescape_LIVE.dat
[2012.05.27 22:07:14 | 000,000,024 | —- | C] () – C:\Users\Ásdis\random.dat
[2012.05.02 14:58:10 | 000,029,184 | —- | C] () – C:\Windows\SysWow64\kdbsdk32.dll
[2012.04.04 07:26:24 | 000,000,263 | —- | C] () – C:\Users\Ásdis\SciTE.session
[2012.03.29 12:31:35 | 000,819,200 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2012.03.29 12:31:35 | 000,180,224 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2012.03.09 04:31:26 | 000,204,952 | —- | C] () – C:\Windows\SysWow64\ativvsvl.dat
[2012.03.09 04:31:26 | 000,157,144 | —- | C] () – C:\Windows\SysWow64\ativvsva.dat
[2012.02.17 20:56:41 | 000,000,268 | —- | C] () – C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2012.02.06 02:13:28 | 000,007,601 | —- | C] () – C:\Users\Ásdis\AppData\Local\Resmon.ResmonCfg
[2012.01.18 06:44:00 | 010,920,984 | —- | C] () – C:\Windows\SysWow64\LogiDPP.dll
[2012.01.18 06:44:00 | 000,336,408 | —- | C] () – C:\Windows\SysWow64\DevManagerCore.dll
[2012.01.18 06:44:00 | 000,104,472 | —- | C] () – C:\Windows\SysWow64\LogiDPPApp.exe
[2012.01.04 21:01:50 | 000,281,688 | —- | C] () – C:\Windows\SysWow64\PnkBstrB.exe
[2012.01.04 21:01:49 | 000,076,888 | —- | C] () – C:\Windows\SysWow64\PnkBstrA.exe
[2012.01.04 15:50:45 | 000,778,702 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012.01.04 15:47:45 | 000,000,003 | —- | C] () – C:\Users\Ásdis\AppData\Local\user_data.ini
[2012.01.04 15:43:48 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2011.09.28 17:44:14 | 000,179,271 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2011.09.12 23:06:16 | 000,003,917 | —- | C] () – C:\Windows\SysWow64\atipblag.dat

========== ZeroAccess Check ==========

[2009.07.14 04:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012.06.09 05:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012.06.09 04:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009.07.14 01:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010.11.21 03:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009.07.14 01:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013.02.20 19:07:57 | 000,000,000 | —D | M] – C:\Users\Ásdis\AppData\Roaming\.minecraft
[2012.04.05 07:13:16 | 000,000,000 | —D | M] – C:\Users\Ásdis\AppData\Roaming\Ambient Design
[2013.02.15 20:44:49 | 000,000,000 | —D | M] – C:\Users\Ásdis\AppData\Roaming\BitTorrent
[2012.12.24 03:57:38 | 000,000,000 | —D | M] – C:\Users\Ásdis\AppData\Roaming\Black Sea Studios
[2012.11.22 03:35:59 | 000,000,000 | —D | M] – C:\Users\Ásdis\AppData\Roaming\DAEMON Tools Lite
[2012.04.04 03:47:06 | 000,000,000 | —D | M] – C:\Users\Ásdis\AppData\Roaming\Darkfall
[2013.02.20 03:18:46 | 000,000,000 | —D | M] – C:\Users\Ásdis\AppData\Roaming\Dropbox
[2012.02.08 08:13:34 | 000,000,000 | —D | M] – C:\Users\Ásdis\AppData\Roaming\Dwarfs
[2012.07.23 05:00:13 | 000,000,000 | —D | M] – C:\Users\Ásdis\AppData\Roaming\Foxit Software
[2013.02.11 15:23:30 | 000,000,000 | —D | M] – C:\Users\Ásdis\AppData\Roaming\Kalypso Media
[2012.01.05 16:56:54 | 000,000,000 | —D | M] – C:\Users\Ásdis\AppData\Roaming\Leadertech
[2012.01.17 22:10:09 | 000,000,000 | —D | M] – C:\Users\Ásdis\AppData\Roaming\Lionhead Studios
[2012.01.13 23:41:13 | 000,000,000 | —D | M] – C:\Users\Ásdis\AppData\Roaming\LolClient
[2012.06.26 12:39:41 | 000,000,000 | —D | M] – C:\Users\Ásdis\AppData\Roaming\LolClient2
[2012.05.29 21:58:41 | 000,000,000 | —D | M] – C:\Users\Ásdis\AppData\Roaming\Mount&Blade Warband
[2012.07.18 00:50:51 | 000,000,000 | —D | M] – C:\Users\Ásdis\AppData\Roaming\Mumble
[2012.02.24 22:01:29 | 000,000,000 | —D | M] – C:\Users\Ásdis\AppData\Roaming\OpenOffice.org
[2012.11.29 21:33:50 | 000,000,000 | —D | M] – C:\Users\Ásdis\AppData\Roaming\Origin
[2012.04.02 11:48:29 | 000,000,000 | —D | M] – C:\Users\Ásdis\AppData\Roaming\Rift
[2012.09.07 18:25:48 | 000,000,000 | —D | M] – C:\Users\Ásdis\AppData\Roaming\RotMG.Production
[2012.12.10 14:40:38 | 000,000,000 | —D | M] – C:\Users\Ásdis\AppData\Roaming\SplitMediaLabs
[2012.07.08 15:12:54 | 000,000,000 | —D | M] – C:\Users\Ásdis\AppData\Roaming\SPORE
[2012.07.04 04:32:58 | 000,000,000 | —D | M] – C:\Users\Ásdis\AppData\Roaming\Three Rings Design
[2013.02.12 12:59:55 | 000,000,000 | —D | M] – C:\Users\Ásdis\AppData\Roaming\Tropico 4
[2012.11.03 14:54:00 | 000,000,000 | —D | M] – C:\Users\Ásdis\AppData\Roaming\TS3Client
[2012.01.13 00:44:57 | 000,000,000 | —D | M] – C:\Users\Ásdis\AppData\Roaming\ts3overlay
[2012.05.21 00:31:13 | 000,000,000 | —D | M] – C:\Users\Ásdis\AppData\Roaming\Ubisoft
[2013.02.02 04:01:23 | 000,000,000 | —D | M] – C:\Users\Ásdis\AppData\Roaming\Unity
[2012.11.03 14:54:00 | 000,000,000 | —D | M] – C:\Users\Ásdis\AppData\Roaming\uTorrent
[2012.04.10 16:34:24 | 000,000,000 | —D | M] – C:\Users\Ásdis\AppData\Roaming\Wacom
[2012.04.11 18:44:49 | 000,000,000 | —D | M] – C:\Users\Ásdis\AppData\Roaming\wacomid-desktop-launcher.DCFD4B89A63EE70BC162777F06D4B93B6397AEC7.1
[2012.10.19 15:23:50 | 000,000,000 | —D | M] – C:\Users\Ásdis\AppData\Roaming\Windows Live Writer
[2012.04.07 13:58:42 | 000,000,000 | —D | M] – C:\Users\Ásdis\AppData\Roaming\WTouch
[2013.01.06 08:01:21 | 000,000,000 | —D | M] – C:\Users\Ásdis\AppData\Roaming\Zeal Game Studio

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2010.11.21 07:06:30 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009.06.10 20:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2011.02.26 05:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011.02.25 06:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011.02.25 06:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011.02.26 06:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010.11.21 03:24:25 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011.02.25 05:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011.02.25 05:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010.11.21 03:24:11 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2010.11.21 07:06:17 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2010.11.21 07:06:17 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2010.11.21 07:06:19 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2010.11.21 07:06:19 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui

< MD5 for: EXPLORER.EXE-A80E4F97.PF >
[2013.02.19 19:43:49 | 000,172,336 | —- | M] () MD5=AA55207CEEA06F4B42B2049E46E11EBA – C:\Windows\Prefetch\EXPLORER.EXE-A80E4F97.pf

< MD5 for: EXPLORER.ZIP >
[2006.03.06 22:48:08 | 000,020,394 | —- | M] () MD5=B469409C2B2A33C542190B720E11BD79 – C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip

< MD5 for: IEXPLORE.EXE >
[2012.06.02 11:47:54 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=004640AB259C1572EBD5FB0A32F63686 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20553_none_0dbfc836999db0ca\iexplore.exe
[2013.01.09 01:53:45 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=0100BCF23941C83462E4A70F94C3392E – C:\Program Files\Internet Explorer\iexplore.exe
[2013.01.09 01:53:45 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=0100BCF23941C83462E4A70F94C3392E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_0d2c5bc980874648\iexplore.exe
[2012.05.17 23:21:54 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=0129BB16161C2FD9A6B19111AB047198 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16446_none_1798a687b4d6030f\iexplore.exe
[2012.11.14 02:56:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_178ed6e5b4dd3857\iexplore.exe
[2012.06.29 05:02:52 | 000,754,784 | —- | M] (Microsoft Corporation) MD5=1223ACBFC1093852DFF039E189599BBD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_0d45fcc9807373c2\iexplore.exe
[2012.08.24 07:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_1787d4dfb4e386f6\iexplore.exe
[2012.05.17 22:59:46 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=268982F1FD671A077C6A2AF41E351436 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20551_none_181271f4ce004017\iexplore.exe
[2012.10.08 08:37:24 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=270A1342BD5AF95CA25A586B4C2F1522 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16455_none_178cd651b4df05a9\iexplore.exe
[2012.08.24 11:23:44 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=2D53C5F71653EF94E7829846405D4ED2 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_0d332a8d8082c4fb\iexplore.exe
[2012.06.02 09:08:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=34B01BBD8F00B6B9C9248DC4F1E3CD01 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16447_none_1799a6d1b4d51c66\iexplore.exe
[2012.10.08 12:29:46 | 000,754,848 | —- | M] (Microsoft Corporation) MD5=49442BA6DCE4B4E3C1CB0AB193FE29AD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16455_none_0d382bff807e43ae\iexplore.exe
[2012.05.18 02:51:05 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=4E99F42504A99D5024C2EFA015001937 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16446_none_0d43fc3580754114\iexplore.exe
[2012.08.24 10:49:07 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=5A150AFABB25BEA50CEDC8650A7B8A9E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_0dc3c95e999a1626\iexplore.exe
[2012.06.29 02:45:31 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=5D03518409F37D1483C98869D86E23FF – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_0dc0c880999cca21\iexplore.exe
[2012.06.02 12:52:21 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=610F6596921C4BAA8834ADBB9BE272EE – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16447_none_0d44fc7f80745a6b\iexplore.exe
[2012.08.24 07:49:25 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=62188720CE27B982B4285C03163C9FB3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_181873b0cdfad821\iexplore.exe
[2013.01.08 22:42:06 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=698EB1E5F8C66344D97C00B5699E871D – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2013.01.08 22:42:06 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=698EB1E5F8C66344D97C00B5699E871D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_1781061bb4e80843\iexplore.exe
[2010.11.21 03:24:43 | 000,695,056 | —- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2012.01.04 16:23:11 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_17a944edb4ca4c7a\iexplore.exe
[2012.06.29 01:00:47 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=93569D46D79F9756ED077156496AFE23 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_179aa71bb4d435bd\iexplore.exe
[2012.11.16 03:08:58 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=AC4957E154F750DF54F36ADC8E3E040D – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_0db6f8de99a3ff69\iexplore.exe
[2012.06.02 08:51:58 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=BE967C74B89577B78FB57C061E12B04C – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20553_none_18147288cdfe72c5\iexplore.exe
[2010.11.21 03:25:08 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe
[2012.10.08 08:22:05 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=CECB15F834FC2B4B150449717ADE18DD – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20562_none_1808a252ce07755f\iexplore.exe
[2012.06.28 23:35:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=EB4105348272018D096FEB655CD1608C – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_181572d2cdfd8c1c\iexplore.exe
[2013.01.09 00:51:57 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=EF1F6F41FB2C9BBB484B21017F380201 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_0daa285e99ade8ac\iexplore.exe
[2013.01.08 21:32:42 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F05982E56ABD835AA8DF260EEC873E5B – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_17fed2b0ce0eaaa7\iexplore.exe
[2012.01.04 16:23:10 | 000,754,480 | —- | M] (Microsoft Corporation) MD5=F1424C1B9B1813BF825E45DF3790BC8A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_0d549a9b80698a7f\iexplore.exe
[2012.10.08 11:09:10 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=F61714ABCF9BF0CEF0A6249AD4FD490B – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20562_none_0db3f80099a6b364\iexplore.exe
[2012.11.14 02:19:28 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F691418EE9A6344AEB5C1B0518FBF8AE – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_180ba330ce04c164\iexplore.exe
[2012.05.18 01:37:57 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=F8B2D47ED17C1D087D14EC747E5AC57A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20551_none_0dbdc7a2999f7e1c\iexplore.exe
[2012.11.14 07:11:18 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=FD0D2E1FAEBAE5031BE2EB8000D973F1 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_0d3a2c93807c765c\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2012.01.04 16:23:10 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2012.01.04 16:23:10 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2012.01.04 16:23:11 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2012.01.04 16:23:11 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui
[2009.07.14 02:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_0b433e7773148b79\iexplore.exe.mui
[2009.07.14 02:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_1597e8c9a7754d74\iexplore.exe.mui

< MD5 for: SERVICES >
[2009.06.10 21:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services

< MD5 for: SERVICES.EXE >
[2009.07.14 01:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009.07.14 01:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2010.11.21 07:06:16 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\SysNative\en-US\services.exe.mui
[2010.11.21 07:06:16 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui

< MD5 for: SERVICES.EXE-511D36F4.PF >
[2013.02.10 13:16:23 | 000,021,318 | —- | M] () MD5=915AA5C6480E677C5FA9345DBC254DF9 – C:\Windows\Prefetch\SERVICES.EXE-511D36F4.pf

< MD5 for: SERVICES.LNK >
[2009.07.14 04:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009.07.14 04:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOCHIADS.COM.SOL >
[2013.02.13 11:44:22 | 000,000,803 | —- | M] () MD5=900AD6FFA304B3BDB035242DD6A12ACD – C:\Users\Ásdis\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\ZBLPXSRZ\mochiads.com\services.mochiads.com.sol

< MD5 for: SERVICES.MOF >
[2009.06.10 20:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2009.06.10 20:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof

< MD5 for: SERVICES.MSC >
[2010.11.21 07:06:14 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\en-US\services.msc
[2009.06.10 20:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\services.msc
[2010.11.21 07:06:17 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\en-US\services.msc
[2009.06.10 21:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2010.11.21 07:06:14 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009.06.10 20:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2010.11.21 07:06:17 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009.06.10 21:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009.07.13 20:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009.07.13 20:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml

< MD5 for: SERVICES.RDB >
[2011.01.17 18:52:22 | 000,237,568 | —- | M] () MD5=507957679AE4579C15D57FA741EA6FFA – C:\Program Files (x86)\OpenOffice.org 3\URE\misc\services.rdb
[2011.01.17 18:51:48 | 005,539,328 | —- | M] () MD5=F2B666905F7FDAA80C86A101A7DE62F9 – C:\Program Files (x86)\OpenOffice.org 3\Basis\program\services.rdb

< MD5 for: WINLOGON.ADML >
[2010.11.21 07:06:30 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009.06.10 21:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2010.11.21 03:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010.11.21 03:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2010.11.21 07:06:14 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2010.11.21 07:06:14 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2010.11.21 07:06:15 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2010.11.21 07:06:15 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009.07.13 20:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2009.07.13 20:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2012.12.26 00:33:45 | 000,000,000 | —- | M] () – C:\AILog.txt
[2012.04.21 18:08:14 | 000,000,216 | —- | M] () – C:\DebugTrace-RockallDLL.log
[2013.02.20 03:17:35 | 2117,378,047 | -HS- | M] () – C:\hiberfil.sys
[2013.02.20 03:17:42 | 4254,826,495 | -HS- | M] () – C:\pagefile.sys
[2012.09.18 13:34:25 | 000,002,200 | —- | M] () – C:\pathping.txt
[2012.01.14 03:17:07 | 000,012,918 | —- | M] () – C:\shared.log
[2012.06.06 16:34:02 | 000,000,592 | —- | M] () – C:\tracert.txt
[2 C:\*.tmp files -> C:\*.tmp -> ]

< %systemroot%\Fonts\*.com >
[2009.07.14 05:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009.07.14 05:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009.07.14 05:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009.07.14 05:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009.06.10 20:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009.07.14 04:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012.01.04 16:28:31 | 000,000,221 | -HS- | M] () – C:\Users\Ásdis\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011.02.23 15:09:12 | 000,270,142 | —- | M] () – C:\Users\Ásdis\Desktop\Minecraft.exe
[2013.02.20 04:06:47 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Ásdis\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >

And the Extra.txt…

OTL Extras logfile created on: 21.2.2013 01:27:15 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Ásdis\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 0000040f | Country: Ísland | Language: ISL | Date Format: d.M.yyyy

7,96 Gb Total Physical Memory | 6,48 Gb Available Physical Memory | 81,39% Memory free
15,92 Gb Paging File | 13,89 Gb Available in Paging File | 87,21% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931,41 Gb Total Space | 230,41 Gb Free Space | 24,74% Space Free | Partition Type: NTFS
Drive D: | 3,90 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Drive E: | 931,51 Gb Total Space | 593,88 Gb Free Space | 63,75% Space Free | Partition Type: NTFS
Drive F: | 1863,01 Gb Total Space | 1208,89 Gb Free Space | 64,89% Space Free | Partition Type: NTFS

Computer Name: ASDIS-PC | User Name: Ásdis | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02940EBB-567E-48BD-87F0-0EDCCE9AC7DA}" = lport=445 | protocol=6 | dir=in | app=system |
"{0D8D2C38-5228-4A20-9549-A8989DDA613B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{1EAC61A0-0706-4913-9720-DBBCB48F8728}" = lport=138 | protocol=17 | dir=in | app=system |
"{267321C4-F93A-4870-9B6C-E626FA35D672}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{2B7AD04B-DE96-48ED-8070-BE057BCC1F59}" = rport=137 | protocol=17 | dir=out | app=system |
"{309163A3-5A48-4E8F-A47A-53081D8E18BA}" = rport=445 | protocol=6 | dir=out | app=system |
"{31596ABF-76BA-4784-A770-9632F3214244}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{34F21972-6FC0-4F5C-A523-DFBD416ED4D3}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{4AF065C8-03DF-421D-A2AC-7ED69FDA9541}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{58901775-E4C2-4EA5-80CD-6803C33F5323}" = lport=137 | protocol=17 | dir=in | app=system |
"{5C55B219-4789-4CB6-AA4E-707AFA4944A2}" = rport=2869 | protocol=6 | dir=out | app=system |
"{63266EB2-42AF-4D38-8113-6FBCD04E3668}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{682C3BCC-3888-47AA-A603-1272C70E71A3}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{696DCE1B-EB9A-4AF8-8F50-C101B0386E54}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{701CBAAC-52E7-4DCF-A041-AB0726E032C8}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{7F127CAE-407F-4946-B35A-A76FDC9C1F0A}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{83142D34-BB30-4EDC-BF17-B6B8B56A650F}" = rport=10243 | protocol=6 | dir=out | app=system |
"{8FEB36F0-CD01-4C14-B80F-859812D683FF}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A2A3A772-20D8-4F3B-86A7-90840988617C}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
"{AD35DBC4-97C2-4034-AD33-F0544BAD252D}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{AE539903-80C4-4DD9-BC8D-41732DBFBC59}" = lport=2869 | protocol=6 | dir=in | app=system |
"{B152D07C-BFF3-4EFE-8305-DA097B996194}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{B68926E4-597C-4439-BCBA-CE089DC51D20}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{C6CB5360-A0BC-4D4A-A3A4-FD75567771E6}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{C7D44626-BAF3-49E5-9909-534A9FAF6D51}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{D2DAF0E8-201D-4D7A-B639-649073ADB04A}" = lport=2869 | protocol=6 | dir=in | app=system |
"{E00AADF5-6EAB-44A8-B310-6DD85CB99AD3}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F5FA9AB0-4E3C-4ADD-A357-A64309F60973}" = rport=138 | protocol=17 | dir=out | app=system |
"{F6240717-D2DA-4D72-AE73-996A6C38EFC8}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{F694EE70-D577-4526-AEB6-FA0F5BEDC4F4}" = rport=139 | protocol=6 | dir=out | app=system |
"{F8A98697-9F42-4E93-AE0E-34BB7AD6650C}" = lport=10243 | protocol=6 | dir=in | app=system |
"{F9414DB3-54F3-4C4B-9488-2E986732155F}" = lport=139 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0081B3C6-0E28-4480-9B25-ADE56D0E5FCA}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{0217441B-9B5E-41B4-9EAB-3E061911D2F0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dwarfs\dwarfs.exe |
"{02BD3973-E9A2-49E8-99D4-6641BA1A6925}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alien swarm\srcds.exe |
"{02C0734C-E6C2-44A5-A31B-3BAD6E6DF339}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{03287D07-082B-4295-802C-F2FB6980C995}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\age of empires iii\age3.exe |
"{0471600F-2E32-470F-B5BF-55F7FB42E161}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{0689E8D1-F816-469F-8571-7245DBB29BE4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\realm of the mad god\realm of the mad god.exe |
"{086522A9-F2D7-42A9-8FB9-337BFC771BB9}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{094EB3B4-2C02-4058-94E9-AB2FDC0E749A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{0A39DD49-0CF9-471D-9B56-1CBF6B2CC286}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\bioware\star wars - the old republic\launcher.exe |
"{0BDE0C36-1848-4F1D-8FDC-339EEED6584D}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{0BEC53A6-4F23-49A4-A299-F0F8B6F0A5AE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2\arma2.exe |
"{0BF988F3-B105-4C58-86F5-5DDC172C0761}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe |
"{10F0D224-C7EE-4E3C-8656-7559033C3D48}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\rift\riftpatchlive.exe |
"{12285517-2ADE-4054-8FD4-FB4A1FD8CD98}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\demigod\bin\demigod.exe |
"{139DB41A-45BD-4C0A-ACA6-7ECB849373A1}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\battlefield 3\bf3.exe |
"{15F0F21C-6652-42BC-A33A-3957C1D6FEDD}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
"{17499B36-4B27-46C4-B3E2-D7D875D77E64}" = protocol=6 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
"{17959EAB-9473-4B18-A371-A04B62BF2271}" = protocol=6 | dir=in | app=c:\users\public\sony online entertainment\installed games\planetside 2 psg\planetside2.exe |
"{17E2EAF5-BD8B-4E11-BE80-6C3BF5345F94}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{1836F131-8933-469D-A0FA-BCC265098A5D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2\arma2.exe |
"{18E06247-EA20-4D2A-83CC-F5A94F7DA34C}" = protocol=6 | dir=in | app=c:\program files (x86)\diablo iii\diablo iii.exe |
"{1B47AF45-D3B5-4B9F-97F3-5DF6F58F921B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mount & blade with fire and sword\mb_wfas.exe |
"{1B849127-8263-416A-B08D-39127AA9A09C}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{1B99F529-E0FB-4708-9913-9E967CBAEE92}" = protocol=17 | dir=in | app=c:\program files (x86)\mass effect 2\binaries\masseffect2.exe |
"{1C621665-D391-4456-B129-1E14D1ABC2FE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\city life 2008\bin\cld.exe |
"{1CB918CE-482E-469D-97B8-3543B7EACBFF}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games for windows - live\client\gfwlive.exe |
"{1CC83151-779E-4AFF-8E7C-648C9C599F00}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\launcher.exe |
"{1E2DAE71-BB3D-4847-8740-BF1692667965}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\magicka\magicka.exe |
"{1EAD1213-4DB6-4153-AADB-E08BCF73F656}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe |
"{24048A77-043F-4A1A-A1CF-09E716E31AA7}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{25AC58FF-52E0-4D45-AF68-252A916E8D56}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\angelcatty\garrysmod\hl2.exe |
"{26B48248-631E-4B1C-B7B6-613C5A161FA4}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\a game of dwarves\a game of dwarves.exe |
"{26DA654D-2336-4493-A1FD-E61FE9D33029}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{28000985-7F22-4A71-8795-A2EA81993F93}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands\binaries\borderlands.exe |
"{283D77B5-37DB-4213-BE4C-1FEF69893FCA}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{28D50210-B1E4-4F38-AC19-623CDFCBA0B7}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{28F002D7-9322-4CCC-B877-CCE6F006EE90}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dwarfs\dwarfs.exe |
"{2995D17B-5B9F-49E3-B70B-C4B344708849}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\arma2oa.exe |
"{29A13D3E-DDF6-484F-80F0-82C6CC5FEF4B}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{2A99BC33-C348-478E-9442-C8905E0163C0}" = dir=in | app=%programfiles% (x86)\kalypso media\tropico 4\tropico4.exe |
"{2BAFBC39-71D7-45C0-9588-9A2809CA0514}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mount & blade with fire and sword\mb_wfas.exe |
"{2DA2E72D-A09B-4F43-AD32-069638146CAC}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\skyrim\skyrimlauncher.exe |
"{2EEB2BEC-6E08-49D9-9331-10EACD17A41E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\saints row the third\saintsrowthethird.exe |
"{2F45FCD8-1029-4319-A7FD-6D4FE0943432}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\daupdatersvc.service.exe |
"{32D0DCE8-2B88-4EA0-A9AA-82FBC85AF5AE}" = protocol=6 | dir=in | app=c:\program files\teamspeak 3 client\ts3client_win64.exe |
"{33129BD5-CB47-469B-86B6-693745DB717E}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{3400D694-1FB4-452F-9A41-CD9F5C32C7C9}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{35280864-B30D-44E6-B40D-81E7AC242FA7}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chivalrymedievalwarfare\binaries\win32\udk.exe |
"{3611A6BA-F843-4029-BEF2-59A29587F38E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\launcher.exe |
"{36646D2E-A207-40BA-B7E8-CA8D51F1E536}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\bioware\star wars - the old republic\launcher.exe |
"{377D609D-2289-4F1E-A598-2709C9E63425}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{388D48FD-10AF-4276-869E-22D6C2078B1E}" = protocol=17 | dir=in | app=c:\program files\microsoft security client\msseces.exe |
"{38BB0CC2-2077-4C08-A9F6-DA52834D60EB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\rift\riftpatchlive.exe |
"{394000BD-A8B6-49D2-AC09-FE1BFF6F006D}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{3A5CC5C9-55B5-4797-B2E6-6D6E64F5958A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\docs\ea help\electronic_arts_technical_support.htm |
"{3A76E004-F1FA-49DA-91AE-10D55FA5364C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\arma2oa.exe |
"{3E981766-C946-4503-8AB2-83D7CB442948}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{41533B0D-D832-41B1-AEB4-1F3215C4057B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal 2\portal2.exe |
"{430B4BC8-32A5-49A1-B29F-20524FFD6886}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\apb reloaded\binaries\apb.exe |
"{434B3A69-11F3-4B4E-BC67-1C46341C5ED2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\terraria\terraria.exe |
"{4430F3AD-A469-45B0-A8B9-252484E9DD35}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{44DFC349-9C73-44FE-8E9E-9A9051231E2F}" = protocol=6 | dir=in | app=c:\program files (x86)\knights of honor\koh.exe |
"{4547934E-6E9D-4846-A9AA-7AA06A0A9546}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 |
"{4753B8F5-FB05-4451-BC6E-14A5219A2FB7}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{47DB7788-0F7F-46DD-BE86-8A26124AFC85}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\launcher.exe |
"{4857818A-C86B-4F84-BA03-58DA263DE870}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal 2\portal2.exe |
"{48DDAB62-9764-44CE-B0E1-47D89FC42911}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{4982E4C9-A9C0-46A7-9849-2BD9A3C0F6A1}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{4AB7C683-A516-407E-81FA-A254D64945AE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\magicka\magicka.exe |
"{4B00B173-5AF6-4353-AAB8-844139F4E8B8}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe |
"{4BF51B9A-A6A1-4CF0-B6F3-95D6263C4A6A}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{4C673511-D14B-4EC9-ADAF-0C47DD320C55}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\bioware\star wars - the old republic\launcher.exe |
"{4C9755B7-AA39-443E-8D3F-54B89FD521E2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
"{4D6CE49D-A3E8-4473-8FF3-2059A1CB19CD}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\quantum conundrum\binaries\win32\trygame-win32-shipping.exe |
"{5074AFCE-06C3-4064-BB77-AADFCCD59FA5}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe |
"{50FAC57D-384D-45F7-BDDC-78865A4A0738}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the guild ii - pirates of the european seas\guildii.exe |
"{51A528E7-B1D9-4F18-8590-33A7926941B7}" = protocol=6 | dir=in | app=c:\program files (x86)\bittorrent\bittorrent.exe |
"{524B2C8E-5074-451A-B2D6-90B239C09ECB}" = protocol=17 | dir=in | app=c:\users\ásdis\appdata\local\temp\gw2.exe |
"{534C8AC2-1603-424D-B4C5-1A4E3139D42B}" = protocol=17 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
"{53530E85-D834-410B-A5E7-EBC00AE5CCCB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\daoriginslauncher.exe |
"{53F93A9D-9C4F-4567-B572-D18227BB0D2C}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{548EF0AE-9098-4EF3-9383-423D4D38FAB5}" = protocol=17 | dir=in | app=c:\program files (x86)\dragon age 2\bin_ship\dragonage2.exe |
"{54A9C30D-0D3F-4676-B9A9-61809A44C034}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{58CC72C5-F3A4-4A76-8F88-E23080F2FE88}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\daorigins.exe |
"{58D1854D-3652-4B2A-BEB3-ACCAFFE0BC3A}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe |
"{5DA3A5C7-8AC1-4D56-98F3-9CF8C7AF85B9}" = protocol=6 | dir=in | app=c:\program files (x86)\ventrilo\ventrilo.exe |
"{5EC9604B-5025-4B85-8E9B-9161EB347D49}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{5F12CDED-D328-4711-8E7F-E024D1632A98}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\mass effect 3\binaries\win32\masseffect3.exe |
"{5F96B5E9-6CB5-4E81-8A94-95E59E26E216}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\terraria\terraria.exe |
"{5FA29DA5-1B38-468B-8343-6C763557AEF8}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alien swarm\swarm.exe |
"{5FC87336-4474-484B-879C-90B0CD634B77}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the guild ii\guildii.exe |
"{61B0D9C9-AE63-49DA-AB0E-1A58680A16DC}" = protocol=6 | dir=in | app=c:\users\ásdis\desktop\minecraft.exe |
"{62240FC9-7672-4924-84C9-C33B72C2AE5A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{631BE2E2-0EA9-40A6-955F-42355F603C5B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\anno 2070\anno5.exe |
"{66B199E6-47B3-4360-B34B-97E344AFE6FE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\killingfloor\system\killingfloor.exe |
"{66FA4A29-7E37-460D-975F-289E423EE766}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{67C2447D-80A3-4556-A0D4-7235294B00C9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe |
"{68200006-67F9-4986-80F2-ADCB16DC1C9D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the guild ii - pirates of the european seas\guildii.exe |
"{6865D7FD-8A96-4750-A274-CF382D81423B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\angelcatty\garrysmod\hl2.exe |
"{694E9226-8E07-401F-A59A-00D8A777A3BB}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{695FE355-19E4-4B76-9EA2-63D56D0EEFE8}" = protocol=6 | dir=in | app=c:\program files (x86)\mass effect 2\masseffect2launcher.exe |
"{69EBC927-28BE-4EDD-ACEF-C69E8767372E}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\mass effect 3\binaries\win32\masseffect3.exe |
"{6A745FF3-4BBE-4471-B23A-FE30C31375E4}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war 2\dow2.exe |
"{6BDDC34F-6665-47B7-902D-877A357B87A8}" = protocol=17 | dir=in | app=c:\users\ásdis\desktop\minecraft.exe |
"{6C2911B1-B486-42E6-8E1E-9227FEBDF5FF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{6F88D058-37B7-43A9-B909-74201891827B}" = protocol=17 | dir=in | app=c:\program files (x86)\guild wars 2\gw2.exe |
"{6F9BFC53-AD91-49BA-97E2-D9819A26947B}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\battlefield 3\bf3.exe |
"{723D1B48-D18C-436B-9273-D171A6B3E012}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2\arma2.exe |
"{723E27F0-00C6-4D0C-B6A7-F3B5831F93C5}" = protocol=6 | dir=in | app=c:\users\ásdis\appdata\local\temp\gw2.exe |
"{740F4653-CDCA-4592-A470-B1BD48683142}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2\arma2.exe |
"{76FC0681-C7E4-4B62-8A95-8166693B7123}" = protocol=6 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
"{771B3F08-B669-4970-9EAE-9FFAB6407249}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\apb reloaded\launcher\apblauncher.exe |
"{7772E33E-0009-4A02-BD2D-F690C37996BB}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{7A1CE6DE-B7AF-4EF3-BCF8-3C876EA0618E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spellforce 2 dragon storm\spellforce2.exe |
"{7B4ACDDC-0356-4E76-AD59-BCFF67BE1C2D}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{7BDF6820-29FB-464C-8B89-298E4BBACAB3}" = protocol=17 | dir=in | app=c:\program files\teamspeak 3 client\ts3client_win64.exe |
"{7C99308A-F796-466B-9616-9AC28573B447}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{7CA68D25-40D8-4431-A3C9-07393180B96C}" = protocol=17 | dir=in | app=c:\program files\world of warcraft\wow-x.x.x.x-4.0.0.12911-eu-downloader.exe |
"{7DFAAF54-DBFC-41E4-832F-3B77859C92FA}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fable 3\fablelauncher.exe |
"{7E6A5026-AA2C-4064-BBB7-C3166C97FC57}" = protocol=6 | dir=in | app=c:\program files\world of warcraft\wow.exe |
"{7F473985-38D7-4AF6-854D-3B4F584078BF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alien swarm\srcds.exe |
"{81FBFC95-274A-4C36-A0DA-56101D108402}" = dir=out | app=%programfiles% (x86)\kalypso media\tropico 4\tropico4.exe |
"{824086D8-FA04-432C-BBCB-D4CE4D746F93}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\docs\ea help\electronic_arts_technical_support.htm |
"{82982210-9B1C-4793-8BBD-2F2C1DF29617}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mountblade warband\mb_warband.exe |
"{82F1F0B5-01DA-48FB-B16E-FF7D7F236862}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\saints row the third\game_launcher.exe |
"{8432F103-5EC9-440F-B309-B40E3B2AC35A}" = protocol=17 | dir=in | app=c:\program files (x86)\age of empires ii\empires2.exe |
"{8512D574-AA58-4B8E-BE82-9707CD92F2E3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\angelcatty\age of chivalry\hl2.exe |
"{85751420-8DE4-4F47-8C27-60A0F12A08B4}" = protocol=6 | dir=in | app=c:\windows\syswow64\dplaysvr.exe |
"{85E95894-24C0-4457-A7A7-8F7AFE372403}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{860296A3-40C5-452F-9932-668DEB047AF3}" = dir=out | app=%programfiles% (x86)\age of empires ii\empires2.exe |
"{86CB698F-6714-4BD1-B17C-4F6AB441143E}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{88BAEDE4-715C-4CCA-A9B6-7154BFEB170D}" = protocol=17 | dir=in | app=c:\program files\world of warcraft\wow.exe |
"{8C9C5552-045E-4337-A516-5D12F3BCBEDB}" = protocol=17 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
"{8E1F1783-175E-4E8B-B1AD-EADEC091D7E5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe |
"{8E8ABFB5-68F4-4563-BDCC-5608FCA23D77}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dwarfs\dwarfs.exe |
"{8EA84B77-0F29-4E5D-A7B2-80692078A907}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe |
"{8F6D24EC-A7B1-454A-A54F-8BDF95FD3F75}" = protocol=17 | dir=in | app=c:\users\ásdis\appdata\roaming\dropbox\bin\dropbox.exe |
"{9071B920-9434-4356-A345-B2E863E1E2B2}" = protocol=6 | dir=in | app=c:\program files (x86)\dragon age 2\bin_ship\dragonage2.exe |
"{915B27B1-F799-4E40-8888-A75388814918}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\angelcatty\garrysmod\hl2.exe |
"{9348D8F7-8C4A-4F1E-A239-18B1A7358404}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\age of empires online\spartan.exe |
"{94992508-D44B-4014-BA59-B78BDE56CE89}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\daoriginslauncher.exe |
"{964D2587-20E0-47A4-BA8E-50C041F18956}" = dir=in | app=%programfiles% (x86)\age of empires ii\empires2.exe |
"{979791CF-19AA-4913-84E0-8B3AC6872378}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\killingfloor\system\killingfloor.exe |
"{9F6D6C3B-EE02-4E16-84C8-9FB7C62B87BD}" = protocol=58 | dir=in | app=system |
"{9FA6E2F4-996E-4942-8606-560801C2470B}" = protocol=6 | dir=in | app=c:\users\ásdis\desktop\minecraft.exe |
"{9FADAF45-177E-44F3-A262-71E91BCA7E79}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\apb reloaded\launcher\apblauncher.exe |
"{A0B2117D-3767-4872-8569-41929DFC9A19}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dont_starve\bin\dontstarve_steam.exe |
"{A1C5FC58-7454-49F8-A619-B430D66A5361}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dwarfs\dwarfs.exe |
"{A2ACC787-D973-4363-9C8D-C3C78BA3A52A}" = protocol=17 | dir=in | app=c:\program files (x86)\dragon age 2\dragonage2launcher.exe |
"{A340A122-9BC2-4074-9072-E1A59905702B}" = protocol=6 | dir=in | app=c:\program files\world of warcraft\wow-x.x.x.x-4.0.0.12911-eu-downloader.exe |
"{A3B7E111-539F-466F-8F35-59205688F9CF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the guild 2 renaissance\guildii.exe |
"{A45E637B-9603-458A-A819-EDDAD7AEDBFF}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 |
"{A554C7E4-1FD5-46C7-BC02-28CABBBBEB6E}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{A79654E0-7078-4747-9F03-EE73419D6D87}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\mass effect 3 demo\binaries\win32\masseffect3demo.exe |
"{A7B964CC-664A-4532-A95F-2A06A3C560A3}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{A953C04E-A993-40DB-ADFE-AE487099E8AF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\besetup\setup_battleyearma2oa.exe |
"{A9E8C8AF-5553-4365-AA66-BF4B85714774}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fable 3\fablelauncher.exe |
"{AE5FA38F-59DC-451D-81B8-22B8C3829998}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{AEE8A5A0-0F05-45A5-AA93-142463EDA040}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\quantum conundrum\binaries\win32\trygame-win32-shipping.exe |
"{B2118B9D-9A67-455F-B73F-61D53C7D1363}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\saints row the third\saintsrowthethird_dx11.exe |
"{B2B818BC-52DC-4F91-903F-03F186132D35}" = protocol=6 | dir=in | app=c:\program files (x86)\ffsplit\ffsplit.exe |
"{B3CD3BE5-A184-4068-80D5-742C9B513760}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\_runa2co.cmd |
"{B52D0D1F-F84E-4695-9E85-6AF3E63ED231}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii public test.exe |
"{B567F789-0DF7-4B3E-BFD9-AAFEC131B57E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\apb reloaded\binaries\apb.exe |
"{B7D39578-513C-472D-A25D-B92812F39985}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\anno 2070\anno5.exe |
"{B889E299-4D09-4667-B411-87787CDF8400}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alien swarm\swarm.exe |
"{B98EB742-A97D-46E5-97C1-0B4FE4D45E33}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{BA35B406-9F29-4211-932F-512BE8498B29}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead\left4dead.exe |
"{BA397BDD-A016-4335-B0F7-0A02C3171CDB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spellforce 2 dragon storm\spellforce2.exe |
"{BB56A63D-A619-4082-A4BE-63D86E658B1A}" = protocol=6 | dir=in | app=c:\program files (x86)\funcom\the secret world\clientpatcher.exe |
"{BB6B0081-5F95-4893-944D-1329C188F938}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe |
"{BCAB3A4A-CC85-43F4-8484-7EF4C9A73296}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\daupdatersvc.service.exe |
"{BCC2ACDA-CC73-4336-AD0C-7DE2B29E276B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead\left4dead.exe |
"{BD462DEA-CB13-4A82-A6BA-071162A0711C}" = protocol=6 | dir=in | app=c:\users\ásdis\appdata\roaming\dropbox\bin\dropbox.exe |
"{BDAB537A-0AEA-449A-A04B-1513B103693C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\skyrim\skyrimlauncher.exe |
"{BE17A47A-2509-40E6-9604-9778CB5A95E2}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{BF6C7FD0-54F3-4BC2-84C8-DADD2688B2CB}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{C0208AE0-EECC-47FF-A23A-B8F27EB5B955}" = dir=out | app=%programfiles% (x86)\wb games\scribblenauts unlimited\launcher.exe |
"{C3BFF15A-5077-4047-8F49-34EA4B4BC86C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the guild 2 renaissance\guildii.exe |
"{C40688CD-4E4B-4D76-9BA3-CDDA99F12FEC}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\saints row the third\saintsrowthethird.exe |
"{C53FC99F-EAEF-46FC-B4E4-FECF7CD96215}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
"{C60AE734-4E04-492B-92B3-C95027BF1394}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
"{C6AE2108-4E02-4380-9D9B-81A9D4A9930C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\skyrim\skyrimlauncher.exe |
"{C7D70B69-6970-41D0-AF7A-693C20D603DB}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal 2\portal2.exe |
"{C912B702-6177-412D-9391-67431D097588}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mountblade warband\mb_warband.exe |
"{CAC01174-6289-4D37-AD06-A9621C2473C0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\amd driver updater, vista and 7, 64 bit\setup.exe |
"{CAD1F612-84FE-4677-A43A-84B35BB4B9B7}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\vampire the masquerade - bloodlines\vampire.exe |
"{CBA23A1D-864F-4E11-85B1-4CBA8BA12787}" = protocol=17 | dir=in | app=c:\program files (x86)\mass effect 2\masseffect2launcher.exe |
"{CBED5789-C4EE-4A06-9E3B-B7EFC36D28E1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\angelcatty\garrysmod\hl2.exe |
"{CC4A1022-6E0E-486B-A57E-7A3DCF82DFA8}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\launcher.exe |
"{CD71DCCD-2226-41D4-B7CF-1810EF69362E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\from dust\from_dust.exe |
"{CF77852D-975A-4ABC-BCCA-D0275E4305E0}" = protocol=17 | dir=in | app=c:\program files (x86)\diablo iii\diablo iii.exe |
"{CF7BEC31-251C-4438-B947-FD980E4729DD}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\amd driver updater, vista and 7, 64 bit\setup.exe |
"{CFF665B6-78A6-4F0B-9D4F-7220D1A02FB1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\skyrim\skyrimlauncher.exe |
"{D0AF618B-5EA4-40D6-8739-B8DA91A5C359}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\a game of dwarves\a game of dwarves.exe |
"{D2C34642-5FE6-476E-9CC2-5995CABFAA98}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{D30543A5-FC42-4E59-93EE-9DCC9F3154CC}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\bioware\star wars - the old republic\launcher.exe |
"{D3336F28-CCB7-4390-8B88-25AB5FDA56DF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{D39A43BB-AA3C-4566-B926-F80AC3D5DC14}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{D411EFE3-1F5F-44B7-95EC-1D95FE443AB4}" = protocol=6 | dir=in | app=c:\program files (x86)\mass effect 2\binaries\masseffect2.exe |
"{D422348C-94EE-44BE-B3E1-ED5B6551CA94}" = protocol=17 | dir=in | app=c:\program files (x86)\ffsplit\ffsplit.exe |
"{D53EC3C1-0DFD-415A-B501-384EB5587C3D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
"{D5B543CB-F13B-49F6-97AE-E22D6C647891}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games for windows - live\client\gfwlive.exe |
"{D5D71B4E-A7DD-4588-9051-48D36654D90E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands\binaries\borderlands.exe |
"{D7B3BCE6-D4B0-4919-94A3-D8B33D63991D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal 2\portal2.exe |
"{D8143CE7-C3FC-40EB-B7D3-1251A370CEC7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\killingfloor\system\killingfloor.exe |
"{D8F58771-A381-4BEB-B43D-6FF443C19769}" = protocol=17 | dir=in | app=c:\users\ásdis\desktop\minecraft.exe |
"{D90E16AC-AD7E-423A-BCD9-E0DF5F6505C2}" = dir=out | app=%programfiles% (x86)\focus home interactive\cities xl 2012\citiesxl_2012.exe |
"{D9436336-133A-491C-8795-D02A038FD323}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{DACCAF39-B33C-42BA-A019-BB2C71BD5180}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
"{DBD0E89F-10A0-445B-B80E-0A754EE164F3}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\city life 2008\bin\cld.exe |
"{DC3C2918-8563-4E2E-90AD-DDEDB3C2EE1C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\_runa2co.cmd |
"{DC4F1EED-F97A-4595-9171-F79B42D19008}" = protocol=17 | dir=in | app=c:\program files (x86)\funcom\the secret world\clientpatcher.exe |
"{DCA715DA-45D2-4F44-BB24-72A72DEEF164}" = protocol=6 | dir=in | app=c:\program files (x86)\guild wars 2\gw2.exe |
"{DE5D69AF-5991-4777-B1AD-BC80CD65AF01}" = protocol=17 | dir=in | app=c:\program files (x86)\bittorrent\bittorrent.exe |
"{DE8345E5-7335-41B5-B3EB-8D5B35AF9579}" = protocol=6 | dir=in | app=c:\program files (x86)\dragon age 2\dragonage2launcher.exe |
"{E07B762D-8401-44DF-BEFC-582024A8A648}" = protocol=17 | dir=in | app=c:\program files (x86)\ventrilo\ventrilo.exe |
"{E18912C7-CB6B-4929-872C-F6C0922DED38}" = protocol=6 | dir=out | app=system |
"{E1D42BD6-3338-4364-8155-A7D0F467D315}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\apb reloaded\binaries\vivoxvoiceservice.exe |
"{E21C10A8-09A6-4E37-BD7A-06D7BB876D50}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war 2\dow2.exe |
"{E290B7E8-C1AE-40B8-A653-54C9FF689411}" = protocol=17 | dir=in | app=c:\windows\syswow64\dplaysvr.exe |
"{E29854A5-BA6B-44C8-9EAB-311C3745961B}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\mass effect 3 demo\binaries\win32\masseffect3demo.exe |
"{E2BF0A44-ED8F-43E1-9519-E01A86471F59}" = dir=out | app=%programfiles% (x86)\wb games\scribblenauts unlimited\scribble.exe |
"{E4703F2B-28A8-42EF-8752-07EFEDFE3296}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{E4904B5F-E9B5-43B6-A326-E8B9112CD518}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\besetup\setup_battleyearma2oa.exe |
"{E5C3BB5B-1AA2-4927-A621-DC40DDFC95D1}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\mass effect 3\binaries\win32\masseffect3.exe |
"{E655FB41-A3C4-4BB0-B588-F49126039C5B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead\left4dead.exe |
"{E71BB247-62B6-402B-A562-23CFB4E42BC4}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{E7A4C16B-B884-4ACC-A67A-5D78ED09F71F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\realm of the mad god\realm of the mad god.exe |
"{EA077E5F-32C9-4B52-9D4A-15E1F328D4EA}" = protocol=6 | dir=in | app=c:\program files\microsoft security client\msseces.exe |
"{EA3219B5-2C21-4CB8-8D8E-AF15E3132C83}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\from dust\from_dust.exe |
"{EA62CECF-653B-4FFC-9EB9-2EB2F2048576}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\apb reloaded\binaries\vivoxvoiceservice.exe |
"{EB07BBA8-CB34-4B12-8375-DA159A067C0B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\killingfloor\system\killingfloor.exe |
"{EC0C2D53-1BB4-4BB4-BC02-C3EC7F6A4927}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{EDE3BD62-7EBE-4614-BD36-43103F22E7A5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\angelcatty\age of chivalry\hl2.exe |
"{EE03CE5D-71A3-4BAC-82B8-3F7A8948A1CE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chivalrymedievalwarfare\binaries\win32\udk.exe |
"{EF8559B4-E62E-40F7-966E-D3B5310E120E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{EFA75A02-0C17-4DA4-8D34-358710C1D8B9}" = protocol=6 | dir=in | app=c:\program files (x86)\age of empires ii\empires2.exe |
"{F02C9191-4381-413E-9BA5-3925E2C276CC}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\saints row the third\game_launcher.exe |
"{F0AC593D-F2D6-4BFB-9B4D-37397EBC01EC}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\saints row the third\saintsrowthethird_dx11.exe |
"{F1443CBF-0C5D-44B9-A716-94F418783710}" = protocol=17 | dir=in | app=c:\users\public\sony online entertainment\installed games\planetside 2 psg\planetside2.exe |
"{F1D37E6A-47B6-4304-8FCC-989FBA7076E9}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{F206844C-2E40-43FD-B710-BD4EA1C659DD}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dont_starve\bin\dontstarve_steam.exe |
"{F2183BC6-0E44-42EA-B70B-0B470A55DBDF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{F292DCC8-7BF0-496F-BEDD-8838976C2E82}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\daorigins.exe |
"{F3DDEAA5-A865-42A5-AADD-C50944257A1D}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\mass effect 3\binaries\win32\masseffect3.exe |
"{F3FD756C-246B-4F5D-8951-779B3187CEF7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead\left4dead.exe |
"{F4D5BD2E-698A-4187-9746-417116FF4AF6}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{F81B8C1D-6E86-42D0-98F5-611914DF5A4C}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii public test.exe |
"{F87A3324-AF29-47AA-9948-0F1C375F4E05}" = protocol=17 | dir=in | app=c:\program files (x86)\knights of honor\koh.exe |
"{F90CDDF4-887A-4A3B-935C-8D319EC03F8D}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{FA8A44BE-D775-4579-8EE5-971ECEF28526}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\vampire the masquerade - bloodlines\vampire.exe |
"{FB1C0A27-29D3-4EE1-843F-13D1448B7A0C}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\age of empires online\spartan.exe |
"{FCAEEA60-6838-4306-95FE-A1A49895F97C}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{FE019F5D-EF52-40F2-926C-13EEF06CD3FC}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\age of empires iii\age3.exe |
"{FE33C1A1-477C-4D71-A898-158FF13239F6}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the guild ii\guildii.exe |
"{FF8D6598-AD27-44D7-B398-5E000D6B4ED3}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\demigod\bin\demigod.exe |
"{FFA49573-7C46-4AAD-B2E5-3929C32A5A29}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe |
"TCP Query User{1E2FCB5B-2817-42E9-83BF-95DD6504C78F}C:\program files (x86)\a game of dwarves\a game of dwarves.exe" = protocol=6 | dir=in | app=c:\program files (x86)\a game of dwarves\a game of dwarves.exe |
"TCP Query User{2197FDA8-5C45-4C2A-A3B1-6F7AFF12645B}C:\program files (x86)\knights of honor\koh.exe" = protocol=6 | dir=in | app=c:\program files (x86)\knights of honor\koh.exe |
"TCP Query User{2EAA1298-28BD-4083-A9A6-EC586045F8EF}C:\program files (x86)\steam\steamapps\common\fable 3\fable3.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fable 3\fable3.exe |
"TCP Query User{380C5B73-90D4-4573-ADDD-9743365B86AD}C:\program files (x86)\funcom\age of conan\conanpatcher.exe" = protocol=6 | dir=in | app=c:\program files (x86)\funcom\age of conan\conanpatcher.exe |
"TCP Query User{3F6BB759-A194-4CD3-94B5-1E9B52B39723}C:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe |
"TCP Query User{572BD165-B9FE-419D-9E09-51D7A2311B76}C:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\expansion\beta\arma2oa.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\expansion\beta\arma2oa.exe |
"TCP Query User{656ED114-7BBC-46FB-A264-7AF65DBE8E6D}C:\users\ásdis\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\ásdis\appdata\roaming\dropbox\bin\dropbox.exe |
"TCP Query User{701463CA-E33F-49D9-9FF3-37EF51275BBD}C:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe |
"TCP Query User{70A8ED9E-7003-4EC6-9C49-C4CCD9DB4F98}C:\users\ásdis\appdata\local\temp\gw2.exe" = protocol=6 | dir=in | app=c:\users\ásdis\appdata\local\temp\gw2.exe |
"TCP Query User{72EAFAB9-92FE-47F7-9526-67D76F95865B}C:\programdata\battle.net\agent\agent.1544\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1544\agent.exe |
"TCP Query User{76DB44BA-B0E0-4616-A6CD-1324FB82556B}C:\program files (x86)\ffsplit\ffsplit.exe" = protocol=6 | dir=in | app=c:\program files (x86)\ffsplit\ffsplit.exe |
"TCP Query User{781C7BC1-67AA-45F0-B72C-90D49CD0C424}C:\program files (x86)\steam\steamapps\angelcatty\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\angelcatty\team fortress 2\hl2.exe |
"TCP Query User{7E8EEAAF-A3D8-4EE3-B623-8B7784FB480D}C:\windows\syswow64\dplaysvr.exe" = protocol=6 | dir=in | app=c:\windows\syswow64\dplaysvr.exe |
"TCP Query User{8313831B-C3CC-4868-BAA6-5F3B5A921498}C:\users\public\sony online entertainment\installed games\planetside 2 psg\planetside2.exe" = protocol=6 | dir=in | app=c:\users\public\sony online entertainment\installed games\planetside 2 psg\planetside2.exe |
"TCP Query User{84DDA5DB-4F25-49E4-9694-1E161D979CDF}C:\users\ásdis\appdata\local\microsoft\age of empires online\spartan.exe" = protocol=6 | dir=in | app=c:\users\ásdis\appdata\local\microsoft\age of empires online\spartan.exe |
"TCP Query User{8BA157C1-4023-4021-BB0E-EB20FE5E0DE4}F:\leikir\mass effect 2\binaries\masseffect2.exe" = protocol=6 | dir=in | app=f:\leikir\mass effect 2\binaries\masseffect2.exe |
"TCP Query User{B44B9CC0-DAB2-4D2C-9C70-6FD90D16EFEB}C:\program files (x86)\xfire\xfire.exe" = protocol=6 | dir=in | app=c:\program files (x86)\xfire\xfire.exe |
"TCP Query User{B605CD75-7CC8-49F5-89B0-BFBAF82773D5}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe |
"TCP Query User{C340725B-465C-4F2C-BEF6-F3AFA652A52C}C:\program files (x86)\turbine\the lord of the rings online\lotroclient.exe" = protocol=6 | dir=in | app=c:\program files (x86)\turbine\the lord of the rings online\lotroclient.exe |
"TCP Query User{C7CE2E5F-EFC5-4126-B6A2-72DF307C4B66}C:\program files (x86)\starcraft ii\versions\base22612\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base22612\sc2.exe |
"TCP Query User{C98653FE-3C3B-41CE-A749-3CA62EC1067C}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"TCP Query User{D024D6C7-3B7A-4945-9B0C-22F05375A890}C:\program files (x86)\farcry 3\bin\farcry3.exe" = protocol=6 | dir=in | app=c:\program files (x86)\farcry 3\bin\farcry3.exe |
"TCP Query User{DB8AE34C-2570-42BF-8477-8ED822F59DFF}C:\program files (x86)\age of empires ii\empires2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\age of empires ii\empires2.exe |
"TCP Query User{DF1AF935-B63F-4776-A075-3B364CA9A5DA}C:\program files (x86)\darkfall\lobby.exe" = protocol=6 | dir=in | app=c:\program files (x86)\darkfall\lobby.exe |
"TCP Query User{E8D3CF5F-7526-48D0-B8EE-2CB3E0167D45}F:\leikir\star wars-the old republic\launcher.exe" = protocol=6 | dir=in | app=f:\leikir\star wars-the old republic\launcher.exe |
"TCP Query User{E963B035-3F0B-454D-87F1-343D6488938B}C:\program files (x86)\guild wars 2\gw2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\guild wars 2\gw2.exe |
"UDP Query User{01CDAA54-F81C-445C-8E89-2463AC34822A}C:\program files (x86)\darkfall\lobby.exe" = protocol=17 | dir=in | app=c:\program files (x86)\darkfall\lobby.exe |
"UDP Query User{03763BA9-3332-4DCE-A9B2-4FD679554D39}C:\program files (x86)\starcraft ii\versions\base22612\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base22612\sc2.exe |
"UDP Query User{0465AF3B-AB9B-453E-821D-FA7ECEA8BB04}C:\program files (x86)\funcom\age of conan\conanpatcher.exe" = protocol=17 | dir=in | app=c:\program files (x86)\funcom\age of conan\conanpatcher.exe |
"UDP Query User{1AB0DAD6-A095-44E0-8691-F836583F36FD}C:\program files (x86)\ffsplit\ffsplit.exe" = protocol=17 | dir=in | app=c:\program files (x86)\ffsplit\ffsplit.exe |
"UDP Query User{2694DC9A-C9AE-49BB-AC26-3F168863F625}C:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\expansion\beta\arma2oa.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\expansion\beta\arma2oa.exe |
"UDP Query User{28D73C8A-D772-4495-AD1F-95BC74E77F7D}F:\leikir\mass effect 2\binaries\masseffect2.exe" = protocol=17 | dir=in | app=f:\leikir\mass effect 2\binaries\masseffect2.exe |
"UDP Query User{35FC5D4D-30D2-4F1F-A122-48AEE81D0280}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"UDP Query User{3A64DD1C-14B5-4CFA-8F75-1FEC0BF1C89F}F:\leikir\star wars-the old republic\launcher.exe" = protocol=17 | dir=in | app=f:\leikir\star wars-the old republic\launcher.exe |
"UDP Query User{47925E92-8BB4-4AEC-A422-9455D6B0712E}C:\users\public\sony online entertainment\installed games\planetside 2 psg\planetside2.exe" = protocol=17 | dir=in | app=c:\users\public\sony online entertainment\installed games\planetside 2 psg\planetside2.exe |
"UDP Query User{54E4BDEB-7075-49DD-A02D-9045739D3C99}C:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe |
"UDP Query User{5E49E365-A4F7-4312-BBDD-C83D13B9C220}C:\program files (x86)\age of empires ii\empires2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\age of empires ii\empires2.exe |
"UDP Query User{64136771-8916-4C1C-A6E7-8E61D892E275}C:\program files (x86)\farcry 3\bin\farcry3.exe" = protocol=17 | dir=in | app=c:\program files (x86)\farcry 3\bin\farcry3.exe |
"UDP Query User{7248F4BC-ABBF-4B83-8284-2861AAB4EF44}C:\users\ásdis\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\ásdis\appdata\roaming\dropbox\bin\dropbox.exe |
"UDP Query User{74E0244B-2462-4DAF-9BF3-E35163324F08}C:\program files (x86)\steam\steamapps\angelcatty\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\angelcatty\team fortress 2\hl2.exe |
"UDP Query User{75B45A86-DD16-49BF-AA83-E00FD80B2DDB}C:\users\ásdis\appdata\local\microsoft\age of empires online\spartan.exe" = protocol=17 | dir=in | app=c:\users\ásdis\appdata\local\microsoft\age of empires online\spartan.exe |
"UDP Query User{8F5F7381-2A29-4686-9945-09FF789369F8}C:\users\ásdis\appdata\local\temp\gw2.exe" = protocol=17 | dir=in | app=c:\users\ásdis\appdata\local\temp\gw2.exe |
"UDP Query User{987F8527-34F7-4AAB-AFD1-0A975914C730}C:\program files (x86)\xfire\xfire.exe" = protocol=17 | dir=in | app=c:\program files (x86)\xfire\xfire.exe |
"UDP Query User{9F02A727-1771-4A01-B1B6-D49538A1DCA5}C:\program files (x86)\steam\steamapps\common\fable 3\fable3.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fable 3\fable3.exe |
"UDP Query User{A38DE52C-2F14-4FA8-9649-030738F72B6D}C:\program files (x86)\knights of honor\koh.exe" = protocol=17 | dir=in | app=c:\program files (x86)\knights of honor\koh.exe |
"UDP Query User{A3A2E305-0B6C-467E-AAE5-992E720F67E5}C:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe |
"UDP Query User{A907FC83-BCB1-40C9-909B-F60F8622BE2D}C:\program files (x86)\a game of dwarves\a game of dwarves.exe" = protocol=17 | dir=in | app=c:\program files (x86)\a game of dwarves\a game of dwarves.exe |
"UDP Query User{A978B4DF-7482-4CF5-B53F-0658392DCDA3}C:\programdata\battle.net\agent\agent.1544\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1544\agent.exe |
"UDP Query User{AA991970-8ACC-48E3-911D-3CD42DBF1B0F}C:\program files (x86)\turbine\the lord of the rings online\lotroclient.exe" = protocol=17 | dir=in | app=c:\program files (x86)\turbine\the lord of the rings online\lotroclient.exe |
"UDP Query User{C1F7933C-93EF-4B89-88B2-813AFD5EB9E2}C:\program files (x86)\guild wars 2\gw2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\guild wars 2\gw2.exe |
"UDP Query User{DED6319A-ADF3-4709-9CE0-6ADB9C368065}C:\windows\syswow64\dplaysvr.exe" = protocol=17 | dir=in | app=c:\windows\syswow64\dplaysvr.exe |
"UDP Query User{E4539271-767F-44D0-85A3-26065DF3E5E6}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{015C5B35-B678-451C-9AEE-821E8D69621C}_is1" = PeerBlock 1.1 (r518)
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{0E5D76AD-A3FB-48D5-8400-8903B10317D3}" = iTunes
"{18A5D014-E9AD-DEFE-FAFE-A409612F51B4}" = AMD Media Foundation Decoders
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{26A24AE4-039D-4CA4-87B4-2F86416030FF}" = Java™ 6 Update 30 (64-bit)
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{46DA7FD9-8BC1-7BA8-98D1-27F46647871B}" = AMD Catalyst Install Manager
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4D533F05-A3F6-F8A9-F1F6-FA6812089D36}" = AMD Drag and Drop Transcoding
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{50BD00DC-127E-BF00-FDD5-E1A93AB3507C}" = ccc-utility64
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{8BF6C901-8C9D-C663-F997-EC95A2CCA228}" = AMD AVIVO64 Codecs
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{90BF0360-A1DB-4599-A643-95AB90A52C1E}" = Microsoft_VC90_MFCLOC_x86_x64
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A1E85B9A-AFAD-4D38-AF01-6B020DD5213A}" = Logitech GamePanel Software 3.06.109
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{BB009B20-0BA0-ABDF-1947-4D56639214C7}" = AMD Accelerated Video Transcoding
"{C78D3032-9DFD-41D0-9DE9-58EAE750CBA4}" = Microsoft Security Client
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{D70884EA-E2CE-4539-91DB-4766CC1E5F5F}" = Apple Mobile Device Support
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"6af12c54-643b-4752-87d0-8335503010de_is1" = Nexus Mod Manager
"Logitech Gaming Software" = Logitech Gaming Software 8.20
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Security Client" = Microsoft Security Essentials
"Pen Tablet Driver" = Bamboo
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"XFast LAN" = XFast LAN v6.61

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0309F85C-B1CC-DA9F-D184-FE93CCF08E1D}" = Application Profiles
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{03AEAB60-A7B3-A8DB-468B-EB30FB4B40B0}" = CCC Help German
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0B5154C0-8F00-4616-B0AB-6240AE80D9CE}" = SimCity™ Societies
"{0CC21836-A5D6-4641-B4AE-6FA01D021E41}" = The Sims Medieval Pirates and Nobles
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{10631C28-62E5-477C-9B40-40C5EA8219BE}" = Black & White® 2 Battle of the Gods
"{106B4413-ACBB-4CDE-8707-587DB9BD77EC}" = LogMeIn Hamachi
"{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1
"{117B6BF6-82C3-420C-B284-9247C8568E53}" = The Sims™ 3 Outdoor Living Stuff
"{162ABED6-E60C-6CFF-100E-43C16ABBC5BE}" = CCC Help Chinese Standard
"{1798D459-6B8B-474B-868D-1229EADA3B95}" = Adobe AIR
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1CB724FF-D18C-8FFB-E7C9-0A09CF8EC066}" = CCC Help Japanese
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{20C14CC3-5E3B-D39A-5B37-B15E59785063}" = CCC Help Chinese Traditional
"{2632A2C0-ECF4-7F79-7136-9FEA4C253A4C}" = CCC Help Turkish
"{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java™ 6 Update 22
"{26A24AE4-039D-4CA4-87B4-2F83216025FF}" = Java™ 6 Update 25
"{26A24AE4-039D-4CA4-87B4-2F83217013FF}" = Java 7 Update 13
"{28E82311-8616-11E1-BEB0-B8AC6F97B88E}" = Google Earth
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0
"{30F712DA-64FE-5DBE-AE76-3F8EA3F8223C}" = CCC Help French
"{339C3693-8554-4A25-A664-E0B74D2DFA04}" = Façade
"{3521BDBD-D453-5D9F-AA55-44B75D214629}" = Adobe Community Help
"{3AF8C37F-696E-871C-0851-CDE980FD665E}" = Bamboo Dock
"{3B11D799-48E0-48ED-BFD7-EA655676D8BB}" = Star Wars: The Old Republic
"{3BBFD444-5FAB-49F6-98B1-A1954E831399}" = The Sims™ 3 Showtime
"{3C39B3CC-4EC8-C756-AF4B-72366504FCA5}" = CCC Help Hungarian
"{3DE92282-CB49-434F-81BF-94E5B380E889}" = The Sims™ 3 Seasons
"{3E171899-0175-47CC-84C4-562ACDD4C021}" = OpenOffice.org 3.3
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{45057FCE-5784-48BE-8176-D9D00AF56C3C}" = The Sims™ 3 Late Night
"{47416F0B-6589-591E-C6F8-4235D2230B14}" = Catalyst Control Center InstallProxy
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AA62353-C8D9-4A05-A425-D9DFC4646B99}_is1" = FFsplit version Alpha
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{4CC9D761-A9B6-D8EA-D2A9-B74B5A90B108}" = CCC Help Norwegian
"{4D530FA3-9B89-4186-98B7-F51000008100}" = Age of Empires Online
"{534A31BD-20F4-46b0-85CE-09778379663C}" = Mass Effect™ 3
"{54B227A6-BDBE-69FA-D450-B99609063044}" = CCC Help Greek
"{54B7A3C7-0940-4C16-A509-FC3C3758D22A}_is1" = Amnesia - The Dark Descent
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6C772996-BFF3-3C8C-860B-B3D48FF05D65}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106
"{70F8B183-99EB-4304-BA35-080E2DFFD2A3}" = Age of Empires III
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71828142-5A24-4BD0-97E7-976DA08CE6CF}" = The Sims™ 3 High-End Loft Stuff
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{75D84EF7-0D8C-4e70-B3FA-7B42A5D4E0EB}" = Mass Effect 2
"{76285C16-411A-488A-BCE3-C83CB933D8CF}" = Battlefield 3™
"{784B9B80-303D-44C6-85D0-C23CF1CD3241}" = Foxit Reader
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7C587778-C433-980E-F3C1-203890DC4FBE}" = CCC Help Polish
"{7DC3EABF-66A2-6D79-B485-6328525CA387}" = CCC Help Swedish
"{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}" = Microsoft Games for Windows - LIVE Redistributable
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83BEEFB4-8C28-4F4F-8A9D-E0D1ADCE335B}" = The Sims Medieval
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{843603C6-75B7-BAB5-80DE-E76FB28DEEF2}" = CCC Help Finnish
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8BBC66FD-0195-29B4-5A58-E0B0554E8F42}" = Catalyst Control Center
"{8D9EEAC7-42D5-3951-612A-EAA7B684C592}" = CCC Help Italian
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8e70e4e1-06d7-470b-9f74-a51bef21088e}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{910F4A29-1134-49E0-AD8B-56E4A3152BD1}" = The Sims™ 3 Ambitions
"{9158FF30-78D7-40EF-B83E-451AC5334640}" = Adobe Photoshop CS5.1
"{918A9082-6287-4D25-9002-5E5D5E4971CB}" = League of Legends
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{9530AE42-DAE1-4619-9594-B23487285D17}" = NVIDIA PhysX
"{9791DAED-B734-2835-988B-157BDA087496}" = CCC Help Dutch
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{98B740C3-FAA4-C523-7478-4DBCAB7B27D1}" = Catalyst Control Center Graphics Previews Common
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9DF0196F-B6B8-4C3A-8790-DE42AA530101}" = SPORE™
"{9F0CAC6D-9B0D-A95F-CF61-6E88952D6181}" = CCC Help Thai
"{A1683CA7-4850-4A21-982B-C6D853C79AF7}" = Mass Effect™ 3 Demo
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A625DB70-98D5-16FD-C49D-4B8B1B2304A4}" = CCC Help Spanish
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A90214C3-3A0C-2F05-6083-E1A4BAD9E30D}" = CCC Help Danish
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA123216-6DE0-E57C-DC57-4FECEACB482F}" = CCC Help Russian
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AC524B17-B82D-414A-B2E2-C38DC4ABF5C9}" = Darkfall
"{B37DAFA5-717D-41F8-BDFB-3A4B68C0B3A1}" = The Sims™ 3 Supernatural
"{B4E343DD-BAAB-4D59-AD9C-DEA0AFE09DF1}" = Mumble 1.2.3
"{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86
"{B810D852-DFD6-FC3-89A5-CC4D47756DAF}_is1" = FarCry 3 version 5.1
"{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}" = The Sims™ 3 World Adventures
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C07F8D75-7A8D-400E-A8F9-A3F396B49BB1}" = SPORE™ Creepy & Cute Parts Pack
"{C12631C6-804D-4B32-B0DD-8A496462F106}" = The Sims™ 3 Pets
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCE825DB-347A-4004-A186-5F4A6FDD8547}" = Apple Application Support
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0837A59-83E6-3392-1BD9-86D3445676DB}" = CCC Help Korean
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D70AB273-113B-D7DE-5C8D-82CABA7CB0AF}" = Catalyst Control Center Localization All
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{D9E52CD1-9DF1-4A8A-9BDC-1E5E53982F2B}" = Black & White® 2
"{DC8772D4-C75F-5235-63E2-BBC73F909B7A}" = CCC Help Czech
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DED7FD3C-DDD2-43BB-B0F5-B07F9D0430D3}" = CCC Help Portuguese
"{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}" = Etron USB3.0 Host Controller
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E157F2EB-E06F-B57F-9105-68F348DB2EAD}" = CCC Help English
"{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}" = Catalyst Control Center - Branding
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}" = Far Cry 3
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E6B88BD6-E4B2-4701-A648-B6DAC6E491CC}" = The Sims™ 3 Generations
"{E824E81C-80A4-3DFF-B5F9-4842A9FF5F7F}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106
"{EA17F4FC-FDBF-4CF8-A529-2D983132D053}" = Skype™ 6.0
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F2E23139-3404-4E3C-9855-7724415D62A5}" = Dragon Age II
"{F4D34EBA-83D6-49E3-A6D6-6889C4A639A3}" = DayZ Commander
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"{FDC85EE3-EDAA-47C9-9885-2A26FC41DC22}" = tbbMeter Loader Service
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"{THEGUILDREN-0010-2010-300520102330}_is1" = Patch v4.17b Update
"12bbe590-c890-11d9-9669-0800200c9a66_is1" = The Lord of the Rings Online™ v03.07.00.8037
"A Game of Dwarves_is1" = A Game of Dwarves
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Age of Conan_is1" = Age of Conan: Unchained
"Astroburn Lite" = Astroburn Lite
"AutoItv3" = AutoIt v3.3.8.1
"Bamboo Dock" = Bamboo Dock
"Battlelog Web Plugins" = Battlelog Web Plugins
"BattlEye for OA" = BattlEye for OA Uninstall
"BitTorrent" = BitTorrent
"BitTorrentBar Toolbar" = BitTorrentBar Toolbar
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"Cities XL 2012" = Cities XL 2012
"DAEMON Tools Lite" = DAEMON Tools Lite
"Desura" = Desura
"Diablo III" = Diablo III
"Endless.Space_is1" = Endless.Space
"ENTERPRISE" = Microsoft Office Enterprise 2007
"ESN Sonar-0.70.4" = ESN Sonar
"Faster Than Light_is1" = Faster Than Light
"GFWL_{4D530FA3-9B89-4186-98B7-F51000008100}" = Age of Empires Online
"GOGPACKTHEMEHOSPITAL_is1" = Theme Hospital
"Guild Wars 2" = Guild Wars 2
"InstallShield_{70F8B183-99EB-4304-BA35-080E2DFFD2A3}" = Age of Empires III
"InstallShield_{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}" = Etron USB3.0 Host Controller
"Knights of Honor" = Knights of Honor
"LogMeIn Hamachi" = LogMeIn Hamachi
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox 14.0.1 (x86 en-US)" = Mozilla Firefox 14.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Origin" = Origin
"ProjectZomboid" = Project Zomboid (remove only)
"PunkBusterSvc" = PunkBuster Services
"quicktime_lite_is1" = QT Lite 4.1.0
"Scribblenauts Unlimited_is1" = Scribblenauts Unlimited
"StarCraft II" = StarCraft II
"Steam App 113400" = APB Reloaded
"Steam App 200010" = Quantum Conundrum
"Steam App 200210" = Realm of the Mad God
"Steam App 200370" = A Game of Dwarves
"Steam App 219640" = Chivalry: Medieval Warfare
"Steam App 219740" = Don't Starve
"Steam App 33910" = ARMA 2
"Steam App 33930" = ARMA 2: Operation Arrowhead
"Steam App 35480" = Dwarfs!?
"Steam App 48240" = Anno 2070
"Steam App 49520" = Borderlands 2
"Steam App 55230" = Saints Row: The Third
"Steam App 570" = Dota 2
"Steam App 72850" = The Elder Scrolls V: Skyrim
"The Secret World_is1" = The Secret World
"Towns V8" = Towns V8
"Uplay" = Uplay
"uTorrent" = µTorrent
"VLC media player" = VLC media player 1.1.11
"Wacom WebTabletPlugin for IE" = WebTablet IE Plugin
"Wacom WebTabletPlugin for Internet Explorer and Netscape" = WebTablet FB Plugin
"Wacom WebTabletPlugin for Netscape" = WebTablet Netscape Plugin
"wacomid-desktop-launcher.DCFD4B89A63EE70BC162777F06D4B93B6397AEC7.1" = Bamboo Dock
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinLiveSuite" = Windows Live Essentials
"WinPcapInst" = WinPcap 4.1.2
"World of Warcraft" = World of Warcraft
"Xfire" = Xfire (remove only)
"Xvid_is1" = Xvid 1.2.2 final uninstall

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"101a9f93b8f0bb6f" = Curse Client
"Dropbox" = Dropbox
"Google Chrome" = Google Chrome
"Puzzle Pirates" = Puzzle Pirates
"SOE-C:/Users/Ásdis/AppData/Local/Sony Online Entertainment/ApplicationUpdater" = applicationupdater
"SOE-C:/Users/Public/Sony Online Entertainment/Installed Games/PlanetSide 2 PSG" = gamelauncher-ps2-psg
"soe-PlanetSide 2 PSG" = PlanetSide 2
"Tropico 4" = Tropico 4 1.00
"UnityWebPlayer" = Unity Web Player

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 20.2.2013 11:29:33 | Computer Name = Asdis-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 9999

Error - 20.2.2013 11:29:33 | Computer Name = Asdis-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 9999

Error - 20.2.2013 11:29:34 | Computer Name = Asdis-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 20.2.2013 11:29:34 | Computer Name = Asdis-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 10998

Error - 20.2.2013 11:29:34 | Computer Name = Asdis-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 10998

Error - 20.2.2013 11:29:35 | Computer Name = Asdis-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 20.2.2013 11:29:35 | Computer Name = Asdis-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 11996

Error - 20.2.2013 11:29:35 | Computer Name = Asdis-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 11996

Error - 20.2.2013 11:29:36 | Computer Name = Asdis-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 20.2.2013 11:29:36 | Computer Name = Asdis-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 12995

Error - 20.2.2013 11:29:36 | Computer Name = Asdis-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 12995

[ System Events ]
Error - 20.2.2013 13:16:47 | Computer Name = Asdis-PC | Source = ipnathlp | ID = 31004
Description =

Error - 20.2.2013 13:16:48 | Computer Name = Asdis-PC | Source = ipnathlp | ID = 30013
Description =

Error - 20.2.2013 13:16:51 | Computer Name = Asdis-PC | Source = WMPNetworkSvc | ID = 866300
Description =

Error - 20.2.2013 13:16:52 | Computer Name = Asdis-PC | Source = ipnathlp | ID = 31004
Description =

Error - 20.2.2013 13:18:38 | Computer Name = Asdis-PC | Source = ipnathlp | ID = 34001
Description =

Error - 20.2.2013 13:25:45 | Computer Name = Asdis-PC | Source = ipnathlp | ID = 34001
Description =

Error - 20.2.2013 15:29:40 | Computer Name = Asdis-PC | Source = ipnathlp | ID = 31004
Description =

Error - 20.2.2013 15:40:01 | Computer Name = Asdis-PC | Source = ipnathlp | ID = 31004
Description =

Error - 20.2.2013 16:21:56 | Computer Name = Asdis-PC | Source = ipnathlp | ID = 31004
Description =

Error - 20.2.2013 21:16:59 | Computer Name = Asdis-PC | Source = ipnathlp | ID = 31004
Description =


< End of report >
Hi Shadecat,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Bittorrent and Utorrent
You have Bittorrent and Utorrent, P2P/file sharing programs installed on your computer. P2P applications like them are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm


I would recommend that you uninstall Bittorrent and Utorrent, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.

You didn't find any information on Win32/small.CA because it isn't a specific virus… it is actually a family of viruses that can manifest any many different ways. There is a good chance that MSSE blocked it. You should note that it normally accesses a system through torrent downloads.

Double click on OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Processes

:OTL
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = is-IS
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = E1 5E 70 87 A1 99 CD 01 [binary data]
IE - HKCU\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_149.dll File not found
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.110.0: File not found
[2012.09.12 19:35:47 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
O2 - BHO: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 10.13.2)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O33 - MountPoints2\{130a1848-370c-11e1-976f-002522fb47a3}\Shell - "" = AutoRun
O33 - MountPoints2\{130a1848-370c-11e1-976f-002522fb47a3}\Shell\AutoRun\command - "" = G:\Autorun.exe
O33 - MountPoints2\{488af93b-36ea-11e1-87a1-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{488af93b-36ea-11e1-87a1-806e6f6e6963}\Shell\AutoRun\command - "" = D:\Autorun.exe – [2012.09.28 13:30:38 | 000,055,176 | R— | M] (Electronic Arts)

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL log.
Hey Tomk, thanks for the swift reply! Two out of the three links you gave me regarding the torrents seem to be outdated, first one sent me to a site to download Internet explorer, and the other gives a 'page not found!' but the third one is working. :) I did as you asked with the OTL, but as the idiot I am. I clicked the X on the report once rebooting, thinking it would be saved already on my desktop as the other two, or at least prompt me to save before closing - but no. Apparently not. I'm really sorry how difficult I am being! :( ( I even looked under notepads recent files, and it wasn't there either. Weird that it didn't even prompt me to save before closing it! I was sure it would be saved, since it even had a name! ) Is there any way that I can re-create the report for you? As certainly if I re-do the fix, that will procure a report that didn't really do anything as it's already been done. Again, I'm really sorry for how difficult I am and thank you for trying to help me.
No biggee. You're not being difficult. The report just verifies that the program did what we told it to do. We can ascertain the same information by noting the differences in a logs after the "fix" was made.

I'd like you to run a different tool this time.

Download ComboFix from here: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.


When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Here you go! Made sure not to screw this log up. :) ComboFix 13-02-21.02 - Ásdis 21.02.2013 15:45:27.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.354.1033.18.8154.6284 [GMT 0:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C} SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\SysWow64\URTTemp c:\windows\SysWow64\URTTemp\regtlib.exe c:\windows\XSxS F:\install.exe . . ((((((((((((((((((((((((( Files Created from 2013-01-21 to 2013-02-21 ))))))))))))))))))))))))))))))) . . 2074-05-07 18:38 . 2006-11-21 20:48 203576 ——w- c:\program files (x86)\Microsoft Games\Age of Empires III\autopatcher2.exe 2013-02-21 15:52 . 2013-02-21 15:52 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-02-21 08:51 . 2013-02-21 08:51 76232 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{961F3B04-2338-49B7-AACF-16528B0A0953}\offreg.dll 2013-02-21 08:46 . 2013-02-21 08:46 ——– d—–w- C:\_OTL 2013-02-21 05:15 . 2013-02-08 00:28 9162192 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{961F3B04-2338-49B7-AACF-16528B0A0953}\mpengine.dll 2013-02-20 17:28 . 2013-02-08 00:28 9162192 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2013-02-20 03:01 . 2013-02-20 03:01 ——– d—–w- c:\windows\Temp5E742C12-6AE7-1086-0CF5-2F558042F9F7-Signatures 2013-02-18 22:39 . 2013-02-21 04:06 ——– d—–w- c:\users\Ásdis\AppData\Roaming\.minecraft 2013-02-18 16:42 . 2013-02-18 16:42 ——– d—–w- c:\program files (x86)\FOXIT SOFTWARE 2013-02-18 16:40 . 2013-02-18 16:40 ——– d—–w- c:\program files\iPod 2013-02-18 16:40 . 2013-02-18 16:41 ——– d—–w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-02-18 16:40 . 2013-02-18 16:41 ——– d—–w- c:\program files\iTunes 2013-02-18 16:40 . 2013-02-18 16:41 ——– d—–w- c:\program files (x86)\iTunes 2013-02-13 03:01 . 2013-01-09 01:10 996352 —-a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll 2013-02-13 03:01 . 2013-01-08 22:01 768000 —-a-w- c:\program files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll 2013-02-13 00:14 . 2013-01-05 05:53 5553512 —-a-w- c:\windows\system32\ntoskrnl.exe 2013-02-13 00:14 . 2013-01-05 05:00 3967848 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2013-02-13 00:14 . 2013-01-05 05:00 3913064 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2013-02-13 00:14 . 2013-01-04 05:46 215040 —-a-w- c:\windows\system32\winsrv.dll 2013-02-13 00:14 . 2013-01-04 03:26 3153408 —-a-w- c:\windows\system32\win32k.sys 2013-02-13 00:14 . 2013-01-04 02:47 25600 —-a-w- c:\windows\SysWow64\setup16.exe 2013-02-13 00:14 . 2013-01-04 02:47 14336 —-a-w- c:\windows\SysWow64\ntvdm64.dll 2013-02-13 00:14 . 2013-01-04 04:51 5120 —-a-w- c:\windows\SysWow64\wow32.dll 2013-02-13 00:14 . 2013-01-04 02:47 7680 —-a-w- c:\windows\SysWow64\instnm.exe 2013-02-13 00:14 . 2013-01-04 02:47 2048 —-a-w- c:\windows\SysWow64\user.exe 2013-02-13 00:14 . 2013-01-03 06:00 1913192 —-a-w- c:\windows\system32\drivers\tcpip.sys 2013-02-13 00:14 . 2013-01-03 06:00 288088 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS 2013-02-12 22:54 . 2013-02-12 22:54 ——– d—–w- c:\users\Ásdis\AppData\Local\WhatPulse 2013-02-12 22:53 . 2013-02-12 22:53 ——– d—–w- c:\program files (x86)\WinPcap 2013-02-11 15:24 . 2013-02-12 12:59 ——– d—–w- c:\users\Ásdis\AppData\Roaming\Tropico 4 2013-02-11 15:23 . 2013-02-11 15:23 ——– d—–w- c:\users\Ásdis\AppData\Roaming\Kalypso Media 2013-02-11 15:12 . 2013-02-11 15:12 ——– d—–w- c:\program files (x86)\Kalypso Media 2013-02-08 13:13 . 2013-02-08 13:13 16365936 —-a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe 2013-02-05 20:16 . 2013-02-05 20:16 ——– d—–w- c:\programdata\Orbit 2013-02-03 10:54 . 2013-02-03 10:54 95648 —-a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-02-02 07:36 . 2013-02-02 07:36 ——– d—–w- c:\program files (x86)\Common Files\logishrd 2013-02-02 07:36 . 2013-02-02 07:36 ——– d—–w- c:\program files\Common Files\logishrd 2013-02-02 04:01 . 2013-02-02 04:01 ——– d—–w- c:\users\Ásdis\AppData\Roaming\Unity 2013-02-02 03:51 . 2013-02-02 03:51 ——– d—–w- c:\users\Ásdis\AppData\Local\Unity 2013-02-01 22:43 . 2013-02-01 22:48 ——– d—–w- c:\program files (x86)\Amnesia - The Dark Descent 2013-01-24 19:30 . 2013-01-24 19:38 ——– d—–w- c:\program files (x86)\FarCry 3 . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-02-13 03:04 . 2012-01-04 16:13 70004024 —-a-w- c:\windows\system32\MRT.exe 2013-02-08 13:13 . 2012-03-30 09:20 697712 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-02-08 13:13 . 2012-01-04 15:49 74096 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-02-05 20:26 . 2012-01-04 21:04 281688 —-a-w- c:\windows\SysWow64\PnkBstrB.xtr 2013-02-05 20:26 . 2012-01-04 21:01 281688 —-a-w- c:\windows\SysWow64\PnkBstrB.exe 2013-02-05 20:18 . 2012-01-04 21:01 281688 —-a-w- c:\windows\SysWow64\PnkBstrB.ex0 2013-02-03 10:54 . 2012-05-27 03:00 861088 —-a-w- c:\windows\SysWow64\npdeployJava1.dll 2013-02-03 10:54 . 2012-01-12 04:09 782240 —-a-w- c:\windows\SysWow64\deployJava1.dll 2013-01-30 10:53 . 2010-11-21 03:27 273840 ——w- c:\windows\system32\MpSigStub.exe 2013-01-04 04:43 . 2013-02-13 00:14 44032 —-a-w- c:\windows\apppatch\acwow64.dll 2012-12-23 02:42 . 2012-05-26 23:37 65600 —-a-w- c:\windows\system32\drivers\pssdklbf.sys 2012-12-23 02:42 . 2012-05-26 23:37 53312 —-a-w- c:\windows\system32\drivers\pssdk42.sys 2012-12-16 17:11 . 2012-12-21 17:43 46080 —-a-w- c:\windows\system32\atmlib.dll 2012-12-16 14:45 . 2012-12-21 17:43 367616 —-a-w- c:\windows\system32\atmfd.dll 2012-12-16 14:13 . 2012-12-21 17:43 295424 —-a-w- c:\windows\SysWow64\atmfd.dll 2012-12-16 14:13 . 2012-12-21 17:43 34304 —-a-w- c:\windows\SysWow64\atmlib.dll 2012-12-07 13:20 . 2013-01-10 01:12 441856 —-a-w- c:\windows\system32\Wpc.dll 2012-12-07 13:15 . 2013-01-10 01:12 2746368 —-a-w- c:\windows\system32\gameux.dll 2012-12-07 12:26 . 2013-01-10 01:12 308736 —-a-w- c:\windows\SysWow64\Wpc.dll 2012-12-07 12:20 . 2013-01-10 01:12 2576384 —-a-w- c:\windows\SysWow64\gameux.dll 2012-12-07 11:20 . 2013-01-10 01:12 30720 —-a-w- c:\windows\system32\usk.rs 2012-12-07 11:20 . 2013-01-10 01:12 43520 —-a-w- c:\windows\system32\csrr.rs 2012-12-07 11:20 . 2013-01-10 01:12 23552 —-a-w- c:\windows\system32\oflc.rs 2012-12-07 11:20 . 2013-01-10 01:12 45568 —-a-w- c:\windows\system32\oflc-nz.rs 2012-12-07 11:20 . 2013-01-10 01:12 44544 —-a-w- c:\windows\system32\pegibbfc.rs 2012-12-07 11:20 . 2013-01-10 01:12 20480 —-a-w- c:\windows\system32\pegi-fi.rs 2012-12-07 11:20 . 2013-01-10 01:12 20480 —-a-w- c:\windows\system32\pegi-pt.rs 2012-12-07 11:19 . 2013-01-10 01:12 20480 —-a-w- c:\windows\system32\pegi.rs 2012-12-07 11:19 . 2013-01-10 01:12 46592 —-a-w- c:\windows\system32\fpb.rs 2012-12-07 11:19 . 2013-01-10 01:12 40960 —-a-w- c:\windows\system32\cob-au.rs 2012-12-07 11:19 . 2013-01-10 01:12 21504 —-a-w- c:\windows\system32\grb.rs 2012-12-07 11:19 . 2013-01-10 01:12 15360 —-a-w- c:\windows\system32\djctq.rs 2012-12-07 11:19 . 2013-01-10 01:12 55296 —-a-w- c:\windows\system32\cero.rs 2012-12-07 11:19 . 2013-01-10 01:12 51712 —-a-w- c:\windows\system32\esrb.rs 2012-12-07 10:46 . 2013-01-10 01:12 43520 —-a-w- c:\windows\SysWow64\csrr.rs 2012-12-07 10:46 . 2013-01-10 01:12 30720 —-a-w- c:\windows\SysWow64\usk.rs 2012-12-07 10:46 . 2013-01-10 01:12 45568 —-a-w- c:\windows\SysWow64\oflc-nz.rs 2012-12-07 10:46 . 2013-01-10 01:12 44544 —-a-w- c:\windows\SysWow64\pegibbfc.rs 2012-12-07 10:46 . 2013-01-10 01:12 20480 —-a-w- c:\windows\SysWow64\pegi-pt.rs 2012-12-07 10:46 . 2013-01-10 01:12 23552 —-a-w- c:\windows\SysWow64\oflc.rs 2012-12-07 10:46 . 2013-01-10 01:12 20480 —-a-w- c:\windows\SysWow64\pegi-fi.rs 2012-12-07 10:46 . 2013-01-10 01:12 46592 —-a-w- c:\windows\SysWow64\fpb.rs 2012-12-07 10:46 . 2013-01-10 01:12 20480 —-a-w- c:\windows\SysWow64\pegi.rs 2012-12-07 10:46 . 2013-01-10 01:12 21504 —-a-w- c:\windows\SysWow64\grb.rs 2012-12-07 10:46 . 2013-01-10 01:12 40960 —-a-w- c:\windows\SysWow64\cob-au.rs 2012-12-07 10:46 . 2013-01-10 01:12 15360 —-a-w- c:\windows\SysWow64\djctq.rs 2012-12-07 10:46 . 2013-01-10 01:12 55296 —-a-w- c:\windows\SysWow64\cero.rs 2012-12-07 10:46 . 2013-01-10 01:12 51712 —-a-w- c:\windows\SysWow64\esrb.rs 2012-11-30 05:45 . 2013-01-10 01:11 362496 —-a-w- c:\windows\system32\wow64win.dll 2012-11-30 05:45 . 2013-01-10 01:11 243200 —-a-w- c:\windows\system32\wow64.dll 2012-11-30 05:45 . 2013-01-10 01:11 13312 —-a-w- c:\windows\system32\wow64cpu.dll 2012-11-30 05:43 . 2013-01-10 01:11 16384 —-a-w- c:\windows\system32\ntvdm64.dll 2012-11-30 05:41 . 2013-01-10 01:11 424448 —-a-w- c:\windows\system32\KernelBase.dll 2012-11-30 05:41 . 2013-01-10 01:11 1161216 —-a-w- c:\windows\system32\kernel32.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 6144 —ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 4608 —ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 4608 —ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 4096 —ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 4096 —ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3584 —ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3584 —ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3584 —ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3584 —ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 5120 —ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 4096 —ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3584 —ha-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3584 —ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3584 —ha-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-io-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 4096 —ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll 2012-11-30 04:53 . 2013-01-10 01:11 274944 —-a-w- c:\windows\SysWow64\KernelBase.dll 2012-11-30 04:45 . 2013-01-10 01:11 4608 —ha-w- c:\windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 4096 —ha-w- c:\windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 4096 —ha-w- c:\windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 3584 —ha-w- c:\windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 3584 —ha-w- c:\windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 3072 —ha-w- c:\windows\SysWow64\api-ms-win-core-string-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 3072 —ha-w- c:\windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 4096 —ha-w- c:\windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 4096 —ha-w- c:\windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 3584 —ha-w- c:\windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 3584 —ha-w- c:\windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 3584 —ha-w- c:\windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 3584 —ha-w- c:\windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 3072 —ha-w- c:\windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 3072 —ha-w- c:\windows\SysWow64\api-ms-win-core-io-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 4096 —ha-w- c:\windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 5120 —ha-w- c:\windows\SysWow64\api-ms-win-core-file-l1-1-0.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="c:\program files (x86)\Steam\Steam.exe" [2013-02-15 1597864] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2011-10-17 284440] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280] "GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040] "BambooCore"="c:\program files (x86)\Bamboo Dock\BambooCore.exe" [2011-09-27 646232] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-09-28 642728] "LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-12-10 2254768] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-12-12 152544] . c:\users\Ásdis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Ásdis\AppData\Roaming\Dropbox\bin\Dropbox.exe [2013-1-20 28539272] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-11-09 160944] R3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\DAUpdaterSvc.Service.exe [2010-10-14 25832] R3 Desura Install Service;Desura Install Service;c:\program files (x86)\Common Files\Desura\desura_service.exe [2012-07-06 131912] R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys [2012-09-19 102368] R3 LGPBTDD;LGPBTDD.sys Display Driver;c:\windows\system32\Drivers\LGPBTDD.sys [2009-07-01 30728] R3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys [2012-01-18 351136] R3 LVUVC64;Logitech HD Webcam C270(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys [2012-01-18 4865568] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2012-08-30 128456] R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-09-12 368896] R3 nmwcdnsucx64;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsucx64.sys [2011-08-17 12800] R3 nmwcdnsux64;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsux64.sys [2011-08-17 171008] R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-06-25 35344] R3 PSSDK42;PSSDK42;c:\windows\system32\Drivers\pssdk42.sys [2012-12-23 53312] R3 PSSDKLBF;PSSDKLBF;c:\windows\system32\Drivers\pssdklbf.sys [2012-12-23 65600] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456] R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys [2012-09-19 203104] R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208] R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys [2011-09-08 13312] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-01-04 1255736] R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [2008-05-06 14464] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-01-05 279616] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-09-28 239616] S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-12-10 2465712] S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-10-17 13592] S2 TabletServicePen;TabletServicePen;c:\program files\Tablet\Pen\Pen_Tablet.exe [2011-09-08 6583160] S2 tbbLoaderService;tbbLoaderService;c:\program files (x86)\thinkbroadband.com\tbbMeter\tbbLoaderService.exe [2010-10-09 14848] S2 TouchServicePen;Wacom Consumer Touch Service;c:\program files\Tablet\Pen\Pen_TouchService.exe [2011-09-08 528760] S2 UMVPFSrv;UMVPFSrv;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2012-01-18 450848] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-05-14 96896] S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys [2011-08-05 57088] S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys [2011-08-05 80384] S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2009-11-24 22408] S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [2009-11-24 16008] S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys [2009-11-18 32344] . . Contents of the 'Scheduled Tasks' folder . 2013-02-21 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-30 13:13] . 2013-02-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-07-25 01:29] . 2013-02-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-07-25 01:29] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 162552 —-a-w- c:\users\Ásdis\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 162552 —-a-w- c:\users\Ásdis\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 162552 —-a-w- c:\users\Ásdis\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 162552 —-a-w- c:\users\Ásdis\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-10-17 13307496] "XFast LAN"="c:\program files\ASRock\XFast LAN\cFosSpeed.exe" [2011-07-04 1441152] "Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2011-12-07 5889816] "Launch LgDeviceAgent"="c:\program files\Logitech\GamePanel Software\LgDevAgt.exe" [2010-08-03 415816] "Launch LCDMon"="c:\program files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2010-08-03 2412616] "Launch LGDCore"="c:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2010-08-03 4725320] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-12 1289704] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-05-30 499608] . ——- Supplementary Scan ——- . uInternet Settings,ProxyOverride = *.local IE: E&xport; to Microsoft Excel - c:\progra~2\MIF5BA~1\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.1.254 FF - ProfilePath - c:\users\Ásdis\AppData\Roaming\Mozilla\Firefox\Profiles\wmczw61l.default\ . - - - - ORPHANS REMOVED - - - - . ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - c:\users\Ásdis\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - c:\users\Ásdis\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - c:\users\Ásdis\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll Wow6432Node-HKCU-Run-whatpulse - c:\program files (x86)\WhatPulse2\whatpulse.exe AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe AddRemove-{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88} - c:\program files (x86)\InstallShield Installation Information\{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}\setup.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions] @Denied: (2) (LocalSystem) "{88C7F2AA-F93F-432C-8F0E-B7D85967A527}"=hex:51,66,7a,6c,4c,1d,38,12,c4,f1,d4, 8c,0d,b7,42,06,f0,18,f4,98,5c,39,e1,33 "{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96, 76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a "{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07, 72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57 "{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23, 94,30,02,d1,0f,f1,da,12,24,73,56,27,d2 "{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db, df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd "{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47, 2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85 "{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16, fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17 "{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9, b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration] @Denied: (2) (LocalSystem) "Timestamp"=hex:21,73,2a,4a,05,3e,cd,01 . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences] @Denied: (2) (LocalSystem) "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,3f,0d,d3,f7,c1,f1,3d,4f,92,eb,96,\ "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,3f,0d,d3,f7,c1,f1,3d,4f,92,eb,96,\ . [HKEY_USERS\S-1-5-21-2006369733-2391191245-1076361487-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-2006369733-2391191245-1076361487-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_USERS\S-1-5-21-2006369733-2391191245-1076361487-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] @Allowed: (Read) (RestrictedCode) . [HKEY_USERS\S-1-5-21-2006369733-2391191245-1076361487-1000\Software\SecuROM\License information*] "datasecu"=hex:ea,b2,b6,70,70,a7,99,d5,2f,8d,9d,9e,7a,53,81,c2,b7,b4,ef,c5,52, c2,e2,f8,7b,b8,8a,35,33,3c,ca,7d,a5,73,d3,49,17,1f,3c,4e,a9,ea,cc,55,67,c7,\ "rkeysecu"=hex:64,b6,bd,e1,3e,80,9e,c4,40,b4,90,83,87,8e,33,49 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_149_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_149_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_149_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_149_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_149.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_149.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_149.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_149.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2013-02-21 15:54:28 ComboFix-quarantined-files.txt 2013-02-21 15:54 . Pre-Run: 251.599.392.768 bytes free Post-Run: 251.202.752.512 bytes free . - - End Of File - - 414D73D244D22F05B3B43AAFCACAEFC8
That looks good.

Let's get an online scan. This one takes awhile. Often measured in hours.

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
Here you go, perhaps time to reinforce to my boyfriend what he can and can't do on my computer. :huh: ESETSmartInstaller@High as CAB hook log: OnlineScanner64.ocx - registred OK OnlineScanner.ocx - registred OK # version=8 # iexplore.exe=9.00.8112.16421 (WIN7_IE9_RTM.110308-0330) # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=ed447d1f7dbddf438edbb03ab0188fd8 # engine=13217 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2013-02-22 11:32:27 # local_time=2013-02-22 11:32:27 (+0000, Greenwich Standard Time) # country="Iceland" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 100 94 71209536 113997797 0 0 # scanned=1435014 # found=6 # cleaned=0 # scan_time=27552 sh=195F9BB7D46147E9BFD671500AF25E79875EE935 ft=1 fh=0b9331985462bb24 vn="Win32/OpenCandy application" ac=I fn="C:\Users\Ásdis\Downloads\DTLite4451-0236.exe" sh=42641E6015220DB5095B28606C82C003E2DB097B ft=1 fh=aff2050af91a0498 vn="a variant of Win32/HackTool.CheatEngine.AB application" ac=I fn="E:\Program Files\Cheat Engine 6.1\cheatengine-i386.exe" sh=25D4228A516DA50E8BD940AA9C96BCF3B06CC5D9 ft=1 fh=9517bb75914b9b95 vn="a variant of Win32/HackTool.Crack.B application" ac=I fn="E:\Users\Asdis\Desktop\Folder\Terraria.exe" sh=594AC6A960A4CA80AEAEC5C32427946C5013CF62 ft=1 fh=ed69c0f980fe174d vn="multiple threats" ac=I fn="E:\Users\Asdis\Downloads\CheatEngine61.exe" sh=9F297EA9ED6DEA165EB9AC430FC4B28C6061922D ft=1 fh=cac44e7c2d58e832 vn="Win32/Toolbar.Widgi application" ac=I fn="F:\D-Diskur\Diskar\Video-Converter\Setup_FreeVideoConverter.exe" sh=18C7CDCD78B2C8C2D61A3BC9CCD185298AF99F4F ft=0 fh=0000000000000000 vn="a variant of Win32/HackTool.Crack.B application" ac=I fn="F:\Downloads\Games\Terraria.v1.0.1.rar"
That's probably a good idea. There is no quicker way to get a nasty infection than downloading pirated/cracked programs.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    C:\Users\Ásdis\Downloads\DTLite4451-0236.exe
    E:\Program Files\Cheat Engine 6.1\cheatengine-i386.exe
    E:\Users\Asdis\Desktop\Folder\Terraria.exe
    E:\Users\Asdis\Downloads\CheatEngine61.exe
    F:\D-Diskur\Diskar\Video-Converter\Setup_FreeVideoConverter.exe
    F:\Downloads\Games\Terraria.v1.0.1.rar
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Here you go: ComboFix 13-02-21.02 - Ásdis 23.02.2013 0:22.2.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.354.1033.18.8154.6163 [GMT 0:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\-sdis\Desktop\CFScript.txt AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C} SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((( Files Created from 2013-01-23 to 2013-02-23 ))))))))))))))))))))))))))))))) . . 2074-05-07 18:38 . 2006-11-21 20:48 203576 ——w- c:\program files (x86)\Microsoft Games\Age of Empires III\autopatcher2.exe 2013-02-23 00:31 . 2013-02-23 00:31 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-02-23 00:31 . 2013-02-23 00:31 ——– d—–w- c:\users\µsdis\AppData\Local\temp 2013-02-22 20:59 . 2013-02-22 20:59 76232 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{5549F932-6F02-4988-BF5A-D2814BBC98C1}\offreg.dll 2013-02-22 16:06 . 2013-02-08 00:28 9162192 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{5549F932-6F02-4988-BF5A-D2814BBC98C1}\mpengine.dll 2013-02-21 20:00 . 2013-02-08 00:28 9162192 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2013-02-21 08:46 . 2013-02-21 08:46 ——– d—–w- C:\_OTL 2013-02-20 03:01 . 2013-02-20 03:01 ——– d—–w- c:\windows\Temp5E742C12-6AE7-1086-0CF5-2F558042F9F7-Signatures 2013-02-18 22:39 . 2013-02-22 20:46 ——– d—–w- c:\users\Ásdis\AppData\Roaming\.minecraft 2013-02-18 16:42 . 2013-02-18 16:42 ——– d—–w- c:\program files (x86)\FOXIT SOFTWARE 2013-02-18 16:40 . 2013-02-18 16:40 ——– d—–w- c:\program files\iPod 2013-02-18 16:40 . 2013-02-18 16:41 ——– d—–w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-02-18 16:40 . 2013-02-18 16:41 ——– d—–w- c:\program files\iTunes 2013-02-18 16:40 . 2013-02-18 16:41 ——– d—–w- c:\program files (x86)\iTunes 2013-02-13 03:01 . 2013-01-09 01:10 996352 —-a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll 2013-02-13 03:01 . 2013-01-08 22:01 768000 —-a-w- c:\program files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll 2013-02-13 00:14 . 2013-01-05 05:53 5553512 —-a-w- c:\windows\system32\ntoskrnl.exe 2013-02-13 00:14 . 2013-01-05 05:00 3967848 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2013-02-13 00:14 . 2013-01-05 05:00 3913064 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2013-02-13 00:14 . 2013-01-04 05:46 215040 —-a-w- c:\windows\system32\winsrv.dll 2013-02-13 00:14 . 2013-01-04 03:26 3153408 —-a-w- c:\windows\system32\win32k.sys 2013-02-13 00:14 . 2013-01-04 02:47 25600 —-a-w- c:\windows\SysWow64\setup16.exe 2013-02-13 00:14 . 2013-01-04 02:47 14336 —-a-w- c:\windows\SysWow64\ntvdm64.dll 2013-02-13 00:14 . 2013-01-04 04:51 5120 —-a-w- c:\windows\SysWow64\wow32.dll 2013-02-13 00:14 . 2013-01-04 02:47 7680 —-a-w- c:\windows\SysWow64\instnm.exe 2013-02-13 00:14 . 2013-01-04 02:47 2048 —-a-w- c:\windows\SysWow64\user.exe 2013-02-13 00:14 . 2013-01-03 06:00 1913192 —-a-w- c:\windows\system32\drivers\tcpip.sys 2013-02-13 00:14 . 2013-01-03 06:00 288088 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS 2013-02-12 22:54 . 2013-02-12 22:54 ——– d—–w- c:\users\Ásdis\AppData\Local\WhatPulse 2013-02-12 22:53 . 2013-02-12 22:53 ——– d—–w- c:\program files (x86)\WinPcap 2013-02-11 15:24 . 2013-02-12 12:59 ——– d—–w- c:\users\Ásdis\AppData\Roaming\Tropico 4 2013-02-11 15:23 . 2013-02-11 15:23 ——– d—–w- c:\users\Ásdis\AppData\Roaming\Kalypso Media 2013-02-11 15:12 . 2013-02-11 15:12 ——– d—–w- c:\program files (x86)\Kalypso Media 2013-02-08 13:13 . 2013-02-08 13:13 16365936 —-a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe 2013-02-05 20:16 . 2013-02-05 20:16 ——– d—–w- c:\programdata\Orbit 2013-02-03 10:54 . 2013-02-03 10:54 95648 —-a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-02-02 07:36 . 2013-02-02 07:36 ——– d—–w- c:\program files (x86)\Common Files\logishrd 2013-02-02 07:36 . 2013-02-02 07:36 ——– d—–w- c:\program files\Common Files\logishrd 2013-02-02 04:01 . 2013-02-02 04:01 ——– d—–w- c:\users\Ásdis\AppData\Roaming\Unity 2013-02-02 03:51 . 2013-02-02 03:51 ——– d—–w- c:\users\Ásdis\AppData\Local\Unity 2013-02-01 22:43 . 2013-02-01 22:48 ——– d—–w- c:\program files (x86)\Amnesia - The Dark Descent 2013-01-24 19:30 . 2013-01-24 19:38 ——– d—–w- c:\program files (x86)\FarCry 3 . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-02-13 03:04 . 2012-01-04 16:13 70004024 —-a-w- c:\windows\system32\MRT.exe 2013-02-08 13:13 . 2012-03-30 09:20 697712 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-02-08 13:13 . 2012-01-04 15:49 74096 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-02-05 20:26 . 2012-01-04 21:04 281688 —-a-w- c:\windows\SysWow64\PnkBstrB.xtr 2013-02-05 20:26 . 2012-01-04 21:01 281688 —-a-w- c:\windows\SysWow64\PnkBstrB.exe 2013-02-05 20:18 . 2012-01-04 21:01 281688 —-a-w- c:\windows\SysWow64\PnkBstrB.ex0 2013-02-03 10:54 . 2012-05-27 03:00 861088 —-a-w- c:\windows\SysWow64\npdeployJava1.dll 2013-02-03 10:54 . 2012-01-12 04:09 782240 —-a-w- c:\windows\SysWow64\deployJava1.dll 2013-01-30 10:53 . 2010-11-21 03:27 273840 ——w- c:\windows\system32\MpSigStub.exe 2013-01-04 04:43 . 2013-02-13 00:14 44032 —-a-w- c:\windows\apppatch\acwow64.dll 2012-12-23 02:42 . 2012-05-26 23:37 65600 —-a-w- c:\windows\system32\drivers\pssdklbf.sys 2012-12-23 02:42 . 2012-05-26 23:37 53312 —-a-w- c:\windows\system32\drivers\pssdk42.sys 2012-12-16 17:11 . 2012-12-21 17:43 46080 —-a-w- c:\windows\system32\atmlib.dll 2012-12-16 14:45 . 2012-12-21 17:43 367616 —-a-w- c:\windows\system32\atmfd.dll 2012-12-16 14:13 . 2012-12-21 17:43 295424 —-a-w- c:\windows\SysWow64\atmfd.dll 2012-12-16 14:13 . 2012-12-21 17:43 34304 —-a-w- c:\windows\SysWow64\atmlib.dll 2012-12-07 13:20 . 2013-01-10 01:12 441856 —-a-w- c:\windows\system32\Wpc.dll 2012-12-07 13:15 . 2013-01-10 01:12 2746368 —-a-w- c:\windows\system32\gameux.dll 2012-12-07 12:26 . 2013-01-10 01:12 308736 —-a-w- c:\windows\SysWow64\Wpc.dll 2012-12-07 12:20 . 2013-01-10 01:12 2576384 —-a-w- c:\windows\SysWow64\gameux.dll 2012-12-07 11:20 . 2013-01-10 01:12 30720 —-a-w- c:\windows\system32\usk.rs 2012-12-07 11:20 . 2013-01-10 01:12 43520 —-a-w- c:\windows\system32\csrr.rs 2012-12-07 11:20 . 2013-01-10 01:12 23552 —-a-w- c:\windows\system32\oflc.rs 2012-12-07 11:20 . 2013-01-10 01:12 45568 —-a-w- c:\windows\system32\oflc-nz.rs 2012-12-07 11:20 . 2013-01-10 01:12 44544 —-a-w- c:\windows\system32\pegibbfc.rs 2012-12-07 11:20 . 2013-01-10 01:12 20480 —-a-w- c:\windows\system32\pegi-fi.rs 2012-12-07 11:20 . 2013-01-10 01:12 20480 —-a-w- c:\windows\system32\pegi-pt.rs 2012-12-07 11:19 . 2013-01-10 01:12 20480 —-a-w- c:\windows\system32\pegi.rs 2012-12-07 11:19 . 2013-01-10 01:12 46592 —-a-w- c:\windows\system32\fpb.rs 2012-12-07 11:19 . 2013-01-10 01:12 40960 —-a-w- c:\windows\system32\cob-au.rs 2012-12-07 11:19 . 2013-01-10 01:12 21504 —-a-w- c:\windows\system32\grb.rs 2012-12-07 11:19 . 2013-01-10 01:12 15360 —-a-w- c:\windows\system32\djctq.rs 2012-12-07 11:19 . 2013-01-10 01:12 55296 —-a-w- c:\windows\system32\cero.rs 2012-12-07 11:19 . 2013-01-10 01:12 51712 —-a-w- c:\windows\system32\esrb.rs 2012-12-07 10:46 . 2013-01-10 01:12 43520 —-a-w- c:\windows\SysWow64\csrr.rs 2012-12-07 10:46 . 2013-01-10 01:12 30720 —-a-w- c:\windows\SysWow64\usk.rs 2012-12-07 10:46 . 2013-01-10 01:12 45568 —-a-w- c:\windows\SysWow64\oflc-nz.rs 2012-12-07 10:46 . 2013-01-10 01:12 44544 —-a-w- c:\windows\SysWow64\pegibbfc.rs 2012-12-07 10:46 . 2013-01-10 01:12 20480 —-a-w- c:\windows\SysWow64\pegi-pt.rs 2012-12-07 10:46 . 2013-01-10 01:12 23552 —-a-w- c:\windows\SysWow64\oflc.rs 2012-12-07 10:46 . 2013-01-10 01:12 20480 —-a-w- c:\windows\SysWow64\pegi-fi.rs 2012-12-07 10:46 . 2013-01-10 01:12 46592 —-a-w- c:\windows\SysWow64\fpb.rs 2012-12-07 10:46 . 2013-01-10 01:12 20480 —-a-w- c:\windows\SysWow64\pegi.rs 2012-12-07 10:46 . 2013-01-10 01:12 21504 —-a-w- c:\windows\SysWow64\grb.rs 2012-12-07 10:46 . 2013-01-10 01:12 40960 —-a-w- c:\windows\SysWow64\cob-au.rs 2012-12-07 10:46 . 2013-01-10 01:12 15360 —-a-w- c:\windows\SysWow64\djctq.rs 2012-12-07 10:46 . 2013-01-10 01:12 55296 —-a-w- c:\windows\SysWow64\cero.rs 2012-12-07 10:46 . 2013-01-10 01:12 51712 —-a-w- c:\windows\SysWow64\esrb.rs 2012-11-30 05:45 . 2013-01-10 01:11 362496 —-a-w- c:\windows\system32\wow64win.dll 2012-11-30 05:45 . 2013-01-10 01:11 243200 —-a-w- c:\windows\system32\wow64.dll 2012-11-30 05:45 . 2013-01-10 01:11 13312 —-a-w- c:\windows\system32\wow64cpu.dll 2012-11-30 05:43 . 2013-01-10 01:11 16384 —-a-w- c:\windows\system32\ntvdm64.dll 2012-11-30 05:41 . 2013-01-10 01:11 424448 —-a-w- c:\windows\system32\KernelBase.dll 2012-11-30 05:41 . 2013-01-10 01:11 1161216 —-a-w- c:\windows\system32\kernel32.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 6144 —ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 4608 —ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 4608 —ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 4096 —ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 4096 —ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3584 —ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3584 —ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3584 —ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3584 —ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 5120 —ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 4096 —ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3584 —ha-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3584 —ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3584 —ha-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-io-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 4096 —ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll 2012-11-30 04:53 . 2013-01-10 01:11 274944 —-a-w- c:\windows\SysWow64\KernelBase.dll 2012-11-30 04:45 . 2013-01-10 01:11 4608 —ha-w- c:\windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 4096 —ha-w- c:\windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 4096 —ha-w- c:\windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 3584 —ha-w- c:\windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 3584 —ha-w- c:\windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 3072 —ha-w- c:\windows\SysWow64\api-ms-win-core-string-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 3072 —ha-w- c:\windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 4096 —ha-w- c:\windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 4096 —ha-w- c:\windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 3584 —ha-w- c:\windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 3584 —ha-w- c:\windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 3584 —ha-w- c:\windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 3584 —ha-w- c:\windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 3072 —ha-w- c:\windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 3072 —ha-w- c:\windows\SysWow64\api-ms-win-core-io-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 4096 —ha-w- c:\windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 5120 —ha-w- c:\windows\SysWow64\api-ms-win-core-file-l1-1-0.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="c:\program files (x86)\Steam\Steam.exe" [2013-02-15 1597864] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2011-10-17 284440] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280] "GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040] "BambooCore"="c:\program files (x86)\Bamboo Dock\BambooCore.exe" [2011-09-27 646232] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-09-28 642728] "LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-12-10 2254768] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-12-12 152544] . c:\users\Ásdis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Ásdis\AppData\Roaming\Dropbox\bin\Dropbox.exe [2013-1-20 28539272] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-11-09 160944] R3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\DAUpdaterSvc.Service.exe [2010-10-14 25832] R3 Desura Install Service;Desura Install Service;c:\program files (x86)\Common Files\Desura\desura_service.exe [2012-07-06 131912] R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys [2012-09-19 102368] R3 LGPBTDD;LGPBTDD.sys Display Driver;c:\windows\system32\Drivers\LGPBTDD.sys [2009-07-01 30728] R3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys [2012-01-18 351136] R3 LVUVC64;Logitech HD Webcam C270(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys [2012-01-18 4865568] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2012-08-30 128456] R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-09-12 368896] R3 nmwcdnsucx64;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsucx64.sys [2011-08-17 12800] R3 nmwcdnsux64;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsux64.sys [2011-08-17 171008] R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-06-25 35344] R3 PSSDK42;PSSDK42;c:\windows\system32\Drivers\pssdk42.sys [2012-12-23 53312] R3 PSSDKLBF;PSSDKLBF;c:\windows\system32\Drivers\pssdklbf.sys [2012-12-23 65600] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456] R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys [2012-09-19 203104] R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208] R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys [2011-09-08 13312] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-01-04 1255736] R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [2008-05-06 14464] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-01-05 279616] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-09-28 239616] S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-12-10 2465712] S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-10-17 13592] S2 TabletServicePen;TabletServicePen;c:\program files\Tablet\Pen\Pen_Tablet.exe [2011-09-08 6583160] S2 tbbLoaderService;tbbLoaderService;c:\program files (x86)\thinkbroadband.com\tbbMeter\tbbLoaderService.exe [2010-10-09 14848] S2 TouchServicePen;Wacom Consumer Touch Service;c:\program files\Tablet\Pen\Pen_TouchService.exe [2011-09-08 528760] S2 UMVPFSrv;UMVPFSrv;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2012-01-18 450848] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-05-14 96896] S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys [2011-08-05 57088] S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys [2011-08-05 80384] S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2009-11-24 22408] S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [2009-11-24 16008] S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys [2009-11-18 32344] . . — Other Services/Drivers In Memory — . *NewlyCreated* - WS2IFSL . Contents of the 'Scheduled Tasks' folder . 2013-02-23 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-30 13:13] . 2013-02-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-07-25 01:29] . 2013-02-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-07-25 01:29] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 162552 —-a-w- c:\users\Ásdis\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-10-17 13307496] "XFast LAN"="c:\program files\ASRock\XFast LAN\cFosSpeed.exe" [2011-07-04 1441152] "Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2011-12-07 5889816] "Launch LgDeviceAgent"="c:\program files\Logitech\GamePanel Software\LgDevAgt.exe" [2010-08-03 415816] "Launch LCDMon"="c:\program files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2010-08-03 2412616] "Launch LGDCore"="c:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2010-08-03 4725320] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-12 1289704] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-05-30 499608] . ——- Supplementary Scan ——- . uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~2\MIF5BA~1\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.1.254 FF - ProfilePath - c:\users\Ásdis\AppData\Roaming\Mozilla\Firefox\Profiles\wmczw61l.default\ . - - - - ORPHANS REMOVED - - - - . ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - (no file) ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - (no file) ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - (no file) AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe AddRemove-{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88} - c:\program files (x86)\InstallShield Installation Information\{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}\setup.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions] @Denied: (2) (LocalSystem) "{88C7F2AA-F93F-432C-8F0E-B7D85967A527}"=hex:51,66,7a,6c,4c,1d,38,12,c4,f1,d4, 8c,0d,b7,42,06,f0,18,f4,98,5c,39,e1,33 "{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96, 76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a "{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07, 72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57 "{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23, 94,30,02,d1,0f,f1,da,12,24,73,56,27,d2 "{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db, df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd "{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47, 2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85 "{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16, fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17 "{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9, b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration] @Denied: (2) (LocalSystem) "Timestamp"=hex:21,73,2a,4a,05,3e,cd,01 . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences] @Denied: (2) (LocalSystem) "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,3f,0d,d3,f7,c1,f1,3d,4f,92,eb,96,\ "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,3f,0d,d3,f7,c1,f1,3d,4f,92,eb,96,\ . [HKEY_USERS\S-1-5-21-2006369733-2391191245-1076361487-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-2006369733-2391191245-1076361487-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_USERS\S-1-5-21-2006369733-2391191245-1076361487-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] @Allowed: (Read) (RestrictedCode) . [HKEY_USERS\S-1-5-21-2006369733-2391191245-1076361487-1000\Software\SecuROM\License information*] "datasecu"=hex:ea,b2,b6,70,70,a7,99,d5,2f,8d,9d,9e,7a,53,81,c2,b7,b4,ef,c5,52, c2,e2,f8,7b,b8,8a,35,33,3c,ca,7d,a5,73,d3,49,17,1f,3c,4e,a9,ea,cc,55,67,c7,\ "rkeysecu"=hex:64,b6,bd,e1,3e,80,9e,c4,40,b4,90,83,87,8e,33,49 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_149_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_149_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_149_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_149_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_149.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_149.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_149.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_149.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2013-02-23 00:32:45 ComboFix-quarantined-files.txt 2013-02-23 00:32 ComboFix2.txt 2013-02-21 15:54 . Pre-Run: 250.764.587.008 bytes free Post-Run: 250.561.912.832 bytes free . - - End Of File - - 0B485F1744346338BA2AE777B201DFF3
Hmmm…. it doesn't appear that the script worked.

Please try it again.

Make sure that you copy everything inside the code box including the File::
Looks like I get the same thing; but I have no sense of what to look for here. I am copying this (see below) into notepad, which I then save as "CFScript.txt" as All files on the desktop - which I then drag into ComboFix. Which starts doing stuff. File:: C:\Users\Ásdis\Downloads\DTLite4451-0236.exe E:\Program Files\Cheat Engine 6.1\cheatengine-i386.exe E:\Users\Asdis\Desktop\Folder\Terraria.exe E:\Users\Asdis\Downloads\CheatEngine61.exe F:\D-Diskur\Diskar\Video-Converter\Setup_FreeVideoConverter.exe F:\Downloads\Games\Terraria.v1.0.1.rar Here's the log: ComboFix 13-02-23.01 - Ásdis 23.02.2013 22:52:42.3.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.354.1033.18.8154.6220 [GMT 0:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe Command switches used :: c:\users\-sdis\Desktop\CFScript.txt AV: Microsoft Security Essentials *Disabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5} SP: Microsoft Security Essentials *Disabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((( Files Created from 2013-01-23 to 2013-02-23 ))))))))))))))))))))))))))))))) . . 2074-05-07 18:38 . 2006-11-21 20:48 203576 ——w- c:\program files (x86)\Microsoft Games\Age of Empires III\autopatcher2.exe 2013-02-23 23:00 . 2013-02-23 23:00 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-02-23 23:00 . 2013-02-23 23:00 ——– d—–w- c:\users\µsdis\AppData\Local\temp 2013-02-23 22:34 . 2013-02-08 00:28 9162192 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3F316425-D02A-4619-86C0-7651C70951FD}\mpengine.dll 2013-02-23 12:36 . 2013-02-23 12:36 95648 —-a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-02-23 00:45 . 2013-02-08 00:28 9162192 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2013-02-21 08:46 . 2013-02-21 08:46 ——– d—–w- C:\_OTL 2013-02-20 03:01 . 2013-02-20 03:01 ——– d—–w- c:\windows\Temp5E742C12-6AE7-1086-0CF5-2F558042F9F7-Signatures 2013-02-18 22:39 . 2013-02-23 12:35 ——– d—–w- c:\users\Ásdis\AppData\Roaming\.minecraft 2013-02-18 16:42 . 2013-02-18 16:42 ——– d—–w- c:\program files (x86)\FOXIT SOFTWARE 2013-02-18 16:40 . 2013-02-18 16:40 ——– d—–w- c:\program files\iPod 2013-02-18 16:40 . 2013-02-18 16:41 ——– d—–w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-02-18 16:40 . 2013-02-18 16:41 ——– d—–w- c:\program files\iTunes 2013-02-18 16:40 . 2013-02-18 16:41 ——– d—–w- c:\program files (x86)\iTunes 2013-02-13 03:01 . 2013-01-09 01:10 996352 —-a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll 2013-02-13 03:01 . 2013-01-08 22:01 768000 —-a-w- c:\program files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll 2013-02-13 00:14 . 2013-01-05 05:53 5553512 —-a-w- c:\windows\system32\ntoskrnl.exe 2013-02-13 00:14 . 2013-01-05 05:00 3967848 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2013-02-13 00:14 . 2013-01-05 05:00 3913064 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2013-02-13 00:14 . 2013-01-04 05:46 215040 —-a-w- c:\windows\system32\winsrv.dll 2013-02-13 00:14 . 2013-01-04 03:26 3153408 —-a-w- c:\windows\system32\win32k.sys 2013-02-13 00:14 . 2013-01-04 02:47 25600 —-a-w- c:\windows\SysWow64\setup16.exe 2013-02-13 00:14 . 2013-01-04 02:47 14336 —-a-w- c:\windows\SysWow64\ntvdm64.dll 2013-02-13 00:14 . 2013-01-04 04:51 5120 —-a-w- c:\windows\SysWow64\wow32.dll 2013-02-13 00:14 . 2013-01-04 02:47 7680 —-a-w- c:\windows\SysWow64\instnm.exe 2013-02-13 00:14 . 2013-01-04 02:47 2048 —-a-w- c:\windows\SysWow64\user.exe 2013-02-13 00:14 . 2013-01-03 06:00 1913192 —-a-w- c:\windows\system32\drivers\tcpip.sys 2013-02-13 00:14 . 2013-01-03 06:00 288088 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS 2013-02-12 22:54 . 2013-02-12 22:54 ——– d—–w- c:\users\Ásdis\AppData\Local\WhatPulse 2013-02-12 22:53 . 2013-02-12 22:53 ——– d—–w- c:\program files (x86)\WinPcap 2013-02-11 15:24 . 2013-02-12 12:59 ——– d—–w- c:\users\Ásdis\AppData\Roaming\Tropico 4 2013-02-11 15:23 . 2013-02-11 15:23 ——– d—–w- c:\users\Ásdis\AppData\Roaming\Kalypso Media 2013-02-11 15:12 . 2013-02-11 15:12 ——– d—–w- c:\program files (x86)\Kalypso Media 2013-02-08 13:13 . 2013-02-08 13:13 16365936 —-a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe 2013-02-05 20:16 . 2013-02-05 20:16 ——– d—–w- c:\programdata\Orbit 2013-02-02 07:36 . 2013-02-02 07:36 ——– d—–w- c:\program files (x86)\Common Files\logishrd 2013-02-02 07:36 . 2013-02-02 07:36 ——– d—–w- c:\program files\Common Files\logishrd 2013-02-02 04:01 . 2013-02-02 04:01 ——– d—–w- c:\users\Ásdis\AppData\Roaming\Unity 2013-02-02 03:51 . 2013-02-02 03:51 ——– d—–w- c:\users\Ásdis\AppData\Local\Unity 2013-02-01 22:43 . 2013-02-01 22:48 ——– d—–w- c:\program files (x86)\Amnesia - The Dark Descent . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-02-23 12:36 . 2012-05-27 03:00 861088 —-a-w- c:\windows\SysWow64\npdeployJava1.dll 2013-02-23 12:36 . 2012-01-12 04:09 782240 —-a-w- c:\windows\SysWow64\deployJava1.dll 2013-02-13 03:04 . 2012-01-04 16:13 70004024 —-a-w- c:\windows\system32\MRT.exe 2013-02-08 13:13 . 2012-03-30 09:20 697712 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-02-08 13:13 . 2012-01-04 15:49 74096 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-02-05 20:26 . 2012-01-04 21:04 281688 —-a-w- c:\windows\SysWow64\PnkBstrB.xtr 2013-02-05 20:26 . 2012-01-04 21:01 281688 —-a-w- c:\windows\SysWow64\PnkBstrB.exe 2013-02-05 20:18 . 2012-01-04 21:01 281688 —-a-w- c:\windows\SysWow64\PnkBstrB.ex0 2013-01-30 10:53 . 2010-11-21 03:27 273840 ——w- c:\windows\system32\MpSigStub.exe 2013-01-20 15:59 . 2013-01-20 15:59 230320 —-a-w- c:\windows\system32\drivers\MpFilter.sys 2013-01-20 15:59 . 2011-04-27 15:25 130008 —-a-w- c:\windows\system32\drivers\NisDrvWFP.sys 2013-01-04 04:43 . 2013-02-13 00:14 44032 —-a-w- c:\windows\apppatch\acwow64.dll 2012-12-23 02:42 . 2012-05-26 23:37 65600 —-a-w- c:\windows\system32\drivers\pssdklbf.sys 2012-12-23 02:42 . 2012-05-26 23:37 53312 —-a-w- c:\windows\system32\drivers\pssdk42.sys 2012-12-16 17:11 . 2012-12-21 17:43 46080 —-a-w- c:\windows\system32\atmlib.dll 2012-12-16 14:45 . 2012-12-21 17:43 367616 —-a-w- c:\windows\system32\atmfd.dll 2012-12-16 14:13 . 2012-12-21 17:43 295424 —-a-w- c:\windows\SysWow64\atmfd.dll 2012-12-16 14:13 . 2012-12-21 17:43 34304 —-a-w- c:\windows\SysWow64\atmlib.dll 2012-12-07 13:20 . 2013-01-10 01:12 441856 —-a-w- c:\windows\system32\Wpc.dll 2012-12-07 13:15 . 2013-01-10 01:12 2746368 —-a-w- c:\windows\system32\gameux.dll 2012-12-07 12:26 . 2013-01-10 01:12 308736 —-a-w- c:\windows\SysWow64\Wpc.dll 2012-12-07 12:20 . 2013-01-10 01:12 2576384 —-a-w- c:\windows\SysWow64\gameux.dll 2012-12-07 11:20 . 2013-01-10 01:12 30720 —-a-w- c:\windows\system32\usk.rs 2012-12-07 11:20 . 2013-01-10 01:12 43520 —-a-w- c:\windows\system32\csrr.rs 2012-12-07 11:20 . 2013-01-10 01:12 23552 —-a-w- c:\windows\system32\oflc.rs 2012-12-07 11:20 . 2013-01-10 01:12 45568 —-a-w- c:\windows\system32\oflc-nz.rs 2012-12-07 11:20 . 2013-01-10 01:12 44544 —-a-w- c:\windows\system32\pegibbfc.rs 2012-12-07 11:20 . 2013-01-10 01:12 20480 —-a-w- c:\windows\system32\pegi-fi.rs 2012-12-07 11:20 . 2013-01-10 01:12 20480 —-a-w- c:\windows\system32\pegi-pt.rs 2012-12-07 11:19 . 2013-01-10 01:12 20480 —-a-w- c:\windows\system32\pegi.rs 2012-12-07 11:19 . 2013-01-10 01:12 46592 —-a-w- c:\windows\system32\fpb.rs 2012-12-07 11:19 . 2013-01-10 01:12 40960 —-a-w- c:\windows\system32\cob-au.rs 2012-12-07 11:19 . 2013-01-10 01:12 21504 —-a-w- c:\windows\system32\grb.rs 2012-12-07 11:19 . 2013-01-10 01:12 15360 —-a-w- c:\windows\system32\djctq.rs 2012-12-07 11:19 . 2013-01-10 01:12 55296 —-a-w- c:\windows\system32\cero.rs 2012-12-07 11:19 . 2013-01-10 01:12 51712 —-a-w- c:\windows\system32\esrb.rs 2012-12-07 10:46 . 2013-01-10 01:12 43520 —-a-w- c:\windows\SysWow64\csrr.rs 2012-12-07 10:46 . 2013-01-10 01:12 30720 —-a-w- c:\windows\SysWow64\usk.rs 2012-12-07 10:46 . 2013-01-10 01:12 45568 —-a-w- c:\windows\SysWow64\oflc-nz.rs 2012-12-07 10:46 . 2013-01-10 01:12 44544 —-a-w- c:\windows\SysWow64\pegibbfc.rs 2012-12-07 10:46 . 2013-01-10 01:12 20480 —-a-w- c:\windows\SysWow64\pegi-pt.rs 2012-12-07 10:46 . 2013-01-10 01:12 23552 —-a-w- c:\windows\SysWow64\oflc.rs 2012-12-07 10:46 . 2013-01-10 01:12 20480 —-a-w- c:\windows\SysWow64\pegi-fi.rs 2012-12-07 10:46 . 2013-01-10 01:12 46592 —-a-w- c:\windows\SysWow64\fpb.rs 2012-12-07 10:46 . 2013-01-10 01:12 20480 —-a-w- c:\windows\SysWow64\pegi.rs 2012-12-07 10:46 . 2013-01-10 01:12 21504 —-a-w- c:\windows\SysWow64\grb.rs 2012-12-07 10:46 . 2013-01-10 01:12 40960 —-a-w- c:\windows\SysWow64\cob-au.rs 2012-12-07 10:46 . 2013-01-10 01:12 15360 —-a-w- c:\windows\SysWow64\djctq.rs 2012-12-07 10:46 . 2013-01-10 01:12 55296 —-a-w- c:\windows\SysWow64\cero.rs 2012-12-07 10:46 . 2013-01-10 01:12 51712 —-a-w- c:\windows\SysWow64\esrb.rs 2012-11-30 05:45 . 2013-01-10 01:11 362496 —-a-w- c:\windows\system32\wow64win.dll 2012-11-30 05:45 . 2013-01-10 01:11 243200 —-a-w- c:\windows\system32\wow64.dll 2012-11-30 05:45 . 2013-01-10 01:11 13312 —-a-w- c:\windows\system32\wow64cpu.dll 2012-11-30 05:43 . 2013-01-10 01:11 16384 —-a-w- c:\windows\system32\ntvdm64.dll 2012-11-30 05:41 . 2013-01-10 01:11 424448 —-a-w- c:\windows\system32\KernelBase.dll 2012-11-30 05:41 . 2013-01-10 01:11 1161216 —-a-w- c:\windows\system32\kernel32.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 6144 —ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 4608 —ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 4608 —ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 4096 —ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 4096 —ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3584 —ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3584 —ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3584 —ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3584 —ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 5120 —ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 4096 —ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3584 —ha-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3584 —ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3584 —ha-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-io-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 4096 —ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll 2012-11-30 05:38 . 2013-01-10 01:11 3072 —ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll 2012-11-30 04:53 . 2013-01-10 01:11 274944 —-a-w- c:\windows\SysWow64\KernelBase.dll 2012-11-30 04:45 . 2013-01-10 01:11 4608 —ha-w- c:\windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 4096 —ha-w- c:\windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 4096 —ha-w- c:\windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 3584 —ha-w- c:\windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 3584 —ha-w- c:\windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 3072 —ha-w- c:\windows\SysWow64\api-ms-win-core-string-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 3072 —ha-w- c:\windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 4096 —ha-w- c:\windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 4096 —ha-w- c:\windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 3584 —ha-w- c:\windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 3584 —ha-w- c:\windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 3584 —ha-w- c:\windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 3584 —ha-w- c:\windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 3072 —ha-w- c:\windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 01:11 3072 —ha-w- c:\windows\SysWow64\api-ms-win-core-io-l1-1-0.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="c:\program files (x86)\Steam\Steam.exe" [2013-02-15 1597864] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2011-10-17 284440] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280] "GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040] "BambooCore"="c:\program files (x86)\Bamboo Dock\BambooCore.exe" [2011-09-27 646232] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-09-28 642728] "LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-12-10 2254768] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-12-12 152544] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] . c:\users\Ásdis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Ásdis\AppData\Roaming\Dropbox\bin\Dropbox.exe [2013-1-20 28539272] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-11-09 160944] R3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\DAUpdaterSvc.Service.exe [2010-10-14 25832] R3 Desura Install Service;Desura Install Service;c:\program files (x86)\Common Files\Desura\desura_service.exe [2012-07-06 131912] R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys [2012-09-19 102368] R3 LGPBTDD;LGPBTDD.sys Display Driver;c:\windows\system32\Drivers\LGPBTDD.sys [2009-07-01 30728] R3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys [2012-01-18 351136] R3 LVUVC64;Logitech HD Webcam C270(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys [2012-01-18 4865568] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2013-01-20 130008] R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2013-01-27 379360] R3 nmwcdnsucx64;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsucx64.sys [2011-08-17 12800] R3 nmwcdnsux64;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsux64.sys [2011-08-17 171008] R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-06-25 35344] R3 PSSDK42;PSSDK42;c:\windows\system32\Drivers\pssdk42.sys [2012-12-23 53312] R3 PSSDKLBF;PSSDKLBF;c:\windows\system32\Drivers\pssdklbf.sys [2012-12-23 65600] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456] R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys [2012-09-19 203104] R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208] R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys [2011-09-08 13312] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-01-04 1255736] R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [2008-05-06 14464] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-01-05 279616] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-09-28 239616] S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-12-10 2465712] S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-10-17 13592] S2 TabletServicePen;TabletServicePen;c:\program files\Tablet\Pen\Pen_Tablet.exe [2011-09-08 6583160] S2 tbbLoaderService;tbbLoaderService;c:\program files (x86)\thinkbroadband.com\tbbMeter\tbbLoaderService.exe [2010-10-09 14848] S2 TouchServicePen;Wacom Consumer Touch Service;c:\program files\Tablet\Pen\Pen_TouchService.exe [2011-09-08 528760] S2 UMVPFSrv;UMVPFSrv;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2012-01-18 450848] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-05-14 96896] S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys [2011-08-05 57088] S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys [2011-08-05 80384] S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2009-11-24 22408] S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [2009-11-24 16008] S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys [2009-11-18 32344] . . Contents of the 'Scheduled Tasks' folder . 2013-02-23 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-30 13:13] . 2013-02-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-07-25 01:29] . 2013-02-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-07-25 01:29] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 162552 —-a-w- c:\users\Ásdis\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 162552 —-a-w- c:\users\Ásdis\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 162552 —-a-w- c:\users\Ásdis\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 162552 —-a-w- c:\users\Ásdis\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-10-17 13307496] "XFast LAN"="c:\program files\ASRock\XFast LAN\cFosSpeed.exe" [2011-07-04 1441152] "Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2011-12-07 5889816] "Launch LgDeviceAgent"="c:\program files\Logitech\GamePanel Software\LgDevAgt.exe" [2010-08-03 415816] "Launch LCDMon"="c:\program files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2010-08-03 2412616] "Launch LGDCore"="c:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2010-08-03 4725320] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 1281512] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-05-30 499608] . ——- Supplementary Scan ——- . uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~2\MIF5BA~1\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.1.254 FF - ProfilePath - c:\users\Ásdis\AppData\Roaming\Mozilla\Firefox\Profiles\wmczw61l.default\ . - - - - ORPHANS REMOVED - - - - . AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe AddRemove-{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88} - c:\program files (x86)\InstallShield Installation Information\{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}\setup.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions] @Denied: (2) (LocalSystem) "{88C7F2AA-F93F-432C-8F0E-B7D85967A527}"=hex:51,66,7a,6c,4c,1d,38,12,c4,f1,d4, 8c,0d,b7,42,06,f0,18,f4,98,5c,39,e1,33 "{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96, 76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a "{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07, 72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57 "{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23, 94,30,02,d1,0f,f1,da,12,24,73,56,27,d2 "{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db, df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd "{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47, 2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85 "{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16, fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17 "{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9, b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration] @Denied: (2) (LocalSystem) "Timestamp"=hex:21,73,2a,4a,05,3e,cd,01 . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences] @Denied: (2) (LocalSystem) "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,3f,0d,d3,f7,c1,f1,3d,4f,92,eb,96,\ "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,3f,0d,d3,f7,c1,f1,3d,4f,92,eb,96,\ . [HKEY_USERS\S-1-5-21-2006369733-2391191245-1076361487-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-2006369733-2391191245-1076361487-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_USERS\S-1-5-21-2006369733-2391191245-1076361487-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] @Allowed: (Read) (RestrictedCode) . [HKEY_USERS\S-1-5-21-2006369733-2391191245-1076361487-1000\Software\SecuROM\License information*] "datasecu"=hex:ea,b2,b6,70,70,a7,99,d5,2f,8d,9d,9e,7a,53,81,c2,b7,b4,ef,c5,52, c2,e2,f8,7b,b8,8a,35,33,3c,ca,7d,a5,73,d3,49,17,1f,3c,4e,a9,ea,cc,55,67,c7,\ "rkeysecu"=hex:64,b6,bd,e1,3e,80,9e,c4,40,b4,90,83,87,8e,33,49 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_149_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_149_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_149_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_149_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_149.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_149.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_149.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_149.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2013-02-23 23:02:25 ComboFix-quarantined-files.txt 2013-02-23 23:02 ComboFix2.txt 2013-02-23 00:32 ComboFix3.txt 2013-02-21 15:54 . Pre-Run: 249.379.020.800 bytes free Post-Run: 249.169.039.360 bytes free . - - End Of File - - 0F956866FA4A17C9DCD6C758EFCD3EE3
Shadecat,

I think you are good to go. :D

Time for some housekeeping
  • Click START then RUN
  • Now type ComboFix /Uninstall in the runbox and click OK.
  • Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]
The above procedure will:
  • Implement some cleanup procedures.
  • Reset System Restore.

  • Double click on OTL to run it.
  • Click on CleanUp!
  • When done, you will be prompted to restart your computer. Please restart your computer.

Please re-enable any security that was disabled.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
Did the above thing! And thank you for the links, will certainly take a look at them. And lecture my boyfriend. :) I can't thank you enough for your help! Thank you so very much! 12 out of 10 stars!! :wub:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI