This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Windows infested :( [Solved]

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Something ate my Avast Pro 8, and more… and I hope it has indigestion! :pullhair:

I have a Dell Inspiron 530 with an Intel Core2 Quat CPU Q6600 @ 2.40GHz, 3.00 GB RAM and an ATI Radeon HD 2600 XT display, running Win Vista Home Ultimate as my OS. About a month ago my power supply and motherboard failed and I had that hardware replaced (the motherboard was replaced with a manufacturer-refurbished unit), and everything seems to have been working fine after the repair… until now.

Just over three years ago now, someone here at What_the_Tech kindly assisted me with another issue. At that time, I was introduced to ATF_Cleaner, a utility I've found very useful ever since.

Earlier this afternoon, I ran (or tried to run) ATF, which I've run without incident a number of times since my hardware repair a month ago and which has co-existed happily with my Avast Pro 8 since I first purchased a year-long Avast subscription last June. To my shock and horror, this afternoon Avast immediately reported that something had infested ATF and had been prevented from running (along with ATF itself, evidently). Avast recommended running a boot-level scan, followed by in-depth follow-up scans after rebooting.

The boot scan began to run. I observed that Avast reported that at least several files were infected in some way, and moved to a security "chest" for safety. The scan was continuing to run for quite a while, and at some point I needed to step away from the computer. By the time I returned, the scan had apparently finished and the system had tried, but failed, to reboot.

After quite a while of fiddling around with the reboot (which seemed to insist that my ATI graphics display driver was not functioning properly, though the driver, which hasn't been changed, does seem to be working as intended now), and a couple of attempts at using system restore to find functional settings for my system, I managed to get Windows rebooted.

Unfortunately, my Avast is no longer functional. It reports that it is turned off, and won't let me turn it back on. It tells me my subscription status is "active" (which it certainly should be) but that there are "0 days remaining" - which doesn't seem right since I purchased it in mid-June 2012. Even if they "backdated" my subscription to the beginning of that month, I should still have an active account through the end of May. I have posted a request for assistance in their tech support forum (marked "emergency") but there has not yet been a response. For the moment, I've activated Windows Defender, which I assume must be at least -slightly- better than using nothing.

Oddly, my sound drivers/speakers no longer work, either (though it was the display driver that Windows seemed to insist was an issue when refusing to reboot).

In summary, I'd like help with:

1) Identifying and destroying the infestation in my system, as quickly and completely as possible.
2) Recovering the functionality of my antivirus software (or a recommendation of something better to use if that's called for).
3) Recovering the functionality of my sound drivers/speakers. And
4) Anything else you may identify as needing correction/improvement.

Per the instructions in the pinned Are You Infected/Welcome topic, I downloaded OTL and ran a custom scan with the details provided.

___________________________________
This is the content of "OTL.Txt":


OTL logfile created on: 4/30/2013 8:22:48 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\LeeAd\Desktop
Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 1.68 Gb Available Physical Memory | 56.14% Memory free
6.20 Gb Paging File | 4.85 Gb Available in Paging File | 78.26% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 688.60 Gb Total Space | 394.42 Gb Free Space | 57.28% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 1.36 Gb Free Space | 13.56% Space Free | Partition Type: NTFS

Computer Name: HOMESYS | User Name: LeeAd | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\LeeAd\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil32_11_7_700_169_ActiveX.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe (Research In Motion Limited)
PRC - C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
PRC - C:\Windows\System32\Ctxfihlp.exe (Creative Technology Ltd)
PRC - C:\Windows\System32\CTxfispi.exe (Creative Technology Ltd)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
PRC - C:\Windows\System32\pmxmiced.exe (Primax Electronics Ltd.)
PRC - C:\Windows\System32\ico.exe (Primax Electronics Ltd.)
PRC - C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe (ScanSoft, Inc.)
PRC - C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe ()
PRC - C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe ()


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Windows\CTXFIRES.DLL ()
MOD - C:\Windows\System32\APOMngr.DLL ()
MOD - C:\Windows\System32\atitmmxx.dll ()
MOD - C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe ()
MOD - C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe ()


========== Services (SafeList) ==========

SRV - (sprtsvc_dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service /p dellsupportcenter File not found
SRV - (SBSDWSCService) – C:\Program Files\Spybot File not found
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (Blackberry Device Manager) – C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe (Research In Motion Limited)
SRV - (RoxioNow Service) – C:\Program Files\Roxio\RoxioNow Player\RNowSvc.exe (Rovi Corporation)
SRV - (SeagateDashboardService) – C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe (Memeo)
SRV - (CTAudSvcService) – C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
SRV - (Maxtor Sync Service) – C:\Program Files\Maxtor\Sync\SyncServices.exe (Seagate Technology LLC)
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (BcmSqlStartupSvc) – C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
SRV - (SBCSSvc) – C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe (Sunbelt Software)
SRV - (RoxLiveShare10) – C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe (Sonic Solutions)
SRV - (RoxWatch10) – C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe (Sonic Solutions)
SRV - (RoxMediaDB10) – C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe (Sonic Solutions)
SRV - (DellAMBrokerService) – C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe ()
SRV - (AdobeActiveFileMonitor6.0) – C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe ()


========== Driver Services (SafeList) ==========

DRV - (sptd) – System32\Drivers\sptd.sys File not found
DRV - (SBAPIFS) – C:\Windows\system32\drivers\sbapifs.sys File not found
DRV - (NwlnkFwd) – system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – system32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – system32\DRIVERS\ipinip.sys File not found
DRV - (CTHWIUT.DLL) – system32\CTHWIUT.DLL File not found
DRV - (CTEXFIFX.DLL) – system32\CTEXFIFX.DLL File not found
DRV - (CT20XUT.DLL) – system32\CT20XUT.DLL File not found
DRV - (blbdrive) – C:\Windows\system32\drivers\blbdrive.sys File not found
DRV - ({1E444BE9-B8EC-4ce6-8C2B-6536FB7F4FB7}) – C:\Program Files\CyberLink\PowerDVD DX\000.fcl File not found
DRV - (aswSnx) – C:\Windows\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswVmm) – C:\Windows\System32\drivers\aswVmm.sys ()
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (AswRdr) – C:\Windows\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswRvrt) – C:\Windows\System32\drivers\aswRvrt.sys ()
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (aswKbd) – C:\Windows\System32\drivers\aswKbd.sys (AVAST Software)
DRV - (PCDSRVC{E9D79540-57D5953E-06020101}_0) – c:\Program Files\Dell Support Center\pcdsrvc.pkms (PC-Doctor, Inc.)
DRV - (AtiHdmiService) – C:\Windows\System32\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV - (Revoflt) – C:\Windows\System32\drivers\revoflt.sys (VS Revo Group)
DRV - (ha20x2k) – C:\Windows\System32\drivers\ha20x2k.sys (Creative Technology Ltd)
DRV - (emupia) – C:\Windows\System32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) – C:\Windows\System32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – C:\Windows\System32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\Windows\System32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctaud2k) – C:\Windows\System32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – C:\Windows\System32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (CTEXFIFX.SYS) – C:\Windows\System32\drivers\CTEXFIFX.sys (Creative Technology Ltd.)
DRV - (CTEXFIFX) – C:\Windows\System32\drivers\CTEXFIFX.sys (Creative Technology Ltd.)
DRV - (CTHWIUT.SYS) – C:\Windows\System32\drivers\CTHWIUT.sys (Creative Technology Ltd.)
DRV - (CTHWIUT) – C:\Windows\System32\drivers\CTHWIUT.sys (Creative Technology Ltd.)
DRV - (CT20XUT.SYS) – C:\Windows\System32\drivers\CT20XUT.sys (Creative Technology Ltd.)
DRV - (CT20XUT) – C:\Windows\System32\drivers\CT20XUT.sys (Creative Technology Ltd.)
DRV - (ha20x22k) – C:\Windows\System32\drivers\ha20x22k.sys (Creative Technology Ltd)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (datunidr) – C:\Windows\System32\drivers\datunidr.sys (Gteko Ltd.)
DRV - (pmxmouse) – C:\Windows\System32\drivers\pmxmouse.sys (Primax Electronics Ltd.)
DRV - (pmxusblf) – C:\Windows\System32\drivers\pmxusblf.sys (Primax Electronics Ltd.)
DRV - (MXOPSWD) – C:\Windows\System32\drivers\mxopswd.sys (Maxtor Corp.)
DRV - (e1express) – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (HSXHWCD2) – C:\Windows\System32\drivers\HSXHWCD2.sys (Conexant Systems, Inc.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (WimFltr) – C:\Windows\System32\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (PTproct) – C:\Program Files\DellAutomatedPCTuneUp\GTAction\triggers\PTproct.sys (Gteko Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…amp;rlz=1I7DKUS

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\..\SearchScopes\{AB79D3B4-AEDB-428a-B504-BAC00521A1C7}: "URL" = http://www.skywebsearch.com/search.php?sai…q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "about:blank"
FF - prefs.js..extensions.enabledAddons: fdm_ffext%40freedownloadmanager.org:[removed]
FF - prefs.js..extensions.enabledAddons: daplinkchecker%40speedbit.com:1.0.0.9
FF - prefs.js..extensions.enabledAddons: searchpredict%40speedbit.com:1.0.1.0
FF - prefs.js..extensions.enabledAddons: %7B0329E7D6-6F54-462D-93F6-F5C3118BADF2%7D:3.0.6
FF - prefs.js..extensions.enabledAddons: %7Ba0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7%7D:20130129
FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:8.0.1483
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20091028
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.9
FF - prefs.js..extensions.enabledItems: [removed]:1.0.1.0
FF - prefs.js..extensions.enabledItems: {0329E7D6-6F54-462D-93F6-F5C3118BADF2}:3.0.6
FF - prefs.js..extensions.enabledItems: [removed]:8.0.1482
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.11.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.1808.5272\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\LeeAd\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\LeeAd\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\DAP\daplinkchecker [2012/08/03 21:27:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\SearchPredict\PRFireFox [2012/08/03 21:28:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}: C:\Program Files\SPEEDbit Video Downloader\SPFireFox [2012/08/03 21:28:12 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013/04/11 14:51:28 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/04/28 13:02:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/04/23 17:44:32 | 000,000,000 | —D | M]

[2010/03/09 23:13:11 | 000,000,000 | —D | M] (No name found) – C:\Users\LeeAd\AppData\Roaming\Mozilla\Extensions
[2013/04/17 20:22:23 | 000,000,000 | —D | M] (No name found) – C:\Users\LeeAd\AppData\Roaming\Mozilla\Firefox\Profiles\bybdu241.default\extensions
[2013/03/06 20:57:14 | 000,000,000 | —D | M] (WOT) – C:\Users\LeeAd\AppData\Roaming\Mozilla\Firefox\Profiles\bybdu241.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2013/03/06 17:25:07 | 000,020,591 | —- | M] () (No name found) – C:\Users\LeeAd\AppData\Roaming\Mozilla\Firefox\Profiles\bybdu241.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi
[2013/04/11 17:01:55 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2013/04/11 14:51:28 | 000,000,000 | —D | M] (avast! WebRep) – C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2012/08/03 21:27:51 | 000,000,000 | —D | M] (DAP Link Checker) – C:\PROGRAM FILES\DAP\DAPLINKCHECKER
[2012/08/03 21:28:08 | 000,000,000 | —D | M] (SearchPredict) – C:\PROGRAM FILES\SEARCHPREDICT\PRFIREFOX
[2012/08/03 21:28:12 | 000,000,000 | —D | M] (SPEEDbit Video Downloader) – C:\PROGRAM FILES\SPEEDBIT VIDEO DOWNLOADER\SPFIREFOX
[2013/01/12 14:58:05 | 000,000,000 | —D | M] (Free Download Manager plugin) – C:\PROGRAMDATA\FREE DOWNLOAD MANAGER\FIREFOX\EXTENSIONS\1.5.7.9
[2013/04/10 02:58:33 | 000,263,064 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/06/28 11:42:00 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files\mozilla firefox\plugins\npwachk.dll
[2013/04/10 02:57:54 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013/04/10 02:57:54 | 000,002,086 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{
google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - homepage: about:blank
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\LeeAd\AppData\Local\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\LeeAd\AppData\Local\Google\Chrome\Application\26.0.1410.64\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\LeeAd\AppData\Local\Google\Chrome\Application\26.0.1410.64\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U24 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Google Updater (Enabled) = C:\Program Files\Google\Google Updater\2.4.1808.5272\npCIDetect14.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: WOT = C:\Users\LeeAd\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.4.6_0\
CHR - Extension: YouTube = C:\Users\LeeAd\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: DAP Link Checker = C:\Users\LeeAd\AppData\Local\Google\Chrome\User Data\Default\Extensions\bodfdknjhecmadheclfjkhhiofeagdbh\1.0.0.9_0\
CHR - Extension: Google Search = C:\Users\LeeAd\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: SpeedBit Video Downloader = C:\Users\LeeAd\AppData\Local\Google\Chrome\User Data\Default\Extensions\djcpfkccckpeeghiklnhienllljccglb\2.0.7_0\
CHR - Extension: Download Accelerator Plus (DAP) = C:\Users\LeeAd\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffdcfjdljhbehggjdkdioajnknjcpbjb\2.0.10_0\
CHR - Extension: avast! WebRep = C:\Users\LeeAd\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\8.0.1483_0\
CHR - Extension: SpeedBit Search Predict = C:\Users\LeeAd\AppData\Local\Google\Chrome\User Data\Default\Extensions\ledcpigomgblcmofccnacobhmcdkpiea\2.0.2_0\
CHR - Extension: AT_TomSachsV7 = C:\Users\LeeAd\AppData\Local\Google\Chrome\User Data\Default\Extensions\lppegiodmddaaljhkfjokkepamifbekj\3\
CHR - Extension: Gmail = C:\Users\LeeAd\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2012/04/17 23:45:07 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (SearchPredictObj Class) - {389943B0-C3A2-4E69-82CB-8596A84CB3DC} - C:\Program Files\SearchPredict\SearchPredict.dll (SpeedBit Ltd.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (SBCONVERT Class) - {92A9ACF4-9333-43AE-9698-DB283326F87F} - C:\Program Files\SPEEDbit Video Downloader\Toolbar\tbcore3.dll ()
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (Free Download Manager) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll (FreeDownloadManager.ORG)
O2 - BHO: (SpeedBit Link Verification Helper) - {D5974A72-C81C-4DC3-BE77-A8A7BBC8864E} - C:\Program Files\DAP\LinkVerifier.dll (Speedbit Ltd.)
O2 - BHO: (GrabberObj Class) - {FF7C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\SPEEDbit Video Downloader\Toolbar\Grabber.dll (SPEEDbit)
O3 - HKLM\..\Toolbar: (SpeedBit Video Downloader) - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - C:\Program Files\SPEEDbit Video Downloader\Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKCU\..\Toolbar\WebBrowser: (SpeedBit Video Downloader) - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - C:\Program Files\SPEEDbit Video Downloader\Toolbar\tbcore3.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CTxfiHlp] C:\Windows\System32\Ctxfihlp.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [PMX Daemon] C:\Windows\System32\ico.exe (Primax Electronics Ltd.)
O4 - HKLM..\Run: [RIMBBLaunchAgent.exe] C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
O4 - HKLM..\Run: [WrtMon.exe] C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe ()
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Download; with &DAP; - C:\Program Files\DAP\dapextie.htm ()
O8 - Extra context menu item: &Verify; with DAP - C:\Program Files\DAP\dapverify.htm ()
O8 - Extra context menu item: Download &all; with DAP - C:\Program Files\DAP\dapextie2.htm ()
O8 - Extra context menu item: Download all with Free Download Manager - C:\Program Files\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Download selected with Free Download Manager - C:\Program Files\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Download video with Free Download Manager - C:\Program Files\Free Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Download with Free Download Manager - C:\Program Files\Free Download Manager\dllink.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: cinemanow.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: cinemanow.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: roxio.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: roxio.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: roxionow.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: roxionow.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: sonic.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: sonic.com ([]https in Trusted sites)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0E48E3E6-4D02-43D7-8C43-DB655581DDB1}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{69C14783-DDEA-45C0-A7DA-D0ADB27D38BF}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll) - File not found
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll) - File not found
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O22 - SharedTaskScheduler: {E31004D1-A431-41B8-826F-E902F9D95C81} - Windows DreamScene - C:\Windows\System32\DreamScene.dll (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Public\Pictures\APOD\M94's recently revealed outer spiral arms - IR+UV composite image [R Jay Gabany, Blackbird Observ - IAC - IoA Cambridge - Cardiff] .jpg
O24 - Desktop BackupWallPaper: C:\Users\Public\Pictures\APOD\M94's recently revealed outer spiral arms - IR+UV composite image [R Jay Gabany, Blackbird Observ - IAC - IoA Cambridge - Cardiff] .jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2008/06/16 19:39:03 | 000,000,042 | —- | M] () - C:\autorunsc.bat – [ NTFS ]
O32 - AutoRun File - [2008/06/16 19:45:16 | 000,100,412 | —- | M] () - C:\autorunsc.csv – [ NTFS ]
O32 - AutoRun File - [2008/06/16 19:39:03 | 000,249,856 | —- | M] (Sysinternals - www.sysinternals.com) - C:\autorunsc.exe – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk /p \??\K:)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/04/30 20:17:40 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\LeeAd\Desktop\OTL.exe
[2013/04/30 19:51:26 | 000,000,000 | —D | C] – C:\Users\LeeAd\AppData\Local\Adobe
[2013/04/30 19:42:06 | 000,237,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2013/04/23 18:44:04 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Creative Labs Shared
[2013/04/23 17:44:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2013/04/23 17:43:51 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2013/04/23 17:42:03 | 040,437,664 | —- | C] (Apple Inc.) – C:\Users\LeeAd\Desktop\QuickTimeInstaller.exe
[2013/04/17 23:20:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Presto! PageManager 7.15
[2013/04/17 23:16:07 | 000,000,000 | —D | C] – C:\Program Files\NewSoft
[2013/04/17 23:16:07 | 000,000,000 | —D | C] – C:\Windows\System32\Color
[2013/04/17 20:32:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
[2013/04/17 20:32:16 | 000,027,192 | —- | C] (VS Revo Group) – C:\Windows\System32\drivers\revoflt.sys
[2013/04/17 20:32:16 | 000,000,000 | —D | C] – C:\ProgramData\VS Revo Group
[2013/04/17 20:32:15 | 000,000,000 | —D | C] – C:\Program Files\VS Revo Group
[2013/04/16 01:30:23 | 000,000,000 | —D | C] – C:\Program Files\TinyPDF
[2013/04/16 00:46:38 | 000,000,000 | —D | C] – C:\Users\LeeAd\AppData\Roaming\Softland
[2013/04/14 15:02:31 | 000,000,000 | —D | C] – C:\Program Files\PC Tools
[2013/04/14 14:54:10 | 000,202,280 | —- | C] (PC Tools) – C:\Windows\System32\drivers\PCTSD.sys
[2013/04/14 14:54:10 | 000,000,000 | —D | C] – C:\Program Files\Common Files\PC Tools
[2013/04/14 14:49:29 | 000,000,000 | —D | C] – C:\ProgramData\PC Tools
[2013/04/14 14:49:28 | 000,000,000 | —D | C] – C:\Users\LeeAd\AppData\Roaming\TestApp
[2013/04/11 17:36:46 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/04/11 17:36:44 | 000,607,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/04/11 17:36:44 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/04/11 17:36:44 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/04/11 17:36:44 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/04/11 17:36:43 | 001,800,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/04/11 17:36:43 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/04/11 17:36:42 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/04/11 17:29:18 | 003,603,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2013/04/11 17:29:17 | 003,551,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2013/04/11 17:29:17 | 000,049,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrsrv.dll
[2013/04/11 17:29:12 | 000,376,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsrv.dll
[2013/04/11 17:28:54 | 000,015,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usb8023.sys
[2013/04/11 17:28:50 | 002,049,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[34 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\System32\drivers\*.tmp files -> C:\Windows\System32\drivers\*.tmp -> ]
[1 C:\Users\Public\Documents\*.tmp files -> C:\Users\Public\Documents\*.tmp -> ]
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/04/30 20:17:40 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\LeeAd\Desktop\OTL.exe
[2013/04/30 19:51:07 | 001,070,136 | —- | M] () – C:\Users\LeeAd\Documents\NEWSOFT
[2013/04/30 19:36:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/04/30 19:23:17 | 000,003,568 | —- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/04/30 19:23:17 | 000,003,568 | —- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/04/30 17:41:51 | 000,000,940 | —- | M] () – C:\Users\LeeAd\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2013/04/30 17:41:35 | 000,000,422 | —- | M] () – C:\Windows\tasks\SystemToolsDailyTest.job
[2013/04/30 17:27:10 | 000,665,634 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/04/30 17:27:10 | 000,126,428 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/04/30 17:23:41 | 000,065,536 | —- | M] () – C:\Windows\System32\Ikeext.etl
[2013/04/30 17:23:14 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/04/30 17:22:56 | 270,559,819 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/04/30 17:21:50 | 000,055,468 | —- | M] () – C:\Windows\System32\BMXStateBkp-{00000002-00000000-00000001-00001102-00000005-60021102}.rfx
[2013/04/30 17:21:50 | 000,055,468 | —- | M] () – C:\Windows\System32\BMXState-{00000002-00000000-00000001-00001102-00000005-60021102}.rfx
[2013/04/30 17:21:50 | 000,000,788 | —- | M] () – C:\Windows\System32\DVCState-{00000002-00000000-00000001-00001102-00000005-60021102}.rfx
[2013/04/29 13:29:17 | 000,008,160 | —- | M] () – C:\Users\LeeAd\AppData\Local\d3d9caps.dat
[2013/04/29 12:38:36 | 000,000,288 | —- | M] () – C:\Windows\tasks\Spybot - Search & Destroy - Scheduled Task.job
[2013/04/29 03:49:55 | 081,981,616 | —- | M] () – C:\Users\LeeAd\AppData\Local\rx_image32.Cache
[2013/04/29 03:49:30 | 004,216,000 | —- | M] () – C:\Users\LeeAd\AppData\Local\rx_audio.Cache
[2013/04/27 15:30:00 | 000,000,314 | —- | M] () – C:\Windows\tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
[2013/04/26 01:45:24 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1499513834-3245736753-3590406765-1003UA.job
[2013/04/26 01:45:24 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/04/26 01:45:24 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/04/26 01:45:24 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1499513834-3245736753-3590406765-1003Core.job
[2013/04/25 21:11:37 | 000,024,174 | —- | M] () – C:\Users\LeeAd\Documents\KP.kdbx
[2013/04/23 18:47:19 | 000,001,080 | —- | M] () – C:\Windows\System32\settingsbkup.sfm
[2013/04/23 18:47:19 | 000,001,080 | —- | M] () – C:\Windows\System32\settings.sfm
[2013/04/23 18:41:07 | 000,444,952 | —- | M] (Creative Labs) – C:\Windows\System32\wrap_oal.dll
[2013/04/23 18:41:07 | 000,109,080 | —- | M] (Portions © Creative Labs Inc. and NVIDIA Corp.) – C:\Windows\System32\OpenAL32.dll
[2013/04/23 18:41:05 | 000,000,087 | RH– | M] () – C:\Windows\ctfile.rfc
[2013/04/23 17:39:46 | 040,437,664 | —- | M] (Apple Inc.) – C:\Users\LeeAd\Desktop\QuickTimeInstaller.exe
[2013/04/22 14:25:17 | 000,000,564 | —- | M] () – C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2013/04/17 23:20:21 | 000,000,941 | —- | M] () – C:\Users\Public\Desktop\MFSeries Software Guide (US).lnk
[2013/04/17 23:20:14 | 000,001,952 | —- | M] () – C:\Users\Public\Desktop\Presto! PageManager 7.15.lnk
[2013/04/17 23:20:05 | 000,151,566 | —- | M] () – C:\Windows\System32\UninstIPP.isu
[2013/04/17 23:19:08 | 000,000,264 | —- | M] () – C:\Windows\setup.iss
[2013/04/17 20:32:18 | 000,001,091 | —- | M] () – C:\Users\LeeAd\Application Data\Microsoft\Internet Explorer\Quick Launch\Revo Uninstaller Pro.lnk
[2013/04/17 20:32:18 | 000,001,067 | —- | M] () – C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
[2013/04/15 23:03:43 | 000,150,528 | —- | M] () – C:\Users\LeeAd\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/04/14 14:54:49 | 002,636,136 | —- | M] () – C:\Windows\System32\drivers\Cat.DB
[2013/04/11 21:47:23 | 000,002,098 | —- | M] () – C:\Users\Public\Desktop\BlackBerry Desktop Software.lnk
[2013/04/11 20:23:16 | 000,002,085 | —- | M] () – C:\Users\LeeAd\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/04/11 17:50:34 | 000,417,176 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2013/04/11 17:02:01 | 000,000,872 | —- | M] () – C:\Users\LeeAd\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013/04/11 17:02:01 | 000,000,848 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013/04/11 15:28:54 | 000,691,592 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2013/04/11 15:28:54 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/04/11 14:51:42 | 000,002,577 | —- | M] () – C:\Windows\System32\config.nt
[34 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\System32\drivers\*.tmp files -> C:\Windows\System32\drivers\*.tmp -> ]
[1 C:\Users\Public\Documents\*.tmp files -> C:\Users\Public\Documents\*.tmp -> ]
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/04/30 17:21:22 | 270,559,819 | —- | C] () – C:\Windows\MEMORY.DMP
[2013/04/23 18:47:19 | 000,055,468 | —- | C] () – C:\Windows\System32\BMXState-{00000002-00000000-00000001-00001102-00000005-60021102}.rfx
[2013/04/23 18:47:19 | 000,001,080 | —- | C] () – C:\Windows\System32\settingsbkup.sfm
[2013/04/23 18:47:19 | 000,001,080 | —- | C] () – C:\Windows\System32\settings.sfm
[2013/04/23 18:47:19 | 000,000,788 | —- | C] () – C:\Windows\System32\DVCState-{00000002-00000000-00000001-00001102-00000005-60021102}.rfx
[2013/04/17 23:20:14 | 000,001,952 | —- | C] () – C:\Users\Public\Desktop\Presto! PageManager 7.15.lnk
[2013/04/17 21:14:07 | 001,070,136 | —- | C] () – C:\Users\LeeAd\Documents\NEWSOFT
[2013/04/17 20:32:18 | 000,001,091 | —- | C] () – C:\Users\LeeAd\Application Data\Microsoft\Internet Explorer\Quick Launch\Revo Uninstaller Pro.lnk
[2013/04/17 20:32:18 | 000,001,067 | —- | C] () – C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
[2013/04/16 00:46:37 | 000,007,549 | —- | C] () – C:\Windows\System32\dopdf7.ctm
[2013/04/16 00:20:48 | 000,116,736 | —- | C] () – C:\Windows\System32\qvredmonnt.dll
[2013/04/14 16:04:54 | 000,000,288 | —- | C] () – C:\Windows\tasks\Spybot - Search & Destroy - Scheduled Task.job
[2013/04/14 16:02:16 | 000,000,314 | —- | C] () – C:\Windows\tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
[2013/04/14 14:54:16 | 002,636,136 | —- | C] () – C:\Windows\System32\drivers\Cat.DB
[2013/04/12 17:56:54 | 000,002,140 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BOINC Manager.lnk
[2013/04/11 15:29:24 | 000,000,830 | —- | C] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/03/05 21:08:26 | 000,164,736 | —- | C] () – C:\Windows\System32\drivers\aswVmm.sys
[2013/03/05 21:08:24 | 000,049,248 | —- | C] () – C:\Windows\System32\drivers\aswRvrt.sys
[2012/08/03 21:27:49 | 000,109,256 | —- | C] () – C:\Windows\System32\EasyHook64.dll
[2012/08/03 21:27:49 | 000,090,824 | —- | C] () – C:\Windows\System32\EasyHook32.dll
[2012/01/15 23:21:24 | 000,098,304 | —- | C] () – C:\Windows\System32\redmonnt.dll
[2011/12/17 18:12:30 | 000,000,146 | —- | C] () – C:\Windows\WININIT.INI
[2009/05/19 21:26:42 | 004,216,000 | —- | C] () – C:\Users\LeeAd\AppData\Local\rx_audio.Cache
[2009/05/19 21:25:54 | 081,981,616 | —- | C] () – C:\Users\LeeAd\AppData\Local\rx_image32.Cache
[2008/06/06 01:56:20 | 000,008,160 | —- | C] () – C:\Users\LeeAd\AppData\Local\d3d9caps.dat
[2008/06/06 00:09:18 | 000,150,528 | —- | C] () – C:\Users\LeeAd\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/06/05 22:12:46 | 003,932,160 | -HS- | C] () – C:\Users\LeeAd\ntuser.bak

========== ZeroAccess Check ==========

[2006/11/02 08:53:06 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 13:47:00 | 011,586,048 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/04/11 02:28:19 | 000,614,912 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/04/11 02:28:25 | 000,347,648 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013/04/25 22:41:22 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\Audacity
[2008/07/17 02:17:41 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\Canon
[2010/01/15 04:26:05 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\ColorCop
[2008/06/06 01:06:21 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\DataSafeOnline
[2013/04/29 03:35:08 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\Free Download Manager
[2008/06/30 01:29:44 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\Genie-Soft
[2013/03/06 17:51:12 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\IrfanView
[2008/06/29 23:57:05 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\JAM Software
[2010/03/09 23:00:39 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\Javacool Software
[2013/04/30 19:48:23 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\KeePass
[2012/08/04 16:17:38 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\Leadertech
[2008/06/24 03:35:04 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\Maximum Output Software
[2012/08/04 16:35:07 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\Memeo
[2012/05/27 17:28:27 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\mp3DirectCut
[2010/03/04 23:09:29 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\NewSoft
[2011/06/11 20:58:51 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\OverDrive
[2010/10/29 19:44:08 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\PCDr
[2009/02/05 17:13:16 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\PKWARE
[2012/04/24 22:44:49 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\Research In Motion
[2008/07/12 16:59:26 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\ScanSoft
[2012/08/04 16:34:42 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\Seagate
[2011/09/11 01:48:48 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\Smart Recorder
[2013/04/16 00:46:38 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\Softland
[2009/05/19 23:42:25 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\StarBurn
[2013/04/14 14:49:28 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\TestApp

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2006/11/02 08:40:18 | 000,002,791 | —- | M] () MD5=B17D3F048712809BE9643AE542B7D6B0 – C:\Windows\PolicyDefinitions\en-US\Explorer.adml
[2006/11/02 08:40:18 | 000,002,791 | —- | M] () MD5=B17D3F048712809BE9643AE542B7D6B0 – C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.0.6000.16386_en-us_20c9bd966d6a6189\Explorer.adml
[2006/11/02 08:40:18 | 000,002,791 | —- | M] () MD5=B17D3F048712809BE9643AE542B7D6B0 – C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.0.6001.18000_en-us_23007f926a55725d\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2006/11/02 08:34:28 | 000,002,840 | —- | M] () MD5=66DA9157D2CBE355555739AA9EDA1C6D – C:\Windows\PolicyDefinitions\Explorer.admx
[2006/11/02 08:34:28 | 000,002,840 | —- | M] () MD5=66DA9157D2CBE355555739AA9EDA1C6D – C:\Windows\winsxs\x86_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.0.6000.16386_none_1383e7b7f3eacf3c\Explorer.admx
[2006/11/02 08:34:28 | 000,002,840 | —- | M] () MD5=66DA9157D2CBE355555739AA9EDA1C6D – C:\Windows\winsxs\x86_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.0.6001.18000_none_15baa9b3f0d5e010\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2008/10/29 02:20:29 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008/10/29 02:29:41 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008/10/29 23:59:17 | 002,927,616 | —- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2008/05/06 22:16:49 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=6D06CD98D954FE87FB2DB8108793B399 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16549_none_4fac29707cae347a\explorer.exe
[2008/05/06 22:16:49 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=BD06F0BF753BC704B653C3A50F89D362 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20668_none_501f261995dcf2cf\explorer.exe
[2009/04/11 02:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\ERDNT\cache\explorer.exe
[2009/04/11 02:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\explorer.exe
[2009/04/11 02:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2008/10/27 22:15:02 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2006/11/02 05:45:07 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=FD8C53FB002217F6F888BCF6F5D7084D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_4f7de5167cd15deb\explorer.exe
[2008/01/19 03:33:10 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2006/11/02 08:39:48 | 000,036,864 | —- | M] (Microsoft Corporation) MD5=192DD053B43250E264383CDC3D564A18 – C:\Windows\en-US\explorer.exe.mui
[2006/11/02 08:39:48 | 000,036,864 | —- | M] (Microsoft Corporation) MD5=192DD053B43250E264383CDC3D564A18 – C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_03bbc52176b6ba20\explorer.exe.mui

< MD5 for: IEXPLORE.EXE >
[2012/05/17 19:21:54 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=0129BB16161C2FD9A6B19111AB047198 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16446_none_5898f8e3ebb5c47b\iexplore.exe
[2011/07/23 07:02:27 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=04D1DC458C723B291179F8449ACC281D – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19120_none_12355fcb2fdc2111\iexplore.exe
[2008/04/25 00:22:36 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=07ED775D6DB4BFA96D7CFB09EB228418 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16681_none_2d26424d1d17e8b7\iexplore.exe
[2009/01/15 00:14:36 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=0844F5B9CB3BB85A917D347EF1565B6C – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16809_none_2d84c7c91ccfce35\iexplore.exe
[2012/11/13 22:56:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16457_none_588f2941ebbcf9c3\iexplore.exe
[2011/09/30 19:49:11 | 000,638,216 | —- | M] (Microsoft Corporation) MD5=0E1695AD4C30E72D68170F01B4818A80 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23250_none_129e8cd2491214ae\iexplore.exe
[2008/06/26 23:54:09 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=157F8DE991396C536820D7FA5C8DCF7D – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16711_none_2d71f3a71cdf2247\iexplore.exe
[2008/06/06 01:26:46 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=182CAF7403705ACCB51211A761080B8F – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20777_none_2dc0b0c03628049a\iexplore.exe
[2008/10/01 23:50:01 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=19403B64906C9EAC627E3C10847B0FDA – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16757_none_2d4cb5b31cfa2a15\iexplore.exe
[2009/11/21 02:42:38 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=1B6362BB14FCEB9E76BCF9A953B04788 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18865_none_120f459f2ff7e1f8\iexplore.exe
[2009/03/03 00:18:52 | 000,636,072 | —- | M] (Microsoft Corporation) MD5=1DD66A2851DACDEC32EAE8F9A8865ABD – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.21023_none_2df29b2236034119\iexplore.exe
[2012/08/24 03:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16450_none_5888273bebc34862\iexplore.exe
[2010/02/23 11:06:13 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=25DB705A7DC85C208B3CF2D20F118AA7 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.22995_none_127872a6492dd595\iexplore.exe
[2012/05/17 18:59:46 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=268982F1FD671A077C6A2AF41E351436 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20551_none_5912c45104e00183\iexplore.exe
[2012/10/08 04:37:24 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=270A1342BD5AF95CA25A586B4C2F1522 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16455_none_588d28adebbec715\iexplore.exe
[2011/11/03 03:33:09 | 000,638,240 | —- | M] (Microsoft Corporation) MD5=2A268DF89913A0E927091077878EDB3E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23266_none_1299bea24914c8a9\iexplore.exe
[2009/04/11 02:27:44 | 000,636,080 | —- | M] (Microsoft Corporation) MD5=2C5168C856455CC43C4B4E1CC1920001 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6002.18005_none_314d791517204c15\iexplore.exe
[2013/02/22 00:10:00 | 000,757,376 | —- | M] (Microsoft Corporation) MD5=32732CEDE2A1106B736EF3D84054EE04 – C:\Program Files\Internet Explorer\iexplore.exe
[2013/02/22 00:10:00 | 000,757,376 | —- | M] (Microsoft Corporation) MD5=32732CEDE2A1106B736EF3D84054EE04 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16476_none_5878891febce184e\iexplore.exe
[2012/06/02 05:08:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=34B01BBD8F00B6B9C9248DC4F1E3CD01 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16447_none_5899f92debb4ddd2\iexplore.exe
[2008/05/06 22:20:05 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=3C1B2AD79DBF750A15A8832AF8192DB4 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20663_none_2dc77d9e36238626\iexplore.exe
[2010/01/02 10:58:26 | 000,638,216 | —- | M] (Microsoft Corporation) MD5=3D8DA00B028DEA9517066F1CECBFC4A2 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.22973_none_128c11ea491f6b05\iexplore.exe
[2013/02/22 00:10:31 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=4145E2B5663F6FACC08EFDB17B658BB2 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20586_none_58f755ff04f3d409\iexplore.exe
[2010/05/04 02:32:18 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=48A6109E8DF0365195298CC527B7426A – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23019_none_12d2cb5048e98eab\iexplore.exe
[2010/09/08 02:26:34 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=4A719476A6393B1DCACFEB4F3AC6599C – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23067_none_129abb204913e7b2\iexplore.exe
[2009/07/22 02:04:09 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=4B5AEA50CE77FBA4C2D169622DC9B489 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.22903_none_12d7c15e48e6a76e\iexplore.exe
[2008/05/06 22:15:25 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=4C1528C481FFE6E4EFE4BAC7271CE251 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20697_none_2dab0f0236383f55\iexplore.exe
[2008/10/16 00:27:53 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=4CBA2F58668F2D5F3259CBE73E227F25 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20937_none_2debf43c36078f24\iexplore.exe
[2011/07/23 07:42:34 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=4D08A4234D645EFCB30605CC0BFA87F4 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23216_none_12cfce3e48ec3cf4\iexplore.exe
[2008/06/26 21:41:30 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=4DBD95312B1C96C5285D38F1D748CD4D – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20868_none_2dcc82dc361eff27\iexplore.exe
[2010/11/02 02:03:13 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=5AB037B17F8A87D052F5A88E0D29A3C8 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18999_none_11f2d8e9300c984e\iexplore.exe
[2008/01/19 03:33:12 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=5B92133D3E7FB2644677686305E29E81 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18000_none_2f62000919fe80c9\iexplore.exe
[2010/05/04 02:00:35 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=5C9B1062EA7A44E8F6BFDE994B68C7AA – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18928_none_123d88132fd4bb60\iexplore.exe
[2012/08/24 03:49:25 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=62188720CE27B982B4285C03163C9FB3 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20557_none_5918c60d04da998d\iexplore.exe
[2008/10/01 23:32:01 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=6655B851D9EEF7C83395EE52D551B448 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20927_none_2df6c42835ff7333\iexplore.exe
[2013/01/08 18:42:06 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=698EB1E5F8C66344D97C00B5699E871D – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16464_none_58815877ebc7c9af\iexplore.exe
[2008/05/06 22:15:25 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=7023BC3AF58F0C47856AF147E290D81A – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16575_none_2d35117b1d0c34fb\iexplore.exe
[2010/06/26 02:06:48 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=7420BE0E7D3D1320054F7ACA0594953D – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18943_none_1222e6c92fe9748f\iexplore.exe
[2010/12/18 03:19:44 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=7852371DA9EFBC17B645558E23780EAC – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23111_none_12cacae648f0c11a\iexplore.exe
[2011/09/30 19:07:49 | 000,638,216 | —- | M] (Microsoft Corporation) MD5=7ACBBC85FCE4989B533220FC3B291633 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19154_none_1218f12f2ff0da40\iexplore.exe
[2011/05/28 03:09:20 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=7EE10C5413AD7ED1AF9E8FAE1B58FC3E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23181_none_127f1b72492984b1\iexplore.exe
[2008/05/06 22:17:21 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=7F2693693511F7ECD2762081F2F19864 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20734_none_2de8ef92360a48d1\iexplore.exe
[2006/11/02 05:45:14 | 000,623,616 | —- | M] (Microsoft Corporation) MD5=8308F01F27DF839E0010B0F72F855E35 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16386_none_2d2b3e0d1d136ff5\iexplore.exe
[2010/01/02 02:40:20 | 000,638,216 | —- | M] (Microsoft Corporation) MD5=88BD42DAE7CFFEB256CA7145A15E4843 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18882_none_11f6a4e9300acdd5\iexplore.exe
[2009/03/03 00:32:44 | 000,636,072 | —- | M] (Microsoft Corporation) MD5=8BA2B7A05F88BE0D45237A0994AD8366 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22389_none_2f9e23da3354de78\iexplore.exe
[2012/01/07 23:03:04 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\ERDNT\cache\iexplore.exe
[2012/01/07 23:03:04 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16421_none_58a99749ebaa0de6\iexplore.exe
[2008/05/06 22:17:21 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=9143C721DD6482374EFB35BC35944324 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16609_none_2d84c3fd1ccfd3e7\iexplore.exe
[2010/11/02 03:13:47 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=92A17B0A89D14815AACC62CD190B6CE3 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23091_none_127449a04931a37b\iexplore.exe
[2012/06/28 21:00:47 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=93569D46D79F9756ED077156496AFE23 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16448_none_589af977ebb3f729\iexplore.exe
[2008/06/06 01:26:47 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=9437CA21CD48C9B6BFD6F5AC0143D251 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16643_none_2d5382911cf5aba1\iexplore.exe
[2011/02/22 03:18:28 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=9CE5543464432CA73134F170FA2BF823 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23143_none_12ac5bb64907479b\iexplore.exe
[2009/03/03 00:40:22 | 000,636,072 | —- | M] (Microsoft Corporation) MD5=9E6C1527D9A2C64BFD780AA23075380F – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18226_none_2f5265b91a094b03\iexplore.exe
[2008/04/24 22:04:08 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=9F1427F203CA078005C9943800929640 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20823_none_2df2c11a360310b0\iexplore.exe
[2010/02/23 02:39:16 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=9F52FBE99C749E3F32C75124F09F1B03 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18904_none_124f26c32fc81e22\iexplore.exe
[2009/03/08 17:09:24 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18702_none_124d22632fc9f126\iexplore.exe
[2010/12/18 02:28:35 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=B988D7F127B94BD5BF8356FE81B985C4 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19019_none_1249306b2fcbec08\iexplore.exe
[2012/06/02 04:51:58 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=BE967C74B89577B78FB57C061E12B04C – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20553_none_5914c4e504de3431\iexplore.exe
[2011/02/22 02:21:12 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=C1D36A2CBE0CEC4DF593DB1288CF586E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19048_none_1227c05d2fe52684\iexplore.exe
[2009/07/21 17:53:43 | 000,638,216 | —- | M] (Microsoft Corporation) MD5=C33BD196A0301F9B23D9A003D30ED8B0 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18813_none_124354a72fd12395\iexplore.exe
[2011/11/03 02:23:19 | 000,638,240 | —- | M] (Microsoft Corporation) MD5=CCDB0B2D1F2E016966B1DB1097E24842 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19170_none_11ff502f3004acc6\iexplore.exe
[2012/10/08 04:22:05 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=CECB15F834FC2B4B150449717ADE18DD – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20562_none_5908f4af04e736cb\iexplore.exe
[2010/09/08 02:02:42 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=D5A730DFDEAE005373E62BC2A866E3BB – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18975_none_120477992ffffb10\iexplore.exe
[2008/10/16 00:42:58 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=D762642A109433EEDCD332B0A9511137 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16764_none_2d3ee4e91d04fa01\iexplore.exe
[2009/11/21 11:05:17 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=E7F8DF50E483D165BB01F367D3519AA7 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.22956_none_12a4b2a0490c7f28\iexplore.exe
[2009/03/03 00:22:10 | 000,636,072 | —- | M] (Microsoft Corporation) MD5=EA4BE33726155F89D89A3FE7142878E0 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16830_none_2d5b556b1cf03df9\iexplore.exe
[2012/06/28 19:35:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=EB4105348272018D096FEB655CD1608C – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20554_none_5915c52f04dd4d88\iexplore.exe
[2011/05/28 02:09:21 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=ED65737D70FDEAC29F738E77D2496EE5 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19088_none_11fc80ad30059648\iexplore.exe
[2008/05/06 22:20:04 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=EDEE147E416398BB3DD5B0DD4F6F1D32 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16546_none_2d5681891cf2fa7f\iexplore.exe
[2013/01/08 17:32:42 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F05982E56ABD835AA8DF260EEC873E5B – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20573_none_58ff250d04ee6c13\iexplore.exe
[2010/06/26 02:52:42 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=F05B3A2C6CB319DD1377AD566CF5ECE5 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23040_none_12a958f24909fe6f\iexplore.exe
[2009/01/15 00:18:47 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=F0B1CA517977BA2FF6DA33F1B966C488 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20996_none_2daa146a36391d73\iexplore.exe
[2012/11/13 22:19:28 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F691418EE9A6344AEB5C1B0518FBF8AE – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20565_none_590bf58d04e482d0\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2006/11/02 08:39:45 | 000,016,384 | —- | M] (Microsoft Corporation) MD5=3CCDDDBC49DEACA370F39A9F0E146A1B – C:\Windows\winsxs\x86_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_3b55b11a57da5590\iexplore.exe.mui
[2012/01/07 23:03:11 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2012/01/07 23:03:11 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.1.8112.16421_en-us_52562cc123574ecd\iexplore.exe.mui
[2009/03/08 17:27:11 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Windows\winsxs\x86_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_8.0.6001.18702_en-us_207795706a90d6c1\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-058FE8F5.PF >
[2013/04/30 20:22:01 | 000,333,326 | —- | M] () MD5=D23712557AF20E1FE9C447859CA2FDAD – C:\Windows\Prefetch\IEXPLORE.EXE-058FE8F5.pf

< MD5 for: SERVICES >
[2006/09/18 17:41:30 | 000,017,244 | —- | M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7 – C:\Windows\System32\drivers\etc\services
[2006/09/18 17:41:30 | 000,017,244 | —- | M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7 – C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.0.6000.16386_none_024e4071fa6fea95\services

< MD5 for: SERVICES.EXE >
[2008/01/19 03:33:28 | 000,279,040 | —- | M] (Microsoft Corporation) MD5=2B336AB6286D6C81FA02CBAB914E3C6C – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe
[2006/11/02 05:45:40 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=329CF3C97CE4C19375C8ABCABAE258B0 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6000.16386_none_cd28fe6bd05df036\services.exe
[2009/04/11 02:27:59 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B – C:\Windows\ERDNT\cache\services.exe
[2009/04/11 02:27:59 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B – C:\Windows\System32\services.exe
[2009/04/11 02:27:59 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2006/11/02 08:39:23 | 000,017,920 | —- | M] (Microsoft Corporation) MD5=1626EACF0E7E59F85C59DDDD27C4169C – C:\Windows\System32\en-US\services.exe.mui
[2006/11/02 08:39:23 | 000,017,920 | —- | M] (Microsoft Corporation) MD5=1626EACF0E7E59F85C59DDDD27C4169C – C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.0.6000.16386_en-us_67c6851b290a1ced\services.exe.mui

< MD5 for: SERVICES.LNK >
[2008/07/18 23:07:40 | 000,001,688 | —- | M] () MD5=DE5A917AA61C2ED6B066E8B73C0D386F – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2008/07/18 23:07:40 | 000,001,688 | —- | M] () MD5=DE5A917AA61C2ED6B066E8B73C0D386F – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2006/09/18 17:46:11 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\System32\wbem\services.mof
[2006/09/18 17:46:11 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6000.16386_none_cd28fe6bd05df036\services.mof
[2006/09/18 17:46:11 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.mof
[2006/09/18 17:46:11 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.mof

< MD5 for: SERVICES.MSC >
[2006/11/02 08:39:59 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\en-US\services.msc
[2006/09/18 17:29:40 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\services.msc
[2006/11/02 08:39:59 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.0.6000.16386_en-us_a2085506ff73b6e0\services.msc
[2006/09/18 17:29:40 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.0.6000.16386_none_cd2d20a848cfd40f\services.msc
[2006/09/18 17:29:40 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.0.6001.18000_none_cf63e2a445bae4e3\services.msc

< MD5 for: SERVICES.PNG >
[2010/10/26 19:44:16 | 000,001,509 | —- | M] () MD5=F4EC3ABEAE15FA9BB42D721E9D543F44 – C:\Program Files\Dell Support Center\Images\icons\png\24_24\services.png

< MD5 for: SERVICES.SBS >
[2011/03/01 09:58:44 | 000,034,818 | —- | M] () MD5=62AFD4B2025CE6D4706B36F4C4808F9B – C:\Program Files\Spybot - Search & Destroy\Includes\Services.sbs

< MD5 for: WINLOGON.ADML >
[2006/11/02 08:40:19 | 000,008,051 | —- | M] () MD5=5911AB4AD86759363C6C00408A522692 – C:\Windows\PolicyDefinitions\en-US\WinLogon.adml
[2006/11/02 08:40:19 | 000,008,051 | —- | M] () MD5=5911AB4AD86759363C6C00408A522692 – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.0.6000.16386_en-us_92cd4f8bdff6e8f5\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2006/11/02 08:34:27 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\PolicyDefinitions\WinLogon.admx
[2006/11/02 08:34:27 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.0.6000.16386_none_78d69ac67c572ad2\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2009/04/11 02:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\ERDNT\cache\winlogon.exe
[2009/04/11 02:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\System32\winlogon.exe
[2009/04/11 02:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2006/11/02 05:45:57 | 000,308,224 | —- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2008/01/19 03:33:37 | 000,314,880 | —- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2008/01/19 03:40:57 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=26AC28BF50DC112BAA794A83E08588F0 – C:\Windows\System32\en-US\winlogon.exe.mui
[2008/01/19 03:40:57 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=26AC28BF50DC112BAA794A83E08588F0 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6001.18000_en-us_caf8918b0416723a\winlogon.exe.mui
[2006/11/02 08:39:20 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=A1D2856F3EC3C86EBBF1442B0245A8B3 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6000.16386_en-us_c8c1cf8f072b6166\winlogon.exe.mui

< MD5 for: WINLOGON.MOF >
[2006/09/18 17:41:56 | 000,002,794 | —- | M] () MD5=545C578F290B9CDD280966939935B9EA – C:\Windows\System32\wbem\winlogon.mof
[2006/09/18 17:41:56 | 000,002,794 | —- | M] () MD5=545C578F290B9CDD280966939935B9EA – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.0.6000.16386_none_7e0207d478fccc94\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2006/09/18 17:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2008/06/16 19:39:03 | 000,000,042 | —- | M] () – C:\autorunsc.bat
[2008/06/16 19:45:16 | 000,100,412 | —- | M] () – C:\autorunsc.csv
[2008/06/16 19:39:03 | 000,249,856 | —- | M] (Sysinternals - www.sysinternals.com) – C:\autorunsc.exe
[2009/04/11 02:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/09/18 17:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2008/05/06 22:29:16 | 000,005,817 | RH– | M] () – C:\dell.sdr
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2008/07/12 17:04:18 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/05/14 12:20:37 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2008/07/12 17:04:18 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2013/04/30 17:22:57 | 3533,127,680 | -HS- | M] () – C:\pagefile.sys
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2006/11/02 08:35:26 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 08:35:26 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 08:35:26 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/08/28 20:32:23 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 17:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 08:34:09 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 19:58:12 | 000,030,512 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\mdippr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2013/03/06 18:32:51 | 000,041,664 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2008/03/04 14:00:16 | 000,811,776 | —- | M] (Space Sciences Laboratory) – C:\Windows\boinc.scr

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/07/18 23:08:15 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/11/02 06:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 06:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 06:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 06:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 06:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/01/07 23:14:57 | 000,000,444 | -HS- | M] () – C:\Users\LeeAd\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2010/03/29 17:58:50 | 055,330,872 | —- | M] (Advanced Micro Devices, Inc.) – C:\Users\LeeAd\Desktop\10-3_vista32_win7_32_dd_ccc_wdm_enu.exe
[2010/03/01 21:09:34 | 000,050,688 | —- | M] (Atribune.org) – C:\Users\LeeAd\Desktop\ATF_Cleaner.exe
[2012/06/14 01:13:33 | 074,761,776 | —- | M] () – C:\Users\LeeAd\Desktop\avast_free_antivirus_setup.exe
[2012/06/23 16:42:09 | 095,435,360 | —- | M] () – C:\Users\LeeAd\Desktop\avast_pro_antivirus_setup.exe
[2008/06/19 00:27:23 | 077,896,616 | —- | M] (Sunbelt Software ) – C:\Users\LeeAd\Desktop\counterspy.exe
[2010/03/01 21:29:10 | 000,791,393 | —- | M] (Lars Hederer ) – C:\Users\LeeAd\Desktop\erunt_setup.exe
[2012/11/10 03:53:43 | 078,545,304 | —- | M] (Apple Inc.) – C:\Users\LeeAd\Desktop\iTunesSetup.exe
[2010/03/03 22:05:08 | 016,258,848 | —- | M] (Sun Microsystems, Inc.) – C:\Users\LeeAd\Desktop\jre-6u18-windows-i586.exe
[2010/03/01 21:42:21 | 005,115,840 | —- | M] (Malwarebytes Corporation ) – C:\Users\LeeAd\Desktop\mbam-setup.exe
[2008/07/17 16:49:29 | 014,906,880 | —- | M] () – C:\Users\LeeAd\Desktop\MF4100_PrtDriver_V200Win_EN.exe
[2013/04/30 20:17:40 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\LeeAd\Desktop\OTL.exe
[2012/01/08 22:33:00 | 000,569,352 | —- | M] () – C:\Users\LeeAd\Desktop\PDFCreatorSetup.exe
[2013/04/23 17:39:46 | 040,437,664 | —- | M] (Apple Inc.) – C:\Users\LeeAd\Desktop\QuickTimeInstaller.exe
[2011/06/26 15:26:10 | 016,409,960 | —- | M] (Safer Networking Limited ) – C:\Users\LeeAd\Desktop\spybotsd162.exe
[2011/06/02 23:14:40 | 138,901,960 | —- | M] (Trend Micro Inc.) – C:\Users\LeeAd\Desktop\TIS17.5pro_dell_en_setup.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-04-28 17:38:55

========== Alternate Data Streams ==========

@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:862BDB1A
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:56E2E879
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:84098FD3
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:DFC5A2B2

< End of report >
_____________________________________

___________________________________
This is the content of "Extras.Txt":


OTL Extras logfile created on: 4/30/2013 8:22:48 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\LeeAd\Desktop
Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 1.68 Gb Available Physical Memory | 56.14% Memory free
6.20 Gb Paging File | 4.85 Gb Available in Paging File | 78.26% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 688.60 Gb Total Space | 394.42 Gb Free Space | 57.28% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 1.36 Gb Free Space | 13.56% Space Free | Partition Type: NTFS

Computer Name: HOMESYS | User Name: LeeAd | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with &IrfanView;] – "C:\Program Files\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [SPEEDbitVideoConverter] – "C:\Program Files\SPEEDbit Video Downloader\Converter.exe" -convert=%1 (SPEEDbit Ltd.)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{16B2024F-9806-4348-95EF-30D9041296BC}" = lport=4482 | protocol=17 | dir=in | name=blackberry desktop software wireless music sync discovery |
"{448BF74B-9E91-40B1-B664-EC97B7D74BCA}" = lport=4482 | protocol=6 | dir=in | name=blackberry desktop software wireless music sync data transfer |
"{58317299-9D36-45D3-A750-16A8C8B96AA1}" = lport=4481 | protocol=6 | dir=in | name=blackberry desktop software wireless music sync data transfer |
"{87EBC1BB-635F-417D-A9A7-90C6BB98E236}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{C74AD69C-A8D2-4131-93AA-978EC4A91A69}" = lport=4481 | protocol=17 | dir=in | name=blackberry desktop software wireless music sync discovery |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{08F3A9DC-8102-4357-80D2-6A6D4896486A}" = protocol=17 | dir=in | app=c:\program files\roxio\roxionow player\rnowshell.exe |
"{12D74AD3-DB44-4D58-835B-56E39F03F08D}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{41FAAD40-3973-44D7-8408-14B89C41531B}" = dir=in | app=c:\program files\seagate\seagate dashboard\hipservagent\hipservagent.exe |
"{5027134B-1998-44D1-9701-E9F5EF8F7F23}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\pdvddxsrv.exe |
"{81278EDF-D2A4-4C28-AB07-E4862C29676F}" = protocol=17 | dir=in | app=c:\program files\research in motion\blackberry desktop\rim.desktop.exe |
"{86D697F5-6D46-4630-8455-AD0FD28D5CD6}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\powerdvd.exe |
"{D1CBF851-B935-4F7B-BF4F-5074CCB8F430}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{D737102E-231A-471E-88B9-C385D7975040}" = protocol=6 | dir=in | app=c:\program files\roxio\roxionow player\rnowshell.exe |
"{DF768CE8-9F83-4232-B771-E0EAC1608A00}" = protocol=6 | dir=in | app=c:\program files\research in motion\blackberry desktop\rim.desktop.exe |
"{DFEFAC2C-EE65-43FE-AA2E-EA2201613197}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{F8D26468-30AB-4EFF-8819-E78EC2394AFF}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"TCP Query User{03873212-5E66-48D1-A65F-13F214D663FB}C:\program files\winamp\winamp.exe" = protocol=6 | dir=in | app=c:\program files\winamp\winamp.exe |
"UDP Query User{361BC85A-DE6F-4B5B-AE05-20FB4223D03F}C:\program files\winamp\winamp.exe" = protocol=17 | dir=in | app=c:\program files\winamp\winamp.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0090A87C-3E0E-43D4-AA71-A71B06563A4A}" = Dell Support Center
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{098122AB-C605-4853-B441-C0A4EB359B75}" = DirectXInstallService
"{0EDEB615-1A60-425E-8306-0E10519C7B55}" = RoxioNow Player
"{0F756CD9-4A1E-409B-B101-601DDC4C03AA}" = QualxServ Service Agreement
"{18F11181-EA1A-42AE-AF89-4867C7F7A6FA}" = Sound Blaster X-Fi
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{239A8D60-270B-42e8-82D3-60D70A2942E0}" = Canon MF4100 Series
"{268278CF-FB69-4D98-B70E-BFEC1CDCA225}" = iTunes
"{28996689-E20A-E63B-2BDA-B662AB807C87}" = ATI Catalyst Install Manager
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{38676C9C-270F-43D1-926A-E45DE8820A6B}" = BlackBerry Device Software Updater
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3E2C691B-B7E6-4053-B5C3-94B8BC407E7A}" = Adobe Premiere Elements 4.0
"{448E2D77-E504-4221-B2C2-93646B344729}" = Mouse Suite for Desktop Computers
"{45C56AA7-ED1B-4800-A97F-EDDF3F3520B1}" = Apple Application Support
"{4D3C9F4B-4B7D-4E5D-99B9-0123AB0D51ED}" = Dell DataSafe Online
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{529125EF-E3AC-4B74-97E6-F688A7C0F1BF}" = Paint.NET v3.5.10
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}" = User's Guides
"{62230596-37E5-4618-A329-0D21F529A86F}" = Browser Address Error Redirector
"{6446BBD0-CB83-40E1-BEA1-0C147065E2A6}" = Maxtor Manager
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler
"{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1" = Revo Uninstaller Pro 3.0.2
"{6767DFEE-8909-453A-B553-C7693912B2EB}" = Canon MF Toolbox 4.9.1.1.mf09
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7136FE70-D1A9-42A5-9BBD-87C440701D9F}" = Sunbelt CounterSpy
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{7670D32F-DAE6-4E49-8C8B-B3F08B5B1686}" = Microsoft SQL Server Native Client
"{777CA40C-0206-4EF6-A0FC-618BF06BF8D0}" = Intel® PRO Network Connections 12.1.11.0
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89CEAE14-DD0F-448E-9554-15781EC9DB24}" = Product Documentation Launcher
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ACC73AA-6511-7C55-B1A9-8E5D1DEAFAA3}" = The Lord of the Rings FREE Trial
"{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}" = Roxio CinePlayer Decoder Pack
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROHYBRIDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROHYBRIDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROHYBRIDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROHYBRIDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROHYBRIDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROHYBRIDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROHYBRIDR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROHYBRIDR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROHYBRIDR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROHYBRIDR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROHYBRIDR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROHYBRIDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{91120000-0031-0000-0000-0000000FF1CE}" = Microsoft Office Professional Hybrid 2007
"{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.4
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{ADF69C76-13FF-49F0-A078-922725A8B1B6}" = BOINC
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{B32C4059-6E7A-41EF-AD20-56DF1872B923}" = Business Contact Manager for Outlook 2007 SP2
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{BB2CB14A-F3A3-4BBF-9111-EBC82049ABA6}" = Roxio Creator Premier
"{BE5B0450-DCCB-4FE9-93E2-3B38D88A745B}" = BlackBerry Desktop Software 7.1
"{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}" = Creative MediaSource 5
"{C0DA129B-1E45-494D-A362-5CD0109C306B}" = WOT for Internet Explorer
"{C1E693A4-B1D5-4DCD-B68D-2087835B7184}" = ScanSoft OmniPage SE 4.0
"{C3A11907-930D-41AC-A135-CC3B12F92011}" = Seagate Dashboard
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240B6}" = WinZip 11.2
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF5C7154-98F4-4D44-A58C-8BC19751CCCC}" = Roxio Creator Premier 10
"{D2D6B9EB-C6DC-4DAA-B4DE-BB7D9735E7DA}" = Presto! PageManager 7.15.14
"{D4AFC7AD-F637-4EDD-BC76-767E4AF78CE1}" = OverDrive Media Console
"{D7769185-9A7C-48D4-8874-5388743A1DE2}" = Music, Photos & Videos Launcher
"{E14ADE0E-75F3-4A46-87E5-26692DD626EC}" = Apple Mobile Device Support
"{E24C2613-6453-4EFE-BDF5-5EA1CA22529E}" = SecureZIP for Windows 12.10.0012
"{E7084B89-69E0-46B3-A118-8F99D06988CD}" = Microsoft SQL Server VSS Writer
"{E8C06CB3-5DB2-4689-B1DC-4A0220DEA96C}" = Consumer Complete Care Services Agreement
"{EC877639-07AB-495C-BFD1-D63AF9140810}" = Roxio Activation Module
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator Premier
"{F54AC413-D2C6-4A24-B324-370C223C6250}" = Adobe Photoshop Elements 6.0
"{F85C7118-F3DC-4ED9-AB27-3E7931EA3D88}" = Adobe Premiere Elements 4.0 Templates
"{FE34691C-4298-4667-9758-D7F534DD0B94}" = Dell Automated PC TuneUp
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"7-Zip" = 7-Zip 9.22beta
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop Elements 6" = Adobe Photoshop Elements 6.0
"Audacity_is1" = Audacity 2.0.3
"AudioCS" = Creative Audio Control Panel
"avast" = avast! Pro Antivirus
"BlackBerry_Desktop" = BlackBerry Desktop Software 7.1
"Business Contact Manager" = Business Contact Manager for Outlook 2007 SP2
"CD Wave Editor_is1" = CD Wave Editor 1.98
"CNXT_MODEM_USB_VID_0803&PID;_1300" = Zoom V92 USB Faxmodem
"CobBackup9" = Cobian Backup 9
"Creative Sound Blaster Properties" = Creative Sound Blaster Properties
"Dell Support Center" = Dell Support Center
"Download Accelerator Plus (DAP)" = Download Accelerator Plus (DAP)
"eMusic Promotion" = 50 FREE MP3s +1 Free Audiobook!
"ERUNT_is1" = ERUNT 1.1j
"EULAlyzer_is1" = EULAlyzer 2.0
"Exact Audio Copy" = Exact Audio Copy 0.99pb5
"FFmpeg for Audacity_is1" = FFmpeg v0.6.2 for Audacity
"FileBack PC" = FileBack PC
"FLAC" = FLAC 1.2.1b (remove only)
"Free Download Manager_is1" = Free Download Manager 3.9.2
"Google Updater" = Google Updater
"GoToAssist" = GoToAssist 8.0.0.514
"InstallShield_{6446BBD0-CB83-40E1-BEA1-0C147065E2A6}" = Maxtor Manager
"IrfanView" = IrfanView (remove only)
"LAME for Audacity_is1" = LAME v3.98.2 for Audacity
"LAME_is1" = LAME v3.99.3 (for Windows)
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Mozilla Firefox 20.0.1 (x86 en-US)" = Mozilla Firefox 20.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"OpenAL" = OpenAL
"PremElem40" = Adobe Premiere Elements 4.0
"PremElem40Templates" = Adobe Premiere Elements 4.0 Templates
"PROHYBRIDR" = 2007 Microsoft Office system
"PROSetDX" = Intel® PRO Network Connections 12.1.11.0
"SPEEDbit Video Downloader" = SpeedBit Video Downloader
"UltSounds" = Windows Sound Schemes
"UltSounds2" = Ultimate Extras sounds from Microsoft® Tinker™
"Winamp" = Winamp
"WinGimp-2.0_is1" = GIMP 2.6.11

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
"Winamp Detect" = Winamp Detector Plug-in

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 4/5/2012 9:13:21 AM | Computer Name = HomeSys | Source = Application Error | ID = 1000
Description = Faulting application SpybotSD.exe, version 1.6.2.46, time stamp 0x2a425e19,
faulting module SpybotSD.exe, version 1.6.2.46, time stamp 0x2a425e19, exception
code 0xc0000005, fault offset 0x00004d8a, process id 0x15dc, application start time
0x01cd132ddeff5402.

Error - 4/5/2012 9:59:12 AM | Computer Name = HomeSys | Source = Perflib | ID = 1010
Description =

Error - 4/5/2012 9:59:21 AM | Computer Name = HomeSys | Source = Perflib | ID = 1008
Description =

Error - 4/5/2012 10:17:20 AM | Computer Name = HomeSys | Source = Windows Search Service | ID = 3013
Description =

Error - 4/5/2012 10:17:20 AM | Computer Name = HomeSys | Source = Windows Search Service | ID = 3013
Description =

Error - 4/6/2012 3:00:08 PM | Computer Name = HomeSys | Source = Perflib | ID = 1010
Description =

Error - 4/6/2012 3:00:11 PM | Computer Name = HomeSys | Source = Perflib | ID = 1008
Description =

Error - 4/6/2012 5:48:48 PM | Computer Name = HomeSys | Source = EventSystem | ID = 4609
Description =

Error - 4/6/2012 6:04:44 PM | Computer Name = HomeSys | Source = EventSystem | ID = 4609
Description =

Error - 4/7/2012 7:46:28 PM | Computer Name = HomeSys | Source = Perflib | ID = 1010
Description =

Error - 4/7/2012 7:46:40 PM | Computer Name = HomeSys | Source = Perflib | ID = 1008
Description =

[ Media Center Events ]
Error - 10/7/2009 5:29:59 PM | Computer Name = HomeSys | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 10/7/2009 7:04:42 PM | Computer Name = HomeSys | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 10/10/2009 6:05:47 AM | Computer Name = HomeSys | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

[ OSession Events ]
Error - 10/16/2012 1:18:57 AM | Computer Name = HomeSys | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 39
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 4/30/2013 4:59:42 PM | Computer Name = HomeSys | Source = DCOM | ID = 10005
Description =

Error - 4/30/2013 4:59:51 PM | Computer Name = HomeSys | Source = DCOM | ID = 10005
Description =

Error - 4/30/2013 4:59:55 PM | Computer Name = HomeSys | Source = DCOM | ID = 10005
Description =

Error - 4/30/2013 5:00:22 PM | Computer Name = HomeSys | Source = Service Control Manager | ID = 7001
Description =

Error - 4/30/2013 5:00:22 PM | Computer Name = HomeSys | Source = Service Control Manager | ID = 7026
Description =

Error - 4/30/2013 5:04:03 PM | Computer Name = HomeSys | Source = DCOM | ID = 10005
Description =

Error - 4/30/2013 5:23:15 PM | Computer Name = HomeSys | Source = EventLog | ID = 6008
Description = The previous system shutdown at 5:21:36 PM on 4/30/2013 was unexpected.

Error - 4/30/2013 5:23:57 PM | Computer Name = HomeSys | Source = Service Control Manager | ID = 7000
Description =

Error - 4/30/2013 5:23:57 PM | Computer Name = HomeSys | Source = Service Control Manager | ID = 7000
Description =

Error - 4/30/2013 5:23:57 PM | Computer Name = HomeSys | Source = Service Control Manager | ID = 7026
Description =


< End of report >
__________________________________

Thank you very much in advance!
Hi Pretzelogic, Welcome to the forums. What version of Avast are you using? Do you have a link to your topic at the Avast forum? If advised to reinstall Avast please do not do so until we can have a look at what was moved to the chest.
oldman960 -

Thanks very much for the prompt response. My Avast (which I have not yet further modified in any way) is version 8.0.1483; the virus definitions set is now listed as "unknown" (although it was updating regularly until yesterday afternoon when all this happened). I will not try to reinstall Avast until advised here that it will not interfere with your efforts to assist me. Of course, since I have not yet had any response to my "emergency" posting in their "tech support" center, that may not be an issue. :smack:

I'm not sure if it will be possible to see what was moved to the "chest" as I'm not certain that anything ultimately was moved there - I saw that the boot scan, while I observed it running, reported that at least a few items had been so moved, but the Avast user interface console currently shows that the "virus chest" is empty. Was/were something(s) moved, and that fact then concealed? Was/were any intended move(s) defeated? Maybe the What_the_Tech team can figure that out…

I can post a link to my topic at Avast if you really need it, but I'm reluctant to do so in this public forum as it used my irl name, not the "user" name I thought I was logging on with…

Gratefully,
"Pretzelogic"

BTW - I almost forgot: the issue with my sound/speakers that I reported in my original post already seems to have "resolved itself". Last night I'd remembered that a few times before such settings had been disrupted when there'd been any difficulty with rebooting, which was "fixed" when a "normal" reboot was accomplished. So, I tried rebooting my system as I would regularly do (just selecting "reboot" from the "shutdown menu") and when the system had rebooted, the sound (at least) was working normally again. The other problems (and, I suspect, any remaining infestation) have probably not changed, of course. Sorry if I'm getting "ahead" of things and/or otherwise being any sort of pain in your butt.
Hi Pretzelogic,

I can post a link to my topic at Avast if you really need it, but I'm reluctant to do so in this public forum as it used my irl name, not the "user" name I thought I was logging on with

That's fine. From your reply I take it you didn't ask for help HERE?

The OTL looks ok. That's not to say there isn't something there. We will check it though.

From your description of the Avast problem it sound like it may be a result of a corrupt install. Some users have experienced this in the last few weeks.

The detection of ATF may have been a flase positive. This happens from time to time with all antivirus programs.

Do you still have your copy of ATF? If you do let's get it analysed.

To submit a file to virustotal, please click on this link

VirusTotal

  • click the choose a file button
  • a window will open
  • navigate to the location of ATF.exe
  • once you click on the file the window should close and the file should appear in the choose a file box
scroll down a bit and click "Scan it", wait for the results and post them in your next reply.

If it reports the file has all ready been submitted click Reanalyse.

Please note that sometimes the scans take a few minutes. Please ensure that the scan has completed and the results are complete

Let's see if Avast will show us anything. Open the Avast interface and click on Maintenance, click Scan logs.

If anything was logged it should appear in the right hand panel. Click on the log that matches the date of detection. Click the View results button in the lower panel. It should list the files detected and the action taken.

Please post back with
  • Virustotal results
  • info from the Avast log(s) if any
Hello again, oldman960. I am indeed honored to be receiving the assistance of an actual "Forum God"! B)

You're correct in surmising that I haven't requested help from the Avast support "forums" (fora?). As a registered user of their product, I posted an "emergency ticket" requesting direct assistance from their tech support staff. From glancing through the forum postings, it didn't look like I could expect the same level of expertise and assistance I have received here on a couple of past occasions (not sure why this forum is now showing me as a "new user" - I first joined in March, 2010 - I guess my older posts have been "recycled" off the forums by now. Probably just as well…

A corrupt Avast install? I suppose it's possible, but I've been using that product since June 2012, and this is the first problem I've had with it.

A false positive detection would be my fondest hope at this point, but I think I have reasonable suspicion that something more may be at work here…

So, to your instructions:

1) Analysis of ATF.exe by VirusTotal:

When I submitted the file, VirusTotal first gave the following response:

File already analyzed

This file was already analyzed by VirusTotal on 2013-05-01 18:32:10.

Detection ratio: 2/46

You can take a look at the last analysis or analyze it again now.

Following your instructions, I clicked on "Reanalyze" and waited for the scan to complete.

At the top of the page were a few items I'm not sure I understand (though I imagine you will). First, it reported:

SHA256: e900d883001ec60353c2e8e1a54e1c5948a11513fffafbd5a28b44c1e319677a

It also reported a "Detection ratio" of 2/46 (the ratio itself displayed in in red font).

Also at the top of the results page, there was a graphic with a red "devil" to the left next to the number "9" and a green "angel" to the right next to the number "11", along with what looked like a graphic representation of a "meter" with a "needle" pointing partly into the green on the right side of the meter. Not really sure I understand how that's intended to be interpreted…

No infection was reported for -most- of the antivirus analyses performed. However, there were two detection results:

Jiangmin found "Trojan/Genome.awfd"

&

TheHacker found "Posible_Worm32".

In case it's important for any reason for you to see the scan results directly, this is the URL of the scan results page: VirusTotal scan results for ATF

In case the scan results page no longer loads correctly, I also saved a copy of it as a "PDF" file and can attach that, but if I am infested I don't know if you'd want to actually open it. Let me know if you need that for any reason.

2) Avast scan logs:

There is no log listed for the scan I was running when this problem first became apparent. The most recent scan listed was a routine scheduled scan that ran at 3:30 am on 4/30/2013 (i.e., the "night" before), and it showed "no virus found".

However, I was interested to note that a similarly routinely scheduled scan from several nights earlier (3:30 am on 4/26/2013) reported that "some files could not be scanned". Whuh? The report details, which I can't seem to print out or copy/paste, list about 80 files I mostly didn't recognize, along with the following information for each: "Severity" was left blank, and "Status" was shown as "Error: the system cannot find the path specified (3)". The scan results invited me to apply one action for all listed items (no individual action seemed possible): "Move to Chest" (other options could be selected from a drop-down list, but that was what seemed to be the offered default). For now I have not taken any "action", and unless/until advised to do so by you, I won't.

Since I couldn't print, copy, or paste the scan log results, I did a "print screen" and saved the list of the first 24 files or so as a "jpg" (see attached, if you dare). I can do the same for the rest of the files listed if you need it.

Looking further back in time, I spotted a couple of other scans with similar results: the scan from 3:30 am on 4/14/2013 listed 11 files with the same details as noted above. The scan from 3/8/2013 listed 5 files. There were no other scans with results like these listed going back as far as August, 2012. I am a bit concerned that the number of files indicated as unscannable seems to have been increasing with each incidence.

I am also curious as to whether it's a normal result for Avast to find unscannable files in routine scheduled scans, and not alert the user. I admit that I'd long since gotten out of the habit of reviewing each report, "no virus found" being the normal result. My bad, I suppose, but I would have thought that in the event the program ever produced a result other than "no virus found" it might have brought it to my attention - it's certainly not shy about intruding with pop-up alerts when updates are done, etc.

Thanks again for all your help; please let me know as soon as possible what (if anything) needs to be done next.
Hi Pretzelogic,

I am indeed honored to be receiving the assistance of an actual "Forum God"!

Don't pay too much attention to that, it's based on a post count. ;)

IMHO the Avast user forum is one of the best support forums around. Real users with real solutions. Plus the developers are active on the forum as well. The "Tech Support" on the other as with other companies, has been contracted out to a third party.

I'm not sure when you updated to Avast8 but it's been a bit of an adventure for some users. Last week I updated to 8 and well I was in the same boat as you. We'll take care of that and that part should be good. It's quite painless.

Unscanable files are quite common. They are usually compressed or another security program's encrypted files. If Avast doesn't support the packer it can't open them or in the case of encrypted files Avast wouldn't know what encryption was used.

I'm pretty sure that the ATF detection was a FP. Avast is not detecting it with 20130502's database. If you go to the link you posted for the ATF scan and click Additional Information you will see ATF has been reported off and on for over 6 years. This is due to ATF's (and some of the tools we use) code resembles a recent malware addition to the AV's database. The code is close enough to trigger a detection. Avast's default action is "Move to chest" for a reason. It guards against the user deleting a FP. Once deleted it's gone for good.

From the logs and the fact that Avast's chest is empty nothing was moved so we can go ahead and fix that problem.

the screenshot you posted are files in the temporary internet folder. Those are bit's and pieces of web pages you recently visited.

Please follow these instructions to preform a clean uninstall-reinstall.

Download aswClear to your Desktop.
Download the correct version of Avast
http://files.avast.com/iavs5x/avast_free_antivirus_setup.exe
http://files.avast.com/iavs5x/avast_pro_antivirus_setup.exe
http://files.avast.com/iavs5x/avast_intern…urity_setup.exe

Disconnect from the net
Uninstall Avast via control panel

  • Boot to Safe Mode.
    • Restart the computer.
    • As soon as BIOS is loaded begin tapping the F8 key until the Advanced Options menu appears.
    • Use the arrow keys to select the Safe mode with Networking menu item
    • Press Enter.
  • Run aswClear
  • In the Select Product to Uninstall dropdown choose the version of Avast that is on your system.
    [external image: Posted Image]
  • Press Uninstall
  • Once complete reboot your system to Normal Mode
  • Reinstall Avast
Try inserting your licence key.

Let me know how it goes.
oldman960,

Please forgive my delay in responding (particularly since you've been so good about being prompt with your offers of assistance).

Following the instructions in your most recent post, I've gotten my Avast back up and running (although it now reports being program version 8.0.1488, instead of the 8.0.1483 I had before, so maybe they've fixed an incompatibility there). Aside from the version number, in other respects it seems to be the same software as before, and working the same way. My "subscription status" information is now displayed correctly and a "full" scan of my system reported no problems after running for a couple of hours to completion.

I even used my ATF_cleaner utility without complaint from Avast (and cleared out over 29 Mb of file clutter).

My system in all other observable respects also seems to be operating normally.

So… so far, so good. I particularly appreciate your help with uninstalling and reinstalling my Avast - not that it was insurmountably difficult (obviously), but the steps required were sufficiently non-obvious (including the need to download an extra uninstall utility and run it while disconnected from the net) that I might have had some trouble figuring that out on my own. It probably seems like no big deal to you, but… :notworthy: BTW, I still haven't had any response from Avast tech support to the "emergency" support ticket I posted, more than 50 hours after posting it. Thank goodness it wasn't an actual matter of life-or-death. :wacko:

I'm even ready to accept your assessment that this was all the result of a false-positive reaction to the ATF.

Still… I can't help but feel a bit hinky about all of this. I mean, the Avast led me to a boot scan, which was definitely running when I stepped away from my computer but appeared to leave no trace of its existence in the end. That part of the boot scan that I observed absolutely identified at least several different files (and at this point I really wish I could remember which ones) as infected and reported that they'd been moved to the "chest" - except that, apparently, they weren't. Something seems to have messed up my Windows system files to the extent that it took me the better part of two hours to get my system rebooted to a mostly normal status, albeit with my sound drivers initially non-functional (though I'll grant that my relative tech-ignorance may have contributed to the length of time required). And at that point my Avast was pretty much completely trashed and non-functional, to the point where you needed to guide me through the process of uninstalling and reinstalling it.

Are we really sure that there's no lurking nasties in my system? No, um, naughty "bits", as Monty Python might say?

And, if so, how should I evaluate the overall experience? Was this sort of extreme reaction to a false-positive (assuming that to be the case for now) something that any antivirus program might have displayed? The Avast seemed to be highly recommended by a variety of trustworthy sources, and for the nearly full year now that I've been using it, it seems to have been doing a pretty good job. However, this was a rather unnerving result, maybe all the more so if it really was much to-do about essentially nothing. My Avast subscription is due to end in just under two more months - should I be considering some other replacement? If so, are there any you would particularly recommend (bearing in mind that, having been laid-off from my job a couple of months ago, and still seeking employment, I'm on a pretty tight budget)?

Thank you very much for all your help and patience with my paranoid inquisitiveness… I sense that we're almost done now.
Hi Pretzelogic,

8.0.1488 is the current version released yesterday.

List of changes
• New SecureLine component
• Screen readers compatibility improved
• Software Updater improvements
• Improved stability & performance
• Fixed glitches in UI

One of Avast's protocol, for the lack of a better term, is to suggest a boottime scan when it makes a detection like it did with ATF. FPs normally don't result in the advanture you had. I think you may have been a victim of circumstance. Whatever went wrong with Avast went wrong at a very unopportune time. Avast may have been holding some windows files open when windows was loading. Since it was the same VPS that detected ATF falsley it would suggest to me it also detected and reported ATF in the System Restore files.

To put your mind at ease we will run a couple of scans.

Download aswMBR.exe to your desktop.

Double click the aswMBR.exe to run it.

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]

There shall also be a file on your desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) folder. Please attach that zipped file in your next reply.

Next

I see you have downloaded MalwareBytes Antimalware but haven't installed it yey. Please install it and run a scan.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Please post back with
  • aswMBR log
  • mbr.zip
  • MBAM log
oldman960 -

Thanks again for all your help - your explanation of the unsettling sequence of events that led me here this time was very reassuring (and these days, it would be just my luck). I also appreciate your patience with helping me to put my "mind at ease" (obviously, sometimes easier said than done).

Per the instructions in your previous post, I downloaded aswMBR and ran a scan with it:
___________________________
Contents of aswMBR.txt:

aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-05-04 00:20:39
—————————–
00:20:39.430 OS Version: Windows 6.0.6002 Service Pack 2
00:20:39.430 Number of processors: 4 586 0xF0B
00:20:39.430 ComputerName: HOMESYS UserName: LeeAd
00:20:41.302 Initialize success
00:20:42.223 AVAST engine defs: 13050301
00:21:01.598 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
00:21:01.598 Disk 0 Vendor: ST3750640AS 3.ADG Size: 715404MB BusType: 3
00:21:01.723 Disk 0 MBR read successfully
00:21:01.723 Disk 0 MBR scan
00:21:01.723 Disk 0 Windows VISTA default MBR code
00:21:01.738 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63
00:21:01.738 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 10240 MB offset 81920
00:21:01.754 Disk 0 Partition 3 80 (A) 07 HPFS/NTFS NTFS 705123 MB offset 21053440
00:21:01.770 Disk 0 scanning sectors +1465145344
00:21:01.832 Disk 0 scanning C:\Windows\system32\drivers
00:21:18.493 Service scanning
00:21:46.042 Modules scanning
00:22:17.960 Disk 0 trace - called modules:
00:22:18.007 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
00:22:18.334 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8ba3d360]
00:22:18.334 3 CLASSPNP.SYS[8fdc48b3] -> nt!IofCallDriver -> [0x8ad8c918]
00:22:18.350 5 acpi.sys[87ea16bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x8adb2b98]
00:22:19.692 AVAST engine scan C:\Windows
00:22:40.814 AVAST engine scan C:\Windows\system32
00:26:16.468 AVAST engine scan C:\Windows\system32\drivers
00:26:35.251 AVAST engine scan C:\Users\LeeAd
00:35:12.625 AVAST engine scan C:\ProgramData
00:45:25.252 Scan finished successfully
00:46:25.447 Disk 0 MBR has been saved successfully to "C:\Users\LeeAd\Desktop\MBR.dat"
00:46:25.447 The log file has been saved successfully to "C:\Users\LeeAd\Desktop\aswMBR.txt"
_________________________________

As you requested, the file MBR.zip is also attached.

You also advised me to install MalwareBytes Antimalware. To be clear, I'd had that installed some time ago, and for some reason I eventually uninstalled it - I think the Avast, when I first installed it, indicated that it would be a conflict, but I'm not sure at this point.

I had some difficulty with the installation at first - it looked like it was proceeding as intended, but then returned an error message at the point of updating its program/database (I've also attached a screenshot of the error message).

It had been long enough since I'd first acquired the installer that it occurred to me it might just be too far out of date to get the job done. So, first I uninstalled (via the Control Panel) whatever parts of MBAM did get loaded. Then I went to malwarebytes.org, where I was directed to cnet.com to download the most recent version. That did the trick - this installed a trial of the "pro" version (1.75.0.1300) and updated smoothly.

I ran the quick scan as you directed, and it identified two items as "detections". One was a freeware pdf generator I'd acquired not that long ago, and had decided not to use anyway, so having it deemed an "adware agent" and "quarantined and deleted" didn't bother me a bit. The other item, though, was a registry key for Avast. The Avast …seems… to be working as intended at the moment, but maybe it and MBAM don't play nicely together?

I trusted your instructions, though, and kept both items selected while allowing MBAM to reboot my system. Everything seemed to come up functional, though it seemed to take longer than usual to reboot.
______________________________________
Anyway, as requested, here's the contents of mbam-log-2013-05-04 (01-40-30).txt:

Malwarebytes Anti-Malware (Trial) 1.75.0.1300
www.malwarebytes.org

Database version: v2013.05.04.02

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
LeeAd :: HOMESYS [administrator]

Protection: Enabled

5/4/2013 1:40:30 AM
mbam-log-2013-05-04 (01-40-30).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 267159
Time elapsed: 6 minute(s), 18 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 1
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvastSvc.exe (Security.Hijack) -> Delete on reboot.

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\Users\LeeAd\Desktop\PDFCreatorSetup.exe (Adware.Agent) -> Quarantined and deleted successfully.

(end)
______________________________________

At this point, I have the following security software operating:
Windows Firewall
Avast Pro 8.0.1488
Spybot Search & Destroy 1.6.2.0 (this seems to have worked nicely with the Avast since I first installed Avast in June 2012)
and now, the MBAM I described installing above.

Thanks again for your help and advice.
Hi Pretzelogic,

Good job installing MBAM. You were correct the problem was an updating issue due to the setup files age.

MBAM and Avast usually but not always will play nice together. You activated the trial version which means for the term of the trial MBAM will scan in real time. Are you noticing anything unusal since you installed MBAM?

The aswMBR log looks good.

With MBAm of the detection is a setup file. A lot of programs come bundled with adware. Not particularly malicious but sometimes you aren't given the option not to install the adware along with the program.

Please Open MBAM and click on the Quarantine tab. Is the line related to Avast in the list?

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvastSvc.exe
oldman960 -

I can't say I've noticed anything unusual in my system since installing the MBAM… :unsure:

As I recall, that pdf-creation utility (the one I ended up not bothering with) did offer optional installation of some other junk software (which I declined) - I'm not going to miss it.

The MBAM is listing that Avast-related registry line in the Quarantine. That said, it doesn't seem to have prevented the Avast from loading after the reboot, or from performing a scheduled scan (which didn't find anything out of the ordinary).

So… now things are looking pretty good, I guess?

:yeah:
Hi Pretzelogic,

Yes things are looking pretty good.

I'd like a closer look at the Avast detection though as it's rather curious.

We may need a couple of post to check a couple of things.

Open OTL
  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following

    HKLM\SOFTWARE\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972} /s
    C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\quarantine\*.* /s
    %appdata%\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\*.* /s
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
There will only be an OTL.txt this time. Please post it in your next reply.
Hi oldman960 -

It's reassuring to hear that things are looking good, although

I'd like a closer look at the Avast detection though as it's rather curious.

:blink:

D'oh. I guess if there's any possibility of naughty "bits" still lurking anywhere in my system, I'd like to find them and root them out. Also, I have to report that, although I hadn't noticed anything "unusual" in my system at the time of my previous post, I have since noticed that somehow, my folder options preference to display file extensions got switched to NOT display them. I have no idea how or why this would have happened; I certainly didn't do that deliberately myself. Hmmm…

I'm sure glad I have you to help ensure that all is well.

______________________________________________________
Here's the latest content of OTL.Txt:

OTL logfile created on: 5/5/2013 3:15:25 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\LeeAd\Desktop
Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 1.53 Gb Available Physical Memory | 51.13% Memory free
6.20 Gb Paging File | 4.37 Gb Available in Paging File | 70.49% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 688.60 Gb Total Space | 387.39 Gb Free Space | 56.26% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 1.46 Gb Free Space | 14.58% Space Free | Partition Type: NTFS

Computer Name: HOMESYS | User Name: LeeAd | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Users\LeeAd\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe (Research In Motion Limited)
PRC - C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
PRC - C:\Program Files\BOINC\projects\setiathome.berkeley.edu\setiathome_6.03_windows_intelx86.exe (Space Sciences Laboratory)
PRC - C:\Windows\System32\Ctxfihlp.exe (Creative Technology Ltd)
PRC - C:\Windows\System32\CTxfispi.exe (Creative Technology Ltd)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files\BOINC\boincmgr.exe (Space Sciences Laboratory)
PRC - C:\Program Files\BOINC\boinc.exe (Space Sciences Laboratory)
PRC - C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
PRC - C:\Windows\System32\pmxmiced.exe (Primax Electronics Ltd.)
PRC - C:\Windows\System32\ico.exe (Primax Electronics Ltd.)
PRC - C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe (ScanSoft, Inc.)
PRC - C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe ()
PRC - C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe ()


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Windows\CTXFIRES.DLL ()
MOD - C:\Windows\System32\APOMngr.DLL ()
MOD - C:\Program Files\BOINC\projects\setiathome.berkeley.edu\libfftw3f-3-1-1a_upx.dll ()
MOD - C:\Windows\System32\atitmmxx.dll ()
MOD - C:\Program Files\BOINC\zlib1.dll ()
MOD - C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe ()
MOD - C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe ()


========== Services (SafeList) ==========

SRV - (sprtsvc_dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service /p dellsupportcenter File not found
SRV - (SBSDWSCService) – C:\Program Files\Spybot File not found
SRV - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (Blackberry Device Manager) – C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe (Research In Motion Limited)
SRV - (RoxioNow Service) – C:\Program Files\Roxio\RoxioNow Player\RNowSvc.exe (Rovi Corporation)
SRV - (SeagateDashboardService) – C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe (Memeo)
SRV - (CTAudSvcService) – C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
SRV - (Maxtor Sync Service) – C:\Program Files\Maxtor\Sync\SyncServices.exe (Seagate Technology LLC)
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (BcmSqlStartupSvc) – C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
SRV - (SBCSSvc) – C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe (Sunbelt Software)
SRV - (RoxLiveShare10) – C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe (Sonic Solutions)
SRV - (RoxWatch10) – C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe (Sonic Solutions)
SRV - (RoxMediaDB10) – C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe (Sonic Solutions)
SRV - (DellAMBrokerService) – C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe ()
SRV - (AdobeActiveFileMonitor6.0) – C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe ()


========== Driver Services (SafeList) ==========

DRV - (sptd) – System32\Drivers\sptd.sys File not found
DRV - (SBAPIFS) – C:\Windows\system32\drivers\sbapifs.sys File not found
DRV - (NwlnkFwd) – system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – system32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – system32\DRIVERS\ipinip.sys File not found
DRV - (CTHWIUT.DLL) – system32\CTHWIUT.DLL File not found
DRV - (CTEXFIFX.DLL) – system32\CTEXFIFX.DLL File not found
DRV - (CT20XUT.DLL) – system32\CT20XUT.DLL File not found
DRV - (blbdrive) – C:\Windows\system32\drivers\blbdrive.sys File not found
DRV - ({1E444BE9-B8EC-4ce6-8C2B-6536FB7F4FB7}) – C:\Program Files\CyberLink\PowerDVD DX\000.fcl File not found
DRV - (aswVmm) – C:\Windows\System32\drivers\aswVmm.sys ()
DRV - (aswSnx) – C:\Windows\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswRvrt) – C:\Windows\System32\drivers\aswRvrt.sys ()
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (AswRdr) – C:\Windows\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswKbd) – C:\Windows\System32\drivers\aswKbd.sys (AVAST Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (MBAMProtector) – C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (PCDSRVC{E9D79540-57D5953E-06020101}_0) – c:\Program Files\Dell Support Center\pcdsrvc.pkms (PC-Doctor, Inc.)
DRV - (AtiHdmiService) – C:\Windows\System32\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV - (Revoflt) – C:\Windows\System32\drivers\revoflt.sys (VS Revo Group)
DRV - (ha20x2k) – C:\Windows\System32\drivers\ha20x2k.sys (Creative Technology Ltd)
DRV - (emupia) – C:\Windows\System32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) – C:\Windows\System32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – C:\Windows\System32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\Windows\System32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctaud2k) – C:\Windows\System32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – C:\Windows\System32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (CTEXFIFX.SYS) – C:\Windows\System32\drivers\CTEXFIFX.sys (Creative Technology Ltd.)
DRV - (CTEXFIFX) – C:\Windows\System32\drivers\CTEXFIFX.sys (Creative Technology Ltd.)
DRV - (CTHWIUT.SYS) – C:\Windows\System32\drivers\CTHWIUT.sys (Creative Technology Ltd.)
DRV - (CTHWIUT) – C:\Windows\System32\drivers\CTHWIUT.sys (Creative Technology Ltd.)
DRV - (CT20XUT.SYS) – C:\Windows\System32\drivers\CT20XUT.sys (Creative Technology Ltd.)
DRV - (CT20XUT) – C:\Windows\System32\drivers\CT20XUT.sys (Creative Technology Ltd.)
DRV - (ha20x22k) – C:\Windows\System32\drivers\ha20x22k.sys (Creative Technology Ltd)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (datunidr) – C:\Windows\System32\drivers\datunidr.sys (Gteko Ltd.)
DRV - (pmxmouse) – C:\Windows\System32\drivers\pmxmouse.sys (Primax Electronics Ltd.)
DRV - (pmxusblf) – C:\Windows\System32\drivers\pmxusblf.sys (Primax Electronics Ltd.)
DRV - (MXOPSWD) – C:\Windows\System32\drivers\mxopswd.sys (Maxtor Corp.)
DRV - (e1express) – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (HSXHWCD2) – C:\Windows\System32\drivers\HSXHWCD2.sys (Conexant Systems, Inc.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (WimFltr) – C:\Windows\System32\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (PTproct) – C:\Program Files\DellAutomatedPCTuneUp\GTAction\triggers\PTproct.sys (Gteko Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…amp;rlz=1I7DKUS

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\..\SearchScopes\{AB79D3B4-AEDB-428a-B504-BAC00521A1C7}: "URL" = http://www.skywebsearch.com/search.php?sai…q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "about:blank"
FF - prefs.js..extensions.enabledAddons: fdm_ffext%40freedownloadmanager.org:[removed]
FF - prefs.js..extensions.enabledAddons: daplinkchecker%40speedbit.com:1.0.0.9
FF - prefs.js..extensions.enabledAddons: searchpredict%40speedbit.com:1.0.1.0
FF - prefs.js..extensions.enabledAddons: %7B0329E7D6-6F54-462D-93F6-F5C3118BADF2%7D:3.0.6
FF - prefs.js..extensions.enabledAddons: %7Ba0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7%7D:20130129
FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:8.0.1483
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20091028
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.9
FF - prefs.js..extensions.enabledItems: [removed]:1.0.1.0
FF - prefs.js..extensions.enabledItems: {0329E7D6-6F54-462D-93F6-F5C3118BADF2}:3.0.6
FF - prefs.js..extensions.enabledItems: [removed]:8.0.1482
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.11.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.1808.5272\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\LeeAd\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\LeeAd\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\DAP\daplinkchecker [2012/08/03 21:27:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\SearchPredict\PRFireFox [2012/08/03 21:28:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}: C:\Program Files\SPEEDbit Video Downloader\SPFireFox [2012/08/03 21:28:12 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013/05/02 16:02:14 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/04/28 13:02:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/04/23 17:44:32 | 000,000,000 | —D | M]

[2010/03/09 23:13:11 | 000,000,000 | —D | M] (No name found) – C:\Users\LeeAd\AppData\Roaming\Mozilla\Extensions
[2013/04/17 20:22:23 | 000,000,000 | —D | M] (No name found) – C:\Users\LeeAd\AppData\Roaming\Mozilla\Firefox\Profiles\bybdu241.default\extensions
[2013/03/06 20:57:14 | 000,000,000 | —D | M] (WOT) – C:\Users\LeeAd\AppData\Roaming\Mozilla\Firefox\Profiles\bybdu241.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2013/03/06 17:25:07 | 000,020,591 | —- | M] () (No name found) – C:\Users\LeeAd\AppData\Roaming\Mozilla\Firefox\Profiles\bybdu241.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi
[2013/04/11 17:01:55 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2013/05/02 16:02:14 | 000,000,000 | —D | M] (avast! Online Security) – C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2012/08/03 21:27:51 | 000,000,000 | —D | M] (DAP Link Checker) – C:\PROGRAM FILES\DAP\DAPLINKCHECKER
[2012/08/03 21:28:08 | 000,000,000 | —D | M] (SearchPredict) – C:\PROGRAM FILES\SEARCHPREDICT\PRFIREFOX
[2012/08/03 21:28:12 | 000,000,000 | —D | M] (SPEEDbit Video Downloader) – C:\PROGRAM FILES\SPEEDBIT VIDEO DOWNLOADER\SPFIREFOX
[2013/01/12 14:58:05 | 000,000,000 | —D | M] (Free Download Manager plugin) – C:\PROGRAMDATA\FREE DOWNLOAD MANAGER\FIREFOX\EXTENSIONS\1.5.7.9
[2013/04/10 02:58:33 | 000,263,064 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/06/28 11:42:00 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files\mozilla firefox\plugins\npwachk.dll
[2013/04/10 02:57:54 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013/04/10 02:57:54 | 000,002,086 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{
google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - homepage: about:blank
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\LeeAd\AppData\Local\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\LeeAd\AppData\Local\Google\Chrome\Application\26.0.1410.64\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\LeeAd\AppData\Local\Google\Chrome\Application\26.0.1410.64\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U24 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Google Updater (Enabled) = C:\Program Files\Google\Google Updater\2.4.1808.5272\npCIDetect14.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: WOT = C:\Users\LeeAd\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.4.6_0\
CHR - Extension: YouTube = C:\Users\LeeAd\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: DAP Link Checker = C:\Users\LeeAd\AppData\Local\Google\Chrome\User Data\Default\Extensions\bodfdknjhecmadheclfjkhhiofeagdbh\1.0.0.9_0\
CHR - Extension: Google Search = C:\Users\LeeAd\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: SpeedBit Video Downloader = C:\Users\LeeAd\AppData\Local\Google\Chrome\User Data\Default\Extensions\djcpfkccckpeeghiklnhienllljccglb\2.0.7_0\
CHR - Extension: Download Accelerator Plus (DAP) = C:\Users\LeeAd\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffdcfjdljhbehggjdkdioajnknjcpbjb\2.0.10_0\
CHR - Extension: avast! WebRep = C:\Users\LeeAd\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\8.0.1483_0\
CHR - Extension: SpeedBit Search Predict = C:\Users\LeeAd\AppData\Local\Google\Chrome\User Data\Default\Extensions\ledcpigomgblcmofccnacobhmcdkpiea\2.0.2_0\
CHR - Extension: AT_TomSachsV7 = C:\Users\LeeAd\AppData\Local\Google\Chrome\User Data\Default\Extensions\lppegiodmddaaljhkfjokkepamifbekj\3\
CHR - Extension: Gmail = C:\Users\LeeAd\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2012/04/17 23:45:07 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (SearchPredictObj Class) - {389943B0-C3A2-4E69-82CB-8596A84CB3DC} - C:\Program Files\SearchPredict\SearchPredict.dll (SpeedBit Ltd.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (SBCONVERT Class) - {92A9ACF4-9333-43AE-9698-DB283326F87F} - C:\Program Files\SPEEDbit Video Downloader\Toolbar\tbcore3.dll ()
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (Free Download Manager) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll (FreeDownloadManager.ORG)
O2 - BHO: (SpeedBit Link Verification Helper) - {D5974A72-C81C-4DC3-BE77-A8A7BBC8864E} - C:\Program Files\DAP\LinkVerifier.dll (Speedbit Ltd.)
O2 - BHO: (GrabberObj Class) - {FF7C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\SPEEDbit Video Downloader\Toolbar\Grabber.dll (SPEEDbit)
O3 - HKLM\..\Toolbar: (SpeedBit Video Downloader) - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - C:\Program Files\SPEEDbit Video Downloader\Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKCU\..\Toolbar\WebBrowser: (SpeedBit Video Downloader) - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - C:\Program Files\SPEEDbit Video Downloader\Toolbar\tbcore3.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CTxfiHlp] C:\Windows\System32\Ctxfihlp.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [PMX Daemon] C:\Windows\System32\ico.exe (Primax Electronics Ltd.)
O4 - HKLM..\Run: [RIMBBLaunchAgent.exe] C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
O4 - HKLM..\Run: [WrtMon.exe] C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe ()
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Download; with &DAP; - C:\Program Files\DAP\dapextie.htm ()
O8 - Extra context menu item: &Verify; with DAP - C:\Program Files\DAP\dapverify.htm ()
O8 - Extra context menu item: Download &all; with DAP - C:\Program Files\DAP\dapextie2.htm ()
O8 - Extra context menu item: Download all with Free Download Manager - C:\Program Files\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Download selected with Free Download Manager - C:\Program Files\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Download video with Free Download Manager - C:\Program Files\Free Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Download with Free Download Manager - C:\Program Files\Free Download Manager\dllink.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: cinemanow.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: cinemanow.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: roxio.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: roxio.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: roxionow.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: roxionow.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: sonic.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: sonic.com ([]https in Trusted sites)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0E48E3E6-4D02-43D7-8C43-DB655581DDB1}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{69C14783-DDEA-45C0-A7DA-D0ADB27D38BF}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll) - File not found
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll) - File not found
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O22 - SharedTaskScheduler: {E31004D1-A431-41B8-826F-E902F9D95C81} - Windows DreamScene - C:\Windows\System32\DreamScene.dll (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Public\Pictures\APOD\M94's recently revealed outer spiral arms - IR+UV composite image [R Jay Gabany, Blackbird Observ - IAC - IoA Cambridge - Cardiff] .jpg
O24 - Desktop BackupWallPaper: C:\Users\Public\Pictures\APOD\M94's recently revealed outer spiral arms - IR+UV composite image [R Jay Gabany, Blackbird Observ - IAC - IoA Cambridge - Cardiff] .jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2008/06/16 19:39:03 | 000,000,042 | —- | M] () - C:\autorunsc.bat – [ NTFS ]
O32 - AutoRun File - [2008/06/16 19:45:16 | 000,100,412 | —- | M] () - C:\autorunsc.csv – [ NTFS ]
O32 - AutoRun File - [2008/06/16 19:39:03 | 000,249,856 | —- | M] (Sysinternals - www.sysinternals.com) - C:\autorunsc.exe – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk /p \??\K:)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/05/05 04:11:29 | 000,000,000 | —D | C] – C:\Users\LeeAd\AppData\Local\Adobe
[2013/05/04 01:36:49 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/05/04 01:36:48 | 000,022,856 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2013/05/04 01:36:48 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2013/05/04 01:32:37 | 010,285,040 | —- | C] (Malwarebytes Corporation ) – C:\Users\LeeAd\Desktop\mbam-setup-1.75.0.1300.exe
[2013/05/04 00:15:24 | 004,745,728 | —- | C] (AVAST Software) – C:\Users\LeeAd\Desktop\aswMBR.exe
[2013/05/02 16:02:51 | 000,029,816 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2013/05/02 16:02:51 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Pro Antivirus
[2013/05/02 16:02:50 | 000,368,944 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswSP.sys
[2013/05/02 16:02:48 | 000,056,080 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswTdi.sys
[2013/05/02 16:02:48 | 000,049,760 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswRdr.sys
[2013/05/02 16:02:47 | 000,021,576 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswKbd.sys
[2013/05/02 16:02:45 | 000,765,736 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswSnx.sys
[2013/05/02 16:02:43 | 000,066,336 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2013/05/02 16:02:36 | 000,229,648 | —- | C] (AVAST Software) – C:\Windows\System32\aswBoot.exe
[2013/05/02 16:01:58 | 000,041,664 | —- | C] (AVAST Software) – C:\Windows\avastSS.scr
[2013/05/02 16:01:09 | 000,000,000 | —D | C] – C:\Program Files\AVAST Software
[2013/04/30 20:17:40 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\LeeAd\Desktop\OTL.exe
[2013/04/30 19:42:06 | 000,237,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2013/04/23 18:44:04 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Creative Labs Shared
[2013/04/23 17:44:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2013/04/23 17:43:51 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2013/04/23 17:42:03 | 040,437,664 | —- | C] (Apple Inc.) – C:\Users\LeeAd\Desktop\QuickTimeInstaller.exe
[2013/04/17 23:20:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Presto! PageManager 7.15
[2013/04/17 23:16:07 | 000,000,000 | —D | C] – C:\Program Files\NewSoft
[2013/04/17 23:16:07 | 000,000,000 | —D | C] – C:\Windows\System32\Color
[2013/04/17 20:32:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
[2013/04/17 20:32:16 | 000,027,192 | —- | C] (VS Revo Group) – C:\Windows\System32\drivers\revoflt.sys
[2013/04/17 20:32:16 | 000,000,000 | —D | C] – C:\ProgramData\VS Revo Group
[2013/04/17 20:32:15 | 000,000,000 | —D | C] – C:\Program Files\VS Revo Group
[2013/04/16 01:30:23 | 000,000,000 | —D | C] – C:\Program Files\TinyPDF
[2013/04/16 00:46:38 | 000,000,000 | —D | C] – C:\Users\LeeAd\AppData\Roaming\Softland
[2013/04/14 15:02:31 | 000,000,000 | —D | C] – C:\Program Files\PC Tools
[2013/04/14 14:54:10 | 000,202,280 | —- | C] (PC Tools) – C:\Windows\System32\drivers\PCTSD.sys
[2013/04/14 14:54:10 | 000,000,000 | —D | C] – C:\Program Files\Common Files\PC Tools
[2013/04/14 14:49:29 | 000,000,000 | —D | C] – C:\ProgramData\PC Tools
[2013/04/14 14:49:28 | 000,000,000 | —D | C] – C:\Users\LeeAd\AppData\Roaming\TestApp
[2013/04/11 17:36:46 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/04/11 17:36:44 | 000,607,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/04/11 17:36:44 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/04/11 17:36:44 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/04/11 17:36:44 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/04/11 17:36:43 | 001,800,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/04/11 17:36:43 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/04/11 17:36:42 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/04/11 17:29:18 | 003,603,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2013/04/11 17:29:17 | 003,551,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2013/04/11 17:29:17 | 000,049,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrsrv.dll
[2013/04/11 17:29:12 | 000,376,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsrv.dll
[2013/04/11 17:28:54 | 000,015,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usb8023.sys
[2013/04/11 17:28:50 | 002,049,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[34 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\System32\drivers\*.tmp files -> C:\Windows\System32\drivers\*.tmp -> ]
[1 C:\Users\Public\Documents\*.tmp files -> C:\Users\Public\Documents\*.tmp -> ]
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/05/05 15:08:40 | 000,000,288 | —- | M] () – C:\Windows\tasks\Spybot - Search & Destroy - Scheduled Task.job
[2013/05/05 15:02:09 | 000,000,422 | —- | M] () – C:\Windows\tasks\SystemToolsDailyTest.job
[2013/05/05 14:36:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/05/05 13:52:40 | 000,003,568 | —- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/05/05 13:52:40 | 000,003,568 | —- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/05/05 04:33:42 | 001,032,823 | —- | M] () – C:\Users\LeeAd\Documents\NEWSOFT
[2013/05/04 21:34:05 | 000,024,334 | —- | M] () – C:\Users\LeeAd\Documents\KP.kdbx
[2013/05/04 15:31:03 | 000,000,314 | —- | M] () – C:\Windows\tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
[2013/05/04 01:53:10 | 000,065,536 | —- | M] () – C:\Windows\System32\Ikeext.etl
[2013/05/04 01:52:41 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/05/04 01:51:45 | 000,055,468 | —- | M] () – C:\Windows\System32\BMXStateBkp-{00000002-00000000-00000001-00001102-00000005-60021102}.rfx
[2013/05/04 01:51:45 | 000,055,468 | —- | M] () – C:\Windows\System32\BMXState-{00000002-00000000-00000001-00001102-00000005-60021102}.rfx
[2013/05/04 01:51:45 | 000,000,788 | —- | M] () – C:\Windows\System32\DVCState-{00000002-00000000-00000001-00001102-00000005-60021102}.rfx
[2013/05/04 01:32:39 | 010,285,040 | —- | M] (Malwarebytes Corporation ) – C:\Users\LeeAd\Desktop\mbam-setup-1.75.0.1300.exe
[2013/05/04 00:49:43 | 000,000,564 | —- | M] () – C:\Users\LeeAd\Desktop\MBR.zip
[2013/05/04 00:46:25 | 000,000,512 | —- | M] () – C:\Users\LeeAd\Desktop\MBR.dat
[2013/05/04 00:16:25 | 004,745,728 | —- | M] (AVAST Software) – C:\Users\LeeAd\Desktop\aswMBR.exe
[2013/05/02 20:06:26 | 000,000,000 | —- | M] () – C:\Users\LeeAd\Desktop\autorunsc.bat
[2013/05/02 16:02:52 | 000,001,831 | —- | M] () – C:\Users\Public\Desktop\avast! Pro Antivirus.lnk
[2013/05/02 16:02:43 | 000,002,577 | —- | M] () – C:\Windows\System32\config.nt
[2013/05/02 15:51:24 | 000,417,176 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2013/05/02 15:45:08 | 000,008,160 | —- | M] () – C:\Users\LeeAd\AppData\Local\d3d9caps.dat
[2013/05/02 10:52:41 | 000,174,664 | —- | M] () – C:\Windows\System32\drivers\aswVmm.sys
[2013/05/01 19:34:09 | 000,765,736 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswSnx.sys
[2013/05/01 19:34:09 | 000,368,944 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswSP.sys
[2013/05/01 19:34:09 | 000,056,080 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswTdi.sys
[2013/05/01 19:34:09 | 000,049,376 | —- | M] () – C:\Windows\System32\drivers\aswRvrt.sys
[2013/05/01 19:34:08 | 000,066,336 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2013/05/01 19:34:08 | 000,049,760 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswRdr.sys
[2013/05/01 19:34:08 | 000,021,576 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswKbd.sys
[2013/05/01 19:34:07 | 000,029,816 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2013/05/01 19:33:35 | 000,041,664 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2013/05/01 19:33:27 | 000,229,648 | —- | M] (AVAST Software) – C:\Windows\System32\aswBoot.exe
[2013/04/30 23:58:05 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/04/30 22:13:01 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1499513834-3245736753-3590406765-1003UA.job
[2013/04/30 22:13:01 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1499513834-3245736753-3590406765-1003Core.job
[2013/04/30 22:13:00 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/04/30 20:17:40 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\LeeAd\Desktop\OTL.exe
[2013/04/30 17:41:51 | 000,000,940 | —- | M] () – C:\Users\LeeAd\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2013/04/30 17:27:10 | 000,665,634 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/04/30 17:27:10 | 000,126,428 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/04/29 03:49:55 | 081,981,616 | —- | M] () – C:\Users\LeeAd\AppData\Local\rx_image32.Cache
[2013/04/29 03:49:30 | 004,216,000 | —- | M] () – C:\Users\LeeAd\AppData\Local\rx_audio.Cache
[2013/04/23 18:47:19 | 000,001,080 | —- | M] () – C:\Windows\System32\settingsbkup.sfm
[2013/04/23 18:47:19 | 000,001,080 | —- | M] () – C:\Windows\System32\settings.sfm
[2013/04/23 18:41:07 | 000,444,952 | —- | M] (Creative Labs) – C:\Windows\System32\wrap_oal.dll
[2013/04/23 18:41:07 | 000,109,080 | —- | M] (Portions © Creative Labs Inc. and NVIDIA Corp.) – C:\Windows\System32\OpenAL32.dll
[2013/04/23 18:41:05 | 000,000,087 | RH– | M] () – C:\Windows\ctfile.rfc
[2013/04/23 17:39:46 | 040,437,664 | —- | M] (Apple Inc.) – C:\Users\LeeAd\Desktop\QuickTimeInstaller.exe
[2013/04/22 14:25:17 | 000,000,564 | —- | M] () – C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2013/04/17 23:20:21 | 000,000,941 | —- | M] () – C:\Users\Public\Desktop\MFSeries Software Guide (US).lnk
[2013/04/17 23:20:14 | 000,001,952 | —- | M] () – C:\Users\Public\Desktop\Presto! PageManager 7.15.lnk
[2013/04/17 23:20:05 | 000,151,566 | —- | M] () – C:\Windows\System32\UninstIPP.isu
[2013/04/17 23:19:08 | 000,000,264 | —- | M] () – C:\Windows\setup.iss
[2013/04/17 20:32:18 | 000,001,091 | —- | M] () – C:\Users\LeeAd\Application Data\Microsoft\Internet Explorer\Quick Launch\Revo Uninstaller Pro.lnk
[2013/04/17 20:32:18 | 000,001,067 | —- | M] () – C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
[2013/04/15 23:03:43 | 000,150,528 | —- | M] () – C:\Users\LeeAd\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/04/14 14:54:49 | 002,636,136 | —- | M] () – C:\Windows\System32\drivers\Cat.DB
[2013/04/11 21:47:23 | 000,002,098 | —- | M] () – C:\Users\Public\Desktop\BlackBerry Desktop Software.lnk
[2013/04/11 20:23:16 | 000,002,085 | —- | M] () – C:\Users\LeeAd\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/04/11 17:02:01 | 000,000,872 | —- | M] () – C:\Users\LeeAd\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013/04/11 17:02:01 | 000,000,848 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013/04/11 15:28:54 | 000,691,592 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2013/04/11 15:28:54 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[34 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\System32\drivers\*.tmp files -> C:\Windows\System32\drivers\*.tmp -> ]
[1 C:\Users\Public\Documents\*.tmp files -> C:\Users\Public\Documents\*.tmp -> ]
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/05/04 00:49:43 | 000,000,564 | —- | C] () – C:\Users\LeeAd\Desktop\MBR.zip
[2013/05/04 00:46:25 | 000,000,512 | —- | C] () – C:\Users\LeeAd\Desktop\MBR.dat
[2013/05/02 20:06:26 | 000,000,000 | —- | C] () – C:\Users\LeeAd\Desktop\autorunsc.bat
[2013/05/02 16:02:52 | 000,001,831 | —- | C] () – C:\Users\Public\Desktop\avast! Pro Antivirus.lnk
[2013/05/02 16:02:44 | 000,174,664 | —- | C] () – C:\Windows\System32\drivers\aswVmm.sys
[2013/05/02 16:02:44 | 000,049,376 | —- | C] () – C:\Windows\System32\drivers\aswRvrt.sys
[2013/04/23 18:47:19 | 000,055,468 | —- | C] () – C:\Windows\System32\BMXState-{00000002-00000000-00000001-00001102-00000005-60021102}.rfx
[2013/04/23 18:47:19 | 000,001,080 | —- | C] () – C:\Windows\System32\settingsbkup.sfm
[2013/04/23 18:47:19 | 000,001,080 | —- | C] () – C:\Windows\System32\settings.sfm
[2013/04/23 18:47:19 | 000,000,788 | —- | C] () – C:\Windows\System32\DVCState-{00000002-00000000-00000001-00001102-00000005-60021102}.rfx
[2013/04/17 23:20:14 | 000,001,952 | —- | C] () – C:\Users\Public\Desktop\Presto! PageManager 7.15.lnk
[2013/04/17 21:14:07 | 001,032,823 | —- | C] () – C:\Users\LeeAd\Documents\NEWSOFT
[2013/04/17 20:32:18 | 000,001,091 | —- | C] () – C:\Users\LeeAd\Application Data\Microsoft\Internet Explorer\Quick Launch\Revo Uninstaller Pro.lnk
[2013/04/17 20:32:18 | 000,001,067 | —- | C] () – C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
[2013/04/16 00:46:37 | 000,007,549 | —- | C] () – C:\Windows\System32\dopdf7.ctm
[2013/04/16 00:20:48 | 000,116,736 | —- | C] () – C:\Windows\System32\qvredmonnt.dll
[2013/04/14 16:04:54 | 000,000,288 | —- | C] () – C:\Windows\tasks\Spybot - Search & Destroy - Scheduled Task.job
[2013/04/14 16:02:16 | 000,000,314 | —- | C] () – C:\Windows\tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
[2013/04/14 14:54:16 | 002,636,136 | —- | C] () – C:\Windows\System32\drivers\Cat.DB
[2013/04/12 17:56:54 | 000,002,140 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BOINC Manager.lnk
[2013/04/11 15:29:24 | 000,000,830 | —- | C] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/08/03 21:27:49 | 000,109,256 | —- | C] () – C:\Windows\System32\EasyHook64.dll
[2012/08/03 21:27:49 | 000,090,824 | —- | C] () – C:\Windows\System32\EasyHook32.dll
[2012/01/15 23:21:24 | 000,098,304 | —- | C] () – C:\Windows\System32\redmonnt.dll
[2011/12/17 18:12:30 | 000,000,146 | —- | C] () – C:\Windows\WININIT.INI
[2009/05/19 21:26:42 | 004,216,000 | —- | C] () – C:\Users\LeeAd\AppData\Local\rx_audio.Cache
[2009/05/19 21:25:54 | 081,981,616 | —- | C] () – C:\Users\LeeAd\AppData\Local\rx_image32.Cache
[2008/06/06 01:56:20 | 000,008,160 | —- | C] () – C:\Users\LeeAd\AppData\Local\d3d9caps.dat
[2008/06/06 00:09:18 | 000,150,528 | —- | C] () – C:\Users\LeeAd\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/06/05 22:12:46 | 003,932,160 | -HS- | C] () – C:\Users\LeeAd\ntuser.bak

========== ZeroAccess Check ==========

[2006/11/02 08:53:06 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 13:47:00 | 011,586,048 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/04/11 02:28:19 | 000,614,912 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/04/11 02:28:25 | 000,347,648 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013/04/25 22:41:22 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\Audacity
[2008/07/17 02:17:41 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\Canon
[2010/01/15 04:26:05 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\ColorCop
[2008/06/06 01:06:21 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\DataSafeOnline
[2013/04/29 03:35:08 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\Free Download Manager
[2008/06/30 01:29:44 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\Genie-Soft
[2013/03/06 17:51:12 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\IrfanView
[2008/06/29 23:57:05 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\JAM Software
[2010/03/09 23:00:39 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\Javacool Software
[2013/05/04 21:34:06 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\KeePass
[2012/08/04 16:17:38 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\Leadertech
[2008/06/24 03:35:04 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\Maximum Output Software
[2012/08/04 16:35:07 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\Memeo
[2012/05/27 17:28:27 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\mp3DirectCut
[2010/03/04 23:09:29 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\NewSoft
[2011/06/11 20:58:51 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\OverDrive
[2010/10/29 19:44:08 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\PCDr
[2009/02/05 17:13:16 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\PKWARE
[2012/04/24 22:44:49 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\Research In Motion
[2008/07/12 16:59:26 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\ScanSoft
[2012/08/04 16:34:42 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\Seagate
[2011/09/11 01:48:48 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\Smart Recorder
[2013/04/16 00:46:38 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\Softland
[2009/05/19 23:42:25 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\StarBurn
[2013/04/14 14:49:28 | 000,000,000 | —D | M] – C:\Users\LeeAd\AppData\Roaming\TestApp

========== Purity Check ==========



========== Custom Scans ==========

< HKLM\SOFTWARE\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972} /s >

< C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\quarantine\*.* /s >
[2006/11/02 09:00:25 | 000,000,006 | -H– | C] () – C:\Windows\Tasks\SA.DAT
[2006/11/02 09:00:25 | 000,032,640 | —- | C] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/03/01 03:58:07 | 000,000,856 | —- | C] () – C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1499513834-3245736753-3590406765-1003Core.job
[2010/03/01 03:58:13 | 000,000,908 | —- | C] () – C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1499513834-3245736753-3590406765-1003UA.job
[2010/03/03 20:25:10 | 000,000,882 | —- | C] () – C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2010/03/03 20:25:13 | 000,000,886 | —- | C] () – C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2010/10/29 20:00:29 | 000,000,422 | —- | C] () – C:\Windows\Tasks\SystemToolsDailyTest.job
[2010/10/29 20:00:31 | 000,000,564 | —- | C] () – C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
[2013/04/11 15:29:24 | 000,000,830 | —- | C] () – C:\Windows\Tasks\Adobe Flash Player Updater.job
[2013/04/14 16:02:16 | 000,000,314 | —- | C] () – C:\Windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
[2013/04/14 16:04:54 | 000,000,288 | —- | C] () – C:\Windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job

< %appdata%\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\*.* /s >
[2013/05/04 01:49:08 | 000,000,721 | —- | M] () – C:\Users\LeeAd\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\0887342019.data
[2013/05/04 01:49:08 | 000,569,352 | —- | M] () – C:\Users\LeeAd\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\0887342019.quar
[2013/05/04 01:49:08 | 000,000,773 | —- | M] () – C:\Users\LeeAd\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\9322434857.data
[2013/05/04 01:49:08 | 000,000,426 | —- | M] () – C:\Users\LeeAd\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\9322434857.quar
[2010/03/01 21:57:15 | 000,000,085 | —- | M] () – C:\Users\LeeAd\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\BACKUP2.26020
[2010/03/01 21:57:15 | 000,000,096 | —- | M] () – C:\Users\LeeAd\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\BACKUP2.76878
[2010/03/01 21:57:15 | 000,000,173 | —- | M] () – C:\Users\LeeAd\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\BACKUP3.35271
[2010/03/01 21:57:15 | 000,000,167 | —- | M] () – C:\Users\LeeAd\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\BACKUP3.35372
[2010/03/01 21:57:15 | 000,000,170 | —- | M] () – C:\Users\LeeAd\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\BACKUP3.76869
[2010/03/01 21:57:15 | 000,000,164 | —- | M] () – C:\Users\LeeAd\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\BACKUP3.84378
[2010/03/01 21:57:15 | 000,000,321 | —- | M] () – C:\Users\LeeAd\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\QUAR3.35271
[2010/03/01 21:57:15 | 000,000,321 | —- | M] () – C:\Users\LeeAd\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\QUAR3.35372
[2010/03/01 21:57:15 | 000,000,465 | —- | M] () – C:\Users\LeeAd\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\QUAR3.76869
[2010/03/01 21:57:15 | 000,000,465 | —- | M] () – C:\Users\LeeAd\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\QUAR3.84378

========== Alternate Data Streams ==========

@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:862BDB1A
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:56E2E879
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:84098FD3
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:DFC5A2B2

< End of report >
__________________________________________________

Thanks again for helping me with this.
Hi - I just thought of another "silly" question related to all this - I've plugged my phone into my computer via USB at various times - can any of the antimalware programs I have be used to scan the phone while it's connected? Is there a chance doing that could mess up anything in the phone's OS? Thanks.
Hi Pretzelogic,

MBAM might scan it if you choose full scan and the phone is recognized as a drive.

I don't think Avast detection is anything serious, I'm just not sure what it is related to.

Let's do it this way.

Open MBAM and click on the Quarantine tab
  • Locate the Avast detection and click Restore
Close MBAM.

Next

Please open OTL.

  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, click the None button near the top (it may looked greyed out)
  • In the window under Custom Scans/Fixes copy and paste the following

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{AEB6717E-7E19-11d0-97EE-00C04FD91972} /s
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvastSvc.exe /s
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad window, OTL.Txt. Please post this log.

Next

We will rerun MBAM a little differently.

Please do the following:
  • press the Windows key and the R key at the same time.
  • This will open the Run box.
  • Copy and paste the following line into the run box
    mbam.exe /developer
  • Click OK, MBAM should open
  • Run the same type of scan you did before and save the logfile and post it.

Please post back with
  • OTL.txt
  • MBAM log

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI