This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

svchost.exe (netsvcs) runnind hard drive non-stop [Solved]

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

About two weeks ago my hard drive began running non-stop. I was able to determine that a file called svchost.exe (netsvcs) was reading/writing to my hard drive at around 50M/s. If I disabled the BITS service svchost.exe (netsvcs) would disappear but as soon as I rebooted my PC the file would start up again. I ran some anti-malware software which removed a few suspect files and eliminated the hard drive problem but now my CPU is maxed out and my internet connection has slowed to a crawl. I am concerned I have a virus so I ran OTL as instructed. The text files are below. Thanks in advance for taking a look at my post.

OTL logfile created on: 3/16/2013 5:26:43 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\WinningOne\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

11.99 Gb Total Physical Memory | 10.10 Gb Available Physical Memory | 84.23% Memory free
23.98 Gb Paging File | 22.12 Gb Available in Paging File | 92.24% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 891.02 Gb Total Space | 740.93 Gb Free Space | 83.15% Space Free | Partition Type: NTFS
Drive D: | 40.00 Gb Total Space | 34.66 Gb Free Space | 86.66% Space Free | Partition Type: NTFS
Drive F: | 7.32 Gb Total Space | 5.44 Gb Free Space | 74.32% Space Free | Partition Type: FAT32

Computer Name: WINNINGONE-PC | User Name: WinningOne | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\WinningOne\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_6_602_180_ActiveX.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
PRC - C:\Users\WinningOne\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files (x86)\Norton 360\Engine\20.3.0.36\ccSvcHst.exe (Symantec Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Steam\bin\chromehtml.dll ()
MOD - C:\Program Files (x86)\Steam\bin\libcef.dll ()
MOD - C:\Program Files (x86)\Steam\sdl.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avcodec-53.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avformat-53.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avutil-51.dll ()
MOD - C:\Program Files (x86)\Norton 360\Engine\20.3.0.36\wincfi39.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (TurboBoost) – C:\Program Files\Intel\TurboBoost\TurboBoost.exe (Intel® Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (Skype C2C Service) – C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
SRV - (N360) – C:\Program Files (x86)\Norton 360\Engine\20.3.0.36\ccSvcHst.exe (Symantec Corporation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (xsherlock) – C:\Windows\SysWOW64\xsherlock.xem (Wellbia.com Co., Ltd.)
SRV - (IntuitUpdateServiceV4) – C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit Inc.)
SRV - (npggsvc) – C:\Windows\SysWOW64\GameMon.des (INCA Internet Co., Ltd.)
SRV - (IAStorDataMgrSvc) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (SymEvent) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (SymNetS) – C:\Windows\SysNative\drivers\N360x64\1403000.024\symnets.sys (Symantec Corporation)
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\drivers\N360x64\1403000.024\SymEFA64.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\drivers\N360x64\1403000.024\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) – C:\Windows\SysNative\drivers\N360x64\1403000.024\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (SymDS) – C:\Windows\SysNative\drivers\N360x64\1403000.024\SymDS64.sys (Symantec Corporation)
DRV:64bit: - (SymIRON) – C:\Windows\SysNative\drivers\N360x64\1403000.024\Ironx64.sys (Symantec Corporation)
DRV:64bit: - (ccSet_N360) – C:\Windows\SysNative\drivers\N360x64\1403000.024\ccSetx64.sys (Symantec Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (rzudd) – C:\Windows\SysNative\drivers\rzudd.sys (Razer USA Ltd)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (RzSynapse) – C:\Windows\SysNative\drivers\RzSynapse.sys (Razer USA Ltd)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (nusb3xhc) – C:\Windows\SysNative\drivers\nusb3xhc.sys (Renesas Electronics Corporation)
DRV:64bit: - (nusb3hub) – C:\Windows\SysNative\drivers\nusb3hub.sys (Renesas Electronics Corporation)
DRV:64bit: - (TurboB) – C:\Windows\SysNative\drivers\TurboB.sys (Intel® Corporation)
DRV:64bit: - (JRAID) – C:\Windows\SysNative\drivers\jraid.sys (JMicron Technology Corp.)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (mv91xx) – C:\Windows\SysNative\drivers\mv91xx.sys (Marvell Semiconductor, Inc.)
DRV:64bit: - (mv91cons) – C:\Windows\SysNative\drivers\mv91cons.sys (Marvell Semiconductor Inc.)
DRV:64bit: - (nm3) – C:\Windows\SysNative\drivers\nm3.sys (Microsoft Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (e1express) – C:\Windows\SysNative\drivers\e1e6032e.sys (Intel Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\IPSDefs\20130313.001\IDSviA64.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130315.025\ex64.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130315.025\eng64.sys (Symantec Corporation)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\BASHDefs\20130301.001\BHDrvx64.sys (Symantec Corporation)
DRV - (Htsysm) – C:\Windows\SysWOW64\HtsysmNT.sys ()
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (NPPTNT2) – C:\Windows\SysWOW64\npptNT2.sys (INCA Internet Co., Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{EF4964C5-BE10-4C5B-B16C-D35EADE22152}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default Download Directory = C:\Users\WinningOne\Desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = FF 09 1D 1E 47 D5 CB 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://searchab.com/?aff=7&uid=53b520c…q={searchTerms}
IE - HKCU\..\SearchScopes\{3593C233-8BF5-48AC-8DC6-92221F5538FF}: "URL" = http://www.mysearchresults.com/search?&…q={searchTerms}
IE - HKCU\..\SearchScopes\{EF4964C5-BE10-4C5B-B16C-D35EADE22152}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_171.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_171.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll File not found
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: C:\Windows\Downloaded Program Files\npsoe.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\IPSFFPlgn\ [2013/03/10 14:17:54 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\coFFPlgn\ [2013/03/16 04:54:46 | 000,000,000 | —D | M]


O1 HOSTS File: ([2013/03/10 09:01:43 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\20.3.0.36\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\20.3.0.36\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\20.3.0.36\CoIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O4 - Startup: C:\Users\WinningOne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\WinningOne\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogOff = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: //@surf.mar@/ ([]money in Local intranet)
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {000F1EA4-5E08-4564-A29B-29076F63A37A} http://launch.soe.com/plugin/web/SOEWebInstaller.cab (SOE Web Installer)
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} http://quickscan.bitdefender.com/qsax/qsax.cab (Bitdefender QuickScan Control)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com//activex/ractrl.cab?lmi=972 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BBEF988E-30BF-4E8B-BF4C-347D68881F7E}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/03/16 05:23:15 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\WinningOne\Desktop\OTL.exe
[2013/03/15 10:18:16 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/03/15 10:18:16 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/03/15 10:18:16 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/03/15 10:18:15 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/03/15 10:18:15 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/03/15 10:18:15 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/03/15 10:18:15 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/03/15 10:18:15 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/03/15 10:18:15 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/03/15 10:18:15 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/03/15 10:18:14 | 002,312,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/03/15 10:18:14 | 000,729,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/03/15 10:18:12 | 000,816,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/03/15 10:18:12 | 000,717,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/03/15 10:18:12 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2013/03/15 07:09:04 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2013/03/15 07:07:44 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2013/03/15 07:07:44 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Silverlight
[2013/03/10 14:17:27 | 000,177,312 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2013/03/10 14:17:27 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2013/03/10 14:17:27 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2013/03/10 14:16:15 | 001,139,800 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1403000.024\SymEFA64.sys
[2013/03/10 14:16:15 | 000,796,248 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1403000.024\srtsp64.sys
[2013/03/10 14:16:15 | 000,493,656 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1403000.024\SymDS64.sys
[2013/03/10 14:16:15 | 000,432,800 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1403000.024\symnets.sys
[2013/03/10 14:16:15 | 000,224,416 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1403000.024\Ironx64.sys
[2013/03/10 14:16:15 | 000,168,096 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1403000.024\ccSetx64.sys
[2013/03/10 14:16:15 | 000,036,952 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1403000.024\srtspx64.sys
[2013/03/10 14:16:15 | 000,023,448 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1403000.024\SymELAM.sys
[2013/03/10 14:16:08 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\N360x64
[2013/03/10 14:16:08 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\N360x64\1403000.024
[2013/03/10 14:16:07 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360
[2013/03/10 14:16:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\Norton 360
[2013/03/10 14:16:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\NortonInstaller
[2013/03/10 14:08:54 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
[2013/03/10 14:08:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\Steam
[2013/03/10 12:40:05 | 000,000,000 | —D | C] – C:\Users\WinningOne\Documents\Network Monitor 3
[2013/03/10 12:39:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Network Monitor 3.4
[2013/03/10 12:39:22 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Network Monitor 3
[2013/03/10 09:41:40 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/03/10 09:36:40 | 000,000,000 | —D | C] – C:\Windows\temp
[2013/03/10 09:19:19 | 005,037,356 | R— | C] (Swearware) – C:\Users\WinningOne\Desktop\ComboFix.exe
[2013/03/10 08:48:47 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2013/03/10 08:48:47 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2013/03/10 08:48:47 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2013/03/10 08:46:49 | 000,000,000 | —D | C] – C:\Qoobox
[2013/03/10 08:46:15 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2013/03/09 05:45:22 | 000,386,464 | —- | C] (Bleeping Computer, LLC) – C:\Users\WinningOne\Desktop\show-hidden.exe
[2013/03/09 05:36:25 | 000,000,000 | —D | C] – C:\Users\WinningOne\Documents\Anti-Malware
[2013/03/07 23:26:24 | 000,000,000 | —D | C] – C:\Users\WinningOne\AppData\Roaming\Malwarebytes
[2013/03/07 23:26:04 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/03/07 22:56:28 | 000,000,000 | —D | C] – C:\ProgramData\BDLogging
[2013/03/07 22:56:12 | 000,511,328 | —- | C] (Microsoft Corporation) – C:\Windows\capicom.dll
[2013/03/07 22:51:45 | 000,000,000 | —D | C] – C:\Program Files\Bitdefender
[2013/03/07 22:51:30 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Bitdefender
[2013/03/07 22:50:51 | 000,000,000 | —D | C] – C:\Users\WinningOne\AppData\Roaming\QuickScan
[2013/03/07 11:03:06 | 000,262,560 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013/03/07 11:02:15 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/03/07 11:02:15 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013/03/07 11:02:15 | 000,095,648 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/03/02 08:54:42 | 000,000,000 | —D | C] – C:\Users\WinningOne\AppData\Local\Targem
[2013/02/27 16:48:22 | 002,776,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msmpeg2vdec.dll
[2013/02/27 16:48:22 | 002,284,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msmpeg2vdec.dll
[2013/02/27 16:48:22 | 000,221,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UIAnimation.dll
[2013/02/27 16:48:22 | 000,187,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UIAnimation.dll
[2013/02/27 16:48:13 | 000,465,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMPhoto.dll
[2013/02/27 16:48:13 | 000,417,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMPhoto.dll
[2013/02/27 16:48:11 | 002,565,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10warp.dll
[2013/02/27 16:48:11 | 000,648,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10level9.dll
[2013/02/27 16:48:11 | 000,522,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2013/02/27 16:48:11 | 000,364,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2013/02/27 16:48:11 | 000,363,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxgi.dll
[2013/02/27 16:48:11 | 000,194,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2013/02/27 16:48:11 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/02/27 16:48:11 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/02/27 16:48:11 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/02/27 16:48:11 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/02/27 16:48:11 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/02/27 16:48:11 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/02/27 16:48:11 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/02/27 16:48:11 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/02/27 16:48:11 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/02/27 16:48:11 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/02/27 16:48:11 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/02/27 16:48:11 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/02/27 16:48:11 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
[2013/02/27 16:48:11 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-version-l1-1-0.dll
[2013/02/27 16:48:11 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/02/27 16:48:11 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/02/27 16:48:11 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/02/27 16:48:11 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/02/27 16:48:10 | 001,887,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d11.dll
[2013/02/27 16:48:10 | 001,682,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2013/02/27 16:48:10 | 001,643,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2013/02/27 16:48:10 | 001,504,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d11.dll
[2013/02/27 16:48:10 | 001,424,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecs.dll
[2013/02/27 16:48:10 | 001,238,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10.dll
[2013/02/27 16:48:10 | 001,158,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2013/02/27 16:48:10 | 000,333,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1core.dll
[2013/02/27 16:48:10 | 000,296,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10core.dll
[2013/02/27 16:48:10 | 000,245,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecsExt.dll
[2013/02/27 16:48:09 | 003,928,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2013/02/26 07:59:10 | 000,000,000 | —D | C] – C:\Users\WinningOne\AppData\Roaming\com.stoicstudio.TheBannerSagaFactions
[2013/02/26 07:59:05 | 000,000,000 | —D | C] – C:\Users\WinningOne\tbs_logs
[2013/02/17 19:08:57 | 000,000,000 | —D | C] – C:\Users\WinningOne\AppData\Roaming\BitTorrent
[2013/02/17 19:06:09 | 000,000,000 | —D | C] – C:\ProgramData\Premium
[2013/02/17 19:03:08 | 000,000,000 | —D | C] – C:\ProgramData\CLSoft LTD
[2013/02/17 19:02:43 | 000,000,000 | —D | C] – C:\ProgramData\InstallMate
[2013/02/17 19:02:02 | 000,000,000 | —D | C] – C:\Users\WinningOne\AppData\Local\SwvUpdater
[2013/02/16 18:55:59 | 000,000,000 | —D | C] – C:\Users\WinningOne\AppData\Local\Solid State Networks
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/03/16 05:23:15 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\WinningOne\Desktop\OTL.exe
[2013/03/16 05:21:28 | 000,007,614 | —- | M] () – C:\Users\WinningOne\AppData\Local\Resmon.ResmonCfg
[2013/03/16 05:01:47 | 000,015,792 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/03/16 05:01:47 | 000,015,792 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/03/16 05:00:31 | 008,857,044 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/03/16 05:00:31 | 002,919,366 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/03/16 05:00:31 | 000,006,676 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/03/16 04:56:07 | 000,000,906 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/03/16 04:55:21 | 000,000,902 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/03/16 04:54:27 | 000,065,536 | —- | M] () – C:\Windows\SysNative\Ikeext.etl
[2013/03/16 04:54:19 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/03/16 04:53:59 | 1066,749,950 | -HS- | M] () – C:\hiberfil.sys
[2013/03/15 10:38:38 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/03/15 10:38:03 | 002,422,653 | —- | M] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\Cat.DB
[2013/03/15 10:11:14 | 000,693,976 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/03/15 10:11:14 | 000,073,432 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/03/10 14:17:27 | 000,177,312 | —- | M] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2013/03/10 14:17:27 | 000,007,466 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2013/03/10 14:17:27 | 000,000,855 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2013/03/10 12:41:44 | 000,000,258 | RHS- | M] () – C:\Users\WinningOne\ntuser.pol
[2013/03/10 09:19:32 | 005,037,356 | R— | M] (Swearware) – C:\Users\WinningOne\Desktop\ComboFix.exe
[2013/03/10 09:01:43 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2013/03/09 17:46:27 | 000,001,067 | —- | M] () – C:\Users\WinningOne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013/03/09 05:45:22 | 000,386,464 | —- | M] (Bleeping Computer, LLC) – C:\Users\WinningOne\Desktop\show-hidden.exe
[2013/03/07 22:57:40 | 000,000,385 | —- | M] () – C:\Windows\SysNative\user_gensett.xml
[2013/03/07 22:56:56 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_Kernel_avchv_01009.Wdf
[2013/03/07 11:02:11 | 000,095,648 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/03/07 11:02:10 | 000,861,088 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\npDeployJava1.dll
[2013/03/07 11:02:10 | 000,782,240 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\deployJava1.dll
[2013/03/07 11:02:10 | 000,262,560 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013/03/07 11:02:10 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/03/07 11:02:10 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013/03/04 00:51:15 | 857,598,933 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/02/22 16:18:41 | 000,027,021 | —- | M] () – C:\Users\WinningOne\Desktop\history.csv
[2013/02/16 12:04:48 | 000,067,629 | —- | M] () – C:\Users\WinningOne\Desktop\Talk on The Law of Sacrifice.rtf
[2013/02/15 16:15:46 | 000,235,583 | —- | M] () – C:\Users\WinningOne\Desktop\The Law of Sacrifice.rtf
[2013/02/14 13:07:34 | 000,000,172 | —- | M] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\isolate.ini
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/03/10 14:39:40 | 000,014,818 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\VT20130115.021
[2013/03/10 14:17:30 | 002,422,653 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\Cat.DB
[2013/03/10 14:17:27 | 000,007,466 | —- | C] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2013/03/10 14:17:27 | 000,000,855 | —- | C] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2013/03/10 14:16:08 | 000,014,818 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\SymVTcer.dat
[2013/03/10 14:16:08 | 000,009,670 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\SymELAM64.cat
[2013/03/10 14:16:08 | 000,007,611 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\ccsetx64.cat
[2013/03/10 14:16:08 | 000,007,601 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\symnet64.cat
[2013/03/10 14:16:08 | 000,007,593 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\iron.cat
[2013/03/10 14:16:08 | 000,007,589 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\srtspx64.cat
[2013/03/10 14:16:08 | 000,007,587 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\SymEFA64.cat
[2013/03/10 14:16:08 | 000,007,585 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\srtsp64.cat
[2013/03/10 14:16:08 | 000,007,581 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\SymDS64.cat
[2013/03/10 14:16:08 | 000,003,434 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\SymEFA.inf
[2013/03/10 14:16:08 | 000,002,852 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\SymDS.inf
[2013/03/10 14:16:08 | 000,001,440 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\SymNet.inf
[2013/03/10 14:16:08 | 000,001,438 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\srtsp64.inf
[2013/03/10 14:16:08 | 000,001,420 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\srtspx64.inf
[2013/03/10 14:16:08 | 000,000,996 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\symELAM.inf
[2013/03/10 14:16:08 | 000,000,853 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\ccSetx64.inf
[2013/03/10 14:16:08 | 000,000,767 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\Iron.inf
[2013/03/10 14:16:08 | 000,000,172 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\isolate.ini
[2013/03/10 08:48:47 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/03/10 08:48:47 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/03/10 08:48:47 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/03/10 08:48:47 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/03/10 08:48:47 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2013/03/09 17:46:27 | 000,001,067 | —- | C] () – C:\Users\WinningOne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013/03/07 22:57:40 | 000,000,385 | —- | C] () – C:\Windows\SysNative\user_gensett.xml
[2013/03/07 22:56:56 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_Kernel_avchv_01009.Wdf
[2013/02/22 15:25:40 | 000,027,021 | —- | C] () – C:\Users\WinningOne\Desktop\history.csv
[2013/02/17 19:02:07 | 000,000,258 | RHS- | C] () – C:\Users\WinningOne\ntuser.pol
[2013/02/16 12:04:48 | 000,067,629 | —- | C] () – C:\Users\WinningOne\Desktop\Talk on The Law of Sacrifice.rtf
[2013/02/15 16:15:45 | 000,235,583 | —- | C] () – C:\Users\WinningOne\Desktop\The Law of Sacrifice.rtf
[2012/12/23 23:51:28 | 000,203,880 | -H– | C] () – C:\Windows\SysWow64\mlfcache.dat
[2012/03/24 12:21:06 | 000,000,193 | —- | C] () – C:\Windows\WORDPAD.INI
[2012/03/09 14:06:14 | 000,024,576 | —- | C] () – C:\Windows\SysWow64\kdbsdk32.dll
[2012/02/25 08:06:06 | 000,086,306 | —- | C] () – C:\Users\WinningOne\AppData\Roaming\icarus-dxdiag.xml
[2012/02/14 21:36:36 | 000,204,952 | —- | C] () – C:\Windows\SysWow64\ativvsvl.dat
[2012/02/14 21:36:36 | 000,157,144 | —- | C] () – C:\Windows\SysWow64\ativvsva.dat
[2012/02/05 20:39:58 | 000,080,896 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2012/01/29 15:18:55 | 000,004,096 | —- | C] () – C:\Windows\d3dx.dat
[2012/01/25 14:47:36 | 000,000,774 | —- | C] () – C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
[2011/12/16 12:50:09 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2011/10/25 22:21:34 | 000,056,832 | —- | C] () – C:\Windows\SysWow64\OVDecoder.dll
[2011/09/28 17:44:14 | 000,179,271 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2011/09/12 17:06:16 | 000,003,917 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2011/08/24 10:10:29 | 000,002,304 | —- | C] () – C:\Windows\SysWow64\HtsysmNT.sys
[2011/06/17 09:50:45 | 000,000,032 | R— | C] () – C:\ProgramData\hash.dat
[2011/05/21 07:47:35 | 000,007,614 | —- | C] () – C:\Users\WinningOne\AppData\Local\Resmon.ResmonCfg
[2011/05/16 12:31:44 | 000,008,592 | —- | C] () – C:\Windows\SysWow64\ractrlkeyhook.dll
[2011/04/30 11:26:05 | 000,000,023 | —- | C] () – C:\Windows\EPSP925.ini
[2011/04/24 15:01:52 | 000,000,023 | —- | C] () – C:\Windows\BlendSettings.ini
[2011/03/25 20:14:57 | 000,000,056 | —- | C] () – C:\Windows\SysWow64\ezsidmv.dat

========== ZeroAccess Check ==========

[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/09 00:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 23:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 20:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 07:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 20:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2011/12/30 18:06:55 | 000,000,000 | —D | M] – C:\Users\WinningOne\AppData\Roaming\.minecraft
[2012/01/26 23:17:23 | 000,000,000 | —D | M] – C:\Users\WinningOne\AppData\Roaming\BigHugeEngine
[2013/02/17 19:19:52 | 000,000,000 | —D | M] – C:\Users\WinningOne\AppData\Roaming\BitTorrent
[2013/02/26 07:59:10 | 000,000,000 | —D | M] – C:\Users\WinningOne\AppData\Roaming\com.stoicstudio.TheBannerSagaFactions
[2012/12/22 22:13:34 | 000,000,000 | —D | M] – C:\Users\WinningOne\AppData\Roaming\com.ynab.YNAB4.LiveSteam
[2013/01/26 20:35:47 | 000,000,000 | —D | M] – C:\Users\WinningOne\AppData\Roaming\DMCache
[2013/03/16 04:55:17 | 000,000,000 | —D | M] – C:\Users\WinningOne\AppData\Roaming\Dropbox
[2013/01/06 19:12:50 | 000,000,000 | —D | M] – C:\Users\WinningOne\AppData\Roaming\GetRightToGo
[2011/02/28 08:57:01 | 000,000,000 | —D | M] – C:\Users\WinningOne\AppData\Roaming\Kalypso Media
[2012/01/29 15:19:25 | 000,000,000 | —D | M] – C:\Users\WinningOne\AppData\Roaming\MinMaxGames
[2013/03/10 12:28:57 | 000,000,000 | —D | M] – C:\Users\WinningOne\AppData\Roaming\Notepad++
[2013/02/03 02:28:49 | 000,000,000 | —D | M] – C:\Users\WinningOne\AppData\Roaming\Omerta Demo
[2011/02/26 22:01:58 | 000,000,000 | —D | M] – C:\Users\WinningOne\AppData\Roaming\OpenOffice.org
[2012/02/17 09:29:26 | 000,000,000 | —D | M] – C:\Users\WinningOne\AppData\Roaming\Origin
[2013/03/07 22:50:55 | 000,000,000 | —D | M] – C:\Users\WinningOne\AppData\Roaming\QuickScan
[2012/09/20 00:02:42 | 000,000,000 | —D | M] – C:\Users\WinningOne\AppData\Roaming\runic games
[2012/03/18 22:02:59 | 000,000,000 | —D | M] – C:\Users\WinningOne\AppData\Roaming\Sony
[2011/06/13 12:49:18 | 000,000,000 | —D | M] – C:\Users\WinningOne\AppData\Roaming\SpyApp
[2013/01/26 20:31:09 | 000,000,000 | —D | M] – C:\Users\WinningOne\AppData\Roaming\TFP
[2012/10/03 22:05:29 | 000,000,000 | —D | M] – C:\Users\WinningOne\AppData\Roaming\The Longest Journey Demo
[2011/07/09 15:47:38 | 000,000,000 | —D | M] – C:\Users\WinningOne\AppData\Roaming\Tific
[2012/03/04 16:08:10 | 000,000,000 | —D | M] – C:\Users\WinningOne\AppData\Roaming\Unity

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2009/07/13 21:30:02 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 15:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2011/02/26 01:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/26 00:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/13 20:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/26 00:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2010/04/19 11:32:33 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/26 00:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\erdnt\cache86\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 01:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 07:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009/11/04 11:50:03 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/04/19 11:32:33 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/11/04 11:50:03 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 08:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2010/04/19 11:32:33 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/11/04 11:50:03 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 20:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2010/04/19 11:32:33 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/02/26 01:26:45 | 002,870,784 | —- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009/11/04 11:50:03 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2009/07/13 21:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2009/07/13 21:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2009/07/13 21:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2009/07/13 21:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui

< MD5 for: IEXPLORE.EXE >
[2012/06/02 06:47:54 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=004640AB259C1572EBD5FB0A32F63686 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20553_none_0dbfc836999db0ca\iexplore.exe
[2013/01/08 20:53:45 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=0100BCF23941C83462E4A70F94C3392E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_0d2c5bc980874648\iexplore.exe
[2012/05/17 18:21:54 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=0129BB16161C2FD9A6B19111AB047198 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16446_none_1798a687b4d6030f\iexplore.exe
[2012/11/13 21:56:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_178ed6e5b4dd3857\iexplore.exe
[2012/06/29 00:02:52 | 000,754,784 | —- | M] (Microsoft Corporation) MD5=1223ACBFC1093852DFF039E189599BBD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_0d45fcc9807373c2\iexplore.exe
[2010/12/17 08:14:18 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=14803EA3E5DD7CB37CB446C74CFDA38F – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20795_none_1a39121b8bff3c23\iexplore.exe
[2012/08/24 02:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_1787d4dfb4e386f6\iexplore.exe
[2012/05/17 17:59:46 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=268982F1FD671A077C6A2AF41E351436 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20551_none_181271f4ce004017\iexplore.exe
[2012/10/08 03:37:24 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=270A1342BD5AF95CA25A586B4C2F1522 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16455_none_178cd651b4df05a9\iexplore.exe
[2009/07/13 20:17:29 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=2C32E3E596CFE660353753EABEFB0540 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_19ba3f8a72d988f3\iexplore.exe
[2012/08/24 06:23:44 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=2D53C5F71653EF94E7829846405D4ED2 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_0d332a8d8082c4fb\iexplore.exe
[2012/06/02 04:08:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=34B01BBD8F00B6B9C9248DC4F1E3CD01 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16447_none_1799a6d1b4d51c66\iexplore.exe
[2010/12/17 08:14:18 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=4879CB864E290BED38C5BDB641144B1B – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20795_none_0fe467c9579e7a28\iexplore.exe
[2012/10/08 07:29:46 | 000,754,848 | —- | M] (Microsoft Corporation) MD5=49442BA6DCE4B4E3C1CB0AB193FE29AD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16455_none_0d382bff807e43ae\iexplore.exe
[2010/12/17 08:14:18 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=498035ABCCF1ED47AE6791D239187587 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16671_none_0f6c69ae3e743d20\iexplore.exe
[2012/05/17 21:51:05 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=4E99F42504A99D5024C2EFA015001937 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16446_none_0d43fc3580754114\iexplore.exe
[2012/08/24 05:49:07 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=5A150AFABB25BEA50CEDC8650A7B8A9E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_0dc3c95e999a1626\iexplore.exe
[2012/06/28 21:45:31 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=5D03518409F37D1483C98869D86E23FF – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_0dc0c880999cca21\iexplore.exe
[2012/06/02 07:52:21 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=610F6596921C4BAA8834ADBB9BE272EE – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16447_none_0d44fc7f80745a6b\iexplore.exe
[2010/12/17 08:14:18 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=61EDBCE47ADF3E52AB0B9F49EE4AEBB8 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16671_none_19c1140072d4ff1b\iexplore.exe
[2012/08/24 02:49:25 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=62188720CE27B982B4285C03163C9FB3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_181873b0cdfad821\iexplore.exe
[2013/01/08 17:42:06 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=698EB1E5F8C66344D97C00B5699E871D – C:\Windows\erdnt\cache86\iexplore.exe
[2013/01/08 17:42:06 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=698EB1E5F8C66344D97C00B5699E871D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_1781061bb4e80843\iexplore.exe
[2010/12/18 01:17:48 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=700B40EA39DFB25517A81032F03D6D20 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16722_none_0fa37b7a3e4ac7e9\iexplore.exe
[2013/02/02 03:09:12 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=7C2923004FFC497E54F38E835F108EE8 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20580_none_0d9c579499b8b898\iexplore.exe
[2010/11/20 08:28:25 | 000,695,056 | —- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2010/12/18 01:11:10 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=8C6C32E4AF8A3D7155656F5897C504E0 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20861_none_1000d84b5789be20\iexplore.exe
[2011/05/13 23:22:12 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_17a944edb4ca4c7a\iexplore.exe
[2010/12/18 00:32:25 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=9321CF0D023528C71E3645F8433C86C8 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20861_none_1a55829d8bea801b\iexplore.exe
[2012/06/28 20:00:47 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=93569D46D79F9756ED077156496AFE23 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_179aa71bb4d435bd\iexplore.exe
[2013/02/01 23:19:03 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=A285E1965C115031DA02B777EE9D7689 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20580_none_17f101e6ce197a93\iexplore.exe
[2013/02/02 02:37:58 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=A8EBEBCD9F5C49475194099FCD276992 – C:\Program Files\Internet Explorer\iexplore.exe
[2013/02/02 02:37:58 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=A8EBEBCD9F5C49475194099FCD276992 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16470_none_0d1d8ab58092fcdd\iexplore.exe
[2010/12/18 00:33:54 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=AA08B68EF4E35EFA170CF85A44B23B70 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16722_none_19f825cc72ab89e4\iexplore.exe
[2011/02/24 00:45:11 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=AB2BB40A5FE49AD236791AC22BD08869 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20908_none_1a9d66118bb386fd\iexplore.exe
[2012/11/15 22:08:58 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=AC4957E154F750DF54F36ADC8E3E040D – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_0db6f8de99a3ff69\iexplore.exe
[2011/02/24 01:29:19 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=B4881B8F6EDB48CABD44BCC9FB5475C4 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20908_none_1048bbbf5752c502\iexplore.exe
[2012/06/02 03:51:58 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=BE967C74B89577B78FB57C061E12B04C – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20553_none_18147288cdfe72c5\iexplore.exe
[2010/11/20 07:22:51 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe
[2011/02/24 00:32:52 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C6697A46554E36541E81182B258A19D6 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16766_none_19d0e74472c85f04\iexplore.exe
[2012/10/08 03:22:05 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=CECB15F834FC2B4B150449717ADE18DD – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20562_none_1808a252ce07755f\iexplore.exe
[2013/02/01 23:19:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=DDE5A0DFAF7C6370FB36402D7A746ED3 – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2013/02/01 23:19:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=DDE5A0DFAF7C6370FB36402D7A746ED3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16470_none_17723507b4f3bed8\iexplore.exe
[2011/02/24 01:32:09 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=E1BBDE0F187194D4B08335234A4B9FC7 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16766_none_0f7c3cf23e679d09\iexplore.exe
[2012/06/28 18:35:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=EB4105348272018D096FEB655CD1608C – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_181572d2cdfd8c1c\iexplore.exe
[2013/01/08 19:51:57 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=EF1F6F41FB2C9BBB484B21017F380201 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_0daa285e99ade8ac\iexplore.exe
[2013/01/08 16:32:42 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F05982E56ABD835AA8DF260EEC873E5B – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_17fed2b0ce0eaaa7\iexplore.exe
[2011/05/13 23:22:12 | 000,754,480 | —- | M] (Microsoft Corporation) MD5=F1424C1B9B1813BF825E45DF3790BC8A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_0d549a9b80698a7f\iexplore.exe
[2009/07/13 20:43:43 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=F2B0D41E1D08D0B2006DF5AA2E74C81E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_0f6595383e78c6f8\iexplore.exe
[2012/10/08 06:09:10 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=F61714ABCF9BF0CEF0A6249AD4FD490B – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20562_none_0db3f80099a6b364\iexplore.exe
[2012/11/13 21:19:28 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F691418EE9A6344AEB5C1B0518FBF8AE – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_180ba330ce04c164\iexplore.exe
[2012/05/17 20:37:57 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=F8B2D47ED17C1D087D14EC747E5AC57A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20551_none_0dbdc7a2999f7e1c\iexplore.exe
[2012/11/14 02:11:18 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=FD0D2E1FAEBAE5031BE2EB8000D973F1 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_0d3a2c93807c765c\iexplore.exe

< MD5 for: IEXPLORE.EXE.2904.DMP >
[2013/02/13 11:46:06 | 009,167,337 | —- | M] () MD5=F51D9AFA621F652774CA33E1F0BAF0DB – C:\ProgramData\Norton\LocalDumps\iexplore.exe.2904.dmp
[2013/02/13 11:46:06 | 009,167,337 | —- | M] () MD5=F51D9AFA621F652774CA33E1F0BAF0DB – C:\Users\All Users\Norton\LocalDumps\iexplore.exe.2904.dmp

< MD5 for: IEXPLORE.EXE.5220.DMP >
[2013/02/13 11:45:37 | 009,902,534 | —- | M] () MD5=151A422620A77093CD1147457283814C – C:\ProgramData\Norton\LocalDumps\iexplore.exe.5220.dmp
[2013/02/13 11:45:37 | 009,902,534 | —- | M] () MD5=151A422620A77093CD1147457283814C – C:\Users\All Users\Norton\LocalDumps\iexplore.exe.5220.dmp

< MD5 for: IEXPLORE.EXE.5416.DMP >
[2013/02/13 12:09:03 | 009,727,685 | —- | M] () MD5=6060B869090A0EF116A9D5BDB795846A – C:\ProgramData\Norton\LocalDumps\iexplore.exe.5416.dmp
[2013/02/13 12:09:03 | 009,727,685 | —- | M] () MD5=6060B869090A0EF116A9D5BDB795846A – C:\Users\All Users\Norton\LocalDumps\iexplore.exe.5416.dmp

< MD5 for: IEXPLORE.EXE.7576.DMP >
[2013/02/13 11:45:49 | 009,278,382 | —- | M] () MD5=E9C8B8AAECC95AD2E94244525B182448 – C:\ProgramData\Norton\LocalDumps\iexplore.exe.7576.dmp
[2013/02/13 11:45:49 | 009,278,382 | —- | M] () MD5=E9C8B8AAECC95AD2E94244525B182448 – C:\Users\All Users\Norton\LocalDumps\iexplore.exe.7576.dmp

< MD5 for: IEXPLORE.EXE.MUI >
[2011/05/13 23:22:12 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2011/05/13 23:22:12 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2011/05/13 23:22:13 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2011/05/13 23:22:13 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui
[2009/07/13 21:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_09122aaf762607df\iexplore.exe.mui
[2009/07/13 21:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_0b433e7773148b79\iexplore.exe.mui
[2009/07/13 21:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_1366d501aa86c9da\iexplore.exe.mui
[2009/07/13 21:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_1597e8c9a7754d74\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-A033F7A0.PF >
[2013/03/16 05:23:12 | 000,534,396 | —- | M] () MD5=5C5B6E6A5B1A13D5F5C337BD651E6FCA – C:\Windows\Prefetch\IEXPLORE.EXE-A033F7A0.pf

< MD5 for: SERVICES >
[2009/06/10 16:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services

< MD5 for: SERVICES.CFG >
[2012/12/18 09:28:18 | 000,558,791 | —- | M] () MD5=A9983CC532F9B3FB1E87918D2313731D – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 12:55:30 | 000,584,045 | R— | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg

< MD5 for: SERVICES.EXE >
[2009/07/13 20:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\erdnt\cache64\services.exe
[2009/07/13 20:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 20:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2009/07/13 21:25:40 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\SysNative\en-US\services.exe.mui
[2009/07/13 21:25:40 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui

< MD5 for: SERVICES.LNK >
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 15:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2009/06/10 15:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof

< MD5 for: SERVICES.MSC >
[2009/07/13 21:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\en-US\services.msc
[2009/06/10 15:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\services.msc
[2009/07/13 21:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\en-US\services.msc
[2009/06/10 16:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2009/07/13 21:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 15:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2009/07/13 21:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 16:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009/07/13 15:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 15:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml

< MD5 for: WINLOGON.ADML >
[2009/07/13 21:25:22 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 16:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2010/11/20 08:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\erdnt\cache64\winlogon.exe
[2010/11/20 08:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 08:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/13 20:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2010/04/19 11:32:33 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2010/04/19 11:32:33 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2010/11/20 08:00:25 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2010/11/20 08:00:25 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui
[2009/07/13 21:29:52 | 000,022,528 | —- | M] (Microsoft Corporation) MD5=56D03B64B8C483C1D12A8E4577B3B332 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7600.16385_en-us_26ed83321dc778e1\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2009/07/13 21:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2009/07/13 21:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 15:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2009/07/13 15:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2013/03/07 23:28:44 | 000,001,796 | —- | M] () – C:\bdlog.txt
[2013/03/10 09:36:39 | 000,024,024 | —- | M] () – C:\ComboFix.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 09:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 09:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2008/04/11 10:07:18 | 000,010,134 | —- | M] () – C:\eula.1049.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2011/03/28 21:03:40 | 001,228,854 | —- | M] () – C:\fsqwr.bmp
[2007/11/07 09:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2013/03/16 04:53:59 | 1066,749,950 | -HS- | M] () – C:\hiberfil.sys
[2007/11/07 09:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2008/04/11 08:03:48 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2008/04/11 08:03:48 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2008/04/11 08:03:48 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2008/04/11 08:03:48 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2008/04/11 08:03:48 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2008/04/11 08:03:48 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2008/04/11 08:03:48 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2008/04/11 10:09:24 | 000,093,200 | —- | M] (Microsoft Corporation) – C:\install.res.1049.dll
[2008/04/11 08:03:48 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2008/04/11 08:03:48 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2013/03/16 04:54:06 | 4285,644,798 | -HS- | M] () – C:\pagefile.sys
[2007/11/07 09:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 09:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 09:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
[2011/04/27 23:05:44 | 000,000,004 | RHS- | M] () – C:\WINOS.SYS
[2012/09/10 16:51:12 | 000,002,232 | —- | M] () – C:\{0F962062-C9A1-4AD6-AC0F-3055B6FFA680}
[2012/05/13 23:16:37 | 000,002,232 | —- | M] () – C:\{36270BD5-DA9B-435A-995C-5E0445B7418A}
[2012/11/07 10:11:38 | 000,002,232 | —- | M] () – C:\{7C51882F-14CA-453F-954B-74C348259785}
[2012/09/17 17:55:48 | 000,002,232 | —- | M] () – C:\{B873CACE-BC5C-462B-99C3-5D7D2B59A789}
[2012/09/24 19:07:01 | 000,002,232 | —- | M] () – C:\{DF7A2EA3-333D-44AE-9417-A4B8A1902654}

< %systemroot%\Fonts\*.com >
[2009/07/14 00:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 15:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 23:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/05/14 08:14:37 | 000,000,221 | -HS- | M] () – C:\Users\WinningOne\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2013/03/10 09:19:32 | 005,037,356 | R— | M] (Swearware) – C:\Users\WinningOne\Desktop\ComboFix.exe
[2013/03/16 05:23:15 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\WinningOne\Desktop\OTL.exe
[2013/03/09 05:45:22 | 000,386,464 | —- | M] (Bleeping Computer, LLC) – C:\Users\WinningOne\Desktop\show-hidden.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:B1FBBD09

< End of report >



OTL Extras logfile created on: 3/16/2013 5:26:43 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\WinningOne\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

11.99 Gb Total Physical Memory | 10.10 Gb Available Physical Memory | 84.23% Memory free
23.98 Gb Paging File | 22.12 Gb Available in Paging File | 92.24% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 891.02 Gb Total Space | 740.93 Gb Free Space | 83.15% Space Free | Partition Type: NTFS
Drive D: | 40.00 Gb Total Space | 34.66 Gb Free Space | 86.66% Space Free | Partition Type: NTFS
Drive F: | 7.32 Gb Total Space | 5.44 Gb Free Space | 74.32% Space Free | Partition Type: FAT32

Computer Name: WINNINGONE-PC | User Name: WinningOne | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DefaultOutboundAction" = 0
"DefaultInboundAction" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{077A2F62-2709-461A-92CB-8815F641DF80}" = rport=10243 | protocol=6 | dir=out | app=system |
"{1406CDD1-A165-4996-B7B9-F5C2911E1806}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{144EBE8B-9A5F-4E52-97B6-6C463775C84F}" = rport=80 | protocol=6 | dir=out | app=c:\program files (x86)\common files\intuit\update service v4\intuitupdater.exe |
"{1648E915-AF98-4F26-A028-B6BBA38C2E86}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{1F42B1CB-EE5E-4CAA-ABE6-B1CC9D4E666B}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{278A5F21-FA21-41E8-92DF-9C2C339F4BFB}" = lport=445 | protocol=6 | dir=in | app=system |
"{2A38FF1F-8C40-479B-ACDD-09F28BB72215}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe |
"{32B802D0-2D87-4544-8250-5CB27A90C826}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{32C6A38F-4280-43FB-AF71-5F13387F1278}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{339BAAD5-525E-4556-884E-AF9F0E30AB5E}" = lport=10243 | protocol=6 | dir=in | app=system |
"{38A44A22-B219-4A14-8621-6B103E8D6154}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{42FC87CF-2739-4E3C-A18F-910F75B5A2BE}" = lport=49173 | protocol=6 | dir=in | name=akamai netsession interface |
"{444DFDE9-C52E-4B54-9FA4-89FF64A59301}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{4E7851C3-06F4-4EA9-BD91-88826429A3E9}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{50210E67-1876-47FE-9640-B174FE5A1873}" = rport=138 | protocol=17 | dir=out | app=system |
"{73A1F695-CE31-4130-8744-48DE26C27C24}" = lport=2869 | protocol=6 | dir=in | app=system |
"{7CC3C232-F26E-4019-B4CB-52522306241A}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{7F9CD04F-38F0-46BA-9942-13FC222B823D}" = lport=139 | protocol=6 | dir=in | app=system |
"{81B6B3D9-EEC6-4D2F-B884-9BC553369F01}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{8667AC1D-C517-40D7-ADEE-D9179B437BAA}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |
"{8974B96D-E04B-4D22-9F34-4FE0F276D72B}" = rport=139 | protocol=6 | dir=out | app=system |
"{8FED2C4B-695C-4409-89AC-6499E56FBB8E}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{9740968A-7B25-4A1A-8CA5-DEC403DBD69F}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{9E5CE491-01C7-45EB-AC74-D71C3E8B0D6E}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{9E8E3059-BB6F-4438-B3FA-B973591E381B}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{9F7A719A-1F2B-413A-B31A-72113B2551BF}" = rport=137 | protocol=17 | dir=out | app=system |
"{A0F2733D-C299-4436-9CC7-DCA0761332CA}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{A17F18F2-E90C-418D-AA70-2472F5D606E6}" = rport=80 | protocol=6 | dir=out | app=c:\program files (x86)\common files\intuit\update service v4\intuitupdateservice.exe |
"{A87E49B6-71DF-4A2F-9C26-F006CC01EEB7}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe |
"{B2E2267F-3112-4767-8A50-7BABDF95052E}" = lport=137 | protocol=17 | dir=in | app=system |
"{B838448C-4F28-4A6D-A438-784D57F65E04}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{C17F7526-E89F-47C7-9F9D-B883EB6DF5BD}" = rport=445 | protocol=6 | dir=out | app=system |
"{CC8B4678-44AE-4289-A8C3-19525C9BD52A}" = lport=138 | protocol=17 | dir=in | app=system |
"{D4ABA63D-DB7B-4ED2-A6E5-F719A82E9B66}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{E3D0AE9A-C3FC-4032-AE52-228400EB16AB}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{EC5AE37C-9B1D-42F3-92D0-5892D47A7158}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{FBA34457-B92F-4D1A-B783-3250844AEC6E}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{018D6BE4-76BC-4A65-BFC6-DAD88DC7D27D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\amd driver updater, vista and 7, 64 bit\setup.exe |
"{0428292B-3930-4261-9483-EB751776B9B4}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{0503935A-88C4-43B5-BD1A-49C93CA39768}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight ii\torchlight2demo.exe |
"{054EB266-E05D-45E9-8AAE-918B5C08A119}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{0656F9FF-4098-4B8E-9BFB-1772FD84F814}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\forsaken world\patcher.exe |
"{0A0C6DA8-8C95-486F-942D-F9FC3DDE0BF5}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{0AC88710-DAA0-4076-8AAF-4A7757E686A0}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{0D4CF483-DFC1-4141-9B26-488EC9386561}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{0DDC9F51-B62F-4CE1-B44E-DF2F02642EBB}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bastion\bastion.exe |
"{0F889E47-EEF3-4412-9B35-7C898AF672AC}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\neverwinter nights 2\nwn2toolsetlauncher.exe |
"{117343AC-25FD-4D18-98A9-BB98E6A90531}" = protocol=17 | dir=in | app=c:\program files (x86)\diablo iii\diablo iii.exe |
"{11AC9462-6523-4106-BF16-7859BFB4A873}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.524\agent.exe |
"{12513551-B607-44D3-A054-E9E9CFB95D09}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight\torchlight.exe |
"{152E136D-E4EC-44E5-AB88-D829B13084E0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead space\dead space.exe |
"{1563DAAE-3C30-49DB-A7FA-0DBD088AE086}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"{15A269A5-2B5E-457A-8E14-4CE01D8EF171}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spiral knights\java_vm\bin\javaw.exe |
"{15FD8D56-41D8-4D46-ACD5-9939D7DB9FED}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\orcs must die!\build\release\orcsmustdie.exe |
"{1715D1DF-FE73-4482-AD6B-7500A09852D1}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe |
"{19C1006C-6CB2-487A-ACF7-704C2A958375}" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.patch.exe |
"{1AD62A6D-DD01-4854-91E8-AFE1452DC01F}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.868\agent.exe |
"{1D3C3023-285B-4A22-A58F-C09E4D5F08DB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight\torchlight.exe |
"{2191DC98-47F9-40A2-B878-FC57DB2C269C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands\binaries\borderlands.exe |
"{22CB70C7-DE5E-48CC-8A95-98076B6EB788}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\ynab 4\ynab 4.exe |
"{22E3D793-31AA-4FD8-81B1-C84215711337}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\skyrim\skyrimlauncher.exe |
"{23C1396E-334A-4A95-B3A7-6F3A72D345E6}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii public test.exe |
"{24881BEB-4BE6-4156-84C8-EF621A512356}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{275145FC-9CEA-416F-8BE1-9297B59AABA2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\splinter cell\system\splintercell.exe |
"{27B43C82-B049-4FEA-8D66-C5BE3BC0784E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\amd driver updater, vista and 7, 64 bit\setup.exe |
"{292635FA-203B-4BFD-9C12-7958923C9E8C}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base21029\sc2.exe |
"{2B97BC34-51B5-4F67-8915-850BE4ABCCE5}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\ufo afterlight\ufo.exe |
"{2BF4D13B-5454-4506-A977-21CED7074D45}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\brawl busters\bin\pblauncher.exe |
"{2CB8FD55-2495-4A91-87F3-BC6BFBA3DCC4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\skyrim\skyrimlauncher.exe |
"{2CCDF422-1B35-4FFF-8A5A-656D709FAA2C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bastion\bastion.exe |
"{2CD308B2-237C-42D4-AF76-838B4D65CF4F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\oblivion\oblivionlauncher.exe |
"{2CFA4DED-C788-40EE-834C-D2E37D2D881D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tom clancy's splinter cell conviction\src\system\conviction_game.exe |
"{2D55D146-9372-41A5-884C-97FECC43F04C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bastion\bastion.exe |
"{2D947969-161B-40EA-BD94-00C9B5BDE6FB}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{2E25AB4E-5663-4C5D-A532-157E7698C08A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\ufo afterlight\ufo.exe |
"{2F107A6D-6047-4E9B-8E52-22C076FF4D6C}" = protocol=6 | dir=out | app=system |
"{2F185B32-398B-449A-84A1-8B44DA669BC0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tom clancy's h.a.w.x - demo\hawx.exe |
"{2F65DFD2-3B12-43D1-BF4C-1AEB11D56E4C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the banner saga factions\win32\the banner saga factions.exe |
"{311B1EAC-11E1-4196-B458-41B372CBDD9F}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe |
"{313691D4-37FC-4118-B7FA-A485DA1CCDC6}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\disciples 3\disciplesiii.exe |
"{31695ED8-2A8C-4018-8F69-9852184A6C18}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\brawl busters\bin\pblauncher.exe |
"{32065FEC-3084-4711-9475-34E7CF73F2CC}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead space\support\ea help\electronic_arts_technical_support.htm |
"{329475A3-BA2F-4A12-A265-14C4A5A49449}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\orcs must die!\build\release\orcsmustdie.exe |
"{3551FA24-0DD6-490C-A7AC-AE86A89FFF71}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\magicka\magicka.exe |
"{37408DE3-F9C8-4089-835D-67CCE72755BA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\magicka\magicka.exe |
"{3867C946-0806-43F6-B22B-2486676CA725}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\space pirates and zombies\spazgame.exe |
"{38B49B24-AA28-47FB-96F8-3202C2C295B7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\ava\reactor.exe |
"{39992D5A-0AB8-4217-9D6C-1CD8F80B30AB}" = protocol=6 | dir=in | app=c:\users\winningone\appdata\local\temp\7zs2c6c.tmp\symnrt.exe |
"{3BB8E318-8176-4385-8982-CBFA6A84AD0D}" = protocol=6 | dir=in | app=c:\program files (x86)\diablo iii\diablo iii.exe |
"{3C67DE7B-DA0B-4C05-AC9E-80608F8D19EB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\daoriginslauncher.exe |
"{3D1F5CC2-28A8-407D-BD3B-AF2104668635}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher enhanced edition\system\djinni!.exe |
"{3FBF6FDE-2425-446B-B0BA-4CAE169B28C4}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{3FDE9B84-11EF-4998-8D1C-CFCFD81B1997}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\splinter cell - double agent\scdalauncher.exe |
"{408BF0AC-4C26-458A-BD50-8D0FFE97FAA4}" = protocol=6 | dir=in | app=c:\nexon\dragonnest\dragonnest.exe |
"{434BD276-2438-42E3-B8CC-611C758F5C0F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\daoriginslauncher.exe |
"{43C20EA0-04EF-4E6C-A37D-5E7BCA2C5237}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{449A7715-D0D8-4261-ABC5-705FC97757AE}" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.exe |
"{44E0CF63-A54F-4CEF-AFBE-392EE9BB7156}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe |
"{462B0CD0-4F22-407B-BB5C-DDF941629E46}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\red faction guerrilla\rfg_launcher.exe |
"{47D66441-E0FA-44C1-B417-810DB9294E9C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tom clancy's splinter cell conviction\src\system\conviction_game.exe |
"{48A4B11F-37EC-47AE-9E16-138EA3A56297}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\amd driver updater, vista and 7, 64 bit\setup.exe |
"{492C70D8-D050-452F-BA4E-2414EAECAB19}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\docs\ea help\electronic_arts_technical_support.htm |
"{4A206092-286F-43A4-B95A-A461A7619C9F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\brawl busters\bin\pbclient.exe |
"{4BF51D02-7693-4E79-A971-9026C248D2D7}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\gamemaker_studio\gamemakerplayer.exe |
"{4C5C906F-4C71-450B-B60E-4E65BF1E84AB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\red faction guerrilla\rfg_launcher.exe |
"{4C7CE30F-7253-4D13-A01D-D8DAB0B27978}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight\torchlight.exe |
"{558D5D04-8D1A-4197-A9B2-EFD8A448A91B}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{56550D75-6700-4810-8983-1113CDF7997B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\skyrim\skyrimlauncher.exe |
"{5675280B-33DD-4CEA-90FA-D82FF5A1B164}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\splintercell chaos theory\system\splintercell3.exe |
"{57B0776D-FB82-46C9-A5DC-15554E10507F}" = protocol=17 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"{58347548-2888-41E7-BA6D-93A9CC2D67FE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\neverwinter nights 2\nwn2.exe |
"{58805589-32FF-4B5C-9FA0-C46673D55B57}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tom clancy's splinter cell conviction\src\system\conviction_game.exe |
"{5883D5A6-7BEB-4CB1-827E-FFE2E4AA2D45}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{58959D3D-02B6-4AB4-AB01-4ACF635C1318}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.913\agent.exe |
"{59F039E5-F332-443F-8730-49EFB1F053E4}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.524\agent.exe |
"{5AB8C64F-CB77-450F-B9BF-15CD4B1DED68}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"{5C077F53-17FF-489A-86D2-F64B2DCE70BE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\skyrim\skyrimlauncher.exe |
"{63C0947F-2AA8-46BD-AF0F-4E90489BFF3F}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe |
"{65AAEA52-241D-4EBB-8D5C-DE9748BB4C18}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe |
"{65BB122B-BFFD-41B9-93A1-7EF383459C94}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{65FC7D5E-5337-44EE-A824-027F125E4A5F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{665D9E52-EDA1-432C-A1F9-299150601651}" = protocol=17 | dir=in | app=c:\aeriagames\edeneternal\_launcher.exe |
"{68BC5202-E7AE-478A-A3E6-0C6FC29BE2F2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\splintercell chaos theory\system\splintercell3.exe |
"{6B64CA53-DDBC-4441-AEF2-B7CEBBC182CA}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\space pirates and zombies\spazgame.exe |
"{6E378A68-2014-4C78-B95A-23555C2D5393}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7206BDA9-DBDC-4552-BF51-AC1426145590}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher enhanced edition\system\witcher.exe |
"{73CDF695-7008-4BBD-9F5E-C51BCD5E40E8}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{75977E9C-47C1-4118-B832-70E6C3BC4809}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{762B1E9C-737B-470C-8E92-62785406A253}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\splinter cell - double agent\scdalauncher.exe |
"{76D6AFD6-0C88-4EBD-9600-ECA7CAB364ED}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher enhanced edition\system\witcher.exe |
"{76F7AEFB-B701-4A04-B451-215A67AB56C7}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead space\dead space.exe |
"{774EE220-C47C-4C67-9B49-FAEAD9D9AD7C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\neverwinter nights 2\nwn2.exe |
"{77AB7435-31DB-495E-B14F-F1CFFF9DD87D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{77B71878-2E43-40ED-8F2E-27B224F978F3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\splintercell chaos theory\system\splintercell3.exe |
"{78E7E5CC-2F78-40D8-A5BB-5E5E60338512}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\red faction guerrilla\rfg_launcher.exe |
"{7978F09F-728C-477A-ADB6-FF48841FDDE6}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{7AEC2B8F-DB52-46E6-AEC2-FDECE46A833F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\red faction guerrilla\rfg_launcher.exe |
"{7B36E131-DFCB-4F22-B025-1CC631DF69C4}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\daorigins.exe |
"{7BC089FA-84EA-47C2-8CAB-8AF8F29B76C6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\oblivion\oblivionlauncher.exe |
"{7C3837EC-9C37-4B8C-B3AF-25B8C1B961CF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\daoriginslauncher.exe |
"{7F230B14-2225-4D99-B074-679E5B9172AB}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\deus ex - human revolution\dxhr.exe |
"{801AF219-9155-483B-A6B4-3ED928911C8B}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe |
"{8040FA16-D4BB-4C70-B716-466DB5DDD261}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.976\agent.exe |
"{82BBF5AE-520A-472F-8C46-709A3CF771FB}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\brawl busters\bin\pbclient.exe |
"{8685DE5E-6FCD-4BDB-BBDB-4E9705351B51}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{8721FD5E-140B-4AAC-99A7-A3BD0103663D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\docs\ea help\electronic_arts_technical_support.htm |
"{89225428-9AF6-4F96-A5DD-203F27A7C7AF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\ava\reactor.exe |
"{89296E18-0893-41CF-951C-0D0D9E7E6708}" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.exe |
"{89525196-6F65-4E01-9AA5-FA09164FADBD}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{8E8CF46E-AF2B-4A12-89A5-68287AB85EF8}" = dir=in | app=c:\program files (x86)\skype\plugin manager\skypepm.exe |
"{919EDB29-97C1-46F3-AFC4-4B91A770457E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\docs\ea help\electronic_arts_technical_support.htm |
"{91A3BB85-CD92-4F3A-9A89-D9DC9818FC50}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{92D1FC15-3088-43C1-9506-557CE121D899}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\oblivion\oblivionlauncher.exe |
"{92D87AE0-0FF8-423A-B1BC-6A228C993FA0}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{960879FF-E5F1-4E76-8CBF-1736F9ADB55B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\oblivion\oblivionlauncher.exe |
"{990A201A-BF0D-482E-9A43-30FA21D895FF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead space\support\ea help\electronic_arts_technical_support.htm |
"{99CD3B7B-A761-4E66-8B94-34A141932F2A}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe |
"{99FB53B4-8BCD-4745-9401-28F32691C799}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the banner saga factions\win32\the banner saga factions.exe |
"{9C030EE0-8D94-4FA3-B9B9-413496B40394}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"{9D2BC353-9E71-4723-83DA-15EE92FF66BD}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\stalker shadow of chernobyl\bin\xr_3da.exe |
"{9EDF9603-90A0-4517-BA55-690F9CBCD952}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tom clancy's h.a.w.x - demo\hawx.exe |
"{9F1C4C70-F265-426F-8357-52E4C84BDE03}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands\binaries\borderlands.exe |
"{A1F7466A-584E-4652-8802-B0A3E662F44F}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.998\agent.exe |
"{A2364E19-0E63-4523-B7B9-C3123891CEDD}" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.exe |
"{A30C959D-C97D-4CD8-986C-B4877FD2929E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\neverwinter nights 2\nwn2toolsetlauncher.exe |
"{A3CF6A79-C5FB-49F8-843E-83DA941BA285}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\daupdatersvc.service.exe |
"{A55E1DBB-47A4-4EE6-A0A0-0FA6A3C96811}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{A6896E18-B2D7-404D-840F-9AE7915C22AE}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{A6A1E7DD-02A5-4751-B996-52A7FD5AE6AF}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.976\agent.exe |
"{A6D34A07-EB1E-4AD0-A8D6-1477D7EC6AFB}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\neverwinter nights 2\nwn2toolsetlauncher.exe |
"{A70DBC8A-7B82-4B1D-BFD1-1C01BA673437}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arcania gothic iv - demo\arcania.exe |
"{A805CC5D-8B48-48EB-AA5F-EE2D49611B8B}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{A834FA69-6E1E-4E91-8239-35F08A160BC3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead space\dead space.exe |
"{AA2BEFF5-3910-47D1-BF52-CE178FCAC1B2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead space\dead space.exe |
"{AA7FDD94-8A58-4137-9866-D22DE795675A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\ynab 4\ynab 4.exe |
"{AB237003-D237-4542-9F8C-12F5FEEC70D0}" = protocol=6 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"{ABA737BA-669C-4FAB-B1C1-7E9E07EE7426}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\daorigins.exe |
"{ABBFDE4B-8806-4183-9F40-B243C98D393E}" = protocol=17 | dir=in | app=c:\users\winningone\appdata\roaming\dropbox\bin\dropbox.exe |
"{AE6D03D6-E97A-421F-A404-31424837E45B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\deus ex - human revolution\dxhr.exe |
"{B0863346-84FC-42CA-8093-5DB6F1EC61C1}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\neverwinter nights 2\nwn2.exe |
"{B1835F3C-AD07-426D-B453-7F8EBFD6DDE8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\splinter cell\system\splintercell.exe |
"{B4EE2F6A-7185-43E0-A9C8-B7DBF79813BF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spiral knights\java_vm\bin\javaw.exe |
"{B60F2D89-BD44-41C6-B172-1396BFB8D0EF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\splintercell chaos theory\system\splintercell3.exe |
"{B877B92E-9E1E-4466-AD91-44198F00F11B}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{BB23FF46-906B-4338-A773-0C0851A4C201}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{BB8C7988-56D7-4E69-B859-5BA047A17DBD}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight\torchlight.exe |
"{BBBF52A6-E4F9-43D2-AF5E-988C6B0332B3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead space\support\ea help\electronic_arts_technical_support.htm |
"{BD3A160D-75FE-401D-B36C-2C97DD459C1B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\daorigins.exe |
"{BEEE0312-5F93-4459-97AE-B5802F57FBB6}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{BF29F2F1-A9D5-4F9F-959D-D6E83BF83E32}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\docs\ea help\electronic_arts_technical_support.htm |
"{C26A4B0D-12C5-4B46-A0FD-CE88FF6D2862}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\amd driver updater, vista and 7, 64 bit\setup.exe |
"{C28E8E7E-1EC6-4D82-9179-CBA4687B4073}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base21029\sc2.exe |
"{C387133D-5CCD-4D76-9B3F-60F71924298B}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{C3DA9873-0D04-4CE0-AAA1-E7FC73CD037D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\disciples 3\disciplesiii.exe |
"{C435A992-3A4F-4264-AC60-0401E79E6B31}" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.patch.exe |
"{C4B64148-0D31-4B34-936F-D9A54B4B633B}" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.patch.exe |
"{C4E50EAD-7BA1-4F6D-830C-FE103BAB768F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\avernum escape from the pit\avernum.exe |
"{C541FCEF-5448-4E57-9898-7A2187269793}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{C54249F7-00FA-4A4E-A9CA-04CAD4BF8902}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\avernum escape from the pit\avernum.exe |
"{C70F9E83-5E39-4E25-B73C-ABF624795448}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii public test.exe |
"{CAE06CA4-8ADB-4850-ABEC-8897EBAE550A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{CD9CE472-C7D9-42DD-9E9C-30F16D7B5C1C}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.998\agent.exe |
"{D0412477-825F-4C55-A321-DC63F4BBB61E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\magicka\magicka.exe |
"{D1C80352-FD87-4C8A-AF26-0DD1C17511BA}" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.patch.exe |
"{D1E289C2-A6A1-4D46-8A67-4A095FA89922}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tom clancy's splinter cell conviction\src\system\conviction_game.exe |
"{D540F554-0CE7-410A-A53F-DDEF8B47BF99}" = protocol=17 | dir=in | app=c:\nexon\dragonnest\dragonnest.exe |
"{D641CA50-8393-474C-9C18-07A42771591B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\daupdatersvc.service.exe |
"{D8F20841-BB90-41AE-A72D-B4F0128B8C78}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\neverwinter nights 2\nwn2.exe |
"{D9412223-2300-4173-ACAD-AB42912BD4D2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\vampire the masquerade - bloodlines\vampire.exe |
"{DAD82EDF-7C70-4645-9338-2D3AEE046D86}" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.exe |
"{DB40BCC6-5B5B-4FD4-A3D0-97FED910CB32}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\forsaken world\patcher.exe |
"{DBE82A58-A4FB-4E91-A008-B3B67947E22E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bastion\bastion.exe |
"{DDD5A17E-1287-4DE3-8BFF-AB1C0E6C71A9}" = protocol=6 | dir=in | app=c:\aeriagames\edeneternal\_launcher.exe |
"{E11F3FD4-37F5-4A97-A7BB-7AF3D3AFB3C9}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.913\agent.exe |
"{E177EEF7-8084-4365-BE47-BAAE7E52A8E2}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{E3FF5D56-70A8-43BE-8AE9-AF0739FE116C}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe |
"{E5CC67F0-7A93-43DE-8A56-771B157434D3}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight ii\torchlight2demo.exe |
"{E65A5EB5-99C1-4F24-AF08-82A5F446665B}" = protocol=17 | dir=in | app=c:\users\winningone\appdata\local\temp\7zs2c6c.tmp\symnrt.exe |
"{E6691218-38B3-4CCE-B77B-976E44CC58A8}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.868\agent.exe |
"{E7EC61AC-EDB5-4615-81F3-0C0A3033A6F5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\magicka\magicka.exe |
"{EA903B79-AC65-4C2A-BE2A-B0D249F4CDE7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\stalker shadow of chernobyl\bin\xr_3da.exe |
"{EB3880B2-BD36-4BE3-B2F1-CEEE09BE438A}" = protocol=17 | dir=in | app=c:\program files (x86)\diablo iii beta\diablo iii.exe |
"{EB57000B-E855-4892-951E-966BF786E2E6}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{ECA4F52A-33D9-470A-A45F-AD7E472B9A97}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\daorigins.exe |
"{ECF3FFE9-5A3E-4D91-BEAE-433FF453170E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\gamemaker_studio\gamemakerplayer.exe |
"{ED81C313-19A5-4216-B94A-0C83705082C6}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{ED98D33F-43E7-4A93-A0A1-3A04207FE9CB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\splinter cell - double agent\scdalauncher.exe |
"{EDDEE351-A488-4D15-8149-AAE3090CA2FE}" = protocol=6 | dir=in | app=c:\program files (x86)\diablo iii beta\diablo iii.exe |
"{F04C2871-63AB-432C-83BC-9C07B14FED09}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher enhanced edition\system\djinni!.exe |
"{F181296E-7174-43F3-9C9C-1F433154C213}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead space\support\ea help\electronic_arts_technical_support.htm |
"{F35A9C61-E1F0-43C0-9E02-1CA822F1484C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\splinter cell\system\splintercell.exe |
"{F6866E86-0238-4D58-9EE8-02BD7E82A15C}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe |
"{F6CBE92A-F5FD-4884-A6C7-C37B7FFA33FC}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\vampire the masquerade - bloodlines\vampire.exe |
"{F7A367D3-81C3-428E-9995-A867D46CDE75}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\splinter cell\system\splintercell.exe |
"{F8034436-0DF5-497F-8527-2F727A72E2B3}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\daoriginslauncher.exe |
"{F9E06EF7-5D89-4A54-9B54-6E0A0C2C855C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arcania gothic iv - demo\arcania.exe |
"{FA60829F-AB1D-4ADC-BD5A-00111594C0B7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\splinter cell - double agent\scdalauncher.exe |
"{FC4CE281-956C-41A9-94A3-00D227C2EDDA}" = protocol=6 | dir=in | app=c:\users\winningone\appdata\roaming\dropbox\bin\dropbox.exe |
"{FD94FE7C-E9BD-4E50-B0B1-8709119DF0A3}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{FE120E3C-3D3E-4572-BAA9-FE673C8DCD89}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"{FE8D8453-8CE6-4419-83C9-4D274437792D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\neverwinter nights 2\nwn2toolsetlauncher.exe |
"{FEB91C0D-E8A7-4AF0-8578-6F61999694C3}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{FF768133-A326-4A71-AAE5-6AEC5A43F986}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe |
"TCP Query User{5CE904A0-C919-4A3F-A523-294CD08647EB}C:\users\winningone\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\winningone\appdata\local\akamai\netsession_win.exe |
"TCP Query User{846CC748-22EF-4DF0-A863-8FADEF430071}C:\users\winningone\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\winningone\appdata\local\akamai\netsession_win.exe |
"TCP Query User{97DC5B7F-1090-4769-BB38-656F63B832FE}C:\program files (x86)\steam\steamapps\common\neverwinter nights 2\nwn2main.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\neverwinter nights 2\nwn2main.exe |
"TCP Query User{A90F30A3-EC0E-4A2F-A296-728212CBF674}C:\program files (x86)\starcraft ii\versions\base17326\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base17326\sc2.exe |
"TCP Query User{B1994F80-C936-484A-AE2F-AB896BD82108}C:\program files (x86)\world of warcraft\temp\wow-4.0.1.2210-enus-tools-downloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\temp\wow-4.0.1.2210-enus-tools-downloader.exe |
"UDP Query User{3458B557-0035-4124-A4FE-622132CA3FF9}C:\users\winningone\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\winningone\appdata\local\akamai\netsession_win.exe |
"UDP Query User{6087E63C-AFBB-422D-B042-CB8C033F0D08}C:\users\winningone\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\winningone\appdata\local\akamai\netsession_win.exe |
"UDP Query User{833A3527-B87F-4D8A-97B5-AFBD17B78F4E}C:\program files (x86)\steam\steamapps\common\neverwinter nights 2\nwn2main.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\neverwinter nights 2\nwn2main.exe |
"UDP Query User{941C30E1-4908-46A7-99EA-3DDC951CAEFC}C:\program files (x86)\world of warcraft\temp\wow-4.0.1.2210-enus-tools-downloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\temp\wow-4.0.1.2210-enus-tools-downloader.exe |
"UDP Query User{BC702499-7F0B-4764-8451-A4ACAB158905}C:\program files (x86)\starcraft ii\versions\base17326\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base17326\sc2.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0CB2E2BC-A312-5821-C5C7-A295A1BEFD08}" = AMD Catalyst Install Manager
"{0E5D76AD-A3FB-48D5-8400-8903B10317D3}" = iTunes
"{119B2F5A-2A06-DB96-FF28-992EC2A10BDF}" = AMD Accelerated Video Transcoding
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4E021D2A-16ED-4FFF-87CB-774F4F62A1A1}" = ccc-utility64
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{572788F2-0AB7-FA0E-6E91-B98044F4B7E6}" = AMD Media Foundation Decoders
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C5B5A11-CBF8-451B-B201-77FAB0D0B77D}" = Microsoft Network Monitor 3.4
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-0015-0409-1000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-1000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-1000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-1000-0000000FF1CE}_Office14.SingleImage_{0242505C-4E90-407F-9299-B5B275F50D86}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-1000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-1000-0000000FF1CE}_Office14.SingleImage_{B51389C8-2890-4633-81D8-47D2A7402274}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-1000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-1000-0000000FF1CE}_Office14.SingleImage_{1779650B-2E44-4A19-8DF6-3866D645764A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-1000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-1000-0000000FF1CE}_Office14.SingleImage_{270CA0B9-9881-44DB-BC3B-37C7E66A044A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-1000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{7BC9B5EB-125A-4E9B-97E1-8D85B5E960B8}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010
"{90140000-0043-0000-1000-0000000FF1CE}_Office14.SingleImage_{E8B6D35B-0B6F-4DCE-9493-859BF3809A7F}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0043-0409-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (English) 2010
"{90140000-0043-0409-1000-0000000FF1CE}_Office14.SingleImage_{FCD1C311-8B02-4DBD-BA46-1079C629577E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-1000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-1000-0000000FF1CE}_Office14.SingleImage_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-1000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-1000-0000000FF1CE}_Office14.SingleImage_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-1000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{963E5FEB-1367-46B9-851D-A957F1A3747F}" = Microsoft Network Monitor: NetworkMonitor Parsers 3.4
"{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}" = Intel® Turbo Boost Technology Monitor 2.0
"{D70884EA-E2CE-4539-91DB-4766CC1E5F5F}" = Apple Mobile Device Support
"{EE269999-1AB7-7B39-7944-513CF3426CB8}" = AMD Drag and Drop Transcoding
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Office14.SingleImage" = Microsoft Office Home and Student 2010
"SAMSUNG Mobile Modem" = SAMSUNG Mobile Modem Driver Set
"Samsung Mobile phone USB driver Drive" = Samsung Mobile phone USB driver Drive Software
"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software
"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software
"WinRAR archiver" = WinRAR 4.20 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}" = Razer Synapse 2.0
"{11083C7A-D0D6-4DA4-8C3A-74B8389EC07B}" = ATI Catalyst Registration
"{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1
"{141B8BA9-BFFD-4635-AF64-078E31010EC3}_is1" = FINAL FANTASY VII
"{14DDF23F-414A-46DB-4762-56569080292C}" = CCC Help Russian
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{21D6A73A-48E6-2195-C408-2158273A914E}" = Catalyst Control Center Localization All
"{2596DB11-997F-FC5B-F5C2-737623D9D8B6}" = Catalyst Control Center
"{26A24AE4-039D-4CA4-87B4-2F83217017FF}" = Java 7 Update 17
"{28904D9A-13A6-ECA2-48D8-21542759D998}" = CCC Help Polish
"{28E82311-8616-11E1-BEB0-B8AC6F97B88E}" = Google Earth
"{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0
"{2C8BBDA6-79A7-B2DE-3E5B-287E7F667C67}" = CCC Help Danish
"{2E119961-E99B-C147-9AC3-A93683172DC1}" = CCC Help Swedish
"{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = JMicron JMB36X Driver
"{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}" = Hi-Rez Studios Authenticate and Update Service
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}" = NVIDIA PhysX
"{41785C66-90F2-40CE-8CB5-1C94BFC97280}" = Microsoft Chart Controls for Microsoft .NET Framework 3.5
"{44ED90A1-453B-5C9A-D9ED-80D8AB0258B8}" = CCC Help Thai
"{45E00595-897E-64B6-28F9-5D0927EBA4A5}" = CCC Help Chinese Standard
"{46DE5F4E-BA8B-AC9E-0EED-05B7D93AD215}" = CCC Help Spanish
"{47FA2C44-D148-4DBC-AF60-B91934AA4842}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"{58AA0670-2352-424B-BE5F-CF59EDD07EA0}" = Razer Anansi
"{5A336D74-E680-4986-96F4-E9CEBC784F56}" = Naga Firmware Updater 1.13
"{5B04E832-4530-B8FF-F742-8BE25ADD43BD}" = CCC Help German
"{5D58EACA-0317-4CFF-9E13-53CCD525DE32}" = Catalyst Control Center InstallProxy
"{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411
"{5ED93D68-5EAA-9343-9B74-B1E276217264}" = CCC Help Dutch
"{653A0F15-C146-46E8-8309-92A97ACEBEF6}" = NWZ-E360 WALKMAN Guide
"{6C3BEF70-5411-11E1-AED6-F04DA23A5C58}" = MSVCRT Redists
"{6D185295-DE89-9C39-18E6-310C148836EB}" = CCC Help Chinese Traditional
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71A8F958-D272-E262-7C9A-7B8F713EE0C3}" = CCC Help French
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73868DD9-CC9A-4F7F-B708-99F096DEAB6D}" = Adobe Shockwave Player 11.5
"{7513D3F0-55BC-273C-7A53-488394EDBFCC}" = CCC Help Italian
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79AA9BFA-F962-A1E9-71CE-D0887A92444C}" = CCC Help Portuguese
"{7ACEF1BF-9306-5AD7-5F30-ECE72A81E924}" = CCC Help Finnish
"{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}" = Microsoft Games for Windows - LIVE Redistributable
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{887868A2-D6DE-3255-AA92-AA0B5A59B874}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{89EC099E-958D-462E-972C-385591946978}" = TurboTax 2012 WinPerFedFormset
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C1EC871-05B9-03B7-96F6-9BD5C0D8F41D}" = Catalyst Control Center Graphics Previews Common
"{A8B1F076-965D-4663-A9D4-C2FB58A42AE4}" = TurboTax 2012 WinPerTaxSupport
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.6)
"{AF9E97C1-7431-426D-A8D5-ABE40995C0B1}" = DirectX 9 Runtime
"{B14E295B-939D-4CE0-99CD-CB8C3B4FFF2E}" = TurboTax 2012 wmniper
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{C4129D57-5C83-3BF0-A11A-3798C008C6C7}" = CCC Help Greek
"{CAF5B770-082F-40C4-853D-3973BB81BDAA}" = TurboTax 2011 WinPerTaxSupport
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCE825DB-347A-4004-A186-5F4A6FDD8547}" = Apple Application Support
"{CFADE4AF-C0CF-4A04-A776-741318F1658F}" = Content Transfer
"{D0BC4101-6C30-ECFF-F693-63408134F29B}" = CCC Help Czech
"{D2402DAD-B180-A4A0-261D-4A8933BFBFEE}" = CCC Help Japanese
"{DA7E8D81-2B14-415B-8FC5-02CE4CF9F839}" = CCC Help Hungarian
"{DB3FBD3C-A061-34C9-0A2B-6CCDD8C96640}" = CCC Help Turkish
"{E086E914-2928-48F9-364B-0C715DFF6A45}" = CCC Help Korean
"{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}" = Catalyst Control Center - Branding
"{E463E171-4082-4744-A466-F7CBE8502789}" = TurboTax 2011 WinPerReleaseEngine
"{E60199E7-0EDB-889A-AA3D-661FFF28303A}" = Application Profiles
"{E83F5F27-43F3-4163-ABE5-F68C989286ED}" = TurboTax 2012 wrapper
"{E8F30BD6-ABAB-C24E-E9A7-BF67EB96152C}" = CCC Help Norwegian
"{E9A5B6CD-7ABB-F295-2E11-F25BC322FF80}" = CCC Help English
"{EA17F4FC-FDBF-4CF8-A529-2D983132D053}" = Skype™ 6.0
"{EB03EF39-C655-D560-FA95-79182B837D64}" =
"{EE556A3E-EB37-4392-9637-BAA8EC2F47FA}" = TurboTax 2011 wrapper
"{F014B696-28C5-4554-802F-A15380418F53}" = TurboTax 2012 WinPerReleaseEngine
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F8511A0F-D91D-4E3D-A59C-3CA8FB8EAFE8}" = MechWarrior Online
"{FAD3D68B-2F9C-459B-AA79-C04B9090FD72}" = TurboTax 2011 WinPerFedFormset
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Din's Curse Demo_is1" = Din's Curse Demo 1.022
"ffdshow_is1" = ffdshow v1.1.3800 [2011-03-28]
"InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"MagniDriver" = marvell 91xx driver
"N360" = Norton 360
"The Longest Journey Demo_is1" = The Longest Journey Demo, Build 161
"TurboTax 2011" = TurboTax 2011
"TurboTax 2012" = TurboTax 2012

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{74d11f91-05cc-44f6-8e49-94fe7f33c79b}" = MechWarrior Online
"Dropbox" = Dropbox

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 3/10/2013 1:27:21 PM | Computer Name = WinningOne-PC | Source = Microsoft-Windows-LoadPerf | ID = 3011
Description = Unloading the performance counter strings for service WmiApRpl (WmiApRpl)
failed. The first DWORD in the Data section contains the error code.

Error - 3/10/2013 2:56:41 PM | Computer Name = WinningOne-PC | Source = Microsoft-Windows-LoadPerf | ID = 3012
Description = The performance strings in the Performance registry value is corrupted
when process Performance extension counter provider. The BaseIndex value from the
Performance registry is the first DWORD in the Data section, LastCounter value
is the second DWORD in the Data section, and LastHelp value is the third DWORD in
the Data section.

Error - 3/10/2013 2:56:41 PM | Computer Name = WinningOne-PC | Source = Microsoft-Windows-LoadPerf | ID = 3011
Description = Unloading the performance counter strings for service WmiApRpl (WmiApRpl)
failed. The first DWORD in the Data section contains the error code.

Error - 3/10/2013 8:00:00 PM | Computer Name = WinningOne-PC | Source = Windows Backup | ID = 4103
Description =

Error - 3/15/2013 7:31:33 AM | Computer Name = WinningOne-PC | Source = Microsoft-Windows-LoadPerf | ID = 3012
Description = The performance strings in the Performance registry value is corrupted
when process Performance extension counter provider. The BaseIndex value from the
Performance registry is the first DWORD in the Data section, LastCounter value
is the second DWORD in the Data section, and LastHelp value is the third DWORD in
the Data section.

Error - 3/15/2013 7:31:33 AM | Computer Name = WinningOne-PC | Source = Microsoft-Windows-LoadPerf | ID = 3011
Description = Unloading the performance counter strings for service WmiApRpl (WmiApRpl)
failed. The first DWORD in the Data section contains the error code.

Error - 3/15/2013 11:14:42 AM | Computer Name = WinningOne-PC | Source = Microsoft-Windows-LoadPerf | ID = 3012
Description = The performance strings in the Performance registry value is corrupted
when process Performance extension counter provider. The BaseIndex value from the
Performance registry is the first DWORD in the Data section, LastCounter value
is the second DWORD in the Data section, and LastHelp value is the third DWORD in
the Data section.

Error - 3/15/2013 11:14:42 AM | Computer Name = WinningOne-PC | Source = Microsoft-Windows-LoadPerf | ID = 3011
Description = Unloading the performance counter strings for service WmiApRpl (WmiApRpl)
failed. The first DWORD in the Data section contains the error code.

Error - 3/16/2013 6:00:28 AM | Computer Name = WinningOne-PC | Source = Microsoft-Windows-LoadPerf | ID = 3012
Description = The performance strings in the Performance registry value is corrupted
when process Performance extension counter provider. The BaseIndex value from the
Performance registry is the first DWORD in the Data section, LastCounter value
is the second DWORD in the Data section, and LastHelp value is the third DWORD in
the Data section.

Error - 3/16/2013 6:00:28 AM | Computer Name = WinningOne-PC | Source = Microsoft-Windows-LoadPerf | ID = 3011
Description = Unloading the performance counter strings for service WmiApRpl (WmiApRpl)
failed. The first DWORD in the Data section contains the error code.

[ Media Center Events ]
Error - 5/26/2012 3:12:07 PM | Computer Name = WinningOne-PC | Source = MCUpdate | ID = 0
Description = 2:12:03 PM - Error connecting to the internet. 2:12:03 PM - Unable
to contact server..

Error - 5/26/2012 11:45:51 PM | Computer Name = WinningOne-PC | Source = MCUpdate | ID = 0
Description = 10:45:51 PM - Error connecting to the internet. 10:45:51 PM - Unable
to contact server..

Error - 6/13/2012 6:42:34 PM | Computer Name = WinningOne-PC | Source = MCUpdate | ID = 0
Description = 5:42:34 PM - Error connecting to the internet. 5:42:34 PM - Unable
to contact server..

Error - 6/13/2012 6:42:43 PM | Computer Name = WinningOne-PC | Source = MCUpdate | ID = 0
Description = 5:42:39 PM - Error connecting to the internet. 5:42:39 PM - Unable
to contact server..

Error - 6/13/2012 7:46:23 PM | Computer Name = WinningOne-PC | Source = MCUpdate | ID = 0
Description = 6:46:23 PM - Error connecting to the internet. 6:46:23 PM - Unable
to contact server..

Error - 6/13/2012 7:46:29 PM | Computer Name = WinningOne-PC | Source = MCUpdate | ID = 0
Description = 6:46:28 PM - Error connecting to the internet. 6:46:28 PM - Unable
to contact server..

Error - 6/13/2012 8:46:33 PM | Computer Name = WinningOne-PC | Source = MCUpdate | ID = 0
Description = 7:46:33 PM - Error connecting to the internet. 7:46:33 PM - Unable
to contact server..

Error - 6/13/2012 8:46:38 PM | Computer Name = WinningOne-PC | Source = MCUpdate | ID = 0
Description = 7:46:38 PM - Error connecting to the internet. 7:46:38 PM - Unable
to contact server..

Error - 6/13/2012 9:47:21 PM | Computer Name = WinningOne-PC | Source = MCUpdate | ID = 0
Description = 8:47:21 PM - Error connecting to the internet. 8:47:21 PM - Unable
to contact server..

Error - 6/13/2012 9:47:26 PM | Computer Name = WinningOne-PC | Source = MCUpdate | ID = 0
Description = 8:47:26 PM - Error connecting to the internet. 8:47:26 PM - Unable
to contact server..

[ System Events ]
Error - 3/10/2013 2:50:46 PM | Computer Name = WinningOne-PC | Source = Service Control Manager | ID = 7000
Description = The Htsysm service failed to start due to the following error: %%2

Error - 3/10/2013 3:10:45 PM | Computer Name = WinningOne-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Steam
Client Service service to connect.

Error - 3/10/2013 3:10:45 PM | Computer Name = WinningOne-PC | Source = Service Control Manager | ID = 7000
Description = The Steam Client Service service failed to start due to the following
error: %%1053

Error - 3/15/2013 7:25:35 AM | Computer Name = WinningOne-PC | Source = Service Control Manager | ID = 7000
Description = The Htsysm service failed to start due to the following error: %%2

Error - 3/15/2013 11:08:45 AM | Computer Name = WinningOne-PC | Source = Service Control Manager | ID = 7000
Description = The Htsysm service failed to start due to the following error: %%2

Error - 3/15/2013 11:10:12 AM | Computer Name = WinningOne-PC | Source = WMPNetworkSvc | ID = 866300
Description =

Error - 3/15/2013 11:38:38 AM | Computer Name = WinningOne-PC | Source = Service Control Manager | ID = 7000
Description = The Htsysm service failed to start due to the following error: %%2

Error - 3/15/2013 11:40:53 AM | Computer Name = WinningOne-PC | Source = DCOM | ID = 10016
Description =

Error - 3/15/2013 11:40:53 AM | Computer Name = WinningOne-PC | Source = DCOM | ID = 10016
Description =

Error - 3/16/2013 5:54:26 AM | Computer Name = WinningOne-PC | Source = Service Control Manager | ID = 7000
Description = The Htsysm service failed to start due to the following error: %%2


< End of report >
Please create a new system restore point before running Malwarebytes Anti-Rootkit if you can.

Download Malwarebytes Anti-Rootkit from HERE
  • Unzip the contents to a folder in a convenient location.
  • Open the folder where the contents were unzipped and run mbar.exe
  • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
  • Click on the Cleanup button to remove any threats and reboot if prompted to do so.
  • Wait while the system shuts down and the cleanup process is performed.
  • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
  • When done, please post the two logs produced they will be in the MBAR folder….. mbar-log.txt and system-log.txt

~~~~~~~~~~~~~~~~~~~~~~~

Note:
If no additional threats were found, verify that your system is now running normally, making sure that the following items are functional:
Internet access
Windows Update
Windows Firewall

If there are additional problems with your system, such as any of those listed above or other system issues, then run the fixdamage tool included with Malwarebytes Anti-Rootkit and reboot.
Verify that your system is now functioning normally.


MrC
Mr. C, I followed your directions and the second run of MB was clear. Since the slow internet connection persisted I also ran the repair tool but the issue remains unchanged. I have a second PC connected to this network and it is able to download at the speeds I am used to. This problematic PC is currently downloading at about 10% of normal. I have pasted the MB text files below. They are the files created by the second, uninfected, run of MB. Regards. ————————————— Malwarebytes Anti-Rootkit BETA 1.01.0.1021 © Malwarebytes Corporation 2011-2012 OS version: 6.1.7601 Windows 7 Service Pack 1 x64 Account is Administrative Internet Explorer version: 9.0.8112.16421 File system is: NTFS Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED CPU speed: 3.073000 GHz Memory total: 12875579392, free: 10835206144 ———— Kernel report ———— 03/16/2013 13:36:14 ———— Loaded modules ———– \SystemRoot\system32\ntoskrnl.exe \SystemRoot\system32\hal.dll \SystemRoot\system32\kdcom.dll \SystemRoot\system32\mcupdate_GenuineIntel.dll \SystemRoot\system32\PSHED.dll \SystemRoot\system32\CLFS.SYS \SystemRoot\system32\CI.dll \SystemRoot\system32\drivers\Wdf01000.sys \SystemRoot\system32\drivers\WDFLDR.SYS \SystemRoot\system32\drivers\ACPI.sys \SystemRoot\system32\drivers\WMILIB.SYS \SystemRoot\system32\drivers\msisadrv.sys \SystemRoot\system32\drivers\pci.sys \SystemRoot\system32\drivers\vdrvroot.sys \SystemRoot\System32\drivers\partmgr.sys \SystemRoot\system32\drivers\volmgr.sys \SystemRoot\System32\drivers\volmgrx.sys \SystemRoot\system32\drivers\pciide.sys \SystemRoot\system32\drivers\PCIIDEX.SYS \SystemRoot\system32\DRIVERS\jraid.sys \SystemRoot\system32\DRIVERS\SCSIPORT.SYS \SystemRoot\system32\DRIVERS\mv91cons.sys \SystemRoot\System32\drivers\mountmgr.sys \SystemRoot\system32\DRIVERS\iaStor.sys \SystemRoot\system32\drivers\iaStorV.sys \SystemRoot\system32\drivers\atapi.sys \SystemRoot\system32\drivers\ataport.SYS \SystemRoot\system32\DRIVERS\mv91xx.sys \SystemRoot\system32\DRIVERS\mvxxmm.sys \SystemRoot\system32\drivers\amdxata.sys \SystemRoot\system32\drivers\fltmgr.sys \SystemRoot\system32\drivers\N360x64\1403000.024\SYMDS64.SYS \SystemRoot\system32\drivers\fileinfo.sys \SystemRoot\system32\drivers\N360x64\1403000.024\SYMEFA64.SYS \SystemRoot\System32\Drivers\PxHlpa64.sys \SystemRoot\System32\Drivers\Ntfs.sys \SystemRoot\System32\Drivers\msrpc.sys \SystemRoot\System32\Drivers\ksecdd.sys \SystemRoot\System32\Drivers\cng.sys \SystemRoot\System32\drivers\pcw.sys \SystemRoot\System32\Drivers\Fs_Rec.sys \SystemRoot\system32\drivers\ndis.sys \SystemRoot\system32\drivers\NETIO.SYS \SystemRoot\System32\Drivers\ksecpkg.sys \SystemRoot\System32\drivers\tcpip.sys \SystemRoot\System32\drivers\fwpkclnt.sys \SystemRoot\system32\drivers\volsnap.sys \SystemRoot\System32\Drivers\spldr.sys \SystemRoot\System32\drivers\rdyboost.sys \SystemRoot\System32\Drivers\mup.sys \SystemRoot\System32\drivers\hwpolicy.sys \SystemRoot\System32\DRIVERS\fvevol.sys \SystemRoot\system32\DRIVERS\disk.sys \SystemRoot\system32\DRIVERS\CLASSPNP.SYS \SystemRoot\System32\Drivers\dump_mvxxmm.sys \SystemRoot\system32\DRIVERS\cdrom.sys \SystemRoot\system32\drivers\N360x64\1403000.024\ccSetx64.sys \SystemRoot\system32\drivers\N360x64\1403000.024\Ironx64.SYS \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \SystemRoot\System32\drivers\vga.sys \SystemRoot\System32\drivers\VIDEOPRT.SYS \SystemRoot\System32\drivers\watchdog.sys \SystemRoot\System32\DRIVERS\RDPCDD.sys \SystemRoot\system32\drivers\rdpencdd.sys \SystemRoot\system32\drivers\rdprefmp.sys \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\system32\DRIVERS\tdx.sys \SystemRoot\system32\DRIVERS\TDI.SYS \SystemRoot\system32\drivers\afd.sys \SystemRoot\System32\DRIVERS\netbt.sys \SystemRoot\system32\drivers\ws2ifsl.sys \SystemRoot\system32\DRIVERS\wfplwf.sys \SystemRoot\system32\DRIVERS\pacer.sys \SystemRoot\system32\DRIVERS\nm3.sys \SystemRoot\system32\DRIVERS\netbios.sys \SystemRoot\system32\DRIVERS\serial.sys \SystemRoot\system32\DRIVERS\wanarp.sys \SystemRoot\system32\drivers\termdd.sys \SystemRoot\system32\drivers\N360x64\1403000.024\SYMNETS.SYS \??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS \SystemRoot\system32\drivers\N360x64\1403000.024\SRTSPX64.SYS \SystemRoot\system32\DRIVERS\rdbss.sys \SystemRoot\system32\drivers\nsiproxy.sys \SystemRoot\system32\drivers\mssmbios.sys \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\IPSDefs\20130313.001\IDSvia64.sys \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys \SystemRoot\System32\drivers\discache.sys \SystemRoot\System32\Drivers\dfsc.sys \SystemRoot\system32\DRIVERS\blbdrive.sys \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\BASHDefs\20130301.001\BHDrvx64.sys \SystemRoot\system32\DRIVERS\tunnel.sys \SystemRoot\system32\DRIVERS\intelppm.sys \SystemRoot\system32\DRIVERS\nusb3xhc.sys \SystemRoot\system32\DRIVERS\USBD.SYS \SystemRoot\system32\DRIVERS\atikmpag.sys \SystemRoot\system32\DRIVERS\atikmdag.sys \SystemRoot\System32\drivers\dxgkrnl.sys \SystemRoot\System32\drivers\dxgmms1.sys \SystemRoot\system32\drivers\HDAudBus.sys \SystemRoot\system32\DRIVERS\usbuhci.sys \SystemRoot\system32\DRIVERS\USBPORT.SYS \SystemRoot\system32\DRIVERS\usbehci.sys \SystemRoot\system32\DRIVERS\Rt64win7.sys \SystemRoot\system32\drivers\1394ohci.sys \SystemRoot\system32\DRIVERS\ASACPI.sys \SystemRoot\system32\DRIVERS\serenum.sys \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys \SystemRoot\system32\drivers\wmiacpi.sys \SystemRoot\system32\drivers\CompositeBus.sys \SystemRoot\system32\DRIVERS\AgileVpn.sys \SystemRoot\system32\DRIVERS\rasl2tp.sys \SystemRoot\system32\DRIVERS\ndistapi.sys \SystemRoot\system32\DRIVERS\ndiswan.sys \SystemRoot\system32\DRIVERS\raspppoe.sys \SystemRoot\system32\DRIVERS\raspptp.sys \SystemRoot\system32\DRIVERS\rassstp.sys \SystemRoot\system32\DRIVERS\kbdclass.sys \SystemRoot\system32\DRIVERS\mouclass.sys \SystemRoot\system32\drivers\swenum.sys \SystemRoot\system32\drivers\ks.sys \SystemRoot\system32\drivers\umbus.sys \SystemRoot\system32\DRIVERS\nusb3hub.sys \SystemRoot\system32\DRIVERS\usbhub.sys \SystemRoot\System32\Drivers\NDProxy.SYS \SystemRoot\system32\drivers\AtihdW76.sys \SystemRoot\system32\drivers\portcls.sys \SystemRoot\system32\drivers\drmk.sys \SystemRoot\system32\drivers\ksthunk.sys \SystemRoot\system32\drivers\HdAudio.sys \SystemRoot\system32\DRIVERS\usbccgp.sys \SystemRoot\system32\DRIVERS\hidusb.sys \SystemRoot\system32\DRIVERS\HIDCLASS.SYS \SystemRoot\system32\DRIVERS\HIDPARSE.SYS \SystemRoot\system32\DRIVERS\kbdhid.sys \SystemRoot\system32\DRIVERS\RzSynapse.sys \SystemRoot\system32\DRIVERS\mouhid.sys \SystemRoot\System32\Drivers\crashdmp.sys \SystemRoot\System32\Drivers\dump_diskdump.sys \SystemRoot\System32\Drivers\dump_mv91xx.sys \SystemRoot\System32\Drivers\dump_dumpfve.sys \SystemRoot\System32\win32k.sys \SystemRoot\System32\drivers\Dxapi.sys \SystemRoot\system32\DRIVERS\USBSTOR.SYS \SystemRoot\system32\DRIVERS\rzudd.sys \SystemRoot\system32\DRIVERS\monitor.sys \SystemRoot\System32\TSDDD.dll \SystemRoot\System32\cdd.dll \SystemRoot\system32\drivers\luafv.sys \SystemRoot\system32\DRIVERS\lltdio.sys \SystemRoot\system32\DRIVERS\rspndr.sys \SystemRoot\system32\DRIVERS\TurboB.sys \SystemRoot\System32\Drivers\fastfat.SYS \SystemRoot\system32\drivers\HTTP.sys \SystemRoot\system32\DRIVERS\bowser.sys \SystemRoot\System32\drivers\mpsdrv.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\system32\DRIVERS\mrxsmb10.sys \SystemRoot\system32\DRIVERS\mrxsmb20.sys \SystemRoot\system32\drivers\peauth.sys \SystemRoot\System32\Drivers\secdrv.SYS \SystemRoot\System32\DRIVERS\srvnet.sys \SystemRoot\System32\drivers\tcpipreg.sys \SystemRoot\System32\DRIVERS\srv2.sys \SystemRoot\System32\DRIVERS\srv.sys \SystemRoot\system32\drivers\WudfPf.sys \SystemRoot\system32\DRIVERS\WUDFRd.sys \SystemRoot\system32\drivers\N360x64\1403000.024\SRTSP64.SYS \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130315.025\EX64.SYS \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130315.025\ENG64.SYS \SystemRoot\system32\drivers\spsys.sys \??\C:\Windows\system32\drivers\mbamchameleon.sys \??\C:\Windows\system32\drivers\mbamswissarmy.sys \Windows\System32\ntdll.dll \Windows\System32\smss.exe \Windows\System32\apisetschema.dll \Windows\System32\autochk.exe \Windows\System32\Wldap32.dll \Windows\System32\normaliz.dll \Windows\System32\shell32.dll \Windows\System32\lpk.dll \Windows\System32\gdi32.dll \Windows\System32\sechost.dll \Windows\System32\clbcatq.dll \Windows\System32\advapi32.dll \Windows\System32\imagehlp.dll \Windows\System32\urlmon.dll \Windows\System32\msvcrt.dll \Windows\System32\ole32.dll \Windows\System32\msctf.dll \Windows\System32\imm32.dll \Windows\System32\nsi.dll \Windows\System32\oleaut32.dll \Windows\System32\user32.dll \Windows\System32\setupapi.dll \Windows\System32\usp10.dll \Windows\System32\iertutil.dll \Windows\System32\wininet.dll \Windows\System32\ws2_32.dll \Windows\System32\psapi.dll \Windows\System32\rpcrt4.dll \Windows\System32\kernel32.dll \Windows\System32\comdlg32.dll \Windows\System32\shlwapi.dll \Windows\System32\difxapi.dll \Windows\System32\wintrust.dll \Windows\System32\devobj.dll \Windows\System32\KernelBase.dll \Windows\System32\cfgmgr32.dll \Windows\System32\comctl32.dll \Windows\System32\crypt32.dll \Windows\System32\msasn1.dll \Windows\SysWOW64\normaliz.dll ———– End ———– <<<1>>> Upper Device Name: \Device\Harddisk1\DR1 Upper Device Object: 0xfffffa800d564060 Upper Device Driver Name: \Driver\Disk\ Lower Device Name: \Device\00000094\ Lower Device Object: 0xfffffa800e503b60 Lower Device Driver Name: \Driver\USBSTOR\ Driver name found: USBSTOR Initialization returned 0x0 Load Function returned 0x0 <<<1>>> Upper Device Name: \Device\Harddisk0\DR0 Upper Device Object: 0xfffffa800ae77790 Upper Device Driver Name: \Driver\Disk\ Lower Device Name: \Device\Scsi\mv91xx1Port2Path0Target0Lun0\ Lower Device Object: 0xfffffa800ab75050 Lower Device Driver Name: \Driver\mv91xx\ Driver name found: mv91xx Initialization returned 0x0 Port sub-driver loaded: \??\C:\Windows\System32\drivers\scsiport.sys (0x0) Load Function returned 0x0 Downloaded database version: v2013.03.16.09 Initializing… Done! <<<2>>> Device number: 0, partition: 2 Physical Sector Size: 512 Drive: 0, DevicePointer: 0xfffffa800ae77790, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ ——— Disk Stack —— DevicePointer: 0xfffffa800ae772c0, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xfffffa800ae77790, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ DevicePointer: 0xfffffa800ab75050, DeviceName: \Device\Scsi\mv91xx1Port2Path0Target0Lun0\, DriverName: \Driver\mv91xx\ ———— End ———- Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ Upper DeviceData: 0xfffff8a00fac0070, 0xfffffa800ae77790, 0xfffffa800a2c3790 Lower DeviceData: 0xfffff8a010c4bc00, 0xfffffa800ab75050, 0xfffffa800ec65e40 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning directory: C:\Windows\system32\drivers… <<<2>>> Device number: 0, partition: 2 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Done! Drive 0 Scanning MBR on drive 0… Inspecting partition table: MBR Signature: 55AA Disk Signature: 93871B88 Partition information: Partition 0 type is Primary (0x7) Partition is ACTIVE. Partition starts at LBA: 2048 Numsec = 1024000 Partition file system is NTFS Partition is bootable Partition 1 type is Extended with LBA (0xf) Partition is NOT ACTIVE. Partition starts at LBA: 1026048 Numsec = 83886080 Partition 2 type is Primary (0x7) Partition is NOT ACTIVE. Partition starts at LBA: 84912128 Numsec = 1868609536 Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Disk Size: 1000204886016 bytes Sector size: 512 bytes Scanning physical sectors of unpartitioned space on drive 0 (1-2047-1953505168-1953525168)… Physical Sector Size: 512 Drive: 1, DevicePointer: 0xfffffa800d564060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\ ——— Disk Stack —— DevicePointer: 0xfffffa800e440b90, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xfffffa800d564060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\ DevicePointer: 0xfffffa800e503b60, DeviceName: \Device\00000094\, DriverName: \Driver\USBSTOR\ ———— End ———- Alternate DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\ Upper DeviceData: 0xfffff8a00f3c57c0, 0xfffffa800d564060, 0xfffffa800a1f5090 Lower DeviceData: 0xfffff8a00f44f5f0, 0xfffffa800e503b60, 0xfffffa800a2d3090 Drive 1 Scanning MBR on drive 1… Inspecting partition table: MBR Signature: 55AA Disk Signature: C3072E18 Partition information: Partition 0 type is Other (0xc) Partition is ACTIVE. Partition starts at LBA: 32 Numsec = 15384544 Partition file system is FAT32 Partition is not bootable Partition 1 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 2 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Disk Size: 7876902912 bytes Sector size: 512 bytes Done! Performing system, memory and registry scan… Infected: c:\Users\WinningOne\AppData\Local\Temp\services.exe.mui –> [Heuristics.Reserved.Word.Exploit] Infected: c:\Users\WinningOne\AppData\Local\Temp\explorer.exe.mui –> [Heuristics.Reserved.Word.Exploit] Done! Scan finished Creating System Restore point… Scheduling clean up… <<<2>>> Device number: 0, partition: 2 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Removal scheduling successful. System shutdown needed. System shutdown occurred ======================================= ————————————— Malwarebytes Anti-Rootkit BETA 1.01.0.1021 © Malwarebytes Corporation 2011-2012 OS version: 6.1.7601 Windows 7 Service Pack 1 x64 Account is Administrative Internet Explorer version: 9.0.8112.16421 File system is: NTFS Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED CPU speed: 3.073000 GHz Memory total: 12875579392, free: 11222978560 Removal queue found; removal started Removing c:\Users\WinningOne\AppData\Local\Temp\services.exe.mui… Removing c:\Users\WinningOne\AppData\Local\Temp\explorer.exe.mui… Removal finished ======================================= ————————————— Malwarebytes Anti-Rootkit BETA 1.01.0.1021 © Malwarebytes Corporation 2011-2012 OS version: 6.1.7601 Windows 7 Service Pack 1 x64 Account is Administrative Internet Explorer version: 9.0.8112.16421 File system is: NTFS Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED CPU speed: 3.073000 GHz Memory total: 12875579392, free: 10747236352 ———— Kernel report ———— 03/16/2013 13:53:15 ———— Loaded modules ———– \SystemRoot\system32\ntoskrnl.exe \SystemRoot\system32\hal.dll \SystemRoot\system32\kdcom.dll \SystemRoot\system32\mcupdate_GenuineIntel.dll \SystemRoot\system32\PSHED.dll \SystemRoot\system32\CLFS.SYS \SystemRoot\system32\CI.dll \SystemRoot\system32\drivers\Wdf01000.sys \SystemRoot\system32\drivers\WDFLDR.SYS \SystemRoot\system32\drivers\ACPI.sys \SystemRoot\system32\drivers\WMILIB.SYS \SystemRoot\system32\drivers\msisadrv.sys \SystemRoot\system32\drivers\pci.sys \SystemRoot\system32\drivers\vdrvroot.sys \SystemRoot\System32\drivers\partmgr.sys \SystemRoot\system32\drivers\volmgr.sys \SystemRoot\System32\drivers\volmgrx.sys \SystemRoot\system32\drivers\pciide.sys \SystemRoot\system32\drivers\PCIIDEX.SYS \SystemRoot\system32\DRIVERS\jraid.sys \SystemRoot\system32\DRIVERS\SCSIPORT.SYS \SystemRoot\system32\DRIVERS\mv91cons.sys \SystemRoot\System32\drivers\mountmgr.sys \SystemRoot\system32\DRIVERS\iaStor.sys \SystemRoot\system32\drivers\iaStorV.sys \SystemRoot\system32\drivers\atapi.sys \SystemRoot\system32\drivers\ataport.SYS \SystemRoot\system32\DRIVERS\mv91xx.sys \SystemRoot\system32\DRIVERS\mvxxmm.sys \SystemRoot\system32\drivers\amdxata.sys \SystemRoot\system32\drivers\fltmgr.sys \SystemRoot\system32\drivers\N360x64\1403000.024\SYMDS64.SYS \SystemRoot\system32\drivers\fileinfo.sys \SystemRoot\system32\drivers\N360x64\1403000.024\SYMEFA64.SYS \SystemRoot\System32\Drivers\PxHlpa64.sys \SystemRoot\System32\Drivers\Ntfs.sys \SystemRoot\System32\Drivers\msrpc.sys \SystemRoot\System32\Drivers\ksecdd.sys \SystemRoot\System32\Drivers\cng.sys \SystemRoot\System32\drivers\pcw.sys \SystemRoot\System32\Drivers\Fs_Rec.sys \SystemRoot\system32\drivers\ndis.sys \SystemRoot\system32\drivers\NETIO.SYS \SystemRoot\System32\Drivers\ksecpkg.sys \SystemRoot\System32\drivers\tcpip.sys \SystemRoot\System32\drivers\fwpkclnt.sys \SystemRoot\system32\drivers\volsnap.sys \SystemRoot\System32\Drivers\spldr.sys \SystemRoot\System32\drivers\rdyboost.sys \SystemRoot\System32\Drivers\mup.sys \SystemRoot\System32\drivers\hwpolicy.sys \SystemRoot\System32\DRIVERS\fvevol.sys \SystemRoot\system32\DRIVERS\disk.sys \SystemRoot\system32\DRIVERS\CLASSPNP.SYS \SystemRoot\System32\Drivers\dump_mvxxmm.sys \SystemRoot\system32\DRIVERS\cdrom.sys \SystemRoot\system32\drivers\N360x64\1403000.024\ccSetx64.sys \SystemRoot\system32\drivers\N360x64\1403000.024\Ironx64.SYS \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \SystemRoot\System32\drivers\vga.sys \SystemRoot\System32\drivers\VIDEOPRT.SYS \SystemRoot\System32\drivers\watchdog.sys \SystemRoot\System32\DRIVERS\RDPCDD.sys \SystemRoot\system32\drivers\rdpencdd.sys \SystemRoot\system32\drivers\rdprefmp.sys \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\system32\DRIVERS\tdx.sys \SystemRoot\system32\DRIVERS\TDI.SYS \SystemRoot\system32\drivers\afd.sys \SystemRoot\System32\DRIVERS\netbt.sys \SystemRoot\system32\drivers\ws2ifsl.sys \SystemRoot\system32\DRIVERS\wfplwf.sys \SystemRoot\system32\DRIVERS\pacer.sys \SystemRoot\system32\DRIVERS\nm3.sys \SystemRoot\system32\DRIVERS\netbios.sys \SystemRoot\system32\DRIVERS\serial.sys \SystemRoot\system32\DRIVERS\wanarp.sys \SystemRoot\system32\drivers\termdd.sys \SystemRoot\system32\drivers\N360x64\1403000.024\SYMNETS.SYS \??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS \SystemRoot\system32\drivers\N360x64\1403000.024\SRTSPX64.SYS \SystemRoot\system32\DRIVERS\rdbss.sys \SystemRoot\system32\drivers\nsiproxy.sys \SystemRoot\system32\drivers\mssmbios.sys \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\IPSDefs\20130313.001\IDSvia64.sys \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys \SystemRoot\System32\drivers\discache.sys \SystemRoot\System32\Drivers\dfsc.sys \SystemRoot\system32\DRIVERS\blbdrive.sys \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\BASHDefs\20130301.001\BHDrvx64.sys \SystemRoot\system32\DRIVERS\tunnel.sys \SystemRoot\system32\DRIVERS\intelppm.sys \SystemRoot\system32\DRIVERS\nusb3xhc.sys \SystemRoot\system32\DRIVERS\USBD.SYS \SystemRoot\system32\DRIVERS\atikmpag.sys \SystemRoot\system32\DRIVERS\atikmdag.sys \SystemRoot\System32\drivers\dxgkrnl.sys \SystemRoot\System32\drivers\dxgmms1.sys \SystemRoot\system32\drivers\HDAudBus.sys \SystemRoot\system32\DRIVERS\usbuhci.sys \SystemRoot\system32\DRIVERS\USBPORT.SYS \SystemRoot\system32\DRIVERS\usbehci.sys \SystemRoot\system32\DRIVERS\Rt64win7.sys \SystemRoot\system32\drivers\1394ohci.sys \SystemRoot\system32\DRIVERS\ASACPI.sys \SystemRoot\system32\DRIVERS\serenum.sys \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys \SystemRoot\system32\drivers\wmiacpi.sys \SystemRoot\system32\drivers\CompositeBus.sys \SystemRoot\system32\DRIVERS\AgileVpn.sys \SystemRoot\system32\DRIVERS\rasl2tp.sys \SystemRoot\system32\DRIVERS\ndistapi.sys \SystemRoot\system32\DRIVERS\ndiswan.sys \SystemRoot\system32\DRIVERS\raspppoe.sys \SystemRoot\system32\DRIVERS\raspptp.sys \SystemRoot\system32\DRIVERS\rassstp.sys \SystemRoot\system32\DRIVERS\kbdclass.sys \SystemRoot\system32\DRIVERS\mouclass.sys \SystemRoot\system32\drivers\swenum.sys \SystemRoot\system32\drivers\ks.sys \SystemRoot\system32\drivers\umbus.sys \SystemRoot\system32\DRIVERS\nusb3hub.sys \SystemRoot\system32\DRIVERS\usbhub.sys \SystemRoot\System32\Drivers\NDProxy.SYS \SystemRoot\system32\drivers\AtihdW76.sys \SystemRoot\system32\drivers\portcls.sys \SystemRoot\system32\drivers\drmk.sys \SystemRoot\system32\drivers\ksthunk.sys \SystemRoot\system32\drivers\HdAudio.sys \SystemRoot\system32\DRIVERS\usbccgp.sys \SystemRoot\system32\DRIVERS\hidusb.sys \SystemRoot\system32\DRIVERS\HIDCLASS.SYS \SystemRoot\system32\DRIVERS\HIDPARSE.SYS \SystemRoot\system32\DRIVERS\kbdhid.sys \SystemRoot\system32\DRIVERS\RzSynapse.sys \SystemRoot\system32\DRIVERS\mouhid.sys \SystemRoot\System32\win32k.sys \SystemRoot\System32\drivers\Dxapi.sys \SystemRoot\System32\Drivers\crashdmp.sys \SystemRoot\System32\Drivers\dump_diskdump.sys \SystemRoot\System32\Drivers\dump_mv91xx.sys \SystemRoot\System32\Drivers\dump_dumpfve.sys \SystemRoot\system32\DRIVERS\rzudd.sys \SystemRoot\system32\DRIVERS\USBSTOR.SYS \SystemRoot\system32\DRIVERS\monitor.sys \SystemRoot\System32\TSDDD.dll \SystemRoot\System32\cdd.dll \SystemRoot\system32\drivers\luafv.sys \SystemRoot\system32\DRIVERS\lltdio.sys \SystemRoot\system32\DRIVERS\rspndr.sys \SystemRoot\system32\DRIVERS\TurboB.sys \SystemRoot\System32\Drivers\fastfat.SYS \SystemRoot\system32\drivers\HTTP.sys \SystemRoot\system32\DRIVERS\bowser.sys \SystemRoot\System32\drivers\mpsdrv.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\system32\DRIVERS\mrxsmb10.sys \SystemRoot\system32\DRIVERS\mrxsmb20.sys \SystemRoot\system32\drivers\peauth.sys \SystemRoot\System32\Drivers\secdrv.SYS \SystemRoot\System32\DRIVERS\srvnet.sys \SystemRoot\System32\drivers\tcpipreg.sys \SystemRoot\System32\DRIVERS\srv2.sys \SystemRoot\System32\DRIVERS\srv.sys \SystemRoot\system32\drivers\WudfPf.sys \SystemRoot\system32\DRIVERS\WUDFRd.sys \SystemRoot\system32\drivers\N360x64\1403000.024\SRTSP64.SYS \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130315.025\EX64.SYS \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130315.025\ENG64.SYS \SystemRoot\system32\drivers\spsys.sys \??\C:\Windows\system32\drivers\mbamchameleon.sys \??\C:\Windows\system32\drivers\mbamswissarmy.sys \Windows\System32\ntdll.dll \Windows\System32\smss.exe \Windows\System32\apisetschema.dll \Windows\System32\autochk.exe \Windows\System32\sechost.dll \Windows\System32\gdi32.dll \Windows\System32\lpk.dll \Windows\System32\comdlg32.dll \Windows\System32\urlmon.dll \Windows\System32\user32.dll \Windows\System32\nsi.dll \Windows\System32\psapi.dll \Windows\System32\shlwapi.dll \Windows\System32\iertutil.dll \Windows\System32\ws2_32.dll \Windows\System32\imm32.dll \Windows\System32\clbcatq.dll \Windows\System32\shell32.dll \Windows\System32\wininet.dll \Windows\System32\usp10.dll \Windows\System32\msctf.dll \Windows\System32\oleaut32.dll \Windows\System32\imagehlp.dll \Windows\System32\normaliz.dll \Windows\System32\ole32.dll \Windows\System32\msvcrt.dll \Windows\System32\Wldap32.dll \Windows\System32\advapi32.dll \Windows\System32\kernel32.dll \Windows\System32\setupapi.dll \Windows\System32\difxapi.dll \Windows\System32\rpcrt4.dll \Windows\System32\KernelBase.dll \Windows\System32\comctl32.dll \Windows\System32\devobj.dll \Windows\System32\cfgmgr32.dll \Windows\System32\wintrust.dll \Windows\System32\crypt32.dll \Windows\System32\msasn1.dll \Windows\SysWOW64\normaliz.dll ———– End ———– <<<1>>> Upper Device Name: \Device\Harddisk1\DR1 Upper Device Object: 0xfffffa800eacc060 Upper Device Driver Name: \Driver\Disk\ Lower Device Name: \Device\0000009a\ Lower Device Object: 0xfffffa800e753a20 Lower Device Driver Name: \Driver\USBSTOR\ Driver name found: USBSTOR Initialization returned 0x0 Load Function returned 0x0 <<<1>>> Upper Device Name: \Device\Harddisk0\DR0 Upper Device Object: 0xfffffa800ae79790 Upper Device Driver Name: \Driver\Disk\ Lower Device Name: \Device\Scsi\mv91xx1Port2Path0Target0Lun0\ Lower Device Object: 0xfffffa800ab5b050 Lower Device Driver Name: \Driver\mv91xx\ Driver name found: mv91xx Initialization returned 0x0 Port sub-driver loaded: \??\C:\Windows\System32\drivers\scsiport.sys (0x0) Load Function returned 0x0 Initializing… Done! <<<2>>> Device number: 0, partition: 2 Physical Sector Size: 512 Drive: 0, DevicePointer: 0xfffffa800ae79790, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ ——— Disk Stack —— DevicePointer: 0xfffffa800ae792c0, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xfffffa800ae79790, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ DevicePointer: 0xfffffa800ab5b050, DeviceName: \Device\Scsi\mv91xx1Port2Path0Target0Lun0\, DriverName: \Driver\mv91xx\ ———— End ———- Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ Upper DeviceData: 0xfffff8a00e761260, 0xfffffa800ae79790, 0xfffffa8009f81790 Lower DeviceData: 0xfffff8a0105ec9c0, 0xfffffa800ab5b050, 0xfffffa800cde7e40 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning directory: C:\Windows\system32\drivers… <<<2>>> Device number: 0, partition: 2 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Done! Drive 0 Scanning MBR on drive 0… Inspecting partition table: MBR Signature: 55AA Disk Signature: 93871B88 Partition information: Partition 0 type is Primary (0x7) Partition is ACTIVE. Partition starts at LBA: 2048 Numsec = 1024000 Partition file system is NTFS Partition is bootable Partition 1 type is Extended with LBA (0xf) Partition is NOT ACTIVE. Partition starts at LBA: 1026048 Numsec = 83886080 Partition 2 type is Primary (0x7) Partition is NOT ACTIVE. Partition starts at LBA: 84912128 Numsec = 1868609536 Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Disk Size: 1000204886016 bytes Sector size: 512 bytes Scanning physical sectors of unpartitioned space on drive 0 (1-2047-1953505168-1953525168)… Physical Sector Size: 512 Drive: 1, DevicePointer: 0xfffffa800eacc060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\ ——— Disk Stack —— DevicePointer: 0xfffffa800e751850, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xfffffa800eacc060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\ DevicePointer: 0xfffffa800e753a20, DeviceName: \Device\0000009a\, DriverName: \Driver\USBSTOR\ ———— End ———- Alternate DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\ Upper DeviceData: 0xfffff8a0115337e0, 0xfffffa800eacc060, 0xfffffa800a56d310 Lower DeviceData: 0xfffff8a011569580, 0xfffffa800e753a20, 0xfffffa800a7e4930 Drive 1 Scanning MBR on drive 1… Inspecting partition table: MBR Signature: 55AA Disk Signature: C3072E18 Partition information: Partition 0 type is Other (0xc) Partition is ACTIVE. Partition starts at LBA: 32 Numsec = 15384544 Partition file system is FAT32 Partition is not bootable Partition 1 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 2 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Disk Size: 7876902912 bytes Sector size: 512 bytes Done! Performing system, memory and registry scan… Done! Scan finished ======================================= ————————————— Malwarebytes Anti-Rootkit BETA 1.01.0.1021 © Malwarebytes Corporation 2011-2012 OS version: 6.1.7601 Windows 7 Service Pack 1 x64 Account is Administrative Internet Explorer version: 9.0.8112.16421 File system is: NTFS Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED CPU speed: 3.073000 GHz Memory total: 12875579392, free: 11276206080 ======================================= Malwarebytes Anti-Rootkit BETA 1.01.0.1021 www.malwarebytes.org Database version: v2013.03.16.09 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 WinningOne :: WINNINGONE-PC [administrator] 3/16/2013 2:01:39 PM mbar-log-2013-03-16 (14-01-39).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P Scan options disabled: Objects scanned: 29867 Time elapsed: 8 minute(s), 12 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
Please download and run ComboFix.

The most important things to remember when running it is to disable all your malware programs and run Combofix from your desktop.

Please visit this webpage for download links, and instructions for running ComboFix

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Information on disabling your malware programs can be found Here.

Make sure you run ComboFix from your desktop.

Give it at least 30-45 minutes to finish if needed.

Please include the C:\ComboFix.txt in your next reply for further review.

———->NOTE<———-

If you get the message Illegal operation attempted on registry key that has been marked for deletion after you run ComboFix….please reboot the computer, this should resolve the problem. You may have to do this several times if needed.

MrC
Mr. C, I ran ComboFix succesfully and have a log. However, I have tried posting the text 7 times and the connection has timed out each time. Is ther another way to get the log file to you?
How is it???

———————————

Please download AdwCleaner from here and save it on your Desktop.

AdwCleaner is a reliable removal tool for Adware, Foistware, toolbars and potentially unwanted programs.

AdwCleaner is a tool that deletes :
· Adwares (software ads)
· PUP/LPI (Potentially Undesirable Program)
· Toolbars
· Hijacker (Hijack of the browser's homepage)

It works with a Search and Deletion methode. It can be easily uninstalled using the "Uninstall" mode.


  • Right-click on adwcleaner.exe and select Run As Administrator (for XP just double click) to launch the application.
  • Now click on the Search tab.
  • Please post the contents of the log-file created in your next post.

Note: The log can also be located at C:\ >> AdwCleaner[XX].txt >> XX <– Denotes the number of times the application has been ran, so in this should be something like R1.

Note:
Please look over what was found……especially any folders, we're going to permanently delete it all in the next step….if there's something you may want to keep…please let me know and I'll explain to why it shouldn't be on your system.
If you see AVG Secure Search being targeted for deletion, Here's Why and Here. You can always Reinstall it.

MrC
Here are the results of the AdwCleaner. My internet connection is still running at around 200 K/s. # AdwCleaner v2.115 - Logfile created 03/17/2013 at 23:19:41 # Updated 17/03/2013 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : WinningOne - WINNINGONE-PC # Boot Mode : Normal # Running from : C:\Users\WinningOne\Desktop\adwcleaner.exe # Option [Search] ***** [Services] ***** ***** [Files / Folders] ***** Folder Found : C:\Program Files (x86)\Red Sky Folder Found : C:\ProgramData\clsoft ltd Folder Found : C:\ProgramData\InstallMate Folder Found : C:\ProgramData\Premium Folder Found : C:\Users\WinningOne\AppData\Local\SwvUpdater ***** [Registry] ***** Key Found : HKCU\Software\AppDataLow\SProtector Key Found : HKCU\Software\Conduit Key Found : HKCU\Software\ilivid Key Found : HKCU\Software\StartSearch Key Found : HKLM\SOFTWARE\Classes\Applications\ilividsetup.exe Key Found : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe Key Found : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755} Key Found : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASMANCS Key Found : HKLM\Software\SP Global Key Found : HKLM\Software\SProtector Key Found : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67} ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16470 [OK] Registry is clean. -\\ Chromium v directory_upgrade: true } File : C:\Users\WinningOne\AppData\Local\Chromium\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[R1].txt - [1583 octets] - [17/03/2013 23:19:41] ########## EOF - C:\AdwCleaner[R1].txt - [1643 octets] ##########
Please create a new system restore point before continuing.

Lots of adware found….lets clear it out…..
  • Please re-run AdwCleaner
  • Click on Delete button.
  • Confirm each time with OK if asked.
  • Your computer will be rebooted automatically. A text file will open after the restart. Please post the content of that logfile in your reply.

Note: You can find the logfile at C:\AdwCleaner[Sn].txt as well - n is the order number.

MrC
Mr. C. Here is the log file from AdwCleaner after the delete. Still no improvement on the internet connection but the PC itself seems to be running faster. # AdwCleaner v2.115 - Logfile created 03/18/2013 at 10:54:04 # Updated 17/03/2013 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : WinningOne - WINNINGONE-PC # Boot Mode : Normal # Running from : C:\Users\WinningOne\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** Folder Deleted : C:\Program Files (x86)\Red Sky Folder Deleted : C:\ProgramData\clsoft ltd Folder Deleted : C:\ProgramData\InstallMate Folder Deleted : C:\ProgramData\Premium Folder Deleted : C:\Users\WinningOne\AppData\Local\SwvUpdater ***** [Registry] ***** Key Deleted : HKCU\Software\AppDataLow\SProtector Key Deleted : HKCU\Software\Conduit Key Deleted : HKCU\Software\ilivid Key Deleted : HKCU\Software\StartSearch Key Deleted : HKLM\SOFTWARE\Classes\Applications\ilividsetup.exe Key Deleted : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755} Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASMANCS Key Deleted : HKLM\Software\SP Global Key Deleted : HKLM\Software\SProtector Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67} ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16470 [OK] Registry is clean. -\\ Chromium v directory_upgrade: true } File : C:\Users\WinningOne\AppData\Local\Chromium\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[R1].txt - [1710 octets] - [17/03/2013 23:19:41] AdwCleaner[R2].txt - [1770 octets] - [18/03/2013 10:53:56] AdwCleaner[S1].txt - [1737 octets] - [18/03/2013 10:54:04] ########## EOF - C:\AdwCleaner[S1].txt - [1797 octets] ##########
You can try TCP Optimizer for your connection issues:
http://www.speedguide.net/downloads.php
http://www.speedguide.net/tcpoptimizer.php

———————————

Lets check your computers security before you go and we have a little cleanup to do also:

Download Security Check by screen317 from HERE or HERE.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt.
  • Please Post the contents of that document.
  • Do Not Attach It!!!
MrC
Here is the log from Security Check. Also, I ran the optimizer and my connection speed is back up to normal. Awesome!

Results of screen317's Security Check version 0.99.61
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 9
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Norton 360
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
JavaFX 2.1.1
Java 7 Update 17
Adobe Flash Player 11.6.602.171
Adobe Reader 10.1.6 Adobe Reader out of Date!
````````Process Check: objlist.exe by Laurent````````
Norton ccSvcHst.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 7%
````````````````````End of Log``````````````````````
Adobe Reader 10.1.6 Adobe Reader out of Date! <—please check for an update if available or uninstall and download and install Foxit Reader which is less vulnerable to malware and much better than Adobe.

——————————

You have out dated programs on the system which are vulnerable to malware.
Please update or uninstall them
Info on doing that can be found in my Preventive Maintenance

~~~~~~~~~~~~~~~~~~~~~

A little clean up to do….

Please Uninstall ComboFix: (if you used it)

Press the Windows logo key + R to bring up the "run box"

Copy and paste next command in the field:

ComboFix /uninstall

Make sure there's a space between Combofix and /

[external image: Posted Image]

Then hit enter.
This will uninstall Combofix, delete its related folders and files, hide file extensions, hide the system/hidden files and clears System Restore cache and create new Restore point

(If that doesn't work…..you can simply rename ComboFix.exe to Uninstall.exe and double click it to complete the uninstall)

———————————

Please download OTL from one of the links below: (you may already have OTL on the system)
http://oldtimer.geekstogo.com/OTL.exe
http://oldtimer.geekstogo.com/OTL.com
http://www.itxassociates.com/OT-Tools/OTL.exe

Save it to your desktop.

Run OTL and hit the CleanUp button. (This will cleanup the tools and logs used including itself)

Any other programs or logs you can manually delete.
IE: RogueKiller.exe, RKreport.txt, RK_Quarantine folder, C:\FRST, MBAR, etc….AdwCleaner > just run the program and click uninstall.

——————————-

Any questions…please post back.

Take a look at My Preventive Maintenance to avoid being infected again.

Good Luck and Thanks for using the forum, MrC

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI