This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Machine running badly [Solved]

39 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OCD: Here is the system info. Outlook at first gave me the error message that it timed out, then nothing. OS Name Microsoft Windows 7 Home Premium Version 6.1.7601 Service Pack 1 Build 7601 Other OS Description Not Available OS Manufacturer Microsoft Corporation System Name RICHARDGMARTIN System Manufacturer TOSHIBA System Model Satellite L505D System Type X86-based PC Processor AMD Turion™ II Dual-Core Mobile M500, 2200 Mhz, 2 Core(s), 2 Logical Processor(s) BIOS Version/Date Insyde Corp. 1.00, 9/7/2009 SMBIOS Version 2.6 Windows Directory C:\windows System Directory C:\windows\system32 Boot Device \Device\HarddiskVolume1 Locale United States Hardware Abstraction Layer Version = "6.1.7601.17514" User Name RICHARDGMARTIN\User Time Zone Eastern Daylight Time Installed Physical Memory (RAM) 3.00 GB Total Physical Memory 2.75 GB Available Physical Memory 1.47 GB Total Virtual Memory 5.49 GB Available Virtual Memory 3.88 GB Page File Space 2.75 GB Page File C:\pagefile.sys
Hi MARTY1946,

I apologize for having you complete all these steps, but the last log unfortunately wasn't definitive enough.
  • Please go to http://biosagentplus.com/ and click the FREE BIOS Scan button
  • Download the small program and run it
  • The window that pops up will tell you the BIOS Version installed
  • Post the BIOS type in your next reply.
Do not install any updates the site may say you need at this point.

Also, in order to help diagnose the BIOS and beeps codes I need to know again how many beeps there are in total, or are the beeps continuous?

You also stated earlier, that you are using a Virtual Keyboard. Is the laptop keyboard not functioning?
Hello OCD; I couldn't get the bios info the popup went away before I could see what it said. I tried to run the program again but it is not responding now. The keyboard is a laptop. The period key is not working, I'm now using the number pad with the numbers key locked, so I can insert the period. The beeping is continuous. Thanks Marty :(
Hi MARTY1946,

1. Boot Sequence in your BIOS

Enter the bios and make sure the hard drive is identified correctly. If not then it may be a case of a failed hard drive.
If the drive is identified correctly then follow the instructions below to make sure your boot sequence is set correctly.
  • Reboot the system and at the first post screen (where it is counting up memory) start repeatedly tapping the F2.
  • This will enter you into the BIOS/CMOS area.
  • Find the Advanced area and click Enter
  • Look for Boot Sequence or Boot Options and highlight that click Enter
  • Follow the directions on the screen on how to modify it and change it if necessary
  • Change the first drive to the C or Main Drive (the drive that your Operating System is located on)
  • Change the second drive to CD/DVD ROM.
  • Once that is done then click F10 to Save and Exit
  • You will prompted to enter "Y" to verify Save and Exit. Click "Y" and the system will now reboot with the new settings.
=========================

2. Run OTL.exe

Windows Vista and Windows 7 users Right Click and select "Run as Administrator"
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2465}: "URL" = http://isearch.fantastigames.com/web?src=i…q={searchTerms}
    IE - HKCU\..\SearchScopes,DefaultScope = {4AC5AF91-2325-4B21-BDCE-AB9014398987}
    IE - HKCU\..\SearchScopes\{4AC5AF91-2325-4B21-BDCE-AB9014398987}: "URL" = http://search.conduit.com/ResultsExt.aspx?…154206&UM=2
    IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2465}: "URL" = http://isearch.fantastigames.com/web?src=i…q={searchTerms}
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Webfetti\bar\2.bin [2013/05/12 08:53:58 | 000,000,000 | —D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\MyOwnSuperhero\bar\2.bin [2013/05/12 08:53:58 | 000,000,000 | —D | M]
    [2013/05/14 08:57:42 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Conduit
    [2013/05/12 11:13:28 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\temp
    
    
    :Commands
    [purity]
    [createrestorepoint]
    [emptyflash]
    [emptyjava]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then re-run OTL and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
=========================

3. FREE BIOS Scan
  • Re-try the BIOS scan. The pop-up window doesn't not stay viewable for very long, but the information should be located on the webpage that is visible.
  • After you run the scan, and the pop-up window has closed. The webpage that is displayed locate (at the top) "RICHARDGMARTIN-PC" that is the name of your computer
  • Directly below it should be the BIOS, if not expand the results.
  • Below the BIOS is a highlighted name or set of letters, that is the information I need.
=========================

4. Questions

Is the period key stuck or just doesn't function?

=========================

In your next post please provide the following:
  • BIOS boot sequence
  • OTL.txt
  • BIOS version/name
  • Answer to "period" key question.
Hello OCD;
The Bios sequence is right first hard drive then cd rom.
Here is the info on the BIOS:

BIOS Type: Toshiba
BIOS Date: September 7th, 2009
BIOS ID: 1.00
BIOS OEM: 1.00
Chipset: AMD 9601 rev 0
SuperIO: Unknown
Manufacturer: AMD
Motherboard: Satellite L505D

When I rebooted this time it ran without the beeping, only thing I see is it stops to ask the Windows 7 operating system.
The period key is not functioning. Doesn't seem to be stuck.
Here is the OTL LOG:

OTL logfile created on: 5/15/2013 5:31:07 PM - Run 6
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\User\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16576)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.75 Gb Total Physical Memory | 1.69 Gb Available Physical Memory | 61.71% Memory free
5.49 Gb Paging File | 4.09 Gb Available in Paging File | 74.54% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 288.71 Gb Total Space | 233.02 Gb Free Space | 80.71% Space Free | Partition Type: NTFS

Computer Name: RICHARDGMARTIN | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\User\AppData\Local\eSupport.com\biosagentplus (1).exe (Copyright © 2010 eSupport.com. All Rights Reserved.)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Users\User\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe ()
PRC - C:\Program Files\AVG\AVG2013\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Xobni\XobniService.exe (Xobni Corporation)
PRC - C:\Program Files\SecureBackupShare\ComcastSecureBackupSharestat.exe (Secure Backup and Share)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\SecureBackupShare\ComcastSecureBackupSharebackup.exe (Secure Backup and Share)
PRC - C:\Program Files\Toshiba Online Backup\ToshibaOnlineBackup.exe ()
PRC - C:\Program Files\ARX\ARX CryptoKit\utils\ARcltsrv.exe (Algorithmic Research Ltd.)
PRC - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TECO\TecoService.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TECO\TEco.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)


========== Modules (No Company Name) ==========

MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\30e3a21202000677d0a9270572251477\System.Windows.Forms.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\764f15e86c82662e977bd418bd6318c1\System.Configuration.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\5ecf01964c70e453d71e5d7653912ff9\System.Web.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\stdole\f698ac346476a20a02725b8e9de422cd\stdole.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\90b89f6e8032310e9ac72a309fd49e83\System.Runtime.Remoting.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\snlFileFormats150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\VirtualTreesDXE150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\JSDialogPack150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl ()
MOD - C:\windows\assembly\GAC\Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll ()
MOD - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSPTLS.DLL ()
MOD - C:\windows\assembly\GAC_MSIL\ARXMLDigSigs\4.3.0.0__cfff1466d316a953\ARXMLDigSigs.dll ()
MOD - C:\Program Files\ARX\ARX Office Signatures\armgrsig.ocx ()
MOD - C:\Program Files\ARX\ARX Office Signatures\arwaddin.dll ()
MOD - C:\Program Files\Toshiba Online Backup\Toast.dll ()
MOD - C:\Program Files\Toshiba Online Backup\ToshibaOnlineBackup.exe ()
MOD - C:\Program Files\Toshiba Online Backup\SdbShared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Wizard\2.0.3497.38831__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager2.Graphics.Dashboard\2.0.3497.38923__90ba9c70f846762e\CLI.Aspect.DisplaysManager2.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboard\2.0.3497.38856__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Dashboard\2.0.3497.38833__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Wizard\2.0.3497.38899__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\2.0.3497.38875__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard\2.0.3497.38855__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.3497.38814__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashboard\2.0.3497.38868__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Dashboard\2.0.3497.38862__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Wizard\2.0.3497.38837__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wizard\2.0.3497.38833__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dashboard\2.0.3497.38833__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Dashboard\2.0.3497.38898__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard\2.0.3497.38868__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Dashboard\2.0.3497.38861__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime\2.0.3497.38856__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtime\2.0.3497.38880__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.3497.38822__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtime\2.0.3497.38863__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtime\2.0.3497.38867__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runtime\2.0.3497.38855__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboard\2.0.3497.38899__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime\2.0.3497.38898__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.3497.38828__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Runtime\2.0.3497.38837__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Runtime\2.0.3497.38860__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Runtime\2.0.3497.38855__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runtime\2.0.3497.38862__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Runtime\2.0.3497.38823__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\MOM.Implementation\2.0.3497.38894__90ba9c70f846762e\MOM.Implementation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.3428.28305__90ba9c70f846762e\CLI.Caste.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Foundation\2.0.3428.28298__90ba9c70f846762e\CLI.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared\2.0.3428.28316__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared\2.0.3428.28315__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\2.0.3428.28314__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Shared\2.0.3428.28314__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Shared\2.0.3428.28314__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.3497.38904__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Shared\2.0.3428.28324__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Shared\2.0.3428.28315__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runtime\2.0.3497.38856__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\LOG.Foundation\2.0.3428.28296__90ba9c70f846762e\LOG.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Shared\2.0.3428.28309__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.3428.28297__90ba9c70f846762e\NEWAEM.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.3428.28354__90ba9c70f846762e\CLI.Foundation.XManifest.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Shared\2.0.3428.28323__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Shared\2.0.3428.28313__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Shared\2.0.3428.28312__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.CustomFormats.Graphics.Shared\2.0.3428.28311__90ba9c70f846762e\CLI.Aspect.CustomFormats.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.3428.28304__90ba9c70f846762e\CLI.Component.Dashboard.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Shared\2.0.3428.28314__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\ResourceManagement.Foundation.Private\2.0.3428.28303__90ba9c70f846762e\ResourceManagement.Foundation.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.3428.28308__90ba9c70f846762e\CLI.Component.Wizard.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.3428.28302__90ba9c70f846762e\CLI.Component.Client.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Shared\2.0.3428.28312__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\APM.Foundation\2.0.3428.28310__90ba9c70f846762e\APM.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.3428.28304__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.3428.28302__90ba9c70f846762e\AEM.Actions.CCAA.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\MOM.Foundation\2.0.3428.28310__90ba9c70f846762e\MOM.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\DEM.Graphics.I0706\2.0.2743.23304__90ba9c70f846762e\DEM.Graphics.I0706.dll ()
MOD - C:\windows\assembly\GAC_MSIL\DEM.Graphics\2.0.3428.28324__90ba9c70f846762e\DEM.Graphics.dll ()
MOD - C:\windows\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.3428.28303__90ba9c70f846762e\CLI.Component.Runtime.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2.0.3428.28313__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared\2.0.3428.28312__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Server.Shared\2.0.3428.28304__90ba9c70f846762e\AEM.Server.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.WinMessages.Shared\2.0.3428.28311__90ba9c70f846762e\AEM.Plugin.WinMessages.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.REG.Shared\2.0.3428.28329__90ba9c70f846762e\AEM.Plugin.REG.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.3428.28327__90ba9c70f846762e\AEM.Plugin.GD.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.3428.28311__90ba9c70f846762e\AEM.Plugin.EEU.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.3428.28327__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Runtime.Extension.EEU\2.0.3497.38810__90ba9c70f846762e\CLI.Component.Runtime.Extension.EEU.dll ()
MOD - C:\windows\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.3497.38819__90ba9c70f846762e\CLI.Component.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.3497.38827__90ba9c70f846762e\CLI.Component.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.3497.38892__90ba9c70f846762e\LOG.Foundation.Implementation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\APM.Server\2.0.3497.38811__90ba9c70f846762e\APM.Server.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.SkinFactory\2.0.3497.38813__90ba9c70f846762e\CLI.Component.SkinFactory.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.3497.38812__90ba9c70f846762e\CLI.Component.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Private\2.0.3428.28311__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Server\2.0.3497.38810__90ba9c70f846762e\AEM.Server.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.3428.28301__90ba9c70f846762e\CLI.Foundation.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private\2.0.3428.28308__90ba9c70f846762e\CLI.Component.Client.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.3428.28303__90ba9c70f846762e\LOG.Foundation.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private\2.0.3428.28311__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.3428.28310__90ba9c70f846762e\LOG.Foundation.Implementation.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Private\2.0.3428.28309__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime.Shared.Private\2.0.3428.28316__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CCC.Implementation\2.0.3497.38893__90ba9c70f846762e\CCC.Implementation.dll ()
MOD - C:\windows\assembly\GAC\office\12.0.0.0__71e9bce111e9429c\office.dll ()
MOD - C:\windows\assembly\GAC\Extensibility\7.0.3300.0__b03f5f7f11d50a3a\Extensibility.dll ()
MOD - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosIPCWraper.dll ()
MOD - C:\Program Files\TOSHIBA\TOSHIBA Disc Creator\NotifyTDC.dll ()
MOD - C:\Program Files\TOSHIBA\FlashCards\Hotkey\FnZ.dll ()
MOD - C:\Program Files\TOSHIBA\FlashCards\BlackPng.dll ()
MOD - C:\Program Files\TOSHIBA\TOSHIBA Assist\NotifyX.dll ()
MOD - C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll ()
MOD - C:\Program Files\TOSHIBA\PCDiag\NotifyPCD.dll ()


========== Services (SafeList) ==========

SRV - (SProtection) – C:\Program Files\Common Files\Umbrella\umbrella.exe File not found
SRV - (SDWSCService) – C:\Program Files\Spybot File not found
SRV - (SDUpdateService) – C:\Program Files\Spybot File not found
SRV - (SDScannerService) – C:\Program Files\Spybot File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (RealNetworks Downloader Resolver Service) – C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe ()
SRV - (XobniService) – C:\Program Files\Xobni\XobniService.exe (Xobni Corporation)
SRV - (GamesAppService) – C:\Program Files\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (ComcastSecureBackupSharebackup) – C:\Program Files\SecureBackupShare\ComcastSecureBackupSharebackup.exe (Secure Backup and Share)
SRV - (Autodesk Licensing Service) – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (ARcltsrv) – C:\Program Files\ARX\ARX CryptoKit\utils\ARcltsrv.exe (Algorithmic Research Ltd.)
SRV - (TosCoSrv) – C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV - (TMachInfo) – C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation)
SRV - (TOSHIBA eco Utility Service) – C:\Program Files\TOSHIBA\TECO\TecoService.exe (TOSHIBA Corporation)
SRV - (cfWiMAXService) – C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe (TOSHIBA CORPORATION)
SRV - (TPCHSrv) – C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe (TOSHIBA Corporation)
SRV - (TOSHIBA HDD SSD Alert Service) – C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation)
SRV - (AMD External Events Utility) – C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (TODDSrv) – C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (ConfigFree Service) – C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)


========== Driver Services (SafeList) ==========

DRV - (USBCCID) – system32\DRIVERS\RtsUCcid.sys File not found
DRV - (RtsUIR) – system32\DRIVERS\Rts516xIR.sys File not found
DRV - (RSUSBSTOR) – System32\Drivers\RtsUStor.sys File not found
DRV - (cpuz134) – C:\Users\User\AppData\Local\Temp\cpuz134\cpuz134_x32.sys File not found
DRV - (catchme) – C:\Users\User\AppData\Local\Temp\catchme.sys File not found
DRV - (DrvAgent32) – C:\Windows\System32\drivers\DrvAgent32.sys (Phoenix Technologies)
DRV - (SWDUMon) – C:\Windows\System32\drivers\SWDUMon.sys ()
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (avgtp) – C:\Windows\System32\drivers\avgtpx86.sys (AVG Technologies)
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avglogx) – C:\Windows\System32\drivers\avglogx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSHX) – C:\Windows\System32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\Windows\System32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (ComcastSecureBackupShareFilter) – C:\Windows\System32\drivers\ComcastSecureBackupShare.sys (Mozy, Inc.)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (winusb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (rtl8192se) – C:\Windows\System32\drivers\rtl8192se.sys (Realtek Semiconductor Corporation )
DRV - (tdcmdpst) – C:\Windows\System32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (tos_sps32) – C:\Windows\System32\drivers\tos_sps32.sys (TOSHIBA Corporation)
DRV - (TVALZ) – C:\Windows\System32\drivers\TVALZ_O.SYS (TOSHIBA Corporation)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (LSI Corp)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (FwLnk) – C:\Windows\System32\drivers\FwLnk.sys (TOSHIBA Corporation)
DRV - (PGEffect) – C:\Windows\System32\drivers\PGEffect.sys (TOSHIBA Corporation)
DRV - (TVALZFL) – C:\Windows\System32\drivers\TVALZFL.sys (TOSHIBA Corporation)
DRV - (dc3d) – C:\Windows\System32\drivers\dc3d.sys (Microsoft Corporation)
DRV - (Point32) – C:\Windows\System32\drivers\point32k.sys (Microsoft Corporation)
DRV - (AtiPcie) – C:\Windows\System32\drivers\AtiPcie.sys (Advanced Micro Devices Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0EF3D5EE-B833-43EC-8265-E0B5C71D50AB}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7TSNA

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKCU\..\SearchScopes\{0EF3D5EE-B833-43EC-8265-E0B5C71D50AB}: "URL" = http://www.google.com/search?sourceid=ie7&…1I7TSNA_enUS360
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF32_11_7_700_202.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@MyOwnSuperhero.com/Plugin: C:\Program Files\MyOwnSuperhero\bar\2.bin\NPv3Stub.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.1.18: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.1.18: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.17: C:\Program Files\Veetle\VLCBroadcast\npvbp.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.17: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.17: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@Webfetti.com/Plugin: C:\Program Files\Webfetti\bar\2.bin\NP7dStub.dll File not found
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\14\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\User\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\discoversoan@orbiscom: C:\Program Files\Discover\SOAN [2010/12/24 13:53:17 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013/03/31 08:50:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{DAC3F861-B30D-40dd-9166-F4E75327FAC7}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2013/03/31 08:50:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Mozilla Firefox\extensions\[removed]


O1 HOSTS File: ([2013/05/12 11:16:45 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (LessTabs) - {3178A392-8963-471E-B7A2-969CB58D6496} - C:\Program Files\LessTabs\IE32\LessTabsClientIE.dll (LessTabs)
O2 - BHO: (Secure Online Account Numbers Helper) - {435EAA86-D32B-484F-869C-53745FCB1642} - C:\Program Files\Discover\SOAN\DiscoverSOANHelper.dll (Orbiscom Ltd. All rights reserved.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Secure Online Account Numbers) - {A8C7C2CA-6DFD-4E16-8458-592361564D38} - C:\Program Files\Discover\SOAN\DiscoverSOANToolbar.dll (Orbiscom Ltd. All rights reserved.)
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [SDTray] C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
O4 - HKLM..\Run: [Secure Online Account Numbers] C:\Program Files\Discover\SOAN\DiscoverSOAN.exe (Orbiscom Ltd. All rights reserved.)
O4 - HKLM..\Run: [SmartFaceVWatcher] C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatcher.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TkBellExe] c:\program files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Toshiba Online Backup] C:\Program Files\Toshiba Online Backup\ToshibaOnlineBackup.exe ()
O4 - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TosWaitSrv] C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TWebCamera] C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
O4 - HKCU..\Run: [MyTOSHIBA] C:\Program Files\TOSHIBA\My Toshiba\MyToshiba.exe (TOSHIBA)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.4.2/jinstall-…indows-i586.cab (Java Plug-in 10.21.2)
O16 - DPF: {CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.4.2/jinstall-…indows-i586.cab (Java Plug-in 1.4.2_04)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.76.76 75.75.75.75
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{ABBFB7FF-852E-4FF6-9DC0-3A692906985E}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CF438D8B-532B-4B7A-972C-707EF7287EFF}: DhcpNameServer = 75.75.76.76 75.75.75.75
O18 - Protocol\Handler\linkscanner - No CLSID value found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/05/15 17:15:00 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Temp
[2013/05/15 10:14:53 | 000,023,456 | —- | C] (Phoenix Technologies) – C:\windows\System32\drivers\DrvAgent32.sys
[2013/05/15 10:14:53 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\eSupport.com
[2013/05/15 08:00:36 | 002,706,432 | —- | C] (Microsoft Corporation) – C:\windows\System32\mshtml.tlb
[2013/05/15 08:00:35 | 002,877,440 | —- | C] (Microsoft Corporation) – C:\windows\System32\jscript9.dll
[2013/05/15 08:00:34 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\windows\System32\ieui.dll
[2013/05/15 08:00:34 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\windows\System32\iesetup.dll
[2013/05/15 08:00:34 | 000,039,424 | —- | C] (Microsoft Corporation) – C:\windows\System32\jsproxy.dll
[2013/05/15 08:00:33 | 000,493,056 | —- | C] (Microsoft Corporation) – C:\windows\System32\msfeeds.dll
[2013/05/15 08:00:33 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\windows\System32\iesysprep.dll
[2013/05/15 08:00:33 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\windows\System32\RegisterIEPKEYs.exe
[2013/05/15 08:00:33 | 000,042,496 | —- | C] (Microsoft Corporation) – C:\windows\System32\ie4uinit.exe
[2013/05/15 08:00:33 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\windows\System32\iernonce.dll
[2013/05/15 07:44:45 | 002,347,520 | —- | C] (Microsoft Corporation) – C:\windows\System32\win32k.sys
[2013/05/15 07:44:45 | 000,218,984 | —- | C] (Microsoft Corporation) – C:\windows\System32\drivers\dxgmms1.sys
[2013/05/15 07:44:41 | 001,796,096 | —- | C] (Microsoft Corporation) – C:\windows\System32\authui.dll
[2013/05/15 07:44:41 | 000,101,720 | —- | C] (Microsoft Corporation) – C:\windows\System32\consent.exe
[2013/05/14 08:56:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAFPlayer
[2013/05/14 08:56:38 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\player
[2013/05/14 08:56:37 | 000,000,000 | —D | C] – C:\Program Files\Tuguu SL
[2013/05/14 08:13:57 | 000,846,864 | —- | C] (Microsoft Corporation) – C:\Users\User\Desktop\IE10-Windows6.1-en-us.exe
[2013/05/13 12:19:59 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\VS Revo Group
[2013/05/13 12:19:54 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
[2013/05/13 12:19:53 | 000,027,192 | —- | C] (VS Revo Group) – C:\windows\System32\drivers\revoflt.sys
[2013/05/13 12:19:53 | 000,000,000 | —D | C] – C:\ProgramData\VS Revo Group
[2013/05/13 12:19:52 | 000,000,000 | —D | C] – C:\Program Files\VS Revo Group
[2013/05/13 12:17:39 | 009,916,056 | —- | C] (VS Revo Group ) – C:\Users\User\Desktop\RevoUninProSetup.exe
[2013/05/13 12:16:41 | 009,916,056 | —- | C] (VS Revo Group ) – C:\Users\User\Desktop\RevoUninProSetup.exe.part
[2013/05/12 11:46:35 | 000,000,000 | —D | C] – C:\windows\temp
[2013/05/12 11:44:57 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/05/12 10:53:14 | 005,069,265 | R— | C] (Swearware) – C:\Users\User\Desktop\ComboFix.exe
[2013/05/12 08:43:24 | 000,518,144 | —- | C] (SteelWerX) – C:\windows\SWREG.exe
[2013/05/12 08:43:24 | 000,406,528 | —- | C] (SteelWerX) – C:\windows\SWSC.exe
[2013/05/12 08:43:24 | 000,060,416 | —- | C] (NirSoft) – C:\windows\NIRCMD.exe
[2013/05/12 08:39:53 | 000,000,000 | —D | C] – C:\Qoobox
[2013/05/12 08:39:26 | 000,000,000 | —D | C] – C:\windows\erdnt
[2013/05/11 09:28:57 | 000,000,000 | —D | C] – C:\Program Files\FGIcon
[2013/05/11 09:28:56 | 000,000,000 | —D | C] – C:\ProgramData\Wincert
[2013/05/11 09:28:25 | 000,000,000 | —D | C] – C:\Program Files\Settings Alerter
[2013/05/11 08:52:58 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\SwvUpdater
[2013/05/11 08:51:56 | 000,000,000 | -HSD | C] – C:\windows\System32\AI_RecycleBin
[2013/05/11 08:49:57 | 000,000,000 | —D | C] – C:\AI_RecycleBin
[2013/05/11 08:49:26 | 000,000,000 | —D | C] – C:\Program Files\LyricsTube
[2013/05/10 18:54:29 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OtShot
[2013/05/10 18:54:29 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OtShot
[2013/05/10 17:58:29 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\CRE
[2013/05/10 17:41:04 | 000,209,736 | —- | C] (Comfort Software Group) – C:\Users\User\Desktop\FreeVK.exe
[2013/05/10 17:40:44 | 000,000,000 | —D | C] – C:\Program Files\LessTabs
[2013/05/10 13:02:51 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\SlimWare Utilities Inc
[2013/05/10 13:02:43 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Downloaded Installers
[2013/05/10 08:04:48 | 000,000,000 | —D | C] – C:\temp
[2013/05/09 21:17:41 | 000,000,000 | —D | C] – C:\_OTL
[2013/05/09 15:53:37 | 000,000,000 | —D | C] – C:\windows\ERUNT
[2013/05/09 15:53:28 | 000,000,000 | —D | C] – C:\JRT
[2013/05/09 09:04:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013/05/09 08:50:18 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Foresight Software
[2013/05/09 08:50:01 | 000,000,000 | —D | C] – C:\ProgramData\Foresight Software
[2013/05/08 18:52:48 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
[2013/05/08 14:56:10 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2013/05/08 14:56:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
[2013/05/08 14:55:47 | 000,015,224 | —- | C] (Safer Networking Limited) – C:\windows\System32\sdnclean.exe
[2013/05/08 14:55:42 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy 2
[2013/05/08 14:55:04 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Programs
[2013/05/01 08:29:22 | 000,174,496 | —- | C] (Oracle Corporation) – C:\windows\System32\javaw.exe
[2013/05/01 08:29:22 | 000,174,496 | —- | C] (Oracle Corporation) – C:\windows\System32\java.exe
[2013/05/01 08:29:22 | 000,094,112 | —- | C] (Oracle Corporation) – C:\windows\System32\WindowsAccessBridge.dll
[2013/04/29 21:34:39 | 000,745,472 | —- | C] (Microsoft Corporation) – C:\windows\System32\MsSpellCheckingFacility.exe
[2013/04/29 21:34:39 | 000,185,344 | —- | C] (Microsoft Corporation) – C:\windows\System32\elshyph.dll
[2013/04/29 21:34:39 | 000,158,720 | —- | C] (Microsoft Corporation) – C:\windows\System32\msls31.dll
[2013/04/29 21:34:38 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\windows\System32\msrating.dll
[2013/04/29 21:34:38 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\windows\System32\iexpress.exe
[2013/04/29 21:34:38 | 000,138,752 | —- | C] (Microsoft Corporation) – C:\windows\System32\wextract.exe
[2013/04/29 21:34:38 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\windows\System32\inseng.dll
[2013/04/29 21:34:37 | 000,137,216 | —- | C] (Microsoft Corporation) – C:\windows\System32\ieUnatt.exe
[2013/04/29 21:34:37 | 000,117,248 | —- | C] (Microsoft Corporation) – C:\windows\System32\iepeers.dll
[2013/04/29 21:34:37 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\windows\System32\IEAdvpack.dll
[2013/04/29 21:34:37 | 000,057,344 | —- | C] (Microsoft Corporation) – C:\windows\System32\pngfilt.dll
[2013/04/29 21:34:37 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\windows\System32\msfeedsbs.dll
[2013/04/29 21:34:37 | 000,038,400 | —- | C] (Microsoft Corporation) – C:\windows\System32\imgutil.dll
[2013/04/29 21:34:37 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\windows\System32\msfeedssync.exe
[2013/04/29 21:34:36 | 000,073,728 | —- | C] (Microsoft Corporation) – C:\windows\System32\SetIEInstalledDate.exe
[2013/04/29 21:34:36 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\windows\System32\mshtmler.dll
[2013/04/29 21:34:35 | 000,361,984 | —- | C] (Microsoft Corporation) – C:\windows\System32\html.iec
[2013/04/29 21:34:35 | 000,226,816 | —- | C] (Microsoft Corporation) – C:\windows\System32\dxtrans.dll
[2013/04/29 21:34:34 | 001,441,280 | —- | C] (Microsoft Corporation) – C:\windows\System32\inetcpl.cpl
[2013/04/29 21:34:34 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\windows\System32\ieapfltr.dat
[2013/04/29 21:34:34 | 000,719,360 | —- | C] (Microsoft Corporation) – C:\windows\System32\mshtmlmedia.dll
[2013/04/29 21:34:34 | 000,629,248 | —- | C] (Microsoft Corporation) – C:\windows\System32\ieapfltr.dll
[2013/04/29 21:34:34 | 000,357,888 | —- | C] (Microsoft Corporation) – C:\windows\System32\dxtmsft.dll
[2013/04/29 21:34:34 | 000,242,200 | —- | C] (Microsoft Corporation) – C:\windows\System32\iedkcs32.dll
[2013/04/29 21:34:34 | 000,232,960 | —- | C] (Microsoft Corporation) – C:\windows\System32\url.dll
[2013/04/29 21:34:34 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\windows\System32\licmgr10.dll
[2013/04/29 21:33:06 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/04/29 21:33:06 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/04/29 21:33:06 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/04/29 21:33:06 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013/04/29 21:33:05 | 002,284,544 | —- | C] (Microsoft Corporation) – C:\windows\System32\msmpeg2vdec.dll
[2013/04/29 21:33:05 | 001,504,768 | —- | C] (Microsoft Corporation) – C:\windows\System32\d3d11.dll
[2013/04/29 21:33:05 | 001,247,744 | —- | C] (Microsoft Corporation) – C:\windows\System32\DWrite.dll
[2013/04/29 21:33:05 | 001,158,144 | —- | C] (Microsoft Corporation) – C:\windows\System32\XpsPrint.dll
[2013/04/29 21:33:05 | 000,417,792 | —- | C] (Microsoft Corporation) – C:\windows\System32\WMPhoto.dll
[2013/04/29 21:33:05 | 000,364,544 | —- | C] (Microsoft Corporation) – C:\windows\System32\XpsGdiConverter.dll
[2013/04/29 21:33:05 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\windows\System32\d3d10core.dll
[2013/04/29 21:33:05 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/04/29 21:33:05 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/04/29 21:33:05 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/04/29 21:33:05 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/04/29 21:33:05 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/04/29 21:33:04 | 003,419,136 | —- | C] (Microsoft Corporation) – C:\windows\System32\d2d1.dll
[2013/04/29 21:33:04 | 001,988,096 | —- | C] (Microsoft Corporation) – C:\windows\System32\d3d10warp.dll
[2013/04/29 21:33:04 | 001,080,832 | —- | C] (Microsoft Corporation) – C:\windows\System32\d3d10.dll
[2013/04/29 21:33:04 | 000,604,160 | —- | C] (Microsoft Corporation) – C:\windows\System32\d3d10level9.dll
[2013/04/29 21:33:04 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\windows\System32\dxgi.dll
[2013/04/29 21:33:04 | 000,249,856 | —- | C] (Microsoft Corporation) – C:\windows\System32\d3d10_1core.dll
[2013/04/29 21:33:04 | 000,207,872 | —- | C] (Microsoft Corporation) – C:\windows\System32\WindowsCodecsExt.dll
[2013/04/29 21:33:04 | 000,187,392 | —- | C] (Microsoft Corporation) – C:\windows\System32\UIAnimation.dll
[2013/04/29 21:33:04 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\windows\System32\d3d10_1.dll
[2011/05/11 07:00:10 | 006,533,152 | —- | C] (Xobni) – C:\Users\User\XobniSetup.exe
[2011/01/25 19:18:13 | 008,969,504 | —- | C] (Secure Backup and Share) – C:\ProgramData\TempComcastSecureBackupShare-update-94576f825cbee21cffeff81117efd21f.exe
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/05/15 17:35:00 | 000,000,830 | —- | M] () – C:\windows\tasks\Adobe Flash Player Updater.job
[2013/05/15 17:25:00 | 000,000,886 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/05/15 17:23:21 | 000,001,112 | —- | M] () – C:\Users\User\Desktop\BiosAgent Plus.lnk
[2013/05/15 17:21:14 | 000,015,792 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/05/15 17:21:14 | 000,015,792 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/05/15 17:13:41 | 000,000,882 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/05/15 17:13:32 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2013/05/15 17:13:25 | 2211,577,856 | -HS- | M] () – C:\hiberfil.sys
[2013/05/15 10:14:53 | 000,023,456 | —- | M] (Phoenix Technologies) – C:\windows\System32\drivers\DrvAgent32.sys
[2013/05/15 08:35:19 | 000,692,104 | —- | M] (Adobe Systems Incorporated) – C:\windows\System32\FlashPlayerApp.exe
[2013/05/15 08:35:19 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\windows\System32\FlashPlayerCPLApp.cpl
[2013/05/15 08:07:33 | 000,433,584 | —- | M] () – C:\windows\System32\FNTCACHE.DAT
[2013/05/15 07:58:13 | 000,662,722 | —- | M] () – C:\windows\System32\perfh009.dat
[2013/05/15 07:58:13 | 000,121,558 | —- | M] () – C:\windows\System32\perfc009.dat
[2013/05/14 21:47:44 | 000,000,152 | —- | M] () – C:\Users\User\Desktop\FreeVK.ini
[2013/05/14 10:50:55 | 000,155,699 | —- | M] () – C:\Users\User\Desktop\bookmarks.html
[2013/05/14 08:56:42 | 000,002,587 | —- | M] () – C:\Users\Public\Desktop\VAFPlayer.lnk
[2013/05/14 08:54:01 | 000,430,480 | —- | M] () – C:\Users\User\Desktop\FlashPlayer_V.128305733b.exe
[2013/05/14 08:14:02 | 000,846,864 | —- | M] (Microsoft Corporation) – C:\Users\User\Desktop\IE10-Windows6.1-en-us.exe
[2013/05/13 18:53:29 | 000,003,416 | —- | M] () – C:\windows\ComcastSecureBackupShare.blk
[2013/05/13 18:53:29 | 000,000,354 | —- | M] () – C:\windows\ComcastSecureBackupShare.flt
[2013/05/13 12:19:54 | 000,001,225 | —- | M] () – C:\Users\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Revo Uninstaller Pro.lnk
[2013/05/13 12:19:54 | 000,001,201 | —- | M] () – C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
[2013/05/13 12:17:39 | 009,916,056 | —- | M] (VS Revo Group ) – C:\Users\User\Desktop\RevoUninProSetup.exe
[2013/05/13 12:16:46 | 009,916,056 | —- | M] (VS Revo Group ) – C:\Users\User\Desktop\RevoUninProSetup.exe.part
[2013/05/12 11:16:45 | 000,000,027 | —- | M] () – C:\windows\System32\drivers\etc\hosts
[2013/05/12 10:53:19 | 005,069,265 | R— | M] (Swearware) – C:\Users\User\Desktop\ComboFix.exe
[2013/05/11 17:59:37 | 000,004,362 | —- | M] () – C:\windows\wininit.ini
[2013/05/11 09:28:58 | 000,001,057 | —- | M] () – C:\Users\User\Desktop\Play Games.lnk
[2013/05/11 09:26:32 | 000,001,150 | —- | M] () – C:\Users\User\Desktop\Continue Free Flash Player Installation.lnk
[2013/05/10 18:54:29 | 000,001,790 | —- | M] () – C:\Users\User\Application Data\Microsoft\Internet Explorer\Quick Launch\OtShot.lnk
[2013/05/10 18:54:29 | 000,000,908 | —- | M] () – C:\Users\User\Desktop\OtShot.lnk
[2013/05/10 18:04:59 | 000,000,596 | —- | M] () – C:\windows\System32\InstallUtil.InstallLog
[2013/05/10 17:41:04 | 000,209,736 | —- | M] (Comfort Software Group) – C:\Users\User\Desktop\FreeVK.exe
[2013/05/10 13:02:52 | 000,013,024 | —- | M] () – C:\windows\System32\drivers\SWDUMon.sys
[2013/05/09 18:27:49 | 000,000,690 | —- | M] () – C:\windows\DeleteOnReboot.bat
[2013/05/09 09:47:09 | 000,000,162 | —- | M] () – C:\windows\Reimage.ini
[2013/05/09 09:04:40 | 000,000,906 | —- | M] () – C:\Users\Public\Desktop\AVG 2013.lnk
[2013/05/09 08:51:52 | 000,002,283 | —- | M] () – C:\Users\User\Windows Easy Transfer.lnk
[2013/05/08 18:52:48 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
[2013/05/08 16:16:17 | 000,001,586 | —- | M] () – C:\Users\User\Documents\cc_20130508_161612.reg
[2013/05/08 14:56:02 | 000,002,090 | —- | M] () – C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
[2013/05/08 14:19:40 | 001,012,646 | —- | M] () – C:\Users\User\AppData\Local\census.cache
[2013/05/08 14:18:41 | 000,196,593 | —- | M] () – C:\Users\User\AppData\Local\ars.cache
[2013/05/08 14:00:25 | 000,000,036 | —- | M] () – C:\Users\User\AppData\Local\housecall.guid.cache
[2013/04/29 21:34:39 | 000,745,472 | —- | M] (Microsoft Corporation) – C:\windows\System32\MsSpellCheckingFacility.exe
[2013/04/29 21:34:39 | 000,185,344 | —- | M] (Microsoft Corporation) – C:\windows\System32\elshyph.dll
[2013/04/29 21:34:39 | 000,158,720 | —- | M] (Microsoft Corporation) – C:\windows\System32\msls31.dll
[2013/04/29 21:34:38 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\windows\System32\msrating.dll
[2013/04/29 21:34:38 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\windows\System32\iexpress.exe
[2013/04/29 21:34:38 | 000,138,752 | —- | M] (Microsoft Corporation) – C:\windows\System32\wextract.exe
[2013/04/29 21:34:38 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\windows\System32\inseng.dll
[2013/04/29 21:34:37 | 000,137,216 | —- | M] (Microsoft Corporation) – C:\windows\System32\ieUnatt.exe
[2013/04/29 21:34:37 | 000,117,248 | —- | M] (Microsoft Corporation) – C:\windows\System32\iepeers.dll
[2013/04/29 21:34:37 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\windows\System32\IEAdvpack.dll
[2013/04/29 21:34:37 | 000,057,344 | —- | M] (Microsoft Corporation) – C:\windows\System32\pngfilt.dll
[2013/04/29 21:34:37 | 000,041,984 | —- | M] (Microsoft Corporation) – C:\windows\System32\msfeedsbs.dll
[2013/04/29 21:34:37 | 000,038,400 | —- | M] (Microsoft Corporation) – C:\windows\System32\imgutil.dll
[2013/04/29 21:34:37 | 000,011,776 | —- | M] (Microsoft Corporation) – C:\windows\System32\msfeedssync.exe
[2013/04/29 21:34:36 | 000,073,728 | —- | M] (Microsoft Corporation) – C:\windows\System32\SetIEInstalledDate.exe
[2013/04/29 21:34:36 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\windows\System32\mshtmler.dll
[2013/04/29 21:34:35 | 000,361,984 | —- | M] (Microsoft Corporation) – C:\windows\System32\html.iec
[2013/04/29 21:34:35 | 000,226,816 | —- | M] (Microsoft Corporation) – C:\windows\System32\dxtrans.dll
[2013/04/29 21:34:34 | 001,441,280 | —- | M] (Microsoft Corporation) – C:\windows\System32\inetcpl.cpl
[2013/04/29 21:34:34 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\windows\System32\ieapfltr.dat
[2013/04/29 21:34:34 | 000,719,360 | —- | M] (Microsoft Corporation) – C:\windows\System32\mshtmlmedia.dll
[2013/04/29 21:34:34 | 000,629,248 | —- | M] (Microsoft Corporation) – C:\windows\System32\ieapfltr.dll
[2013/04/29 21:34:34 | 000,357,888 | —- | M] (Microsoft Corporation) – C:\windows\System32\dxtmsft.dll
[2013/04/29 21:34:34 | 000,242,200 | —- | M] (Microsoft Corporation) – C:\windows\System32\iedkcs32.dll
[2013/04/29 21:34:34 | 000,232,960 | —- | M] (Microsoft Corporation) – C:\windows\System32\url.dll
[2013/04/29 21:34:34 | 000,025,185 | —- | M] () – C:\windows\System32\ieuinit.inf
[2013/04/29 21:34:34 | 000,023,040 | —- | M] (Microsoft Corporation) – C:\windows\System32\licmgr10.dll
[2013/04/29 21:33:06 | 000,009,728 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/04/29 21:33:06 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/04/29 21:33:06 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/04/29 21:33:06 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013/04/29 21:33:05 | 002,284,544 | —- | M] (Microsoft Corporation) – C:\windows\System32\msmpeg2vdec.dll
[2013/04/29 21:33:05 | 001,504,768 | —- | M] (Microsoft Corporation) – C:\windows\System32\d3d11.dll
[2013/04/29 21:33:05 | 001,247,744 | —- | M] (Microsoft Corporation) – C:\windows\System32\DWrite.dll
[2013/04/29 21:33:05 | 001,158,144 | —- | M] (Microsoft Corporation) – C:\windows\System32\XpsPrint.dll
[2013/04/29 21:33:05 | 000,417,792 | —- | M] (Microsoft Corporation) – C:\windows\System32\WMPhoto.dll
[2013/04/29 21:33:05 | 000,364,544 | —- | M] (Microsoft Corporation) – C:\windows\System32\XpsGdiConverter.dll
[2013/04/29 21:33:05 | 000,220,160 | —- | M] (Microsoft Corporation) – C:\windows\System32\d3d10core.dll
[2013/04/29 21:33:05 | 000,010,752 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/04/29 21:33:05 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/04/29 21:33:05 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/04/29 21:33:05 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/04/29 21:33:05 | 000,002,560 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/04/29 21:33:04 | 003,419,136 | —- | M] (Microsoft Corporation) – C:\windows\System32\d2d1.dll
[2013/04/29 21:33:04 | 001,988,096 | —- | M] (Microsoft Corporation) – C:\windows\System32\d3d10warp.dll
[2013/04/29 21:33:04 | 001,080,832 | —- | M] (Microsoft Corporation) – C:\windows\System32\d3d10.dll
[2013/04/29 21:33:04 | 000,604,160 | —- | M] (Microsoft Corporation) – C:\windows\System32\d3d10level9.dll
[2013/04/29 21:33:04 | 000,293,376 | —- | M] (Microsoft Corporation) – C:\windows\System32\dxgi.dll
[2013/04/29 21:33:04 | 000,249,856 | —- | M] (Microsoft Corporation) – C:\windows\System32\d3d10_1core.dll
[2013/04/29 21:33:04 | 000,207,872 | —- | M] (Microsoft Corporation) – C:\windows\System32\WindowsCodecsExt.dll
[2013/04/29 21:33:04 | 000,187,392 | —- | M] (Microsoft Corporation) – C:\windows\System32\UIAnimation.dll
[2013/04/29 21:33:04 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\windows\System32\d3d10_1.dll
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/05/15 17:23:21 | 000,001,112 | —- | C] () – C:\Users\User\Desktop\BiosAgent Plus.lnk
[2013/05/14 10:50:55 | 000,155,699 | —- | C] () – C:\Users\User\Desktop\bookmarks.html
[2013/05/14 08:56:42 | 000,002,587 | —- | C] () – C:\Users\Public\Desktop\VAFPlayer.lnk
[2013/05/14 08:54:00 | 000,430,480 | —- | C] () – C:\Users\User\Desktop\FlashPlayer_V.128305733b.exe
[2013/05/13 12:19:54 | 000,001,225 | —- | C] () – C:\Users\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Revo Uninstaller Pro.lnk
[2013/05/13 12:19:54 | 000,001,201 | —- | C] () – C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
[2013/05/12 08:43:24 | 000,256,000 | —- | C] () – C:\windows\PEV.exe
[2013/05/12 08:43:24 | 000,208,896 | —- | C] () – C:\windows\MBR.exe
[2013/05/12 08:43:24 | 000,098,816 | —- | C] () – C:\windows\sed.exe
[2013/05/12 08:43:24 | 000,080,412 | —- | C] () – C:\windows\grep.exe
[2013/05/12 08:43:24 | 000,068,096 | —- | C] () – C:\windows\zip.exe
[2013/05/11 09:28:58 | 000,001,057 | —- | C] () – C:\Users\User\Desktop\Play Games.lnk
[2013/05/11 09:26:32 | 000,001,150 | —- | C] () – C:\Users\User\Desktop\Continue Free Flash Player Installation.lnk
[2013/05/10 18:54:29 | 000,001,790 | —- | C] () – C:\Users\User\Application Data\Microsoft\Internet Explorer\Quick Launch\OtShot.lnk
[2013/05/10 18:54:29 | 000,000,920 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OtShot.lnk
[2013/05/10 18:54:29 | 000,000,908 | —- | C] () – C:\Users\User\Desktop\OtShot.lnk
[2013/05/10 18:04:57 | 000,000,596 | —- | C] () – C:\windows\System32\InstallUtil.InstallLog
[2013/05/10 17:41:05 | 000,000,152 | —- | C] () – C:\Users\User\Desktop\FreeVK.ini
[2013/05/10 13:02:52 | 000,013,024 | —- | C] () – C:\windows\System32\drivers\SWDUMon.sys
[2013/05/09 11:00:45 | 000,000,690 | —- | C] () – C:\windows\DeleteOnReboot.bat
[2013/05/08 18:18:39 | 000,000,162 | —- | C] () – C:\windows\Reimage.ini
[2013/05/08 16:16:15 | 000,001,586 | —- | C] () – C:\Users\User\Documents\cc_20130508_161612.reg
[2013/05/08 15:45:22 | 000,004,362 | —- | C] () – C:\windows\wininit.ini
[2013/05/08 14:56:02 | 000,002,102 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
[2013/05/08 14:56:02 | 000,002,090 | —- | C] () – C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
[2013/05/08 14:19:40 | 001,012,646 | —- | C] () – C:\Users\User\AppData\Local\census.cache
[2013/05/08 14:18:41 | 000,196,593 | —- | C] () – C:\Users\User\AppData\Local\ars.cache
[2013/05/08 14:00:25 | 000,000,036 | —- | C] () – C:\Users\User\AppData\Local\housecall.guid.cache
[2013/04/29 21:34:34 | 000,025,185 | —- | C] () – C:\windows\System32\ieuinit.inf
[2011/10/08 08:48:11 | 000,000,210 | —- | C] () – C:\Users\User\AppData\Roaming\wklnhst.dat
[2011/04/13 17:51:02 | 000,001,502 | —- | C] () – C:\Users\User\.recently-used.xbel
[2011/03/16 18:54:03 | 000,000,000 | —- | C] () – C:\Users\User\AppData\Local\prvlcl.dat
[2010/12/05 03:58:53 | 000,026,837 | —- | C] () – C:\Users\User\AppData\Roaming\Comma Separated Values (Windows).ADR
[2010/12/02 10:05:38 | 000,000,017 | —- | C] () – C:\Users\User\AppData\Local\resmon.resmoncfg
[2010/12/01 03:12:28 | 000,002,283 | —- | C] () – C:\Users\User\Windows Easy Transfer.lnk
[2010/12/01 03:12:28 | 000,000,706 | —- | C] () – C:\Users\User\autorun.inf

========== ZeroAccess Check ==========

[2009/07/14 00:42:31 | 000,000,227 | RHS- | M] () – C:\windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/27 00:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 08:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/13 21:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

< End of report >
Thank You Very much for your time.
Marty
Hi MARTY1946,

only thing I see is it stops to ask the Windows 7 operating system.

When this occurs, does it count down and then boot windows 7? Or is it necessary for you to physically make the selection?

If you are not sure please test on next reboot. When it occurs allow ample time to see if it boots without any input by you.

1. Run OTL.exe

Windows Vista and Windows 7 users Right Click and select "Run as Administrator"
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    [2013/05/10 18:54:29 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OtShot
    [2013/05/10 18:54:29 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OtShot
    [2013/05/10 18:54:29 | 000,001,790 | —- | M] () – C:\Users\User\Application Data\Microsoft\Internet Explorer\Quick Launch\OtShot.lnk
    [2013/05/10 18:54:29 | 000,000,908 | —- | M] () – C:\Users\User\Desktop\OtShot.lnk
    [2013/05/10 18:54:29 | 000,001,790 | —- | C] () – C:\Users\User\Application Data\Microsoft\Internet Explorer\Quick Launch\OtShot.lnk
    [2013/05/10 18:54:29 | 000,000,920 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OtShot.lnk
    
    FF - HKLM\Software\MozillaPlugins\@MyOwnSuperhero.com/Plugin: C:\Program Files\MyOwnSuperhero\bar\2.bin\NPv3Stub.dll File not found
    
    :Files
    C:\Program Files\Common Files\Umbrella
    
    :Services
    SProtection
    
    :Commands
    [purity]
    [createrestorepoint]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then re-run OTL and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
=========================

In your next post please provide the following:
  • OTL.txt
  • Answer to the questions above
Hello OCD; I ran OTL as asked. The machine did not restart correctly. Got the BEEPING again. Here is the log what is left of it. Something inputs a series of periods, and deletes as it goes. Only way to stop it, is to type something in search for, in the start menu. …………………………………………………………………….. …………………………………………………………All processes killed ========== OTL ========== C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OtShot folder moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OtShot folder moved successfully. C:\Users\User\Application Data\Microsoft\Internet Explorer\Quick Launch\OtShot.lnk moved successfully. C:\Users\User\Desktop\OtShot.lnk moved successfully. File C:\Users\User\Application Data\Microsoft\Internet Explorer\Quick Launch\OtShot.lnk not found. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OtShot.lnk moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@MyOwnSuperhero.com/Plugin\ deleted successfully. ========== FILES ========== File\Folder C:\Program Files\Common Files\Umbrella not found. ========== SERVICES/DRIVERS ========== Service SProtection stopped successfully! Service SProtection deleted successfully! ========== COMMANDS ========== Restore point Set: OTL Restore Point [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->Flash cache emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public ->Temp folder emptied: 0 bytes User: User ->Temp folder emptied: 68483767 bytes ->Temporary Internet Files folder emptied: 200937766 bytes ->Java cache emptied: 0 bytes ->Opera cache emptied: 0 bytes ->Flash cache emptied: 598 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 17571232 bytes RecycleBin emptied: 1092 bytes Total Files Cleaned = 274.00 mb OTL by OldTimer - Version 3.2.69.0 log created on 05152013_192456 Files\Folders moved on Reboot… PendingFileRenameOperations files… Registry entries deleted on Reboot… Thanks again Marty
Hi MARTY1946, Please re-run OTL and generate a fresh scan. The reason I'm asking for these scans is I need to be sure the computer is malware free. The inserting of periods may indicate that the period key is sticking in some manner. Do you have a can of compressed air? If so, clean the keyboard paying close attention to the period key. Reply with the fresh OTL and any input about the questions asked
Hello OCD:
Here is the OTL Log.
The period key is still not working.

OTL logfile created on: 5/15/2013 8:35:36 PM - Run 7
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\User\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16576)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.75 Gb Total Physical Memory | 1.84 Gb Available Physical Memory | 67.12% Memory free
5.49 Gb Paging File | 4.20 Gb Available in Paging File | 76.48% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 288.71 Gb Total Space | 233.58 Gb Free Space | 80.91% Space Free | Partition Type: NTFS

Computer Name: RICHARDGMARTIN | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Users\User\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe ()
PRC - C:\Program Files\AVG\AVG2013\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Xobni\XobniService.exe (Xobni Corporation)
PRC - C:\Program Files\SecureBackupShare\ComcastSecureBackupSharestat.exe (Secure Backup and Share)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\SecureBackupShare\ComcastSecureBackupSharebackup.exe (Secure Backup and Share)
PRC - C:\Program Files\Toshiba Online Backup\ToshibaOnlineBackup.exe ()
PRC - C:\Program Files\ARX\ARX CryptoKit\utils\ARcltsrv.exe (Algorithmic Research Ltd.)
PRC - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TECO\TecoService.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TECO\TEco.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe (TOSHIBA CORPORATION)
PRC - C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)


========== Modules (No Company Name) ==========

MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\30e3a21202000677d0a9270572251477\System.Windows.Forms.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\764f15e86c82662e977bd418bd6318c1\System.Configuration.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\5ecf01964c70e453d71e5d7653912ff9\System.Web.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\90b89f6e8032310e9ac72a309fd49e83\System.Runtime.Remoting.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\snlFileFormats150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\VirtualTreesDXE150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\JSDialogPack150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl ()
MOD - C:\Program Files\Toshiba Online Backup\Toast.dll ()
MOD - C:\Program Files\Toshiba Online Backup\ToshibaOnlineBackup.exe ()
MOD - C:\Program Files\Toshiba Online Backup\SdbShared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Wizard\2.0.3497.38831__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager2.Graphics.Dashboard\2.0.3497.38923__90ba9c70f846762e\CLI.Aspect.DisplaysManager2.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboard\2.0.3497.38856__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Dashboard\2.0.3497.38833__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Wizard\2.0.3497.38899__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\2.0.3497.38875__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard\2.0.3497.38855__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.3497.38814__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashboard\2.0.3497.38868__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Dashboard\2.0.3497.38862__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Wizard\2.0.3497.38837__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wizard\2.0.3497.38833__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dashboard\2.0.3497.38833__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Dashboard\2.0.3497.38898__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard\2.0.3497.38868__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Dashboard\2.0.3497.38861__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime\2.0.3497.38856__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtime\2.0.3497.38880__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.3497.38822__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtime\2.0.3497.38863__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtime\2.0.3497.38867__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runtime\2.0.3497.38855__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboard\2.0.3497.38899__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime\2.0.3497.38898__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.3497.38828__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Runtime\2.0.3497.38837__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Runtime\2.0.3497.38860__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Runtime\2.0.3497.38855__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runtime\2.0.3497.38862__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Runtime\2.0.3497.38823__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\MOM.Implementation\2.0.3497.38894__90ba9c70f846762e\MOM.Implementation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.3428.28305__90ba9c70f846762e\CLI.Caste.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Foundation\2.0.3428.28298__90ba9c70f846762e\CLI.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared\2.0.3428.28316__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared\2.0.3428.28315__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\2.0.3428.28314__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Shared\2.0.3428.28314__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Shared\2.0.3428.28314__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.3497.38904__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Shared\2.0.3428.28324__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Shared\2.0.3428.28315__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runtime\2.0.3497.38856__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\LOG.Foundation\2.0.3428.28296__90ba9c70f846762e\LOG.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Shared\2.0.3428.28309__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.3428.28297__90ba9c70f846762e\NEWAEM.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.3428.28354__90ba9c70f846762e\CLI.Foundation.XManifest.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Shared\2.0.3428.28323__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Shared\2.0.3428.28313__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Shared\2.0.3428.28312__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.CustomFormats.Graphics.Shared\2.0.3428.28311__90ba9c70f846762e\CLI.Aspect.CustomFormats.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.3428.28304__90ba9c70f846762e\CLI.Component.Dashboard.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Shared\2.0.3428.28314__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\ResourceManagement.Foundation.Private\2.0.3428.28303__90ba9c70f846762e\ResourceManagement.Foundation.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.3428.28308__90ba9c70f846762e\CLI.Component.Wizard.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.3428.28302__90ba9c70f846762e\CLI.Component.Client.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Shared\2.0.3428.28312__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\APM.Foundation\2.0.3428.28310__90ba9c70f846762e\APM.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.3428.28304__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.3428.28302__90ba9c70f846762e\AEM.Actions.CCAA.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\MOM.Foundation\2.0.3428.28310__90ba9c70f846762e\MOM.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\DEM.Graphics.I0706\2.0.2743.23304__90ba9c70f846762e\DEM.Graphics.I0706.dll ()
MOD - C:\windows\assembly\GAC_MSIL\DEM.Graphics\2.0.3428.28324__90ba9c70f846762e\DEM.Graphics.dll ()
MOD - C:\windows\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.3428.28303__90ba9c70f846762e\CLI.Component.Runtime.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2.0.3428.28313__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared\2.0.3428.28312__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Server.Shared\2.0.3428.28304__90ba9c70f846762e\AEM.Server.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.WinMessages.Shared\2.0.3428.28311__90ba9c70f846762e\AEM.Plugin.WinMessages.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.REG.Shared\2.0.3428.28329__90ba9c70f846762e\AEM.Plugin.REG.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.3428.28327__90ba9c70f846762e\AEM.Plugin.GD.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.3428.28311__90ba9c70f846762e\AEM.Plugin.EEU.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.3428.28327__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Runtime.Extension.EEU\2.0.3497.38810__90ba9c70f846762e\CLI.Component.Runtime.Extension.EEU.dll ()
MOD - C:\windows\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.3497.38819__90ba9c70f846762e\CLI.Component.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.3497.38827__90ba9c70f846762e\CLI.Component.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.3497.38892__90ba9c70f846762e\LOG.Foundation.Implementation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\APM.Server\2.0.3497.38811__90ba9c70f846762e\APM.Server.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.SkinFactory\2.0.3497.38813__90ba9c70f846762e\CLI.Component.SkinFactory.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.3497.38812__90ba9c70f846762e\CLI.Component.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Private\2.0.3428.28311__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Server\2.0.3497.38810__90ba9c70f846762e\AEM.Server.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.3428.28301__90ba9c70f846762e\CLI.Foundation.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private\2.0.3428.28308__90ba9c70f846762e\CLI.Component.Client.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.3428.28303__90ba9c70f846762e\LOG.Foundation.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private\2.0.3428.28311__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.3428.28310__90ba9c70f846762e\LOG.Foundation.Implementation.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Private\2.0.3428.28309__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime.Shared.Private\2.0.3428.28316__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CCC.Implementation\2.0.3497.38893__90ba9c70f846762e\CCC.Implementation.dll ()
MOD - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosIPCWraper.dll ()
MOD - C:\Program Files\TOSHIBA\TOSHIBA Disc Creator\NotifyTDC.dll ()
MOD - C:\Program Files\TOSHIBA\FlashCards\Hotkey\FnZ.dll ()
MOD - C:\Program Files\TOSHIBA\FlashCards\BlackPng.dll ()
MOD - C:\Program Files\TOSHIBA\TOSHIBA Assist\NotifyX.dll ()
MOD - C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll ()
MOD - C:\Program Files\TOSHIBA\PCDiag\NotifyPCD.dll ()


========== Services (SafeList) ==========

SRV - (SDWSCService) – C:\Program Files\Spybot File not found
SRV - (SDUpdateService) – C:\Program Files\Spybot File not found
SRV - (SDScannerService) – C:\Program Files\Spybot File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (RealNetworks Downloader Resolver Service) – C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe ()
SRV - (XobniService) – C:\Program Files\Xobni\XobniService.exe (Xobni Corporation)
SRV - (GamesAppService) – C:\Program Files\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (ComcastSecureBackupSharebackup) – C:\Program Files\SecureBackupShare\ComcastSecureBackupSharebackup.exe (Secure Backup and Share)
SRV - (Autodesk Licensing Service) – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (ARcltsrv) – C:\Program Files\ARX\ARX CryptoKit\utils\ARcltsrv.exe (Algorithmic Research Ltd.)
SRV - (TosCoSrv) – C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV - (TMachInfo) – C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation)
SRV - (TOSHIBA eco Utility Service) – C:\Program Files\TOSHIBA\TECO\TecoService.exe (TOSHIBA Corporation)
SRV - (cfWiMAXService) – C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe (TOSHIBA CORPORATION)
SRV - (TPCHSrv) – C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe (TOSHIBA Corporation)
SRV - (TOSHIBA HDD SSD Alert Service) – C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation)
SRV - (AMD External Events Utility) – C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (TODDSrv) – C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (ConfigFree Service) – C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)


========== Driver Services (SafeList) ==========

DRV - (USBCCID) – system32\DRIVERS\RtsUCcid.sys File not found
DRV - (RtsUIR) – system32\DRIVERS\Rts516xIR.sys File not found
DRV - (RSUSBSTOR) – System32\Drivers\RtsUStor.sys File not found
DRV - (cpuz134) – C:\Users\User\AppData\Local\Temp\cpuz134\cpuz134_x32.sys File not found
DRV - (catchme) – C:\Users\User\AppData\Local\Temp\catchme.sys File not found
DRV - (DrvAgent32) – C:\Windows\System32\drivers\DrvAgent32.sys (Phoenix Technologies)
DRV - (SWDUMon) – C:\Windows\System32\drivers\SWDUMon.sys ()
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (avgtp) – C:\Windows\System32\drivers\avgtpx86.sys (AVG Technologies)
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avglogx) – C:\Windows\System32\drivers\avglogx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSHX) – C:\Windows\System32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\Windows\System32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (ComcastSecureBackupShareFilter) – C:\Windows\System32\drivers\ComcastSecureBackupShare.sys (Mozy, Inc.)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (winusb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (rtl8192se) – C:\Windows\System32\drivers\rtl8192se.sys (Realtek Semiconductor Corporation )
DRV - (tdcmdpst) – C:\Windows\System32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (tos_sps32) – C:\Windows\System32\drivers\tos_sps32.sys (TOSHIBA Corporation)
DRV - (TVALZ) – C:\Windows\System32\drivers\TVALZ_O.SYS (TOSHIBA Corporation)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (Serial) – C:\Windows\System32\drivers\serial.sys (Brother Industries Ltd.)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (LSI Corp)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (FwLnk) – C:\Windows\System32\drivers\FwLnk.sys (TOSHIBA Corporation)
DRV - (PGEffect) – C:\Windows\System32\drivers\PGEffect.sys (TOSHIBA Corporation)
DRV - (TVALZFL) – C:\Windows\System32\drivers\TVALZFL.sys (TOSHIBA Corporation)
DRV - (dc3d) – C:\Windows\System32\drivers\dc3d.sys (Microsoft Corporation)
DRV - (Point32) – C:\Windows\System32\drivers\point32k.sys (Microsoft Corporation)
DRV - (AtiPcie) – C:\Windows\System32\drivers\AtiPcie.sys (Advanced Micro Devices Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0EF3D5EE-B833-43EC-8265-E0B5C71D50AB}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7TSNA

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKCU\..\SearchScopes\{0EF3D5EE-B833-43EC-8265-E0B5C71D50AB}: "URL" = http://www.google.com/search?sourceid=ie7&…1I7TSNA_enUS360
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF32_11_7_700_202.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.1.18: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.1.18: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.17: C:\Program Files\Veetle\VLCBroadcast\npvbp.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.17: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.17: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@Webfetti.com/Plugin: C:\Program Files\Webfetti\bar\2.bin\NP7dStub.dll File not found
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\14\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\User\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\discoversoan@orbiscom: C:\Program Files\Discover\SOAN [2010/12/24 13:53:17 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013/03/31 08:50:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{DAC3F861-B30D-40dd-9166-F4E75327FAC7}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2013/03/31 08:50:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Mozilla Firefox\extensions\[removed]


O1 HOSTS File: ([2013/05/12 11:16:45 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (LessTabs) - {3178A392-8963-471E-B7A2-969CB58D6496} - C:\Program Files\LessTabs\IE32\LessTabsClientIE.dll (LessTabs)
O2 - BHO: (Secure Online Account Numbers Helper) - {435EAA86-D32B-484F-869C-53745FCB1642} - C:\Program Files\Discover\SOAN\DiscoverSOANHelper.dll (Orbiscom Ltd. All rights reserved.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Secure Online Account Numbers) - {A8C7C2CA-6DFD-4E16-8458-592361564D38} - C:\Program Files\Discover\SOAN\DiscoverSOANToolbar.dll (Orbiscom Ltd. All rights reserved.)
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [SDTray] C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
O4 - HKLM..\Run: [Secure Online Account Numbers] C:\Program Files\Discover\SOAN\DiscoverSOAN.exe (Orbiscom Ltd. All rights reserved.)
O4 - HKLM..\Run: [SmartFaceVWatcher] C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatcher.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TkBellExe] c:\program files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Toshiba Online Backup] C:\Program Files\Toshiba Online Backup\ToshibaOnlineBackup.exe ()
O4 - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TosWaitSrv] C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TWebCamera] C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
O4 - HKCU..\Run: [MyTOSHIBA] C:\Program Files\TOSHIBA\My Toshiba\MyToshiba.exe (TOSHIBA)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.4.2/jinstall-…indows-i586.cab (Java Plug-in 10.21.2)
O16 - DPF: {CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.4.2/jinstall-…indows-i586.cab (Java Plug-in 1.4.2_04)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.76.76 75.75.75.75
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{ABBFB7FF-852E-4FF6-9DC0-3A692906985E}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CF438D8B-532B-4B7A-972C-707EF7287EFF}: DhcpNameServer = 75.75.76.76 75.75.75.75
O18 - Protocol\Handler\linkscanner - No CLSID value found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/05/15 17:15:00 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Temp
[2013/05/15 10:14:53 | 000,023,456 | —- | C] (Phoenix Technologies) – C:\windows\System32\drivers\DrvAgent32.sys
[2013/05/15 10:14:53 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\eSupport.com
[2013/05/15 08:00:36 | 002,706,432 | —- | C] (Microsoft Corporation) – C:\windows\System32\mshtml.tlb
[2013/05/15 08:00:35 | 002,877,440 | —- | C] (Microsoft Corporation) – C:\windows\System32\jscript9.dll
[2013/05/15 08:00:34 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\windows\System32\ieui.dll
[2013/05/15 08:00:34 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\windows\System32\iesetup.dll
[2013/05/15 08:00:34 | 000,039,424 | —- | C] (Microsoft Corporation) – C:\windows\System32\jsproxy.dll
[2013/05/15 08:00:33 | 000,493,056 | —- | C] (Microsoft Corporation) – C:\windows\System32\msfeeds.dll
[2013/05/15 08:00:33 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\windows\System32\iesysprep.dll
[2013/05/15 08:00:33 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\windows\System32\RegisterIEPKEYs.exe
[2013/05/15 08:00:33 | 000,042,496 | —- | C] (Microsoft Corporation) – C:\windows\System32\ie4uinit.exe
[2013/05/15 08:00:33 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\windows\System32\iernonce.dll
[2013/05/15 07:44:45 | 002,347,520 | —- | C] (Microsoft Corporation) – C:\windows\System32\win32k.sys
[2013/05/15 07:44:45 | 000,218,984 | —- | C] (Microsoft Corporation) – C:\windows\System32\drivers\dxgmms1.sys
[2013/05/15 07:44:41 | 001,796,096 | —- | C] (Microsoft Corporation) – C:\windows\System32\authui.dll
[2013/05/15 07:44:41 | 000,101,720 | —- | C] (Microsoft Corporation) – C:\windows\System32\consent.exe
[2013/05/14 08:56:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAFPlayer
[2013/05/14 08:56:38 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\player
[2013/05/14 08:56:37 | 000,000,000 | —D | C] – C:\Program Files\Tuguu SL
[2013/05/14 08:13:57 | 000,846,864 | —- | C] (Microsoft Corporation) – C:\Users\User\Desktop\IE10-Windows6.1-en-us.exe
[2013/05/13 12:19:59 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\VS Revo Group
[2013/05/13 12:19:54 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
[2013/05/13 12:19:53 | 000,027,192 | —- | C] (VS Revo Group) – C:\windows\System32\drivers\revoflt.sys
[2013/05/13 12:19:53 | 000,000,000 | —D | C] – C:\ProgramData\VS Revo Group
[2013/05/13 12:19:52 | 000,000,000 | —D | C] – C:\Program Files\VS Revo Group
[2013/05/13 12:17:39 | 009,916,056 | —- | C] (VS Revo Group ) – C:\Users\User\Desktop\RevoUninProSetup.exe
[2013/05/13 12:16:41 | 009,916,056 | —- | C] (VS Revo Group ) – C:\Users\User\Desktop\RevoUninProSetup.exe.part
[2013/05/12 11:46:35 | 000,000,000 | —D | C] – C:\windows\temp
[2013/05/12 11:44:57 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/05/12 10:53:14 | 005,069,265 | R— | C] (Swearware) – C:\Users\User\Desktop\ComboFix.exe
[2013/05/12 08:43:24 | 000,518,144 | —- | C] (SteelWerX) – C:\windows\SWREG.exe
[2013/05/12 08:43:24 | 000,406,528 | —- | C] (SteelWerX) – C:\windows\SWSC.exe
[2013/05/12 08:43:24 | 000,060,416 | —- | C] (NirSoft) – C:\windows\NIRCMD.exe
[2013/05/12 08:39:53 | 000,000,000 | —D | C] – C:\Qoobox
[2013/05/12 08:39:26 | 000,000,000 | —D | C] – C:\windows\erdnt
[2013/05/11 09:28:57 | 000,000,000 | —D | C] – C:\Program Files\FGIcon
[2013/05/11 09:28:56 | 000,000,000 | —D | C] – C:\ProgramData\Wincert
[2013/05/11 09:28:25 | 000,000,000 | —D | C] – C:\Program Files\Settings Alerter
[2013/05/11 08:52:58 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\SwvUpdater
[2013/05/11 08:51:56 | 000,000,000 | -HSD | C] – C:\windows\System32\AI_RecycleBin
[2013/05/11 08:49:57 | 000,000,000 | —D | C] – C:\AI_RecycleBin
[2013/05/11 08:49:26 | 000,000,000 | —D | C] – C:\Program Files\LyricsTube
[2013/05/10 17:58:29 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\CRE
[2013/05/10 17:41:04 | 000,209,736 | —- | C] (Comfort Software Group) – C:\Users\User\Desktop\FreeVK.exe
[2013/05/10 17:40:44 | 000,000,000 | —D | C] – C:\Program Files\LessTabs
[2013/05/10 13:02:51 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\SlimWare Utilities Inc
[2013/05/10 13:02:43 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Downloaded Installers
[2013/05/10 08:04:48 | 000,000,000 | —D | C] – C:\temp
[2013/05/09 21:17:41 | 000,000,000 | —D | C] – C:\_OTL
[2013/05/09 15:53:37 | 000,000,000 | —D | C] – C:\windows\ERUNT
[2013/05/09 15:53:28 | 000,000,000 | —D | C] – C:\JRT
[2013/05/09 09:04:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013/05/09 08:50:18 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Foresight Software
[2013/05/09 08:50:01 | 000,000,000 | —D | C] – C:\ProgramData\Foresight Software
[2013/05/08 18:52:48 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
[2013/05/08 14:56:10 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2013/05/08 14:56:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
[2013/05/08 14:55:47 | 000,015,224 | —- | C] (Safer Networking Limited) – C:\windows\System32\sdnclean.exe
[2013/05/08 14:55:42 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy 2
[2013/05/08 14:55:04 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Programs
[2013/05/01 08:29:22 | 000,174,496 | —- | C] (Oracle Corporation) – C:\windows\System32\javaw.exe
[2013/05/01 08:29:22 | 000,174,496 | —- | C] (Oracle Corporation) – C:\windows\System32\java.exe
[2013/05/01 08:29:22 | 000,094,112 | —- | C] (Oracle Corporation) – C:\windows\System32\WindowsAccessBridge.dll
[2013/04/29 21:34:39 | 000,745,472 | —- | C] (Microsoft Corporation) – C:\windows\System32\MsSpellCheckingFacility.exe
[2013/04/29 21:34:39 | 000,185,344 | —- | C] (Microsoft Corporation) – C:\windows\System32\elshyph.dll
[2013/04/29 21:34:39 | 000,158,720 | —- | C] (Microsoft Corporation) – C:\windows\System32\msls31.dll
[2013/04/29 21:34:38 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\windows\System32\msrating.dll
[2013/04/29 21:34:38 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\windows\System32\iexpress.exe
[2013/04/29 21:34:38 | 000,138,752 | —- | C] (Microsoft Corporation) – C:\windows\System32\wextract.exe
[2013/04/29 21:34:38 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\windows\System32\inseng.dll
[2013/04/29 21:34:37 | 000,137,216 | —- | C] (Microsoft Corporation) – C:\windows\System32\ieUnatt.exe
[2013/04/29 21:34:37 | 000,117,248 | —- | C] (Microsoft Corporation) – C:\windows\System32\iepeers.dll
[2013/04/29 21:34:37 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\windows\System32\IEAdvpack.dll
[2013/04/29 21:34:37 | 000,057,344 | —- | C] (Microsoft Corporation) – C:\windows\System32\pngfilt.dll
[2013/04/29 21:34:37 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\windows\System32\msfeedsbs.dll
[2013/04/29 21:34:37 | 000,038,400 | —- | C] (Microsoft Corporation) – C:\windows\System32\imgutil.dll
[2013/04/29 21:34:37 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\windows\System32\msfeedssync.exe
[2013/04/29 21:34:36 | 000,073,728 | —- | C] (Microsoft Corporation) – C:\windows\System32\SetIEInstalledDate.exe
[2013/04/29 21:34:36 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\windows\System32\mshtmler.dll
[2013/04/29 21:34:35 | 000,361,984 | —- | C] (Microsoft Corporation) – C:\windows\System32\html.iec
[2013/04/29 21:34:35 | 000,226,816 | —- | C] (Microsoft Corporation) – C:\windows\System32\dxtrans.dll
[2013/04/29 21:34:34 | 001,441,280 | —- | C] (Microsoft Corporation) – C:\windows\System32\inetcpl.cpl
[2013/04/29 21:34:34 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\windows\System32\ieapfltr.dat
[2013/04/29 21:34:34 | 000,719,360 | —- | C] (Microsoft Corporation) – C:\windows\System32\mshtmlmedia.dll
[2013/04/29 21:34:34 | 000,629,248 | —- | C] (Microsoft Corporation) – C:\windows\System32\ieapfltr.dll
[2013/04/29 21:34:34 | 000,357,888 | —- | C] (Microsoft Corporation) – C:\windows\System32\dxtmsft.dll
[2013/04/29 21:34:34 | 000,242,200 | —- | C] (Microsoft Corporation) – C:\windows\System32\iedkcs32.dll
[2013/04/29 21:34:34 | 000,232,960 | —- | C] (Microsoft Corporation) – C:\windows\System32\url.dll
[2013/04/29 21:34:34 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\windows\System32\licmgr10.dll
[2013/04/29 21:33:06 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/04/29 21:33:06 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/04/29 21:33:06 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/04/29 21:33:06 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013/04/29 21:33:05 | 002,284,544 | —- | C] (Microsoft Corporation) – C:\windows\System32\msmpeg2vdec.dll
[2013/04/29 21:33:05 | 001,504,768 | —- | C] (Microsoft Corporation) – C:\windows\System32\d3d11.dll
[2013/04/29 21:33:05 | 001,247,744 | —- | C] (Microsoft Corporation) – C:\windows\System32\DWrite.dll
[2013/04/29 21:33:05 | 001,158,144 | —- | C] (Microsoft Corporation) – C:\windows\System32\XpsPrint.dll
[2013/04/29 21:33:05 | 000,417,792 | —- | C] (Microsoft Corporation) – C:\windows\System32\WMPhoto.dll
[2013/04/29 21:33:05 | 000,364,544 | —- | C] (Microsoft Corporation) – C:\windows\System32\XpsGdiConverter.dll
[2013/04/29 21:33:05 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\windows\System32\d3d10core.dll
[2013/04/29 21:33:05 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/04/29 21:33:05 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/04/29 21:33:05 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/04/29 21:33:05 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/04/29 21:33:05 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/04/29 21:33:04 | 003,419,136 | —- | C] (Microsoft Corporation) – C:\windows\System32\d2d1.dll
[2013/04/29 21:33:04 | 001,988,096 | —- | C] (Microsoft Corporation) – C:\windows\System32\d3d10warp.dll
[2013/04/29 21:33:04 | 001,080,832 | —- | C] (Microsoft Corporation) – C:\windows\System32\d3d10.dll
[2013/04/29 21:33:04 | 000,604,160 | —- | C] (Microsoft Corporation) – C:\windows\System32\d3d10level9.dll
[2013/04/29 21:33:04 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\windows\System32\dxgi.dll
[2013/04/29 21:33:04 | 000,249,856 | —- | C] (Microsoft Corporation) – C:\windows\System32\d3d10_1core.dll
[2013/04/29 21:33:04 | 000,207,872 | —- | C] (Microsoft Corporation) – C:\windows\System32\WindowsCodecsExt.dll
[2013/04/29 21:33:04 | 000,187,392 | —- | C] (Microsoft Corporation) – C:\windows\System32\UIAnimation.dll
[2013/04/29 21:33:04 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\windows\System32\d3d10_1.dll
[2011/05/11 07:00:10 | 006,533,152 | —- | C] (Xobni) – C:\Users\User\XobniSetup.exe
[2011/01/25 19:18:13 | 008,969,504 | —- | C] (Secure Backup and Share) – C:\ProgramData\TempComcastSecureBackupShare-update-94576f825cbee21cffeff81117efd21f.exe

========== Files - Modified Within 30 Days ==========

[2013/05/15 20:36:02 | 000,015,792 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/05/15 20:36:02 | 000,015,792 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/05/15 20:35:00 | 000,000,830 | —- | M] () – C:\windows\tasks\Adobe Flash Player Updater.job
[2013/05/15 20:27:31 | 000,000,882 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/05/15 20:27:26 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2013/05/15 20:27:23 | 2211,577,856 | -HS- | M] () – C:\hiberfil.sys
[2013/05/15 19:25:00 | 000,000,886 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/05/15 19:17:45 | 000,003,416 | —- | M] () – C:\windows\ComcastSecureBackupShare.blk
[2013/05/15 19:17:45 | 000,000,354 | —- | M] () – C:\windows\ComcastSecureBackupShare.flt
[2013/05/15 17:23:21 | 000,001,112 | —- | M] () – C:\Users\User\Desktop\BiosAgent Plus.lnk
[2013/05/15 10:14:53 | 000,023,456 | —- | M] (Phoenix Technologies) – C:\windows\System32\drivers\DrvAgent32.sys
[2013/05/15 08:35:19 | 000,692,104 | —- | M] (Adobe Systems Incorporated) – C:\windows\System32\FlashPlayerApp.exe
[2013/05/15 08:35:19 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\windows\System32\FlashPlayerCPLApp.cpl
[2013/05/15 08:07:33 | 000,433,584 | —- | M] () – C:\windows\System32\FNTCACHE.DAT
[2013/05/15 07:58:13 | 000,662,722 | —- | M] () – C:\windows\System32\perfh009.dat
[2013/05/15 07:58:13 | 000,121,558 | —- | M] () – C:\windows\System32\perfc009.dat
[2013/05/14 21:47:44 | 000,000,152 | —- | M] () – C:\Users\User\Desktop\FreeVK.ini
[2013/05/14 10:50:55 | 000,155,699 | —- | M] () – C:\Users\User\Desktop\bookmarks.html
[2013/05/14 08:56:42 | 000,002,587 | —- | M] () – C:\Users\Public\Desktop\VAFPlayer.lnk
[2013/05/14 08:54:01 | 000,430,480 | —- | M] () – C:\Users\User\Desktop\FlashPlayer_V.128305733b.exe
[2013/05/14 08:14:02 | 000,846,864 | —- | M] (Microsoft Corporation) – C:\Users\User\Desktop\IE10-Windows6.1-en-us.exe
[2013/05/13 12:19:54 | 000,001,225 | —- | M] () – C:\Users\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Revo Uninstaller Pro.lnk
[2013/05/13 12:19:54 | 000,001,201 | —- | M] () – C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
[2013/05/13 12:17:39 | 009,916,056 | —- | M] (VS Revo Group ) – C:\Users\User\Desktop\RevoUninProSetup.exe
[2013/05/13 12:16:46 | 009,916,056 | —- | M] (VS Revo Group ) – C:\Users\User\Desktop\RevoUninProSetup.exe.part
[2013/05/12 11:16:45 | 000,000,027 | —- | M] () – C:\windows\System32\drivers\etc\hosts
[2013/05/12 10:53:19 | 005,069,265 | R— | M] (Swearware) – C:\Users\User\Desktop\ComboFix.exe
[2013/05/11 17:59:37 | 000,004,362 | —- | M] () – C:\windows\wininit.ini
[2013/05/11 09:28:58 | 000,001,057 | —- | M] () – C:\Users\User\Desktop\Play Games.lnk
[2013/05/11 09:26:32 | 000,001,150 | —- | M] () – C:\Users\User\Desktop\Continue Free Flash Player Installation.lnk
[2013/05/10 18:04:59 | 000,000,596 | —- | M] () – C:\windows\System32\InstallUtil.InstallLog
[2013/05/10 17:41:04 | 000,209,736 | —- | M] (Comfort Software Group) – C:\Users\User\Desktop\FreeVK.exe
[2013/05/10 13:02:52 | 000,013,024 | —- | M] () – C:\windows\System32\drivers\SWDUMon.sys
[2013/05/09 18:27:49 | 000,000,690 | —- | M] () – C:\windows\DeleteOnReboot.bat
[2013/05/09 09:47:09 | 000,000,162 | —- | M] () – C:\windows\Reimage.ini
[2013/05/09 09:04:40 | 000,000,906 | —- | M] () – C:\Users\Public\Desktop\AVG 2013.lnk
[2013/05/09 08:51:52 | 000,002,283 | —- | M] () – C:\Users\User\Windows Easy Transfer.lnk
[2013/05/08 18:52:48 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
[2013/05/08 16:16:17 | 000,001,586 | —- | M] () – C:\Users\User\Documents\cc_20130508_161612.reg
[2013/05/08 14:56:02 | 000,002,090 | —- | M] () – C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
[2013/05/08 14:19:40 | 001,012,646 | —- | M] () – C:\Users\User\AppData\Local\census.cache
[2013/05/08 14:18:41 | 000,196,593 | —- | M] () – C:\Users\User\AppData\Local\ars.cache
[2013/05/08 14:00:25 | 000,000,036 | —- | M] () – C:\Users\User\AppData\Local\housecall.guid.cache
[2013/04/29 21:34:39 | 000,745,472 | —- | M] (Microsoft Corporation) – C:\windows\System32\MsSpellCheckingFacility.exe
[2013/04/29 21:34:39 | 000,185,344 | —- | M] (Microsoft Corporation) – C:\windows\System32\elshyph.dll
[2013/04/29 21:34:39 | 000,158,720 | —- | M] (Microsoft Corporation) – C:\windows\System32\msls31.dll
[2013/04/29 21:34:38 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\windows\System32\msrating.dll
[2013/04/29 21:34:38 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\windows\System32\iexpress.exe
[2013/04/29 21:34:38 | 000,138,752 | —- | M] (Microsoft Corporation) – C:\windows\System32\wextract.exe
[2013/04/29 21:34:38 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\windows\System32\inseng.dll
[2013/04/29 21:34:37 | 000,137,216 | —- | M] (Microsoft Corporation) – C:\windows\System32\ieUnatt.exe
[2013/04/29 21:34:37 | 000,117,248 | —- | M] (Microsoft Corporation) – C:\windows\System32\iepeers.dll
[2013/04/29 21:34:37 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\windows\System32\IEAdvpack.dll
[2013/04/29 21:34:37 | 000,057,344 | —- | M] (Microsoft Corporation) – C:\windows\System32\pngfilt.dll
[2013/04/29 21:34:37 | 000,041,984 | —- | M] (Microsoft Corporation) – C:\windows\System32\msfeedsbs.dll
[2013/04/29 21:34:37 | 000,038,400 | —- | M] (Microsoft Corporation) – C:\windows\System32\imgutil.dll
[2013/04/29 21:34:37 | 000,011,776 | —- | M] (Microsoft Corporation) – C:\windows\System32\msfeedssync.exe
[2013/04/29 21:34:36 | 000,073,728 | —- | M] (Microsoft Corporation) – C:\windows\System32\SetIEInstalledDate.exe
[2013/04/29 21:34:36 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\windows\System32\mshtmler.dll
[2013/04/29 21:34:35 | 000,361,984 | —- | M] (Microsoft Corporation) – C:\windows\System32\html.iec
[2013/04/29 21:34:35 | 000,226,816 | —- | M] (Microsoft Corporation) – C:\windows\System32\dxtrans.dll
[2013/04/29 21:34:34 | 001,441,280 | —- | M] (Microsoft Corporation) – C:\windows\System32\inetcpl.cpl
[2013/04/29 21:34:34 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\windows\System32\ieapfltr.dat
[2013/04/29 21:34:34 | 000,719,360 | —- | M] (Microsoft Corporation) – C:\windows\System32\mshtmlmedia.dll
[2013/04/29 21:34:34 | 000,629,248 | —- | M] (Microsoft Corporation) – C:\windows\System32\ieapfltr.dll
[2013/04/29 21:34:34 | 000,357,888 | —- | M] (Microsoft Corporation) – C:\windows\System32\dxtmsft.dll
[2013/04/29 21:34:34 | 000,242,200 | —- | M] (Microsoft Corporation) – C:\windows\System32\iedkcs32.dll
[2013/04/29 21:34:34 | 000,232,960 | —- | M] (Microsoft Corporation) – C:\windows\System32\url.dll
[2013/04/29 21:34:34 | 000,025,185 | —- | M] () – C:\windows\System32\ieuinit.inf
[2013/04/29 21:34:34 | 000,023,040 | —- | M] (Microsoft Corporation) – C:\windows\System32\licmgr10.dll
[2013/04/29 21:33:06 | 000,009,728 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/04/29 21:33:06 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/04/29 21:33:06 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/04/29 21:33:06 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013/04/29 21:33:05 | 002,284,544 | —- | M] (Microsoft Corporation) – C:\windows\System32\msmpeg2vdec.dll
[2013/04/29 21:33:05 | 001,504,768 | —- | M] (Microsoft Corporation) – C:\windows\System32\d3d11.dll
[2013/04/29 21:33:05 | 001,247,744 | —- | M] (Microsoft Corporation) – C:\windows\System32\DWrite.dll
[2013/04/29 21:33:05 | 001,158,144 | —- | M] (Microsoft Corporation) – C:\windows\System32\XpsPrint.dll
[2013/04/29 21:33:05 | 000,417,792 | —- | M] (Microsoft Corporation) – C:\windows\System32\WMPhoto.dll
[2013/04/29 21:33:05 | 000,364,544 | —- | M] (Microsoft Corporation) – C:\windows\System32\XpsGdiConverter.dll
[2013/04/29 21:33:05 | 000,220,160 | —- | M] (Microsoft Corporation) – C:\windows\System32\d3d10core.dll
[2013/04/29 21:33:05 | 000,010,752 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/04/29 21:33:05 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/04/29 21:33:05 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/04/29 21:33:05 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/04/29 21:33:05 | 000,002,560 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/04/29 21:33:04 | 003,419,136 | —- | M] (Microsoft Corporation) – C:\windows\System32\d2d1.dll
[2013/04/29 21:33:04 | 001,988,096 | —- | M] (Microsoft Corporation) – C:\windows\System32\d3d10warp.dll
[2013/04/29 21:33:04 | 001,080,832 | —- | M] (Microsoft Corporation) – C:\windows\System32\d3d10.dll
[2013/04/29 21:33:04 | 000,604,160 | —- | M] (Microsoft Corporation) – C:\windows\System32\d3d10level9.dll
[2013/04/29 21:33:04 | 000,293,376 | —- | M] (Microsoft Corporation) – C:\windows\System32\dxgi.dll
[2013/04/29 21:33:04 | 000,249,856 | —- | M] (Microsoft Corporation) – C:\windows\System32\d3d10_1core.dll
[2013/04/29 21:33:04 | 000,207,872 | —- | M] (Microsoft Corporation) – C:\windows\System32\WindowsCodecsExt.dll
[2013/04/29 21:33:04 | 000,187,392 | —- | M] (Microsoft Corporation) – C:\windows\System32\UIAnimation.dll
[2013/04/29 21:33:04 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\windows\System32\d3d10_1.dll

========== Files Created - No Company Name ==========

[2013/05/15 17:23:21 | 000,001,112 | —- | C] () – C:\Users\User\Desktop\BiosAgent Plus.lnk
[2013/05/14 10:50:55 | 000,155,699 | —- | C] () – C:\Users\User\Desktop\bookmarks.html
[2013/05/14 08:56:42 | 000,002,587 | —- | C] () – C:\Users\Public\Desktop\VAFPlayer.lnk
[2013/05/14 08:54:00 | 000,430,480 | —- | C] () – C:\Users\User\Desktop\FlashPlayer_V.128305733b.exe
[2013/05/13 12:19:54 | 000,001,225 | —- | C] () – C:\Users\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Revo Uninstaller Pro.lnk
[2013/05/13 12:19:54 | 000,001,201 | —- | C] () – C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
[2013/05/12 08:43:24 | 000,256,000 | —- | C] () – C:\windows\PEV.exe
[2013/05/12 08:43:24 | 000,208,896 | —- | C] () – C:\windows\MBR.exe
[2013/05/12 08:43:24 | 000,098,816 | —- | C] () – C:\windows\sed.exe
[2013/05/12 08:43:24 | 000,080,412 | —- | C] () – C:\windows\grep.exe
[2013/05/12 08:43:24 | 000,068,096 | —- | C] () – C:\windows\zip.exe
[2013/05/11 09:28:58 | 000,001,057 | —- | C] () – C:\Users\User\Desktop\Play Games.lnk
[2013/05/11 09:26:32 | 000,001,150 | —- | C] () – C:\Users\User\Desktop\Continue Free Flash Player Installation.lnk
[2013/05/10 18:04:57 | 000,000,596 | —- | C] () – C:\windows\System32\InstallUtil.InstallLog
[2013/05/10 17:41:05 | 000,000,152 | —- | C] () – C:\Users\User\Desktop\FreeVK.ini
[2013/05/10 13:02:52 | 000,013,024 | —- | C] () – C:\windows\System32\drivers\SWDUMon.sys
[2013/05/09 11:00:45 | 000,000,690 | —- | C] () – C:\windows\DeleteOnReboot.bat
[2013/05/08 18:18:39 | 000,000,162 | —- | C] () – C:\windows\Reimage.ini
[2013/05/08 16:16:15 | 000,001,586 | —- | C] () – C:\Users\User\Documents\cc_20130508_161612.reg
[2013/05/08 15:45:22 | 000,004,362 | —- | C] () – C:\windows\wininit.ini
[2013/05/08 14:56:02 | 000,002,102 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
[2013/05/08 14:56:02 | 000,002,090 | —- | C] () – C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
[2013/05/08 14:19:40 | 001,012,646 | —- | C] () – C:\Users\User\AppData\Local\census.cache
[2013/05/08 14:18:41 | 000,196,593 | —- | C] () – C:\Users\User\AppData\Local\ars.cache
[2013/05/08 14:00:25 | 000,000,036 | —- | C] () – C:\Users\User\AppData\Local\housecall.guid.cache
[2013/04/29 21:34:34 | 000,025,185 | —- | C] () – C:\windows\System32\ieuinit.inf
[2011/10/08 08:48:11 | 000,000,210 | —- | C] () – C:\Users\User\AppData\Roaming\wklnhst.dat
[2011/04/13 17:51:02 | 000,001,502 | —- | C] () – C:\Users\User\.recently-used.xbel
[2011/03/16 18:54:03 | 000,000,000 | —- | C] () – C:\Users\User\AppData\Local\prvlcl.dat
[2010/12/05 03:58:53 | 000,026,837 | —- | C] () – C:\Users\User\AppData\Roaming\Comma Separated Values (Windows).ADR
[2010/12/02 10:05:38 | 000,000,017 | —- | C] () – C:\Users\User\AppData\Local\resmon.resmoncfg
[2010/12/01 03:12:28 | 000,002,283 | —- | C] () – C:\Users\User\Windows Easy Transfer.lnk
[2010/12/01 03:12:28 | 000,000,706 | —- | C] () – C:\Users\User\autorun.inf

========== ZeroAccess Check ==========

[2009/07/14 00:42:31 | 000,000,227 | RHS- | M] () – C:\windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/27 00:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 08:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/13 21:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

< End of report >
Thanks Marty
Hi MARTY1946,

I'm getting some input from some of my collegues about the beep issue. Let's run a few more tools to verify we have gotten the malware removed.

1. Malwarebytes' Anti-Malware

Please download Malwarebytes' Anti-Malware to your desktop.

  • Right click and select "Run as Administrator" mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan as shown below.

    [external image: Posted Image]

  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
=========================

2. ESET Online Scanner

*Note:
  • It is recommended to disable on-board antivirus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
  • Please don't go surfing while your resident protection is disabled!
  • Once the scan is finished remember to re-enable your antivirus along with your anti-spyware programs.
** You need to run your browser with Administrator Rights, to do so right click your browsers short cut and select "Run as Administrator".

= = = = = = = = = = = = = = = = = = = =

Go here to run ESET Online Scanner

(Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • When the scan completes, click List of found threats
  • click Export to Text file and save the file to your desktop using a unique name, such as ESETScan.
  • Include the contents of this report in your next reply

    Note - when ESET doesn't find any threats, no report will be created.
  • Push the back button.
  • Push Finish
  • Re-enable your Antivirus software.
=========================

In your next post please provide the following:
  • MBAM.txt
  • ESET's log.txt
  • How old is the computer?
  • Is the computer still under warranty?
Hi MARTY1946,

:thumbup: See you tomorrow.

1. Key Test

The beeping may be a stuck key error.

Have a look at this site. There is a box at the bottom that will capture the keystroke and report the code.

http://www.webonweboff.com/tips/js/event_key_codes.aspx

Scroll down to the bottom of the page, Click on the box and don't press any key and see if it will capture a "keystroke" if the period appears.

= = = = = = = = = = = = = = = = = = = =

Post the results
Hello OCD; Eset didn't find any infected files. Went to site about the sticking key, nothing to report. My computer is out of warranty, it' 3 yrs old. here is mbam log. Malwarebytes Anti-Malware (Trial) 1.75.0.1300 www.malwarebytes.org Database version: v2013.05.16.06 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 10.0.9200.16576 User :: RICHARDGMARTIN [administrator] Protection: Enabled 5/16/2013 8:19:02 AM mbam-log-2013-05-16 (08-19-02).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 221497 Time elapsed: 11 minute(s), 26 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 2 HKCR\AppID\GamevanceText.DLL (Adware.GameVance) -> Quarantined and deleted successfully. HKCU\Software\AppDataLow\gvtl (Adware.GameVance) -> Quarantined and deleted successfully. Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 3 C:\Users\User\Desktop\FlashPlayer_V.128305733b.exe (PUP.FakeFlash.Domaiq) -> Quarantined and deleted successfully. C:\Users\User\Downloads\EpicPlaySetup.exe (Adware.Gamevance) -> Quarantined and deleted successfully. C:\Users\User\Downloads\FlashPlayer_V.119896123b.exe (PUP.FakeFlash.Domaiq) -> Quarantined and deleted successfully. (end) Thanks Marty
Hi MARTY1946,

Well the good news is there is no malware showing in your logs. :D

1. USB Keyboard

Do you happen to have a USB powered keyboard accessible? If so please try plugging it in let it install whatever drivers are needed and see if it replicates the "period" key issue

=========================
Hello OCD;

That is great news, the machine is clean! :D

I don't have a USB keyboard, but I probably will buy one, I can live with it for now.

These other issues are probably that there are some hardware problems.

Thank You very much for your help.
Marty1946 :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI