This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan.Gen.2 Trojan.Zeroaccess.B Trojan.Zeroaccess.C removal [Solved]

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am having trouble with three trojans: Trojan.Gen.2, Trojan.Zeroaccess.B, and Trojan.Zeroaccess.C. Norton blocks these every 5 minutes or so and I have no idea how to remove them as I can not find the file they are coming from. I ran a complete computer scan with Norton and this did not solve my problem. My computer is running windows vista home premium and is 64-bit. I have just finished running the "OTL" scan as directed from the Getting started post and here are my results. Thank you in advance for anyone who is willing to help me with my trojans.

OTL logfile created on: 3/23/2013 8:15:15 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Gary\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

6.00 Gb Total Physical Memory | 3.84 Gb Available Physical Memory | 63.96% Memory free
12.11 Gb Paging File | 10.42 Gb Available in Paging File | 86.08% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 687.32 Gb Total Space | 77.62 Gb Free Space | 11.29% Space Free | Partition Type: NTFS
Drive D: | 11.31 Gb Total Space | 1.10 Gb Free Space | 9.77% Space Free | Partition Type: NTFS

Computer Name: GARY-PC | User Name: Gary | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Gary\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.)
PRC - C:\WINDOWS\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Norton Security Suite\Engine\3.8.3.6\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe ()
PRC - C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperAgent.exe ()
PRC - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files (x86)\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
PRC - C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe (Citrix Systems, Inc.)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - c:\hp\HPEZBTN\HPBtnSrv.exe ()
PRC - C:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperAgent.exe ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
MOD - \\.\globalroot\systemroot\syswow64\mswsock.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (LBTServ) – C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV:64bit: - (XAudioService) – C:\Windows\SysNative\DRIVERS\xaudio64.exe (Conexant Systems, Inc.)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (McComponentHostService) – C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe (McAfee, Inc.)
SRV - (PnkBstrA) – C:\WINDOWS\SysWOW64\PnkBstrA.exe ()
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (npggsvc) – C:\WINDOWS\SysWOW64\GameMon.des (INCA Internet Co., Ltd.)
SRV - (N360) – C:\Program Files (x86)\Norton Security Suite\Engine\3.8.3.6\ccSvcHst.exe (Symantec Corporation)
SRV - (MotoHelper) – C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe ()
SRV - (clr_optimization_v4.0.30319_32) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (HPSLPSVC) – C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL (Hewlett-Packard Co.)
SRV - (IAANTMON) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (HPBtnSrv) – c:\hp\HPEZBTN\HPBtnSrv.exe ()


========== Driver Services (SafeList) ==========

DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (ccHP) – C:\Windows\SysNative\Drivers\N360x64\0308030.006\ccHPx64.sys (Symantec Corporation)
DRV:64bit: - (SYMTDI) – C:\Windows\SysNative\Drivers\N360x64\0308030.006\SYMTDI.SYS (Symantec Corporation)
DRV:64bit: - (SYMFW) – C:\Windows\SysNative\Drivers\N360x64\0308030.006\SYMFW.SYS (Symantec Corporation)
DRV:64bit: - (SYMNDISV) – C:\Windows\SysNative\Drivers\N360x64\0308030.006\SYMNDISV.SYS (Symantec Corporation)
DRV:64bit: - (LMouFilt) – C:\Windows\SysNative\DRIVERS\LMouFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LHidFilt) – C:\Windows\SysNative\DRIVERS\LHidFilt.Sys (Logitech, Inc.)
DRV:64bit: - (SaiNtBus) – C:\Windows\SysNative\drivers\SaiBus.sys (Saitek)
DRV:64bit: - (SaiMini) – C:\Windows\SysNative\DRIVERS\SaiMini.sys (Saitek)
DRV:64bit: - (BVRPMPR5a64) – C:\Windows\SysNative\drivers\BVRPMPR5a64.SYS (Avanquest Software)
DRV:64bit: - (motmodem) – C:\Windows\SysNative\DRIVERS\motmodem.sys (Motorola)
DRV:64bit: - (motccgp) – C:\Windows\SysNative\DRIVERS\motccgp.sys (Motorola)
DRV:64bit: - (Motousbnet) – C:\Windows\SysNative\DRIVERS\Motousbnet.sys (Motorola)
DRV:64bit: - (SymEvent) – C:\Windows\SysNative\Drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\Drivers\N360x64\0308030.006\SRTSP64.SYS (Symantec Corporation)
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\drivers\N360x64\0308030.006\SYMEFA64.SYS (Symantec Corporation)
DRV:64bit: - (BHDrvx64) – C:\Windows\SysNative\Drivers\N360x64\0308030.006\BHDrvx64.sys (Symantec Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (SRTSPX) – C:\Windows\SysNative\drivers\N360x64\0308030.006\SRTSPX64.SYS (Symantec Corporation)
DRV:64bit: - (SymIM) – C:\Windows\SysNative\DRIVERS\SymIMv.sys (Symantec Corporation)
DRV:64bit: - (motusbdevice) – C:\Windows\SysNative\DRIVERS\motusbdevice.sys (Motorola Inc)
DRV:64bit: - (WpdUsb) – C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (ctxusbm) – C:\Windows\SysNative\DRIVERS\ctxusbm.sys (Citrix Systems, Inc.)
DRV:64bit: - (motccgpfl) – C:\Windows\SysNative\DRIVERS\motccgpfl.sys (Motorola)
DRV:64bit: - (BTCFilterService) – C:\Windows\SysNative\DRIVERS\motfilt.sys (Motorola Inc)
DRV:64bit: - (RTL8169) – C:\Windows\SysNative\DRIVERS\Rtlh64.sys (Realtek Corporation )
DRV:64bit: - (netr28x) – C:\Windows\SysNative\DRIVERS\netr28x.sys (Ralink Technology, Corp.)
DRV:64bit: - (CAXHWBS2) – C:\Windows\SysNative\DRIVERS\CAXHWBS2.sys (Conexant Systems, Inc.)
DRV:64bit: - (winachsf) – C:\Windows\SysNative\DRIVERS\CAX_CNXT.sys (Conexant Systems, Inc.)
DRV:64bit: - (HSF_DP) – C:\Windows\SysNative\DRIVERS\CAX_DP.sys (Conexant Systems, Inc.)
DRV:64bit: - (HCW85BDA) – C:\Windows\SysNative\drivers\HCW85BDA.sys (Hauppauge Computer Works)
DRV:64bit: - (StillCam) – C:\Windows\SysNative\DRIVERS\serscan.sys (Microsoft Corporation)
DRV:64bit: - (WSDPrintDevice) – C:\Windows\SysNative\DRIVERS\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (MotoSwitchService) – C:\Windows\SysNative\DRIVERS\motswch.sys (Motorola)
DRV:64bit: - (XAudio) – C:\Windows\SysNative\DRIVERS\xaudio64.sys (Conexant Systems, Inc.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iastor.sys (Intel Corporation)
DRV:64bit: - (SaiHFF0C) – C:\Windows\SysNative\DRIVERS\SaiHFF0C.sys (Saitek)
DRV:64bit: - (SaiUFF0C) – C:\Windows\SysNative\DRIVERS\SaiUFF0C.sys (Saitek)
DRV:64bit: - (mdmxsdk) – C:\Windows\SysNative\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20130322.032\ex64.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20130322.032\eng64.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20130322.001\IDSviA64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NPPTNT2) – C:\WINDOWS\SysWOW64\npptNT2.sys (INCA Internet Co., Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cndt
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cndt
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {DB4376FF-E866-4999-8C9A-FF552D841782}
IE:64bit: - HKLM\..\SearchScopes\{BC61999D-5EB7-4538-A46E-D6EF1D314085}: "URL" = http://www.ask.com/web?q={searchterms}&l;=dis&o;=ushpd
IE:64bit: - HKLM\..\SearchScopes\{DB4376FF-E866-4999-8C9A-FF552D841782}: "URL" = http://search.yahoo.com/search?p={searchTe…&fr;=hp-pvdt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cndt
IE - HKLM\..\SearchScopes,DefaultScope = {DB4376FF-E866-4999-8C9A-FF552D841782}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?&o;=101881&l;…q={SEARCHTERMS}
IE - HKLM\..\SearchScopes\{BC61999D-5EB7-4538-A46E-D6EF1D314085}: "URL" = http://www.ask.com/web?q={searchterms}&l;=dis&o;=ushpd
IE - HKLM\..\SearchScopes\{DB4376FF-E866-4999-8C9A-FF552D841782}: "URL" = http://search.yahoo.com/search?p={searchTe…&fr;=hp-pvdt

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cndt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cndt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2
IE - HKCU\..\SearchScopes,DefaultScope = {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}
IE - HKCU\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=i…8C-31E5178BEF9B
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?&o;=101881&l;…q={SEARCHTERMS}
IE - HKCU\..\SearchScopes\{DB4376FF-E866-4999-8C9A-FF552D841782}: "URL" = http://search.yahoo.com/search?p={searchTe…&fr;=hp-pvdt
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledAddons: secureLogin%40blueimp.net:1.0.3
FF - prefs.js..extensions.enabledAddons: wkdfblgwib%40wkdfblgwib.org:1.0
FF - prefs.js..extensions.enabledAddons: %7Be4a8a97b-f2ed-450b-b12d-ee082ba24781%7D:1.8
FF - prefs.js..extensions.enabledAddons: xpirftoolbar%40roboform.com:3.4.9
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.3
FF - prefs.js..extensions.enabledItems: [removed]:0.9.7
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_180.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.11.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.11.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.13.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.13.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@thrixxx.com/WebLaunch: C:\Program Files (x86)\thriXXX\WebLaunch\Binaries\npWebLaunch.dll ( )
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@thrixxx.com/WebLaunch: C:\Program Files (x86)\thriXXX\WebLaunch\Binaries\npWebLaunch.dll ( )
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\ [2011/11/01 07:15:38 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/03/08 08:36:07 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/03/08 08:36:02 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/03/08 08:36:07 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/03/08 08:36:02 | 000,000,000 | —D | M]

[2011/06/16 19:16:25 | 000,000,000 | —D | M] (No name found) – C:\Users\Gary\AppData\Roaming\Mozilla\Extensions
[2011/06/16 19:16:25 | 000,000,000 | —D | M] (No name found) – C:\Users\Gary\AppData\Roaming\Mozilla\Extensions\[removed]
[2013/03/05 09:02:46 | 000,000,000 | —D | M] (No name found) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\wmubwp91.default\extensions
[2012/11/27 08:23:31 | 000,083,379 | —- | M] () (No name found) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\wmubwp91.default\extensions\[removed]
[2012/07/31 07:25:42 | 000,001,678 | —- | M] () (No name found) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\wmubwp91.default\extensions\[removed]
[2013/03/05 09:02:46 | 000,651,703 | —- | M] () (No name found) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\wmubwp91.default\extensions\[removed]
[2012/02/19 08:31:14 | 000,020,591 | —- | M] () (No name found) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\wmubwp91.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi
[2013/02/28 10:10:05 | 000,269,007 | —- | M] () (No name found) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\wmubwp91.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
[2011/04/10 09:15:08 | 000,002,574 | —- | M] () – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\wmubwp91.default\searchplugins\askcom.xml
[2013/03/23 07:39:33 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2013/03/08 08:36:06 | 000,263,064 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2009/09/12 23:05:42 | 000,124,240 | —- | M] (Citrix Systems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\CCMSDK.dll
[2009/09/12 23:06:22 | 000,070,488 | —- | M] (Citrix Systems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\CgpCore.dll
[2009/09/12 23:06:32 | 000,091,480 | —- | M] (Citrix Systems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\confmgr.dll
[2009/09/12 23:06:28 | 000,022,360 | —- | M] (Citrix Systems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\ctxlogging.dll
[2009/09/12 23:08:36 | 000,406,864 | —- | M] () – C:\Program Files (x86)\mozilla firefox\plugins\npicaN.dll
[2006/08/09 06:16:08 | 000,030,408 | —- | M] ( ) – C:\Program Files (x86)\mozilla firefox\plugins\npWebLaunch.dll
[2009/09/12 23:06:24 | 000,023,896 | —- | M] (Citrix Systems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\TcpPServ.dll
[2012/08/30 08:51:53 | 000,002,465 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2013/02/20 08:47:21 | 000,002,086 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2006/09/18 17:37:24 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Security Suite\Engine\3.8.3.6\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Security Suite\Engine\3.8.3.6\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security Suite\Engine\3.8.3.6\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security Suite\Engine\3.8.3.6\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll ()
O4:64bit: - HKLM..\Run: [Bluetooth Connection Assistant] LBTWIZ.EXE -silent File not found
O4:64bit: - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe File not found
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (X86)\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [ProfilerU] C:\Program Files\Saitek\SD6\Software\ProfilerU.exe (Saitek)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [SaiMfd] C:\Program Files\Saitek\SD6\Software\SaiMfd.exe (Saitek)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [4StoryPrePatch] C:\Program Files (x86)\Gameforge4D\GatesofAndaron\PrePatch.exe (Zamiinc)
O4 - HKLM..\Run: [ConnectionCenter] C:\Program Files (x86)\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [hpqSRMon] File not found
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [KBD] C:\hp\KBD\KbdStub.exe ()
O4 - HKLM..\Run: [ScrewDrivers RDP Plugin] C:\Program Files (x86)\triCerat\Simplify Printing\ScrewDrivers Client v4\install_rdp.exe ()
O4 - HKCU..\Run: [assembly] rundll32.exe "C:\Users\Gary\AppData\Local\Citrix\assembly\cwcojk.dll",AVCConfigGetAPIExtW File not found
O4 - HKCU..\Run: [PlayNC Launcher] File not found
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre7\bin\jp2iexp.dll ()
O9 - Extra Button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files (x86)\PokerStars.NET\PokerStarsUpdate.exe (PokerStars)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {2E4A92AB-F2C0-456A-9935-B715439790D7} https://www.opinionsquare.com/Config/packages/op/opsetup.cab (Setup Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 10.13.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6DE92507-B466-474D-9E8F-F4A5EC774184}: DhcpNameServer = 10.0.0.1
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\symres - No CLSID value found
O18 - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - C:\Program Files (x86)\Norton Security Suite\Engine\3.8.3.6\CoIEPlg.dll (Symantec Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Gary\Desktop\Cactus\Cactus Background-1.jpg
O24 - Desktop BackupWallPaper: C:\Users\Gary\Desktop\Cactus\Cactus Background-1.jpg
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{2a7efca5-41fe-11e2-8580-0022153ec960}\Shell - "" = AutoRun
O33 - MountPoints2\{2a7efca5-41fe-11e2-8580-0022153ec960}\Shell\AutoRun\command - "" = G:\setup.exe -a
O33 - MountPoints2\{be2a7d8a-0590-11e0-a294-0022153ec960}\Shell - "" = AutoRun
O33 - MountPoints2\{be2a7d8a-0590-11e0-a294-0022153ec960}\Shell\AutoRun\command - "" = F:\setup.exe -a
O33 - MountPoints2\{d6b7dfa2-60f6-11df-9eb9-0022153ec960}\Shell - "" = AutoRun
O33 - MountPoints2\{d6b7dfa2-60f6-11df-9eb9-0022153ec960}\Shell\AutoRun\command - "" = L:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)


Drivers32:64bit: msacm.ac3acm - AC3ACM.acm (fccHandler)
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.ac3filter - ac3filter.acm File not found
Drivers32: msacm.l3acm - C:\WINDOWS\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
Drivers32: vidc.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
System Restore Service not available.

========== Files/Folders - Created Within 30 Days ==========

[2013/03/23 08:09:41 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Gary\Desktop\OTL.exe
[2013/03/22 08:08:45 | 000,000,000 | —D | C] – C:\Users\Gary\AppData\Local\Symantec
[2013/03/21 23:28:30 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2013/03/21 17:22:06 | 000,000,000 | —D | C] – C:\ProgramData\Playrix Entertainment
[2013/03/21 17:20:56 | 000,000,000 | —D | C] – C:\Users\Public\Documents\AlawarWrapper
[2013/03/21 17:20:51 | 000,000,000 | —D | C] – C:\ProgramData\AlawarWrapper
[2013/03/21 17:19:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Alawar
[2013/03/21 14:41:14 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usb8023.sys
[2013/03/13 17:35:12 | 000,761,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/03/13 17:35:12 | 000,479,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/03/13 17:35:11 | 000,623,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/03/13 17:35:11 | 000,485,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2013/03/13 17:35:11 | 000,422,400 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2013/03/13 17:35:11 | 000,389,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2013/03/13 17:35:11 | 000,249,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2013/03/13 17:35:11 | 000,224,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/03/13 17:35:11 | 000,193,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2013/03/13 17:35:11 | 000,180,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/03/13 17:35:11 | 000,108,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/03/13 17:35:11 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/03/13 17:35:10 | 000,380,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2013/03/08 08:35:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2013/03/03 14:30:59 | 000,000,000 | —D | C] – C:\Users\Gary\AppData\Local\eclipse
[2013/02/23 18:38:02 | 000,000,000 | —D | C] – C:\Users\Gary\AppData\Roaming\Unified Remote
[2013/02/23 18:37:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Unified Remote
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Gary\*.tmp files -> C:\Users\Gary\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/03/23 08:09:42 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Gary\Desktop\OTL.exe
[2013/03/23 08:07:13 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/03/23 08:07:13 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/03/23 07:40:46 | 000,000,890 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/03/23 07:39:01 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/03/22 22:31:01 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/03/22 22:26:01 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/03/21 07:09:41 | 000,769,622 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/03/21 07:09:41 | 000,649,388 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/03/21 07:09:41 | 000,122,898 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/03/18 20:23:37 | 000,000,400 | -H– | M] () – C:\Windows\tasks\Norton Security Scan for Gary.job
[2013/03/17 09:32:24 | 000,317,757 | —- | M] () – C:\Users\Gary\Desktop\contacts.xps
[2013/03/12 19:31:28 | 000,693,976 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/03/12 19:31:28 | 000,073,432 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/03/06 23:52:03 | 000,000,330 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForGary.job
[2013/02/25 16:53:48 | 000,147,586 | —- | M] () – C:\Users\Gary\Desktop\8.jpg
[2013/02/25 16:53:37 | 000,150,227 | —- | M] () – C:\Users\Gary\Desktop\7.jpg
[2013/02/25 13:49:04 | 000,108,554 | —- | M] () – C:\Users\Gary\Desktop\5.xps
[2013/02/25 12:26:04 | 000,000,957 | —- | M] () – C:\Users\Gary\Desktop\Dropbox.lnk
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Gary\*.tmp files -> C:\Users\Gary\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/03/21 17:20:25 | 000,001,748 | —- | C] () – C:\Users\Gary\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Alawar Games.lnk
[2013/03/21 17:19:44 | 000,001,039 | —- | C] () – C:\Users\Gary\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Royal Envoy 2.lnk
[2013/03/17 09:32:21 | 000,317,757 | —- | C] () – C:\Users\Gary\Desktop\contacts.xps
[2013/02/25 16:53:48 | 000,147,586 | —- | C] () – C:\Users\Gary\Desktop\8.jpg
[2013/02/25 16:53:37 | 000,150,227 | —- | C] () – C:\Users\Gary\Desktop\7.jpg
[2013/02/25 13:49:03 | 000,108,554 | —- | C] () – C:\Users\Gary\Desktop\5.xps
[2012/07/15 09:49:45 | 000,000,680 | —- | C] () – C:\Users\Gary\AppData\Local\d3d9caps.dat
[2012/02/25 09:39:39 | 000,012,717 | R— | C] () – C:\Windows\hpwscr14.dat
[2012/02/25 09:36:01 | 000,179,745 | —- | C] () – C:\Windows\hpwins14.dat
[2011/12/13 09:20:01 | 000,000,044 | —- | C] () – C:\Users\Gary\jagex_cl_runescape_LIVE3.dat
[2011/12/13 09:13:07 | 000,000,044 | —- | C] () – C:\Users\Gary\jagex_cl_runescape_LIVE2.dat
[2011/12/12 23:41:34 | 000,000,044 | —- | C] () – C:\Users\Gary\jagex_cl_runescape_LIVE1.dat
[2011/12/12 21:29:01 | 000,000,043 | —- | C] () – C:\Users\Gary\jagex_cl_runescape_LIVE.dat
[2011/12/12 21:29:01 | 000,000,024 | —- | C] () – C:\Users\Gary\random.dat
[2011/09/28 17:44:14 | 000,179,271 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2011/05/27 08:22:24 | 000,106,496 | —- | C] () – C:\Windows\SysWow64\SaiCfg.dll
[2011/05/27 08:22:24 | 000,102,400 | —- | C] () – C:\Windows\SysWow64\NX.exe
[2011/05/27 08:22:24 | 000,045,056 | —- | C] () – C:\Windows\SysWow64\E2.exe
[2011/05/23 08:44:15 | 000,000,000 | —- | C] () – C:\Users\Gary\AppData\Roaming\wklnhst.dat
[2011/05/18 17:47:00 | 000,001,940 | —- | C] () – C:\Users\Gary\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/06/08 07:55:03 | 000,000,092 | —- | C] () – C:\Users\Gary\AppData\Local\fusioncache.dat
[2010/03/21 21:09:21 | 000,031,776 | —- | C] () – C:\ProgramData\nvModes.001
[2010/03/21 20:58:31 | 000,031,776 | —- | C] () – C:\ProgramData\nvModes.dat
[2010/03/18 17:07:28 | 000,232,960 | —- | C] () – C:\Users\Gary\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2011/11/18 16:55:05 | 000,002,048 | -HS- | M] () – C:\WINDOWS\Installer\{d92f3496-7bbe-9d45-e14b-44aee0e2a1ce}\@
[2011/11/18 16:55:05 | 000,000,000 | -HSD | M] – C:\WINDOWS\Installer\{d92f3496-7bbe-9d45-e14b-44aee0e2a1ce}\L
[2013/03/23 08:17:38 | 000,000,000 | -HSD | M] – C:\WINDOWS\Installer\{d92f3496-7bbe-9d45-e14b-44aee0e2a1ce}\U
[2013/03/21 21:10:21 | 000,001,024 | —- | M] () – C:\WINDOWS\Installer\{d92f3496-7bbe-9d45-e14b-44aee0e2a1ce}\U\00000008.@
[2011/11/18 16:55:05 | 000,002,048 | -HS- | M] () – C:\Users\Gary\AppData\Local\{d92f3496-7bbe-9d45-e14b-44aee0e2a1ce}\@
[2011/11/18 16:55:05 | 000,000,000 | -HSD | M] – C:\Users\Gary\AppData\Local\{d92f3496-7bbe-9d45-e14b-44aee0e2a1ce}\L
[2011/11/18 16:55:05 | 000,000,000 | -HSD | M] – C:\Users\Gary\AppData\Local\{d92f3496-7bbe-9d45-e14b-44aee0e2a1ce}\U
[2006/11/02 11:30:40 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[2013/03/23 07:38:59 | 000,004,608 | -HS- | M] () – C:\Windows\assembly\GAC_32\Desktop.ini
[2013/03/23 07:38:57 | 000,006,144 | -HS- | M] () – C:\Windows\assembly\GAC_64\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"ThreadingModel" = Both
"" = C:\Users\Gary\AppData\Local\{d92f3496-7bbe-9d45-e14b-44aee0e2a1ce}\n.

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/08 13:59:03 | 012,899,840 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\SysWow64\shell32.dll – [2012/06/08 13:47:00 | 011,586,048 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/04/11 03:11:14 | 000,891,392 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %SystemRoot%\SysWow64\wbem\fastprox.dll – [2009/04/11 02:28:19 | 000,614,912 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2008/01/20 22:50:58 | 000,513,024 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2010/03/18 17:19:20 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\acccore
[2011/06/08 17:16:38 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Anvil Studio
[2010/10/22 14:02:51 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\avidemux
[2012/09/10 15:44:48 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Carbon
[2010/06/19 09:34:42 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\CoffeeCup Software
[2013/03/22 08:08:34 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Dropbox
[2012/12/17 09:00:24 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\FileZilla
[2010/10/01 18:29:45 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\funkitron
[2013/01/13 13:43:01 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\GoforFiles
[2012/08/30 14:08:16 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\GroundSchool FAA
[2011/03/14 17:50:49 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\ICAClient
[2011/03/14 20:06:31 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Leadertech
[2011/06/18 09:44:29 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\LimeWire
[2011/04/16 13:04:43 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\muvee Technologies
[2012/03/01 19:52:17 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\RadarChaos
[2011/05/14 13:40:03 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\runic games
[2011/05/23 08:44:18 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Template
[2010/08/31 11:34:41 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\thriXXX
[2013/02/23 18:38:16 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Unified Remote
[2012/08/12 13:42:09 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\vghd
[2010/06/19 10:40:22 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Web Page Maker
[2010/04/24 17:24:32 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\WinBatch

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.EXE >
[2008/10/29 02:20:29 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE – C:\WINDOWS\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_b5f700fe698beb14\explorer.exe
[2008/10/29 02:29:41 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D – C:\WINDOWS\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_b7eb106e66a7ac19\explorer.exe
[2008/10/29 02:15:50 | 003,087,360 | —- | M] (Microsoft Corporation) MD5=50514057C28A74BAC2BD04B7B990D615 – C:\WINDOWS\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_aba256ac352b2919\explorer.exe
[2008/10/29 23:59:17 | 002,927,616 | —- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E – C:\WINDOWS\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_b8583e9d7fda0512\explorer.exe
[2009/04/11 03:10:17 | 003,079,168 | —- | M] (Microsoft Corporation) MD5=6B08E54A451B3F95E4109DBA7E594270 – C:\WINDOWS\explorer.exe
[2009/04/11 03:10:17 | 003,079,168 | —- | M] (Microsoft Corporation) MD5=6B08E54A451B3F95E4109DBA7E594270 – C:\WINDOWS\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_afbebba22f3bab41\explorer.exe
[2008/10/27 22:30:12 | 003,086,848 | —- | M] (Microsoft Corporation) MD5=72B9990E45C25AA3C75C4FB50A9D6CE0 – C:\WINDOWS\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_ac5266dd4e2b0a41\explorer.exe
[2008/10/29 02:49:22 | 003,080,704 | —- | M] (Microsoft Corporation) MD5=BBD8E74F23D7605CB0CDB57A1B25D826 – C:\WINDOWS\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_ad96661c3246ea1e\explorer.exe
[2009/04/11 02:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\WINDOWS\SysWOW64\explorer.exe
[2009/04/11 02:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\WINDOWS\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_ba1365f4639c6d3c\explorer.exe
[2008/10/30 01:30:07 | 003,081,216 | —- | M] (Microsoft Corporation) MD5=E404A65EF890140410E9F3D405841C95 – C:\WINDOWS\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_ae03944b4b794317\explorer.exe
[2008/10/27 22:15:02 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB – C:\WINDOWS\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_b6a7112f828bcc3c\explorer.exe
[2008/01/20 22:48:44 | 003,080,704 | —- | M] (Microsoft Corporation) MD5=F6D765FB6B457542D954682F50C26E4F – C:\WINDOWS\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_add342963219dff5\explorer.exe
[2008/01/20 22:49:23 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F – C:\WINDOWS\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_b827ece8667aa1f0\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2006/11/02 11:13:38 | 000,036,864 | —- | M] (Microsoft Corporation) MD5=192DD053B43250E264383CDC3D564A18 – C:\WINDOWS\SysWOW64\en-US\explorer.exe.mui
[2006/11/02 11:13:38 | 000,036,864 | —- | M] (Microsoft Corporation) MD5=192DD053B43250E264383CDC3D564A18 – C:\WINDOWS\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_6a2f0af76374ed51\explorer.exe.mui
[2006/11/02 11:13:32 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=872D519975CA4D7CC596FC93470D49E0 – C:\WINDOWS\en-US\explorer.exe.mui
[2006/11/02 11:13:32 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=872D519975CA4D7CC596FC93470D49E0 – C:\WINDOWS\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_5fda60a52f142b56\explorer.exe.mui

< MD5 for: EXPLORER.EXE-7A3328DA.PF >
[2013/03/23 07:40:37 | 000,300,464 | —- | M] () MD5=5834154F6526862616837E364EE60B3A – C:\WINDOWS\Prefetch\EXPLORER.EXE-7A3328DA.pf

< MD5 for: EXPLORER.HTM >
[2006/01/11 02:04:38 | 000,006,995 | —- | M] () MD5=0CFD32939C792D5BB0FFB9590324B7ED – C:\Program Files (x86)\Evrsoft First Page 2006\Help\1stPage Guide\explorer.htm

< MD5 for: EXPLORER.ZIP >
[2006/03/06 22:48:08 | 000,020,394 | —- | M] () MD5=B469409C2B2A33C542190B720E11BD79 – C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip

< MD5 for: IEXPLORE.EXE >
[2010/09/08 13:30:52 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=02FF22F3AF0108DA2A563ABC9867049F – C:\WINDOWS\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18527_none_95c6b18b06c68f00\iexplore.exe
[2010/09/08 12:49:16 | 000,711,448 | —- | M] (Microsoft Corporation) MD5=04AE9CFD3F53936223BED7F52C28E5D1 – C:\WINDOWS\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18527_none_8b720738d265cd05\iexplore.exe
[2010/05/04 15:05:56 | 000,711,448 | —- | M] (Microsoft Corporation) MD5=0F1D27BFB65CAC093563CD46E56EAC57 – C:\WINDOWS\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22685_none_8bb8c3e7ebb5e1c7\iexplore.exe
[2009/12/18 08:28:58 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=115076DAD84312F3A51698C15BC39D39 – C:\WINDOWS\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.21184_none_942603a022f1326e\iexplore.exe
[2010/03/09 12:56:18 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=259E27152180B895DF395ED3E412B90E – C:\WINDOWS\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.17037_none_93d5774f09a852f4\iexplore.exe
[2010/05/04 14:56:53 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=29A7F81290165264010B784A7D217561 – C:\WINDOWS\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18470_none_95899e0306f56c2d\iexplore.exe
[2009/04/11 02:27:44 | 000,636,080 | —- | M] (Microsoft Corporation) MD5=2C5168C856455CC43C4B4E1CC1920001 – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2009/04/11 02:27:44 | 000,636,080 | —- | M] (Microsoft Corporation) MD5=2C5168C856455CC43C4B4E1CC1920001 – C:\WINDOWS\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6002.18005_none_97c0beeb03de7f46\iexplore.exe
[2010/09/09 11:50:19 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=3EF3476EF687FE18856A6148C6082452 – C:\WINDOWS\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22760_none_961e0e86200aea54\iexplore.exe
[2010/05/04 14:31:09 | 000,634,656 | —- | M] (Microsoft Corporation) MD5=424CEA5CB5999B2A6A3ED643EA20C97F – C:\WINDOWS\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22685_none_960d6e3a2016a3c2\iexplore.exe
[2010/12/20 11:42:20 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=4319F2A5C725D9E0B9E01744E02D32BE – C:\WINDOWS\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18565_none_9599714706e8cc16\iexplore.exe
[2010/06/28 12:58:49 | 000,711,456 | —- | M] (Microsoft Corporation) MD5=451108714ABD6C6923BECBD61BC9B867 – C:\WINDOWS\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18498_none_8b275628d29daccc\iexplore.exe
[2010/10/20 14:34:04 | 000,711,448 | —- | M] (Microsoft Corporation) MD5=47045D1D8170F3121EBCB30442B434A7 – C:\WINDOWS\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18542_none_8b5765eed27a8634\iexplore.exe
[2009/04/11 03:11:08 | 000,712,864 | —- | M] (Microsoft Corporation) MD5=58136AB5A3DF2D44BBB483629188584A – C:\Program Files\Internet Explorer\iexplore.exe
[2009/04/11 03:11:08 | 000,712,864 | —- | M] (Microsoft Corporation) MD5=58136AB5A3DF2D44BBB483629188584A – C:\WINDOWS\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6002.18005_none_8d6c1498cf7dbd4b\iexplore.exe
[2008/01/20 22:48:06 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=5B92133D3E7FB2644677686305E29E81 – C:\WINDOWS\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18000_none_95d545df06bcb3fa\iexplore.exe
[2010/06/28 12:45:03 | 000,711,456 | —- | M] (Microsoft Corporation) MD5=6183CA49F334FD6B10A99AB2723AD55B – C:\WINDOWS\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22720_none_8bf4a3e3eb89b895\iexplore.exe
[2010/10/20 13:48:33 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=63E2F08404C9824C6CE6EE4A308B4083 – C:\WINDOWS\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18542_none_95ac104106db482f\iexplore.exe
[2010/10/21 15:11:56 | 000,711,448 | —- | M] (Microsoft Corporation) MD5=659654C25D55B7D0D4CCE8DCB65D581E – C:\WINDOWS\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22784_none_8bb7c583ebb6c597\iexplore.exe
[2010/03/11 12:40:22 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=67C769016A79E6FC65D1755E5D6ADAB3 – C:\WINDOWS\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22653_none_962bdd6a20001d41\iexplore.exe
[2010/03/11 13:12:09 | 000,711,456 | —- | M] (Microsoft Corporation) MD5=698D39FD901FA2EF5A9FF85D10B78FC5 – C:\WINDOWS\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22653_none_8bd73317eb9f5b46\iexplore.exe
[2009/12/18 11:42:45 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=6C8AC3469BBEFE194BB18B2D84D98252 – C:\WINDOWS\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18385_none_9583cda306f909aa\iexplore.exe
[2011/04/21 10:34:57 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=6C93AC7C0A8718E2A1543DB1B1B3B19F – C:\WINDOWS\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22905_none_9663f34c1fd5bbaf\iexplore.exe
[2010/03/09 12:30:03 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=74E60C93D1C9A40354D839776CCF53DF – C:\WINDOWS\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18444_none_95ae0eef06d97db6\iexplore.exe
[2011/04/21 11:02:30 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=77B9A891222FB46B13E414B99E1AF842 – C:\WINDOWS\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18639_none_95bde41906ccdac6\iexplore.exe
[2010/12/20 12:10:31 | 000,711,448 | —- | M] (Microsoft Corporation) MD5=7D15B77F30D15CC58F23CC3D3AA21BFB – C:\WINDOWS\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18565_none_8b44c6f4d2880a1b\iexplore.exe
[2011/04/21 11:31:40 | 000,711,448 | —- | M] (Microsoft Corporation) MD5=7DE6E0C4FD95FD20255E842FC78AC9EF – C:\WINDOWS\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18639_none_8b6939c6d26c18cb\iexplore.exe
[2009/12/18 09:02:44 | 000,711,448 | —- | M] (Microsoft Corporation) MD5=85EB45D31F684BD7071A00D42C382433 – C:\WINDOWS\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22585_none_8bb8c201ebb5e4a0\iexplore.exe
[2010/06/28 12:33:13 | 000,634,656 | —- | M] (Microsoft Corporation) MD5=867D06F3C473F65921F5EDF35866FF14 – C:\WINDOWS\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22720_none_96494e361fea7a90\iexplore.exe
[2010/03/09 13:09:55 | 000,711,448 | —- | M] (Microsoft Corporation) MD5=93D54DD14D9FE237DF830ED7522B35D4 – C:\WINDOWS\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.17037_none_8980ccfcd54790f9\iexplore.exe
[2010/03/09 12:32:31 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=97496AA4590CB101EF990060F7055F3D – C:\WINDOWS\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.21242_none_944f44a222d28d23\iexplore.exe
[2008/01/20 22:50:37 | 000,701,952 | —- | M] (Microsoft Corporation) MD5=AC2C3BAFD177B60C3B5E4DDBCC2C2DB3 – C:\WINDOWS\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18000_none_8b809b8cd25bf1ff\iexplore.exe
[2009/12/18 09:20:04 | 000,711,432 | —- | M] (Microsoft Corporation) MD5=AE8E53D125AF9E62E7AC360AC61D036D – C:\WINDOWS\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.21184_none_89d1594dee907073\iexplore.exe
[2010/05/04 15:50:33 | 000,711,456 | —- | M] (Microsoft Corporation) MD5=AEA20B66F0AACBFF8E7F554E616DF207 – C:\WINDOWS\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18470_none_8b34f3b0d294aa32\iexplore.exe
[2010/12/20 11:29:40 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B021EBF2A5344FF71A641B2EFDAF813E – C:\WINDOWS\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22816_none_965a21c41fdcf3d0\iexplore.exe
[2010/06/28 12:19:40 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B6D7D54B736056991109F169737592C7 – C:\WINDOWS\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18498_none_957c007b06fe6ec7\iexplore.exe
[2011/04/21 11:18:01 | 000,711,448 | —- | M] (Microsoft Corporation) MD5=B884E379175705357D541DAE90A962A9 – C:\WINDOWS\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22905_none_8c0f48f9eb74f9b4\iexplore.exe
[2011/02/18 12:00:39 | 000,711,448 | —- | M] (Microsoft Corporation) MD5=BCD3DE5D8693BF4F2A1201900B9E5E71 – C:\WINDOWS\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18602_none_8b82a784d25a1397\iexplore.exe
[2011/02/18 11:23:49 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=BECD30E162ACFD7A04B1F87FBBAFF70E – C:\WINDOWS\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22857_none_962fe25e1ffc7ceb\iexplore.exe
[2009/12/18 08:56:05 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=C071905121F6DE5F399550FC70138FEC – C:\WINDOWS\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16982_none_939a8e1f09d52cb4\iexplore.exe
[2009/12/18 09:15:41 | 000,711,432 | —- | M] (Microsoft Corporation) MD5=C2736FB489245B698691DC2FBC08BA2C – C:\WINDOWS\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18385_none_8b2f2350d29847af\iexplore.exe
[2011/02/18 11:49:27 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=C84ABBF7D7AF2F7D004D800D10430FF5 – C:\WINDOWS\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18602_none_95d751d706bad592\iexplore.exe
[2010/03/09 12:56:10 | 000,711,448 | —- | M] (Microsoft Corporation) MD5=CDF4EDBA0498EF0FDEFDBB1C5E5B2CD6 – C:\WINDOWS\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18444_none_8b59649cd278bbbb\iexplore.exe
[2009/12/18 09:17:05 | 000,711,432 | —- | M] (Microsoft Corporation) MD5=E3542162B46EFB2D6FA1C7DD2C3B810D – C:\WINDOWS\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16982_none_8945e3ccd5746ab9\iexplore.exe
[2010/03/09 13:08:05 | 000,711,448 | —- | M] (Microsoft Corporation) MD5=E35AAC70094E88367FA984AD891D812C – C:\WINDOWS\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.21242_none_89fa9a4fee71cb28\iexplore.exe
[2010/10/21 14:50:10 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=ED748658B126A4617A4BA4A8F4F10DBE – C:\WINDOWS\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22784_none_960c6fd620178792\iexplore.exe
[2011/02/18 11:39:31 | 000,711,448 | —- | M] (Microsoft Corporation) MD5=F451E3E1709CCEABEAC734184ACA00E0 – C:\WINDOWS\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22857_none_8bdb380beb9bbaf0\iexplore.exe
[2010/12/20 11:47:18 | 000,711,448 | —- | M] (Microsoft Corporation) MD5=F474DFA13C957F1385ECC42A1096C976 – C:\WINDOWS\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22816_none_8c057771eb7c31d5\iexplore.exe
[2009/12/18 08:27:08 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=F47755101C622AF18EE669ECEB3A97AD – C:\WINDOWS\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22585_none_960d6c542016a69b\iexplore.exe
[2010/09/09 12:23:15 | 000,711,448 | —- | M] (Microsoft Corporation) MD5=F8C856A2A1C1550D95EE08DC57641C57 – C:\WINDOWS\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22760_none_8bc96433ebaa2859\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2006/11/02 11:13:34 | 000,016,384 | —- | M] (Microsoft Corporation) MD5=3CCDDDBC49DEACA370F39A9F0E146A1B – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2006/11/02 11:13:34 | 000,016,384 | —- | M] (Microsoft Corporation) MD5=3CCDDDBC49DEACA370F39A9F0E146A1B – C:\WINDOWS\winsxs\wow64_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_a1c8f6f0449888c1\iexplore.exe.mui
[2006/11/02 11:13:29 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=D421BD7B9646679254B0D855823C6F21 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2006/11/02 11:13:29 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=D421BD7B9646679254B0D855823C6F21 – C:\WINDOWS\winsxs\amd64_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_97744c9e1037c6c6\iexplore.exe.mui

< MD5 for: SERVICES >
[2006/09/18 17:37:24 | 000,017,244 | —- | M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7 – C:\WINDOWS\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.0.6001.18000_none_60a39df1afb86c9f\services

< MD5 for: SERVICES.CFG >
[2012/12/18 10:28:18 | 000,558,791 | —- | M] () MD5=A9983CC532F9B3FB1E87918D2313731D – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 13:55:30 | 000,584,045 | R— | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E – C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg

< MD5 for: SERVICES.CNF >
[2010/03/31 10:02:17 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Users\Gary\Documents\My Web Sites\_vti_pvt\services.cnf

< MD5 for: SERVICES.EXE >
[2008/01/20 22:50:34 | 000,279,040 | —- | M] (Microsoft Corporation) MD5=2B336AB6286D6C81FA02CBAB914E3C6C – C:\WINDOWS\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe
[2009/04/11 03:10:50 | 000,384,512 | —- | M] (Microsoft Corporation) MD5=934E0B7D77FF78C18D9F8891221B6DE3 – C:\WINDOWS\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_2d69d4f782c83d8c\services.exe
[2009/04/11 03:10:50 | 000,381,952 | —- | M] (Microsoft Corporation) MD5=B8844F93D2C5F1DCDB179AAA9AF134B7 – C:\Windows\SysNative\services.exe
[2009/04/11 02:27:59 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B – C:\WINDOWS\SysWOW64\services.exe
[2009/04/11 02:27:59 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B – C:\WINDOWS\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe
[2008/01/20 22:49:44 | 000,384,512 | —- | M] (Microsoft Corporation) MD5=DFAC660F0F139276CC9299812DE42719 – C:\WINDOWS\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_2b7e5beb85a67240\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2006/11/02 11:13:31 | 000,017,920 | —- | M] (Microsoft Corporation) MD5=1626EACF0E7E59F85C59DDDD27C4169C – C:\WINDOWS\SysWOW64\en-US\services.exe.mui
[2006/11/02 11:13:31 | 000,017,920 | —- | M] (Microsoft Corporation) MD5=1626EACF0E7E59F85C59DDDD27C4169C – C:\WINDOWS\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.0.6000.16386_en-us_67c6851b290a1ced\services.exe.mui
[2006/11/02 11:13:56 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=F514B57C09E143F1E14415A9E9ADD695 – C:\Windows\SysNative\en-US\services.exe.mui
[2006/11/02 11:13:56 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=F514B57C09E143F1E14415A9E9ADD695 – C:\WINDOWS\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.0.6000.16386_en-us_c3e5209ee1678e23\services.exe.mui

< MD5 for: SERVICES.HTM >
[2006/10/26 20:42:16 | 000,003,140 | —- | M] () MD5=065B93C99612C4DED50A5B82D1907D7A – C:\Program Files (x86)\Microsoft Expression\Templates\1033\WEBS12\smallbiz4.tem\SERVICES.HTM
[2009/06/09 09:59:08 | 000,003,662 | —- | M] () MD5=2D2B9857EE9194DE0D19180CE8BE3023 – C:\Program Files (x86)\Microsoft Expression\Web 3\en\WEBS\smallbiz2.tem\SERVICES.HTM
[2009/06/09 09:59:08 | 000,003,660 | —- | M] () MD5=385F319812E977BD0925828CB94E8B0D – C:\Program Files (x86)\Microsoft Expression\Web 3\en\WEBS\smallbiz3.tem\SERVICES.HTM
[2009/06/09 09:59:08 | 000,003,145 | —- | M] () MD5=4AF3252172928C3C2D801273F289FAC3 – C:\Program Files (x86)\Microsoft Expression\Web 3\en\WEBS\smallbiz4.tem\SERVICES.HTM
[2009/06/09 09:59:06 | 000,003,692 | —- | M] () MD5=7C0A432F0867E6E27067925774C6BB03 – C:\Program Files (x86)\Microsoft Expression\Web 3\en\WEBS\smallbiz1.tem\SERVICES.HTM
[2006/10/26 20:42:24 | 000,003,127 | —- | M] () MD5=8637B342EC124A00EC27DFCE45A3FCB7 – C:\Program Files (x86)\Microsoft Expression\Templates\1033\WEBS12\smallbiz5.tem\SERVICES.HTM
[2006/10/26 20:42:00 | 000,003,657 | —- | M] () MD5=9B68D7B32277521CB5240E7AFFD75ED3 – C:\Program Files (x86)\Microsoft Expression\Templates\1033\WEBS12\smallbiz2.tem\SERVICES.HTM
[2006/10/26 20:41:52 | 000,003,687 | —- | M] () MD5=A208808966BAB0309243FFB278B919EF – C:\Program Files (x86)\Microsoft Expression\Templates\1033\WEBS12\smallbiz1.tem\SERVICES.HTM
[2009/06/09 09:59:08 | 000,003,132 | —- | M] () MD5=BA10F0A870E107AD714B52D19F13556D – C:\Program Files (x86)\Microsoft Expression\Web 3\en\WEBS\smallbiz5.tem\SERVICES.HTM
[2009/06/09 09:59:08 | 000,003,119 | —- | M] () MD5=BF1F2DF30B367C20603E49284B55B5CD – C:\Program Files (x86)\Microsoft Expression\Web 3\en\WEBS\smallbiz6.tem\SERVICES.HTM
[2006/10/26 20:42:32 | 000,003,114 | —- | M] () MD5=C921BDE5D523A04DE3A7319B6C8E38A2 – C:\Program Files (x86)\Microsoft Expression\Templates\1033\WEBS12\smallbiz6.tem\SERVICES.HTM
[2006/10/26 20:42:08 | 000,003,655 | —- | M] () MD5=CF0DF3B55D7754DE445768728CF3EB66 – C:\Program Files (x86)\Microsoft Expression\Templates\1033\WEBS12\smallbiz3.tem\SERVICES.HTM

< MD5 for: SERVICES.JPG >
[2005/08/26 10:38:58 | 000,009,430 | —- | M] () MD5=5B42FB058ED1B06EC596BDCF3253CBD5 – C:\Program Files (x86)\Microsoft Expression\Templates\1033\WEBS12\smallbiz1.tem\SERVICES.JPG
[2005/08/26 10:46:14 | 000,009,430 | —- | M] () MD5=5B42FB058ED1B06EC596BDCF3253CBD5 – C:\Program Files (x86)\Microsoft Expression\Templates\1033\WEBS12\smallbiz2.tem\SERVICES.JPG
[2005/08/26 10:46:42 | 000,009,430 | —- | M] () MD5=5B42FB058ED1B06EC596BDCF3253CBD5 – C:\Program Files (x86)\Microsoft Expression\Templates\1033\WEBS12\smallbiz3.tem\SERVICES.JPG
[2005/08/26 10:47:18 | 000,009,430 | —- | M] () MD5=5B42FB058ED1B06EC596BDCF3253CBD5 – C:\Program Files (x86)\Microsoft Expression\Templates\1033\WEBS12\smallbiz4.tem\SERVICES.JPG
[2005/08/26 10:52:10 | 000,009,430 | —- | M] () MD5=5B42FB058ED1B06EC596BDCF3253CBD5 – C:\Program Files (x86)\Microsoft Expression\Templates\1033\WEBS12\smallbiz5.tem\SERVICES.JPG
[2005/08/26 10:52:32 | 000,009,430 | —- | M] () MD5=5B42FB058ED1B06EC596BDCF3253CBD5 – C:\Program Files (x86)\Microsoft Expression\Templates\1033\WEBS12\smallbiz6.tem\SERVICES.JPG
[2009/06/09 09:59:06 | 000,009,430 | —- | M] () MD5=5B42FB058ED1B06EC596BDCF3253CBD5 – C:\Program Files (x86)\Microsoft Expression\Web 3\en\WEBS\smallbiz1.tem\SERVICES.JPG
[2009/06/09 09:59:06 | 000,009,430 | —- | M] () MD5=5B42FB058ED1B06EC596BDCF3253CBD5 – C:\Program Files (x86)\Microsoft Expression\Web 3\en\WEBS\smallbiz2.tem\SERVICES.JPG
[2009/06/09 09:59:08 | 000,009,430 | —- | M] () MD5=5B42FB058ED1B06EC596BDCF3253CBD5 – C:\Program Files (x86)\Microsoft Expression\Web 3\en\WEBS\smallbiz3.tem\SERVICES.JPG
[2009/06/09 09:59:08 | 000,009,430 | —- | M] () MD5=5B42FB058ED1B06EC596BDCF3253CBD5 – C:\Program Files (x86)\Microsoft Expression\Web 3\en\WEBS\smallbiz4.tem\SERVICES.JPG
[2009/06/09 09:59:08 | 000,009,430 | —- | M] () MD5=5B42FB058ED1B06EC596BDCF3253CBD5 – C:\Program Files (x86)\Microsoft Expression\Web 3\en\WEBS\smallbiz5.tem\SERVICES.JPG
[2009/06/09 09:59:08 | 000,009,430 | —- | M] () MD5=5B42FB058ED1B06EC596BDCF3253CBD5 – C:\Program Files (x86)\Microsoft Expression\Web 3\en\WEBS\smallbiz6.tem\SERVICES.JPG

< MD5 for: SERVICES.LNK >
[2008/01/20 23:20:59 | 000,001,688 | —- | M] () MD5=EFDD08F4E5E26430885F26F0C35B8C62 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2008/01/20 23:20:59 | 000,001,688 | —- | M] () MD5=EFDD08F4E5E26430885F26F0C35B8C62 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2006/09/18 17:44:54 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2006/09/18 17:46:11 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\WINDOWS\SysWOW64\wbem\services.mof
[2006/09/18 17:44:54 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\WINDOWS\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_2b7e5beb85a67240\services.mof
[2006/09/18 17:44:54 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\WINDOWS\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_2d69d4f782c83d8c\services.mof
[2006/09/18 17:46:11 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\WINDOWS\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.mof
[2006/09/18 17:46:11 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\WINDOWS\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.mof

< MD5 for: SERVICES.MSC >
[2006/11/02 11:13:51 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\en-US\services.msc
[2006/09/18 17:29:41 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\services.msc
[2006/11/02 11:14:00 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\WINDOWS\SysWOW64\en-US\services.msc
[2006/09/18 17:29:40 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\WINDOWS\SysWOW64\services.msc
[2006/11/02 11:13:51 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\WINDOWS\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.0.6000.16386_en-us_fe26f08ab7d12816\services.msc
[2006/09/18 17:29:41 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\WINDOWS\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.0.6001.18000_none_2b827e27fe185619\services.msc
[2006/11/02 11:14:00 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\WINDOWS\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.0.6000.16386_en-us_a2085506ff73b6e0\services.msc
[2006/09/18 17:29:40 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\WINDOWS\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.0.6001.18000_none_cf63e2a445bae4e3\services.msc

< MD5 for: SERVICES.PNG >
[2008/03/26 14:02:52 | 000,000,875 | —- | M] () MD5=3382D191625A7528ED791FEDCCE3F212 – C:\Program Files (x86)\PC-Doctor 5 for Windows\Images\img16_16\services.png
[2008/03/27 05:57:28 | 000,003,334 | —- | M] () MD5=5FF3A00670DE8D80ADA4BD034B55D154 – C:\Program Files (x86)\CoffeeCup Software\CoffeeCup Free HTML Editor\Graphics\CoffeeCup Graphics Pack Samples\Red\services.png
[2008/03/26 14:03:00 | 000,002,244 | —- | M] () MD5=8C5F2C34A5FB317B868565F9451BF74C – C:\Program Files (x86)\PC-Doctor 5 for Windows\Images\img32_32\services.png
[2008/03/26 14:03:08 | 000,006,479 | —- | M] () MD5=AFCA60ED198BE9309943722FE8758392 – C:\Program Files (x86)\PC-Doctor 5 for Windows\Images\img64_64\services.png
[2008/03/27 05:38:18 | 000,003,827 | —- | M] () MD5=BFC0958B73C61EE6C5EEA8D8C6073D26 – C:\Program Files (x86)\CoffeeCup Software\CoffeeCup Free HTML Editor\Graphics\CoffeeCup Graphics Pack Samples\Blue\services.png
[2008/03/26 14:03:04 | 000,004,193 | —- | M] () MD5=E1C3A20056206C394E65B37CE1D43851 – C:\Program Files (x86)\PC-Doctor 5 for Windows\Images\img48_48\services.png
[2008/03/26 14:02:56 | 000,001,509 | —- | M] () MD5=F4EC3ABEAE15FA9BB42D721E9D543F44 – C:\Program Files (x86)\PC-Doctor 5 for Windows\Images\img24_24\services.png

< MD5 for: WINLOGON.EXE >
[2009/04/11 03:11:08 | 000,405,504 | —- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A – C:\Windows\SysNative\winlogon.exe
[2009/04/11 03:11:08 | 000,405,504 | —- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A – C:\WINDOWS\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_cdcd15a68a70b877\winlogon.exe
[2008/01/20 22:49:47 | 000,406,016 | —- | M] (Microsoft Corporation) MD5=856491FCED98093D824B9EB2892F564A – C:\WINDOWS\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_cbe19c9a8d4eed2b\winlogon.exe
[2009/04/11 02:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\WINDOWS\SysWOW64\winlogon.exe
[2009/04/11 02:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\WINDOWS\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008/01/20 22:50:38 | 000,314,880 | —- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 – C:\WINDOWS\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2008/01/20 22:52:39 | 000,019,968 | —- | M] (Microsoft Corporation) MD5=1DB95B0920FA9783476AC46F187C06F6 – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2008/01/20 22:52:39 | 000,019,968 | —- | M] (Microsoft Corporation) MD5=1DB95B0920FA9783476AC46F187C06F6 – C:\WINDOWS\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6001.18000_en-us_27172d0ebc73e370\winlogon.exe.mui
[2008/01/20 22:52:28 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=26AC28BF50DC112BAA794A83E08588F0 – C:\WINDOWS\SysWOW64\en-US\winlogon.exe.mui
[2008/01/20 22:52:28 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=26AC28BF50DC112BAA794A83E08588F0 – C:\WINDOWS\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6001.18000_en-us_caf8918b0416723a\winlogon.exe.mui
[2006/11/02 11:13:52 | 000,019,968 | —- | M] (Microsoft Corporation) MD5=2D30AB05DBA78517B34C0AAC71DF5299 – C:\WINDOWS\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6000.16386_en-us_24e06b12bf88d29c\winlogon.exe.mui
[2006/11/02 11:13:03 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=A1D2856F3EC3C86EBBF1442B0245A8B3 – C:\WINDOWS\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6000.16386_en-us_c8c1cf8f072b6166\winlogon.exe.mui

< MD5 for: WINLOGON.MOF >
[2006/09/18 17:38:40 | 000,002,794 | —- | M] () MD5=545C578F290B9CDD280966939935B9EA – C:\Windows\SysNative\wbem\winlogon.mof
[2006/09/18 17:41:56 | 000,002,794 | —- | M] () MD5=545C578F290B9CDD280966939935B9EA – C:\WINDOWS\SysWOW64\wbem\winlogon.mof
[2006/09/18 17:38:40 | 000,002,794 | —- | M] () MD5=545C578F290B9CDD280966939935B9EA – C:\WINDOWS\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.0.6000.16386_none_da20a358315a3dca\winlogon.mof
[2006/09/18 17:41:56 | 000,002,794 | —- | M] () MD5=545C578F290B9CDD280966939935B9EA – C:\WINDOWS\winsxs\x86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.0.6000.16386_none_7e0207d478fccc94\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2009/04/11 02:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2008/05/17 00:03:10 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 09:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 09:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 09:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2007/11/06 22:13:41 | 000,359,256 | —- | M] (Hewlett-Packard) – C:\hpzids40.dll
[2007/11/07 09:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 09:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 09:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 09:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 09:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 09:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 09:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 09:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 09:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2011/02/12 19:30:02 | 000,000,730 | -H– | M] () – C:\IPH.PH
[2006/12/02 02:37:14 | 000,904,704 | —- | M] (Microsoft Corporation) – C:\msdia80.dll
[2013/03/23 07:38:49 | 2460,303,359 | -HS- | M] () – C:\pagefile.sys
[2007/11/07 09:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 09:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 09:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2006/11/02 11:06:41 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 11:06:41 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 11:06:41 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2010/03/23 08:50:24 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 17:35:48 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2010/05/16 10:57:33 | 000,001,642 | -H– | M] () – C:\Users\Gary\AppData\Roaming\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >
[2008/01/20 23:21:59 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/03/23 09:06:34 | 000,000,286 | -HS- | M] () – C:\Users\Gary\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2012/09/10 15:42:26 | 004,497,920 | —- | M] () – C:\Users\Gary\Desktop\AirMech.exe
[2012/09/27 19:10:41 | 006,523,640 | —- | M] (Macrovision Corporation) – C:\Users\Gary\Desktop\NCsoftLauncherSetup.exe
[2013/03/23 08:09:42 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Gary\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 64 bytes -> C:\Users\Gary\Desktop\30.Minutes.or.Less.2011.BluRay.720p.xvid-hibbs1.avi:TOC.WMV
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:B2AA1B61

< End of report >

OTL Extras logfile created on: 3/23/2013 8:15:15 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Gary\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

6.00 Gb Total Physical Memory | 3.84 Gb Available Physical Memory | 63.96% Memory free
12.11 Gb Paging File | 10.42 Gb Available in Paging File | 86.08% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 687.32 Gb Total Space | 77.62 Gb Free Space | 11.29% Space Free | Partition Type: NTFS
Drive D: | 11.31 Gb Total Space | 1.10 Gb Free Space | 9.77% Space Free | Partition Type: NTFS

Computer Name: GARY-PC | User Name: Gary | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
InternetShortcut [print] – rundll32.exe C:\Windows\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]
"VistaSp2" = A5 BF CE 35 89 CA CA 01 [binary data]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1

========== Firewall Settings ==========

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{15262012-213A-4f65-9019-C8A409EC0156}" = HP Officejet J6400 Series
"{240FCE0B-F553-4ab3-9C7B-3CD082FCA117}" = NetDeviceManager64
"{26A24AE4-039D-4CA4-87B4-2F86417011FF}" = Java 7 Update 11 (64-bit)
"{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}" = Paint.NET v3.5.10
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6D41B4C4-FCD7-4F9B-99B9-A01F63F71F0F}" = Smart Technology Programming Software [removed]
"{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{82ED9FB2-55AF-4A61-A6F3-506CEE112779}" = Motorola Mobile Drivers Installation 4.7.1
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{8F473675-D702-45F9-8EBC-342B40C17BF5}" = Apple Mobile Device Support
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{9545E9DB-6F4C-4404-BF25-E221BE8B44C5}" = iTunes
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 296.10
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.12.0213
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.10.8
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{C5856970-6B43-41AC-B4A6-BB0B3E80F52B}_is1" = HP Demo
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{E4F5E48E-7155-4CF9-88CD-7F377EC9AC54}" = Bonjour
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer
"AC3ACM" = AC-3 ACM Codec
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2F20&SUBSYS;_200C14F1" = Soft Data Fax Modem with SmartCP
"HP Document Manager" = HP Document Manager 1.0
"HP Imaging Device Functions" = HP Imaging Device Functions 10.0
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"HP Smart Web Printing" = HP Smart Web Printing
"HP Solution Center & Imaging Support Tools" = HP Solution Center 10.0
"HPExtendedCapabilities" = HP Customer Participation Program 10.0
"HPOCR" = OCR Software by I.R.I.S. 10.0
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"OfficeTrial" = Microsoft Office Home and Student 60 day trial
"Shop for HP Supplies" = Shop for HP Supplies
"sp6" = Logitech SetPoint 6.20
"UDK-20cb887a-3656-4f82-9238-fc15b5fecad2" = My Game Long Name

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{000E79B7-E725-4F01-870A-C12942B7F8E4}" = Crysis®
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{034B8288-5C7B-E367-9E50-DFC71D599675}" = Acukwik
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{04858915-9F49-4B2A-AED4-DC49A7DE6A7B}" = Battlefield 2™
"{06B7DE4D-9098-41AF-B0C0-D3129C72E483}" = Roads of Rome 2
"{0A2C5854-557E-48C8-835A-3B9F074BDCAA}" = Python 2.5
"{0BCA9EFD-F2D6-4638-B053-8693BA0404BE}" = Citrix online plug-in (Web)
"{0F7C2E47-089E-4d23-B9F7-39BE00100776}" = Toolbox
"{13086F8B-2AA9-4488-BC9C-BB6B912A5524}" = muvee autoProducer 6.1
"{14DC0059-00F1-4F62-BD1A-AB23CD51A95E}" = Adobe AIR
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{18669FF9-C8FE-407a-9F70-E674896B1DB4}" = GPBaseService
"{188C0E25-3D65-4DAC-9C00-7483FBA4C7EB}" = Status
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1ADE23D7-7A1E-4AEC-BA5D-EB8A21BED943}" = Video DVD Maker v3.10.0.28
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check for Health Check
"{26A24AE4-039D-4CA4-87B4-2F83217013FF}" = Java 7 Update 13
"{279D3818-7287-4ab4-A927-542EBEA9E365}" = ProductContext
"{2DC94AFD-A6E2-4AB4-9132-4A3F8E07B386}" = Apple Application Support
"{2EA870FA-585F-4187-903D-CB9FFD21E2E0}" = DHTML Editing Component
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{305D4B08-5807-4475-B1C8-D54685534864}" = LightScribeTemplateLabeler
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{36FDBE6E-6684-462b-AE98-9A39A1B200CC}" = HPProductAssistant
"{37D4AB78-5281-44EE-91D8-B65CFE509851}" = Unified Remote
"{380CC749-8C28-4C74-BE01-45921D062302}" = BPDSoftware_Ini
"{3A9E0E2F-B0D1-452B-B833-7A7300EA1231}" = Saitek NT Controller Drivers
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{41853D20-40CC-4266-978D-F128BB97CA96}" = 6400_Help
"{44F2B651-A86A-4B6C-8563-07B66F00F8F8}_is1" = Hawke BRC 1.1.0
"{468D22C0-8080-11E2-B86E-B8AC6F98CCE3}" = Google Earth
"{46BA053F-57B3-4153-BDB6-D37EEC8B12D7}" = LightScribe System Software
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{4D87DC92-C328-46EC-A7B4-9C88129DC696}" = Dead Space™
"{4F94119D-1B71-400e-9F04-B4E5CEAE71F8}_is1" = Sothink Movie DVD Maker
"{5109C064-813E-4e87-B0DE-C8AF7B5BC02B}" = SmartWebPrintingOC
"{52A69E11-7CEB-4a7d-9607-68BA4F39A89B}" = DeviceDiscovery
"{55392E52-1AAD-44C4-BE49-258FFE72434F}" = Citrix online plug-in (USB)
"{55979C41-7D6A-49CC-B591-64AC1BBE2C8B}" = HP Picasso Media Center Add-In
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5ACE69F0-A3E8-44eb-88C1-0A841E700180}" = TrayApp
"{5BB4D7C1-52F2-4BFD-9E40-0D419E2E3021}" = bpd_scan
"{5D934326-165A-413b-B056-26BE1EC082AF}" = J6400
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{5F4C776F-8CBD-4C4F-892F-B568ABDD70C8}" = GameSpy Comrade
"{5F8E2CBB-949D-4175-AC98-5ADE7F6C9697}" = NCsoft Launcher
"{6033673D-2530-4587-8AD0-EB059FC263F9}" = Crysis® 2
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{65BCF909-6AF7-4B01-8EB3-713CE2873DC8}" = Microsoft Expression Web 3
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{676981B7-A2D9-49D0-9F4C-03018F131DA9}" = DocProc
"{687FEF8A-8597-40b4-832C-297EA3F35817}" = BufferChm
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6F3D2F66-F050-45E3-BEB1-6523FE6D6690}" = MotoHelper MergeModules
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{744F6CCF-9F56-40A0-A33D-2A45D53B6046}" = Hoyle Card Games 2004
"{752E90AC-3F11-4EA3-88EA-96441047EC31}" = Microsoft Expression Web 3 SP1
"{75D84EF7-0D8C-4e70-B3FA-7B42A5D4E0EB}" = Mass Effect 2
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{79896C28-C277-42d5-990A-D98E10682654}" = Titan Quest
"{80533B67-C407-485D-8B5D-63BB8ED9D878}" = Scan
"{812424AC-A8B5-44E6-8D48-07E939D1AD9A}" = Citrix online plug-in (HDX)
"{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}" = Microsoft Games for Windows - LIVE Redistributable
"{85C8D391-0EAE-4492-8A0A-2EE8B0B6DA03}" = BPDSoftware
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A85DEAD-7C1F-4368-881C-72AC74CB2E91}" = UnloadSupport
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ULTIMATER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ULTIMATER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ULTIMATER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ULTIMATER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ULTIMATER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ULTIMATER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ULTIMATER_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}_WebDesigner_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ULTIMATER_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}_WebDesigner_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ULTIMATER_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}_WebDesigner_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-0026-0000-0000-0000000FF1CE}" = Microsoft Expression Web
"{90120000-0026-0000-0000-0000000FF1CE}_WebDesigner_{9037FDA8-8383-4B6F-859D-D49C3C625225}" = Microsoft Expression Web Service Pack 1 (SP1)
"{90120000-0026-0409-0000-0000000FF1CE}" = Microsoft Expression Web MUI (English)
"{90120000-0026-0409-0000-0000000FF1CE}_WebDesigner_{C00A9857-850C-4C68-A583-2EF4F24706F5}" = Microsoft Office SharePoint Designer 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_ULTIMATER_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_WebDesigner_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0409-1000-0000000FF1CE}_ULTIMATER_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0409-1000-0000000FF1CE}_WebDesigner_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ULTIMATER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ULTIMATER_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}_WebDesigner_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ULTIMATER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ULTIMATER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ULTIMATER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ULTIMATER_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}_WebDesigner_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0116-0409-1000-0000000FF1CE}_ULTIMATER_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0116-0409-1000-0000000FF1CE}_WebDesigner_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ULTIMATER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{90A4562F-D4A1-4B65-906D-41F236CF6902}" = Path of Exile
"{91120000-002E-0000-0000-0000000FF1CE}" = Microsoft Office Ultimate 2007
"{91120000-002E-0000-0000-0000000FF1CE}_ULTIMATER_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{92BCABD5-D3E4-4983-AA10-315813E2A373}" = ScrewDrivers Client v4 with Citrix Web Client 11.2
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9DBA770F-BF73-4D39-B1DF-6035D95268FC}" = HP Customer Feedback
"{A5AB9D5E-52E2-440e-A3ED-9512E253C81A}" = SolutionCenter
"{A864E257-3554-1299-FB1B-E5D82C2F1077}" = RadarChaos
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A979B2D8-E3EE-4523-A26C-4AF0A6809280}" = Sniper Elite Demo
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{ABA00898-9467-4689-9F40-DE7F58C8429C}" = Fax
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.6)
"{B8DBED1E-8BC3-4d08-B94A-F9D7D88E9BBF}" = HPSSupply
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{C27C82E4-9C53-4D76-9ED3-A01A3D5EE679}" = HP Customer Experience Enhancements
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCB9B81A-167F-4832-B305-D2A0430840B3}" = WebReg
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BD}" = WinZip 14.5
"{CF53CF7C-D996-43EB-9904-DBED57C25625}" = Citrix online plug-in (DV)
"{D142FE39-3386-4d82-9AD3-36D4A92AC3C2}" = DocMgr
"{D2E0F0CC-6BE0-490b-B08B-9267083E34C9}" = MarketResearch
"{D99A8E3A-AE5A-4692-8B19-6F16D454E240}" = Destination Component
"{DA909E62-3B45-4BA1-8B58-FCAEBA4BCEC9}" = NVIDIA PhysX
"{E0810CC2-4B5B-4439-B1D0-452306AF2D64}" = HP Active Support Library
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{EA2DB6E0-72C5-4ef9-A3A0-E6705F4A6A9E}" = Nexon Game Manager
"{EF7E931D-DC84-471B-8DB6-A83358095474}" = EA Download Manager
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{f32502b5-5b64-4882-bf61-77f23edcac4f}" = HP Total Care Advisor
"{FA3B34BE-4246-4062-90A3-34CBBEA12B72}" = HPTCSSetup
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"3DSexVilla2-099.001" = thriXXX 3DSexVilla2-099.001
"AC3Filter" = AC3Filter (remove only)
"AC3Filter_is1" = AC3Filter 1.63b
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"AIM_7" = AIM 7
"AnvSoft Movie DVD Maker_is1" = Movie DVD Maker 3.01
"AsUninst.exe" = Anvil Studio
"ATC Career Prep Software Suite" = ATC Career Prep Software Suite
"Avidemux 2.5" = Avidemux 2.5
"AviSynth" = AviSynth 2.5
"CarbonPoker Odds Calculator_is1" = CarbonPoker Odds Calculator 1.0.3
"CitrixOnlinePluginPackWeb" = Citrix online plug-in - web
"CoffeeCup Free HTML Editor" = CoffeeCup Free HTML Editor
"com.penton.acukwik" = Acukwik
"Crimsonland_is1" = Crimsonland
"Diablo II" = Diablo II
"Diablo III" = Diablo III
"Diablo III Beta" = Diablo III Beta
"DivX Setup.divx.com" = DivX Setup
"EADM" = EA Download Manager
"Evrsoft First Page 2006_is1" = Evrsoft First Page 2006
"ffdshow_is1" = ffdshow [rev 2583] [2009-01-05]
"FreeMacroPlayer" = FreeMacroPlayer
"GameSpy Arcade" = GameSpy Arcade
"gatesofandaron_is1" = Gates of Andaron
"GroundSchool - Airline Transport Pilot (ATP)_is1" = GroundSchool - Airline Transport Pilot (ATP)
"HaaliMkx" = Haali Media Splitter
"Heroes In the Sky" = Heroes In the Sky
"Heroes of Might and Magic® III" = Heroes of Might and Magic® III
"InstallShield_{744F6CCF-9F56-40A0-A33D-2A45D53B6046}" = Hoyle Card Games 2004
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"LimeWire" = LimeWire PRO 5.2.10
"MapleStory" = MapleStory
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"MightyMagoo" = Mighty Magoo
"MotoHelper" = MotoHelper 2.0.24 Driver 4.7.1
"Movie DVD Maker_is1" = Movie DVD Maker 2.7.1021
"Mozilla Firefox 19.0.2 (x86 en-US)" = Mozilla Firefox 19.0.2 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Mystery Case Files - Prime Suspects" = Mystery Case Files - Prime Suspects (remove only)
"N360" = Norton Security Suite
"NoteWorthy Composer 2" = NoteWorthy Composer 2
"NSS" = Norton Security Scan
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"OpenAL" = OpenAL
"PC-Doctor 5 for Windows" = Hardware Diagnostic Tools
"PokerStars.net" = PokerStars.net
"PunkBusterSvc" = PunkBuster Services
"RadarChaos" = RadarChaos
"Runic Games Torchlight" = Torchlight
"Search Toolbar" = Search Toolbar
"Shot Online" = Shot Online
"ShotOnline International" = ShotOnline International- remove only
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"sp43111" = sp43111
"sp44626" = sp44626
"Steam App 10" = Counter-Strike
"Steam App 100" = Counter-Strike: Condition Zero Deleted Scenes
"Steam App 105430" = Age of Empires Online
"Steam App 107100" = Bastion
"Steam App 130" = Half-Life: Blue Shift
"Steam App 18400" = Crazy Machines 2
"Steam App 18420" = Crazy Machines
"Steam App 18450" = Crazy Machines 1.5 New from the Lab
"Steam App 18460" = Crazy Machines 1.5 Inventors Training Camp
"Steam App 20" = Team Fortress Classic
"Steam App 200710" = Torchlight II
"Steam App 204610" = Q.U.B.E. Demo
"Steam App 20730" = Mr. Robot Demo
"Steam App 219850" = Torchlight II Demo
"Steam App 220" = Half-Life 2
"Steam App 240" = Counter-Strike: Source
"Steam App 260" = Counter-Strike: Source Beta
"Steam App 280" = Half-Life: Source
"Steam App 30" = Day of Defeat
"Steam App 300" = Day of Defeat: Source
"Steam App 320" = Half-Life 2: Deathmatch
"Steam App 340" = Half-Life 2: Lost Coast
"Steam App 360" = Half-Life Deathmatch: Source
"Steam App 380" = Half-Life 2: Episode One
"Steam App 40" = Deathmatch Classic
"Steam App 400" = Portal
"Steam App 420" = Half-Life 2: Episode Two
"Steam App 440" = Team Fortress 2
"Steam App 4540" = Titan Quest
"Steam App 4550" = Titan Quest: Immortal Throne
"Steam App 50" = Half-Life: Opposing Force
"Steam App 500" = Left 4 Dead
"Steam App 520" = Team Fortress 2 Beta
"Steam App 550" = Left 4 Dead 2
"Steam App 60" = Ricochet
"Steam App 620" = Portal 2
"Steam App 70" = Half-Life
"Steam App 80" = Counter-Strike: Condition Zero
"thriXXX WebLaunch" = thriXXX WebLaunch
"ULTIMATER" = Microsoft Office Ultimate 2007
"Verizon V CAST Media Manager" = Verizon V CAST Media Manager
"vghd" = VirtuaGirl
"VLC media player" = VLC media player 1.1.11
"Web_3.0.3813.0" = Microsoft Expression Web 3
"WebDesigner" = Microsoft Expression Web Trial
"WildTangent hp Master Uninstall" = My HP Games
"Xvid_is1" = Xvid 1.2.2 final uninstall
"Yahoo! Companion" = Yahoo! Toolbar

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"CarbonPoker" = CarbonPoker
"DirectDownloader" = DirectDownloader
"Dropbox" = Dropbox
"FileZilla Client" = FileZilla Client 3.3.2.1
"NCsoft-Aion" = Aion

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 3/22/2013 8:07:29 AM | Computer Name = Gary-PC | Source = Application Hang | ID = 1002
Description = The program Explorer.EXE version 6.0.6002.18005 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: e30 Start Time: 01ce26f4b2d15121 Termination Time: 15

Error - 3/22/2013 8:12:13 AM | Computer Name = Gary-PC | Source = WinMgmt | ID = 28
Description =

Error - 3/22/2013 6:01:23 PM | Computer Name = Gary-PC | Source = WinMgmt | ID = 28
Description =

Error - 3/22/2013 6:09:34 PM | Computer Name = Gary-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 3/22/2013 6:09:34 PM | Computer Name = Gary-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 3/22/2013 8:10:52 PM | Computer Name = Gary-PC | Source = System Restore | ID = 8199
Description =

Error - 3/22/2013 8:10:52 PM | Computer Name = Gary-PC | Source = VSS | ID = 12293
Description =

Error - 3/22/2013 9:07:28 PM | Computer Name = Gary-PC | Source = System Restore | ID = 8199
Description =

Error - 3/23/2013 7:39:37 AM | Computer Name = Gary-PC | Source = WinMgmt | ID = 28
Description =

Error - 3/23/2013 7:58:02 AM | Computer Name = Gary-PC | Source = System Restore | ID = 8199
Description =

[ Media Center Events ]
Error - 5/22/2012 5:48:53 PM | Computer Name = Gary-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 5/22/2012 7:34:03 PM | Computer Name = Gary-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 5/22/2012 8:35:32 PM | Computer Name = Gary-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 5/22/2012 10:28:14 PM | Computer Name = Gary-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 5/23/2012 7:25:49 AM | Computer Name = Gary-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 5/25/2012 10:58:11 PM | Computer Name = Gary-PC | Source = ehRecvr | ID = 3
Description =

Error - 5/25/2012 10:58:12 PM | Computer Name = Gary-PC | Source = ehRecvr | ID = 3
Description =

Error - 7/5/2012 9:58:13 AM | Computer Name = Gary-PC | Source = ehRecvr | ID = 3
Description =

Error - 7/5/2012 9:58:24 AM | Computer Name = Gary-PC | Source = ehRecvr | ID = 3
Description =

Error - 8/16/2012 1:54:33 PM | Computer Name = Gary-PC | Source = ehSched | ID = 5
Description = CResourceMgr::GetEhepgdat Error GetEhepgdatDispatcher 0x80080005

[ OSession Events ]
Error - 11/19/2010 8:53:22 AM | Computer Name = Gary-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 471
seconds with 120 seconds of active time. This session ended with a crash.

Error - 11/19/2010 8:53:34 AM | Computer Name = Gary-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 3
seconds with 0 seconds of active time. This session ended with a crash.

Error - 11/19/2010 8:54:15 AM | Computer Name = Gary-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 35
seconds with 0 seconds of active time. This session ended with a crash.

Error - 8/21/2011 10:12:47 AM | Computer Name = Gary-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6557.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 164
seconds with 120 seconds of active time. This session ended with a crash.

Error - 2/7/2013 9:36:21 AM | Computer Name = Gary-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 87
seconds with 60 seconds of active time. This session ended with a crash.

Error - 2/7/2013 9:44:36 AM | Computer Name = Gary-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 419
seconds with 120 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 3/23/2013 7:39:44 AM | Computer Name = Gary-PC | Source = Print | ID = 19
Description = The print spooler failed to share printer HPC1DF0F (HP Officejet J6400
series) with shared resource name HPC1DF0F (HP Officejet J6400 series). Error 1753.
The printer cannot be used by others on the network.

Error - 3/23/2013 7:39:44 AM | Computer Name = Gary-PC | Source = Print | ID = 19
Description = The print spooler failed to share printer HP Officejet J6400 series
(Copy 1) fax with shared resource name HP Officejet J6400 series (Copy 1) fax.
Error 1753. The printer cannot be used by others on the network.

Error - 3/23/2013 7:39:44 AM | Computer Name = Gary-PC | Source = Print | ID = 19
Description = The print spooler failed to share printer HP Officejet J6400 series
(Copy 1) with shared resource name HP Officejet J6400 series (Copy 1). Error 1753.
The printer cannot be used by others on the network.

Error - 3/23/2013 7:39:44 AM | Computer Name = Gary-PC | Source = Print | ID = 19
Description = The print spooler failed to share printer HP Officejet J6400 series
with shared resource name HP Officejet J6400 series. Error 1753. The printer cannot
be used by others on the network.

Error - 3/23/2013 7:40:43 AM | Computer Name = Gary-PC | Source = DCOM | ID = 10016
Description =

Error - 3/23/2013 7:50:43 AM | Computer Name = Gary-PC | Source = DCOM | ID = 10016
Description =

Error - 3/23/2013 8:00:43 AM | Computer Name = Gary-PC | Source = DCOM | ID = 10016
Description =

Error - 3/23/2013 8:10:43 AM | Computer Name = Gary-PC | Source = DCOM | ID = 10016
Description =

Error - 3/23/2013 8:20:43 AM | Computer Name = Gary-PC | Source = DCOM | ID = 10016
Description =

Error - 3/23/2013 8:30:43 AM | Computer Name = Gary-PC | Source = DCOM | ID = 10016
Description =


< End of report >
Hi , welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Right click on ComboFix.exe, click Run as Administrator & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. If after running combofix you recieve an message "Illegal operation attempted on a registery key that has been marked for deletion" or similar reboot the computer.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with the combofix log.

Thanks
Thank you for taking the time to help me. I have downloaded Combofix to my desktop and disabled my Norton AntiVirus and Antispyware. I then right clicked on combofix and ran as administrator. The program had started running and I have not clicked on it, however it appears to be stuck for the past hour and I was not sure if this is normal. The last two logs being shown are: Output folder: C:\32788R22FWJFW\N_ Output folder: C:\32788R22FWJFW Should I attempt to restart my machine and run combofix as administrator again? or do I just let it sit as this is part of the process?
Hi biggary1689,


If there isn't even the slightest hint of harddrive activity them combofix has indeed stalled. So we'll go about it differently.

First locate the copy of combofix that you have previously downloaded to your desktop and right click it and click delete. Download a new copy with the instructions below.

Please read through the instructions to familarize youself with what to expect when the tool runs.

It is vitally important that combofix is renamed before it is even started to download


Please download ComboFix from Link 1or Link 2 to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
    -Tools->Options->Main tab
    -Set to "Always ask me where to Save the files".
  • During the download, before you save it to your desktop, rename Combofix to jgh.exe

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix

———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

  • Right click on ComboFix.exe (jgh.exe in your case) and click "Run as Administrator" & follow the prompts.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.



Please post back with
  • combofix log
How is the computer?

Thanks
I have followed the new steps and have gotten past the point where it stalled the last time. However it appears to be stuck again. It opened up a blue box with the title "administrator: AutoScan". It has completed stage_50 and says System file is infected !! Attempting to restore "C:\Windows\system32\Services.exe" with a blinking underscore underneath.
I do have a 1GB and a 4GB flashdrive. However, I do not have a Windows Vista disk. I have a Windows XP Home Edition disk, and a Windows Vista upgrade disk for 32-bit both from an old laptop. Not sure if either of these will help.
Hi biggary1689,

I'm not sure if the Vista upgrade dsk will help. Let's see if the Recovery Environment is installed on the computer.

Reboot the computer and as soon as the computer starts but before the windows logo appears start tapping the F8 key to access the Advanced Boot Options.

When the Advanced Boot Options screen appears do you see an option named Repair your computer?
Hi biggary1689,

Good, that should make this easier. We'll just be using the USB device to run a tool and transfer some small notepads.

Download Farbar Recovery Scan Tool 64-Bit and save it to a flash drive.

Plug the flashdrive into the infected PC. (If you are using the infected computer leave the flashdrive connected)

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.

On the System Recovery Options menu you will get the following options:Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt

[*]Select Command Prompt

[*]In the command window type in notepad and press Enter.

[*]The notepad opens. Under File menu select Open.

[*]Select "Computer" and find your flash drive letter and close the notepad.

[*]In the command window type e:\frst64.exe and press Enter

Note: Replace letter e with the drive letter of your flash drive.
[*]The tool will start to run.

[*]When the tool opens click Yes to disclaimer.

[*]Press Scan button.

[*]It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 13-03-2013 (ATTENTION: FRST version is 11 days old) Ran by [removed] at 24-03-2013 08:27:47 Running from F:\ Windows Vista ™ Home Premium Service Pack 1 (X64) OS Language: English(US) The current controlset is ControlSet001 ==================== Registry (Whitelisted) =================== HKLM\…\Run: [RtHDVCpl] RAVCpl64.exe [x] HKLM\…\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [x] HKLM\…\Run: [IAAnotif] "C:\Program Files (X86)\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [178712 2007-07-12] (Intel Corporation) HKLM\…\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming [1680976 2010-10-28] (Logitech, Inc.) HKLM\…\Run: [Bluetooth Connection Assistant] LBTWIZ.EXE -silent [x] HKLM\…\Run: [ProfilerU] C:\Program Files\Saitek\SD6\Software\ProfilerU.exe [310272 2010-07-29] (Saitek) HKLM\…\Run: [SaiMfd] C:\Program Files\Saitek\SD6\Software\SaiMfd.exe [158208 2010-07-29] (Saitek) HKLM-x32\…\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe [65536 2007-04-18] (Hewlett-Packard Company) HKLM-x32\…\Run: [KBD] C:\HP\KBD\KbdStub.EXE [65536 2006-12-08] () HKLM-x32\…\Run: [] [x] HKLM-x32\…\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\…\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [1135912 2010-03-05] () HKLM-x32\…\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49152 2007-10-14] (Hewlett-Packard) HKLM-x32\…\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2010-11-29] (Apple Inc.) HKLM-x32\…\Run: [ConnectionCenter] "C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup [103768 2009-09-12] (Citrix Systems, Inc.) HKLM-x32\…\Run: [ScrewDrivers RDP Plugin] C:\Program Files (x86)\triCerat\Simplify Printing\ScrewDrivers Client v4\install_rdp.exe [44872 2009-11-12] () HKLM-x32\…\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421160 2011-03-07] (Apple Inc.) HKLM-x32\…\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [946352 2012-12-02] (Adobe Systems Incorporated) HKLM-x32\…\Run: [hpqSRMon] [x] HKLM-x32\…\Run: [4StoryPrePatch] "C:\Program Files (x86)\Gameforge4D\GatesofAndaron\PrePatch.exe" [335872 2010-10-11] (Zamiinc) HKLM-x32\…\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.) HKU\Default\…\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter [2438656 2009-04-10] (Microsoft Corporation) HKU\Default\…\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [972128 2008-04-14] (Hewlett-Packard) HKU\Default User\…\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter [2438656 2009-04-10] (Microsoft Corporation) HKU\Default User\…\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [972128 2008-04-14] (Hewlett-Packard) HKU\Gary\…\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [138240 2008-01-20] (Microsoft Corporation) HKU\Gary\…\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent [1597864 2013-02-14] (Valve Corporation) HKU\Gary\…\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe [x] HKU\Gary\…\Run: [PlayNC Launcher] [x] HKU\Gary\…\Run: [assembly] rundll32.exe "C:\Users\Gary\AppData\Local\Citrix\assembly\cwcojk.dll",AVCConfigGetAPIExtW [x] HKU\UpdatusUser\…\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter [2438656 2009-04-10] (Microsoft Corporation) HKU\UpdatusUser\…\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [972128 2008-04-14] (Hewlett-Packard) Tcpip\Parameters: [DhcpNameServer] 10.0.0.1 Startup: C:\ProgramData\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) Startup: C:\ProgramData\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.) Startup: C:\ProgramData\Start Menu\Programs\Startup\WinZip Quick Pick.lnk ShortcutTarget: WinZip Quick Pick.lnk -> C:\Program Files (x86)\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.) ==================== Services (Whitelisted) =================== 2 HPBtnSrv; C:\hp\HPEZBTN\HPBtnSrv.exe [198240 2007-05-29] () 3 McComponentHostService; "C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe" [235216 2013-02-05] (McAfee, Inc.) 2 MotoHelper; C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe [202048 2010-09-07] () 2 N360; "C:\Program Files (x86)\Norton Security Suite\Engine\3.8.3.6\ccSvcHst.exe" /s "N360" /m "C:\Program Files (x86)\Norton Security Suite\Engine\3.8.3.6\diMaster.dll" /prefetch:1 [135024 2011-10-31] (Symantec Corporation) 2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2012-12-24] () ==================== Drivers (Whitelisted) ===================== 1 BHDrvx64; C:\Windows\System32\Drivers\N360x64\0308030.006\BHDrvx64.sys [334384 2010-03-18] (Symantec Corporation) 1 ccHP; C:\Windows\System32\Drivers\N360x64\0308030.006\ccHPx64.sys [561800 2011-10-11] (Symantec Corporation) 1 eeCtrl; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2012-11-13] (Symantec Corporation) 3 EraserUtilRebootDrv; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [138912 2012-07-31] (Symantec Corporation) 3 HSF_DP; C:\Windows\System32\DRIVERS\CAX_DP.sys [1487872 2008-05-08] (Conexant Systems, Inc.) 1 IDSVia64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20130322.001\IDSvia64.sys [513184 2012-08-31] (Symantec Corporation) 3 NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20130323.008\ENG64.SYS [126192 2013-03-10] (Symantec Corporation) 3 NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20130323.008\EX64.SYS [2087664 2013-03-10] (Symantec Corporation) 3 Ps2; C:\Windows\System32\Drivers\Ps2.sys [21504 2006-09-07] () 3 SaiHFF0C; C:\Windows\System32\Drivers\SaiHFF0C.sys [171144 2007-05-01] (Saitek) 3 SaiMini; C:\Windows\System32\Drivers\SaiMini.sys [22792 2010-08-10] (Saitek) 3 SaiNtBus; C:\Windows\System32\drivers\SaiBus.sys [50056 2010-08-10] (Saitek) 3 SaiUFF0C; C:\Windows\System32\Drivers\SaiUFF0C.sys [34304 2007-05-01] (Saitek) 1 SRTSP; C:\Windows\System32\Drivers\N360x64\0308030.006\SRTSP64.SYS [476720 2010-03-18] (Symantec Corporation) 1 SRTSPX; C:\Windows\system32\drivers\N360x64\0308030.006\SRTSPX64.SYS [32304 2010-03-18] (Symantec Corporation) 0 SymEFA; C:\Windows\System32\drivers\N360x64\0308030.006\SYMEFA64.SYS [402992 2010-03-18] (Symantec Corporation) 3 SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [172592 2010-03-18] (Symantec Corporation) 3 SYMFW; C:\Windows\System32\Drivers\N360x64\0308030.006\SYMFW.SYS [120952 2011-10-11] (Symantec Corporation) 1 SymIM; C:\Windows\System32\DRIVERS\SymIMv.sys [31280 2010-03-18] (Symantec Corporation) 3 SYMNDISV; C:\Windows\System32\Drivers\N360x64\0308030.006\SYMNDISV.SYS [56952 2011-10-11] (Symantec Corporation) 1 SYMTDI; C:\Windows\System32\Drivers\N360x64\0308030.006\SYMTDI.SYS [279160 2011-10-11] (Symantec Corporation) 3 dump_wmimmc; \??\C:\GamesCampus\Shot Online\GameGuard\dump_wmimmc.sys [x] 3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x] 3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x] 3 NPPTNT2; \??\C:\Windows\system32\npptNT2.sys [x] 3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x] 3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x] ==================== NetSvcs (Whitelisted) ==================== ==================== One Month Created Files and Folders ======== 2013-03-24 08:27 - 2013-03-24 08:27 - 00000000 ____D C:\FRST 2013-03-23 10:36 - 2013-03-23 10:58 - 00000000 ___SD C:\jgh 2013-03-23 09:17 - 2011-06-25 22:45 - 00256000 ____A C:\Windows\PEV.exe 2013-03-23 09:17 - 2010-11-07 09:20 - 00208896 ____A C:\Windows\MBR.exe 2013-03-23 09:17 - 2009-04-19 20:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe 2013-03-23 09:17 - 2000-08-30 16:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe 2013-03-23 09:17 - 2000-08-30 16:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe 2013-03-23 09:17 - 2000-08-30 16:00 - 00098816 ____A C:\Windows\sed.exe 2013-03-23 09:17 - 2000-08-30 16:00 - 00080412 ____A C:\Windows\grep.exe 2013-03-23 09:17 - 2000-08-30 16:00 - 00068096 ____A C:\Windows\zip.exe 2013-03-23 09:13 - 2013-03-23 09:14 - 05042224 ____R (Swearware) C:\Users\Gary\Desktop\jgh.exe 2013-03-23 07:26 - 2013-03-23 07:26 - 00000000 ____D C:\Windows\erdnt 2013-03-23 07:26 - 2013-03-23 07:26 - 00000000 ____D C:\Qoobox 2013-03-23 04:33 - 2013-03-23 04:33 - 00072296 ____A C:\Users\Gary\Desktop\Extras.Txt 2013-03-23 04:31 - 2013-03-23 04:31 - 00168338 ____A C:\Users\Gary\Desktop\OTL.Txt 2013-03-23 04:09 - 2013-03-23 04:09 - 00602112 ____A (OldTimer Tools) C:\Users\Gary\Desktop\OTL.exe 2013-03-22 04:08 - 2013-03-22 04:08 - 00000000 ____D C:\Users\Gary\Local Settings\Symantec 2013-03-22 04:08 - 2013-03-22 04:08 - 00000000 ____D C:\Users\Gary\Local Settings\Application Data\Symantec 2013-03-22 04:08 - 2013-03-22 04:08 - 00000000 ____D C:\Users\Gary\AppData\Local\Symantec 2013-03-21 13:22 - 2013-03-21 13:22 - 00000000 ____D C:\ProgramData\Playrix Entertainment 2013-03-21 13:22 - 2013-03-21 13:22 - 00000000 ____D C:\ProgramData\Application Data\Playrix Entertainment 2013-03-21 13:20 - 2013-03-22 03:37 - 00000000 ____D C:\ProgramData\Application Data\AlawarWrapper 2013-03-21 13:20 - 2013-03-22 03:37 - 00000000 ____D C:\ProgramData\AlawarWrapper 2013-03-21 13:20 - 2013-03-21 13:20 - 00000000 ____D C:\Users\Public\Documents\AlawarWrapper 2013-03-21 13:20 - 2013-03-21 13:20 - 00000000 ____D C:\ProgramData\Documents\AlawarWrapper 2013-03-21 13:19 - 2013-03-22 03:46 - 00000000 ____D C:\Program Files (x86)\Alawar 2013-03-21 10:41 - 2013-02-11 18:18 - 00019456 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usb8023.sys 2013-03-17 05:32 - 2013-03-17 05:32 - 00317757 ____A C:\Users\Gary\Desktop\contacts.xps 2013-03-13 13:35 - 2013-01-31 20:09 - 01428992 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-03-13 13:35 - 2013-01-31 20:09 - 01032192 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-03-13 13:35 - 2013-01-31 20:09 - 00108544 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2013-03-13 13:35 - 2013-01-31 20:08 - 01129984 ____A (Microsoft Corporation) C:\Windows\System32\mstime.dll 2013-03-13 13:35 - 2013-01-31 20:07 - 07050752 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-03-13 13:35 - 2013-01-31 20:07 - 05725696 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-03-13 13:35 - 2013-01-31 20:07 - 00761856 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2013-03-13 13:35 - 2013-01-31 20:07 - 00623616 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-03-13 13:35 - 2013-01-31 20:07 - 00422400 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll 2013-03-13 13:35 - 2013-01-31 20:07 - 00375808 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-03-13 13:35 - 2013-01-31 20:07 - 00249856 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll 2013-03-13 13:35 - 2013-01-31 20:07 - 00224768 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-03-13 13:35 - 2013-01-31 20:07 - 00032256 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-03-13 13:35 - 2013-01-31 19:51 - 01176576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-03-13 13:35 - 2013-01-31 19:51 - 00834048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-03-13 13:35 - 2013-01-31 19:51 - 00106496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-03-13 13:35 - 2013-01-31 19:50 - 03621888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-03-13 13:35 - 2013-01-31 19:50 - 00671232 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstime.dll 2013-03-13 13:35 - 2013-01-31 19:50 - 00498688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-03-13 13:35 - 2013-01-31 19:50 - 00479232 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-03-13 13:35 - 2013-01-31 19:49 - 06118400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-03-13 13:35 - 2013-01-31 19:49 - 00380928 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-03-13 13:35 - 2013-01-31 19:49 - 00270336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-03-13 13:35 - 2013-01-31 19:49 - 00193024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-03-13 13:35 - 2013-01-31 19:49 - 00180736 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-03-13 13:35 - 2013-01-31 19:49 - 00027648 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-03-13 13:35 - 2013-01-31 18:51 - 00485376 ____A (Microsoft Corporation) C:\Windows\System32\html.iec 2013-03-13 13:35 - 2013-01-31 18:14 - 01383424 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-03-13 13:35 - 2013-01-31 18:13 - 00389632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-03-13 13:35 - 2013-01-31 17:48 - 01383424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-03-09 04:52 - 2013-03-09 08:31 - 1048088193 ____A C:\Users\Gary\Downloads\ice-thisis40bd72-G.mkv 2013-03-08 04:35 - 2013-03-08 04:36 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-03-06 15:37 - 2013-03-06 15:38 - 13990280 ____A (triCerat, Inc. ) C:\Users\Gary\Downloads\IPCNETWORKCONNECT.exe 2013-03-03 10:30 - 2013-03-03 10:30 - 00000000 ____D C:\Users\Gary\Local Settings\eclipse 2013-03-03 10:30 - 2013-03-03 10:30 - 00000000 ____D C:\Users\Gary\Local Settings\Application Data\eclipse 2013-03-03 10:30 - 2013-03-03 10:30 - 00000000 ____D C:\Users\Gary\AppData\Local\eclipse 2013-02-28 15:44 - 2013-02-28 16:42 - 942816349 ____A C:\Users\Gary\Downloads\lfofpiiiii72bd.dago.mkv 2013-02-25 09:49 - 2013-02-25 09:49 - 00108554 ____A C:\Users\Gary\Desktop\5.xps 2013-02-23 14:38 - 2013-02-23 14:38 - 00000000 ____D C:\Users\Gary\Application Data\Unified Remote 2013-02-23 14:38 - 2013-02-23 14:38 - 00000000 ____D C:\Users\Gary\AppData\Roaming\Unified Remote 2013-02-23 14:37 - 2013-02-23 14:37 - 00000000 ____D C:\Program Files (x86)\Unified Remote 2013-02-23 14:36 - 2013-02-23 14:36 - 04907008 ____A C:\Users\Gary\Downloads\UnifiedRemote_Setup_v2_7_2.msi 2013-02-22 14:45 - 2013-02-22 15:01 - 310891878 ____A C:\Users\Gary\Downloads\suits.s02e16.hdtv.x264-2hd.mp4 ==================== One Month Modified Files and Folders ======= 2013-03-24 04:22 - 2010-03-18 12:39 - 01955771 ____A C:\Windows\WindowsUpdate.log 2013-03-24 04:22 - 2006-11-02 07:42 - 00032630 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2013-03-24 04:22 - 2006-11-02 07:42 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-03-24 04:22 - 2006-11-02 07:22 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-03-24 04:22 - 2006-11-02 07:22 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-03-24 04:14 - 2006-11-02 04:46 - 00769448 ____A C:\Windows\System32\PerfStringBackup.INI 2013-03-24 03:32 - 2011-12-18 11:34 - 00000000 ____D C:\Program Files (x86)\Steam 2013-03-24 03:32 - 2011-11-20 10:54 - 00000890 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-03-24 03:31 - 2013-01-21 13:12 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-03-24 03:30 - 2006-11-02 07:07 - 00000000 ___RD C:\Users\Public\Recorded TV 2013-03-24 03:27 - 2008-05-16 19:19 - 00000000 ____D C:\ProgramData\NVIDIA 2013-03-24 03:27 - 2008-05-16 19:19 - 00000000 ____D C:\ProgramData\Application Data\NVIDIA 2013-03-23 18:25 - 2011-11-20 10:54 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-03-23 11:02 - 2008-01-20 19:26 - 00404048 ____A C:\Windows\PFRO.log 2013-03-23 10:58 - 2013-03-23 10:36 - 00000000 ___SD C:\jgh 2013-03-23 09:14 - 2013-03-23 09:13 - 05042224 ____R (Swearware) C:\Users\Gary\Desktop\jgh.exe 2013-03-23 07:26 - 2013-03-23 07:26 - 00000000 ____D C:\Windows\erdnt 2013-03-23 07:26 - 2013-03-23 07:26 - 00000000 ____D C:\Qoobox 2013-03-23 07:03 - 2011-01-28 04:42 - 00000000 ____D C:\Users\Gary\Application Data\GroundSchool FAA 2013-03-23 07:03 - 2011-01-28 04:42 - 00000000 ____D C:\Users\Gary\AppData\Roaming\GroundSchool FAA 2013-03-23 04:33 - 2013-03-23 04:33 - 00072296 ____A C:\Users\Gary\Desktop\Extras.Txt 2013-03-23 04:31 - 2013-03-23 04:31 - 00168338 ____A C:\Users\Gary\Desktop\OTL.Txt 2013-03-23 04:09 - 2013-03-23 04:09 - 00602112 ____A (OldTimer Tools) C:\Users\Gary\Desktop\OTL.exe 2013-03-22 04:08 - 2013-03-22 04:08 - 00000000 ____D C:\Users\Gary\Local Settings\Symantec 2013-03-22 04:08 - 2013-03-22 04:08 - 00000000 ____D C:\Users\Gary\Local Settings\Application Data\Symantec 2013-03-22 04:08 - 2013-03-22 04:08 - 00000000 ____D C:\Users\Gary\AppData\Local\Symantec 2013-03-22 04:08 - 2012-12-09 10:44 - 00000000 ___RD C:\Users\Gary\Dropbox 2013-03-22 04:08 - 2012-12-09 10:40 - 00000000 ____D C:\Users\Gary\Application Data\Dropbox 2013-03-22 04:08 - 2012-12-09 10:40 - 00000000 ____D C:\Users\Gary\AppData\Roaming\Dropbox 2013-03-22 03:46 - 2013-03-21 13:19 - 00000000 ____D C:\Program Files (x86)\Alawar 2013-03-22 03:39 - 2010-03-18 13:06 - 00000000 ___RD C:\Users\Gary\Desktop\Gary 2013-03-22 03:37 - 2013-03-21 13:20 - 00000000 ____D C:\ProgramData\Application Data\AlawarWrapper 2013-03-22 03:37 - 2013-03-21 13:20 - 00000000 ____D C:\ProgramData\AlawarWrapper 2013-03-21 19:27 - 2011-11-20 10:54 - 00000000 ____D C:\Program Files (x86)\Google 2013-03-21 13:22 - 2013-03-21 13:22 - 00000000 ____D C:\ProgramData\Playrix Entertainment 2013-03-21 13:22 - 2013-03-21 13:22 - 00000000 ____D C:\ProgramData\Application Data\Playrix Entertainment 2013-03-21 13:20 - 2013-03-21 13:20 - 00000000 ____D C:\Users\Public\Documents\AlawarWrapper 2013-03-21 13:20 - 2013-03-21 13:20 - 00000000 ____D C:\ProgramData\Documents\AlawarWrapper 2013-03-18 16:23 - 2010-03-28 05:10 - 00000400 ___AH C:\Windows\Tasks\Norton Security Scan for Gary.job 2013-03-17 05:32 - 2013-03-17 05:32 - 00317757 ____A C:\Users\Gary\Desktop\contacts.xps 2013-03-16 09:44 - 2010-12-04 07:39 - 00000000 ___RD C:\Users\Gary\Desktop\Midlantic Jet 2013-03-14 13:43 - 2010-03-22 09:03 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-03-14 04:23 - 2010-03-18 12:58 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-03-14 04:23 - 2010-03-18 12:58 - 00000000 ____D C:\ProgramData\Application Data\Microsoft Help 2013-03-14 03:24 - 2006-11-02 04:35 - 72013344 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe 2013-03-12 15:31 - 2012-08-23 04:01 - 00693976 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-03-12 15:31 - 2011-09-01 04:10 - 00073432 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-03-09 08:31 - 2013-03-09 04:52 - 1048088193 ____A C:\Users\Gary\Downloads\ice-thisis40bd72-G.mkv 2013-03-08 15:53 - 2012-05-03 05:27 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-03-08 04:36 - 2013-03-08 04:35 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-03-06 19:52 - 2010-03-18 12:52 - 00000330 ____A C:\Windows\Tasks\HPCeeScheduleForGary.job 2013-03-06 17:34 - 2012-06-18 12:21 - 00000000 ____D C:\Users\Gary\Local Settings\Paint.NET 2013-03-06 17:34 - 2012-06-18 12:21 - 00000000 ____D C:\Users\Gary\Local Settings\Application Data\Paint.NET 2013-03-06 17:34 - 2012-06-18 12:21 - 00000000 ____D C:\Users\Gary\AppData\Local\Paint.NET 2013-03-06 15:38 - 2013-03-06 15:37 - 13990280 ____A (triCerat, Inc. ) C:\Users\Gary\Downloads\IPCNETWORKCONNECT.exe 2013-03-03 12:22 - 2012-07-29 04:09 - 00000000 ____D C:\Program Files (x86)\CarbonPoker 2013-03-03 10:30 - 2013-03-03 10:30 - 00000000 ____D C:\Users\Gary\Local Settings\eclipse 2013-03-03 10:30 - 2013-03-03 10:30 - 00000000 ____D C:\Users\Gary\Local Settings\Application Data\eclipse 2013-03-03 10:30 - 2013-03-03 10:30 - 00000000 ____D C:\Users\Gary\AppData\Local\eclipse 2013-03-03 10:29 - 2010-03-18 16:35 - 00000000 ____D C:\Users\Gary\Application Data\Mozilla 2013-03-03 10:29 - 2010-03-18 16:35 - 00000000 ____D C:\Users\Gary\AppData\Roaming\Mozilla 2013-02-28 16:42 - 2013-02-28 15:44 - 942816349 ____A C:\Users\Gary\Downloads\lfofpiiiii72bd.dago.mkv 2013-02-25 09:49 - 2013-02-25 09:49 - 00108554 ____A C:\Users\Gary\Desktop\5.xps 2013-02-25 08:26 - 2012-12-09 10:44 - 00000957 ____A C:\Users\Gary\Desktop\Dropbox.lnk 2013-02-23 14:38 - 2013-02-23 14:38 - 00000000 ____D C:\Users\Gary\Application Data\Unified Remote 2013-02-23 14:38 - 2013-02-23 14:38 - 00000000 ____D C:\Users\Gary\AppData\Roaming\Unified Remote 2013-02-23 14:37 - 2013-02-23 14:37 - 00000000 ____D C:\Program Files (x86)\Unified Remote 2013-02-23 14:36 - 2013-02-23 14:36 - 04907008 ____A C:\Users\Gary\Downloads\UnifiedRemote_Setup_v2_7_2.msi 2013-02-22 15:01 - 2013-02-22 14:45 - 310891878 ____A C:\Users\Gary\Downloads\suits.s02e16.hdtv.x264-2hd.mp4 ZeroAccess: C:\Windows\Installer\{d92f3496-7bbe-9d45-e14b-44aee0e2a1ce} C:\Windows\Installer\{d92f3496-7bbe-9d45-e14b-44aee0e2a1ce}\L C:\Windows\Installer\{d92f3496-7bbe-9d45-e14b-44aee0e2a1ce}\U ZeroAccess: C:\Windows\assembly\GAC_32\Desktop.ini ZeroAccess: C:\Windows\assembly\GAC_64\Desktop.ini ZeroAccess: C:\Users\Gary\AppData\Local\{d92f3496-7bbe-9d45-e14b-44aee0e2a1ce} C:\Users\Gary\AppData\Local\{d92f3496-7bbe-9d45-e14b-44aee0e2a1ce}\@ C:\Users\Gary\AppData\Local\{d92f3496-7bbe-9d45-e14b-44aee0e2a1ce}\L C:\Users\Gary\AppData\Local\{d92f3496-7bbe-9d45-e14b-44aee0e2a1ce}\U ==================== Known DLLs (Whitelisted) ================= ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe B8844F93D2C5F1DCDB179AAA9AF134B7 ZeroAccess <==== ATTENTION!. C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys [2012-12-12 04:30] - [2012-08-21 03:50] - 0267648 ____A (Microsoft Corporation) 582F710097B46140F5A89A19A6573D4B ==================== EXE ASSOCIATION ===================== HKLM\…\.exe: exefile => OK HKLM\…\exefile\DefaultIcon: %1 => OK HKLM\…\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= Restore point made on: 2013-02-07 10:37:58 Restore point made on: 2013-02-09 10:37:24 Restore point made on: 2013-02-09 15:45:47 Restore point made on: 2013-02-09 15:51:42 Restore point made on: 2013-02-09 15:52:42 Restore point made on: 2013-02-10 14:05:50 Restore point made on: 2013-02-14 04:22:14 Restore point made on: 2013-02-23 14:37:40 Restore point made on: 2013-02-25 09:17:14 Restore point made on: 2013-02-26 17:49:49 Restore point made on: 2013-02-28 10:14:24 Restore point made on: 2013-03-04 15:27:03 Restore point made on: 2013-03-05 16:20:42 Restore point made on: 2013-03-07 09:53:57 Restore point made on: 2013-03-09 12:41:12 Restore point made on: 2013-03-10 02:47:30 Restore point made on: 2013-03-11 08:35:40 Restore point made on: 2013-03-14 03:21:59 Restore point made on: 2013-03-14 04:20:04 Restore point made on: 2013-03-15 14:51:33 Restore point made on: 2013-03-16 08:01:57 Restore point made on: 2013-03-17 06:51:41 Restore point made on: 2013-03-22 03:22:46 Restore point made on: 2013-03-22 16:08:34 Restore point made on: 2013-03-23 03:57:27 ==================== Memory info =========================== Percentage of memory in use: 12% Total physical RAM: 6142.33 MB Available physical RAM: 5358.03 MB Total Pagefile: 5730.75 MB Available Pagefile: 5326.54 MB Total Virtual: 8192 MB Available Virtual: 8191.91 MB ==================== Partitions ============================= 1 Drive c: (HP) (Fixed) (Total:687.32 GB) (Free:78.64 GB) NTFS ==>[Drive with boot components (obtained from BCD)] 2 Drive d: (FACTORY_IMAGE) (Fixed) (Total:11.31 GB) (Free:1.1 GB) NTFS ==>[System with boot components (obtained from reading drive)] 4 Drive f: () (Removable) (Total:0.95 GB) (Free:0.89 GB) FAT 10 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Disk ### Status Size Free Dyn Gpt ——– ———- ——- ——- — — Disk 0 Online 699 GB 0 B Disk 1 Online 974 MB 0 B Disk 2 No Media 0 B 0 B Disk 3 No Media 0 B 0 B Disk 4 No Media 0 B 0 B Disk 5 No Media 0 B 0 B Partitions of Disk 0: =============== Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 Primary 687 GB 32 KB Partition 2 Primary 11 GB 687 GB ================================================================================ == Disk: 0 Partition 1 Type : 07 Hidden: No Active: Yes Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 2 C HP NTFS Partition 687 GB Healthy ========================================================= Disk: 0 Partition 2 Type : 07 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 3 D FACTORY_IMA NTFS Partition 11 GB Healthy ========================================================= Partitions of Disk 1: =============== Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 Primary 973 MB 124 KB ================================================================================ == Disk: 1 Partition 1 Type : 06 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 4 F FAT Removable 973 MB Healthy ========================================================= ============================== MBR Partition Table ================== ============================== Partitions of Disk 0: =============== Disk ID: 1549F232 Partition 1: ========= Hex: 8001010007FEFFFF3F0000003D43EA55 Active: YES Type: 07 (NTFS) Size: 687 GB Partition 2: ========= Hex: 00FEFFFF07FEFFFF7C43EA55850F6A01 Active: NO Type: 07 (NTFS) Size: 11 GB ============================== Partitions of Disk 1: =============== Disk ID: 00000000 Partition 1: ========= Hex: 00033B00061FFFDCF7000000696B1E00 Active: NO Type: 06 Size: 973 MB Last Boot: 2013-03-24 03:36 ==================== End Of Log =============================
Hi biggary1689,

Reenter System Recovery like you did before. This time when you run FRST64:

Type the following in the edit box after "Search:".

services.exe


Click Search button and post the log (Search.txt) it makes to your reply.
Farbar Recovery Scan Tool (x64) Version: 13-03-2013 Ran by [removed] at 2013-03-24 09:39:24 Running from F:\ ================== Search: "services.exe" =================== C:\WINDOWS\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe [2010-03-23 04:39] - [2009-04-10 22:27] - 0279552 ____A (Microsoft Corporation) D4E6D91C1349B7BFB3599A6ADA56851B C:\WINDOWS\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe [2008-01-20 18:50] - [2008-01-20 18:50] - 0279040 ____A (Microsoft Corporation) 2B336AB6286D6C81FA02CBAB914E3C6C C:\WINDOWS\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_2d69d4f782c83d8c\services.exe [2010-03-23 04:39] - [2009-04-10 23:10] - 0384512 ____A (Microsoft Corporation) 934E0B7D77FF78C18D9F8891221B6DE3 C:\WINDOWS\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_2b7e5beb85a67240\services.exe [2008-01-20 18:49] - [2008-01-20 18:49] - 0384512 ____A (Microsoft Corporation) DFAC660F0F139276CC9299812DE42719 C:\WINDOWS\SysWOW64\services.exe [2010-03-23 04:39] - [2009-04-10 22:27] - 0279552 ____A (Microsoft Corporation) D4E6D91C1349B7BFB3599A6ADA56851B C:\WINDOWS\System32\services.exe [2010-03-23 04:39] - [2009-04-10 23:10] - 0381952 ____A (Microsoft Corporation) B8844F93D2C5F1DCDB179AAA9AF134B7 ====== End Of Search ======
Hi biggary1689,

Next, download and save to your flashdrive the attached file fixlist.txt

📎fixlist.txt

Next boot the the System Recovery Options like you did before when you did the FRST scan.

Once FRST is open
  • Press Fix button.
  • FRST will process the script in Fixlist.txt
  • It will make a log (fixlog.txt) on the flash drive. Please copy and paste it to your reply.

After running the FRST fix reboot the computer to normal windows.

Please post the log, fixlog.txt

How's the computer?
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-03-2013 Ran by [removed] at 2013-03-24 15:00:50 Run:1 Running from F:\ ============================================== C:\WINDOWS\System32\services.exe moved successfully. C:\WINDOWS\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_2d69d4f782c83d8c\services.exe copied successfully to C:\WINDOWS\System32\services.exe C:\Windows\Installer\{d92f3496-7bbe-9d45-e14b-44aee0e2a1ce} moved successfully. C:\Windows\Installer\{d92f3496-7bbe-9d45-e14b-44aee0e2a1ce}\L not found. C:\Windows\Installer\{d92f3496-7bbe-9d45-e14b-44aee0e2a1ce}\U not found. C:\Windows\assembly\GAC_32\Desktop.ini moved successfully. C:\Windows\assembly\GAC_64\Desktop.ini moved successfully. C:\Users\Gary\AppData\Local\{d92f3496-7bbe-9d45-e14b-44aee0e2a1ce} moved successfully. C:\Users\Gary\AppData\Local\{d92f3496-7bbe-9d45-e14b-44aee0e2a1ce}\@ not found. C:\Users\Gary\AppData\Local\{d92f3496-7bbe-9d45-e14b-44aee0e2a1ce}\L not found. C:\Users\Gary\AppData\Local\{d92f3496-7bbe-9d45-e14b-44aee0e2a1ce}\U not found. ==== End of Fixlog ==== The computer appears to be running good. I am not seeing any trojan popups from Norton.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI