This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

possible reinfection [Closed]

44 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there, I have to admit to you all, that I did come here previously for help but the tech and I did not complete the cleaning because I could not continue comming back. Do to this, I think I have been re-infected, but I do ask you all if you could please excuse my previous reasons of leaving before the cleaning process was completed as opposed to scorning me about what I should of done. In any event, here is my new situation. In Google Chrome, every so often when I click on a link, it will popup a new window displaying that my Flash Player is out of date. I one clicked on the download and Norton AV said that the download was a malicious file, so I had canceled the download and closed the window. However, even though I now know this popup is a link to a malicious file, I still get the popup window every so often. I do not know how it gets triggered, since it does not happen when surfing at one particular website and I am not sure if it has to do with how many clicked links I go on etc. In addition, at the bottom of Google Chrome, a sliding popup window displays an ad every time a webpage gets loaded, and when I am surfing forums, common ad-words turn into ad-links. For example, someone might say, "dude take a valium!", and the word valium becomes a link, which directs you to a special offer; something like save 25% on your next purchase after completing this survey. so enough chatting, and here is my DDS log…. . DDS (Ver_11-03-05.01) - NTFS_AMD64 Run by [removed] at 10:26:10.06 on Sat 05/25/2013 Internet Explorer: 9.10.9200.16576 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4009.1532 [GMT -4:00] . AV: Norton 360 *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} FW: Norton 360 *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe C:\Program Files (x86)\Connectify\ConnectifyService.exe C:\Program Files (x86)\DefaultTab\DefaultTabSearch.exe C:\Program Files (x86)\Connectify\ConnectifyD.exe C:\Users\BigPapa\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe C:\Windows\system32\hserver.exe C:\Program Files (x86)\Norton 360\Engine\20.3.1.22\ccSvcHst.exe C:\Windows\system32\conhost.exe C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files (x86)\Norton 360\Engine\20.3.1.22\ccSvcHst.exe C:\Windows\system32\taskhost.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ uInternet Settings,ProxyOverride = uURLSearchHooks: InternetHelper3 Toolbar: {b920380d-fbe7-45c7-96ab-37e9870a566c} - C:\Program Files (x86)\InternetHelper3\prxtbInte.dll mURLSearchHooks: InternetHelper3 Toolbar: {b920380d-fbe7-45c7-96ab-37e9870a566c} - C:\Program Files (x86)\InternetHelper3\prxtbInte.dll BHO: Qwiklinx: {3e7c8b5a-96ab-438f-bf9b-782400655440} - C:\Users\BigPapa\AppData\Roaming\Qwiklinx\Qwiklinx.dll BHO: Norton Identity Protection: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - C:\Program Files (x86)\Norton 360\Engine\20.3.1.22\coIEPlg.dll BHO: Norton Vulnerability Protection: {6d53ec84-6aae-4787-aeee-f4628f01010c} - C:\Program Files (x86)\Norton 360\Engine\20.3.1.22\IPS\IPSBHO.DLL BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll BHO: DefaultTab Browser Helper: {7f6afbf1-e065-4627-a2fd-810366367d01} - C:\Users\BigPapa\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL BHO: Cartwheel: {b50df051-e1d4-439c-b94e-f4de82b56542} - C:\Users\BigPapa\AppData\Roaming\Cartwheel\Cartwheel.dll BHO: InternetHelper3 Toolbar: {b920380d-fbe7-45c7-96ab-37e9870a566c} - C:\Program Files (x86)\InternetHelper3\prxtbInte.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll TB: InternetHelper3 Toolbar: {b920380d-fbe7-45c7-96ab-37e9870a566c} - C:\Program Files (x86)\InternetHelper3\prxtbInte.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - C:\Program Files (x86)\Norton 360\Engine\20.3.1.22\coIEPlg.dll EB: Developer Tools: {1a6fe369-f28c-4ad9-a3e6-2bcb50807cf1} - C:\Program Files (x86)\Internet Explorer\iedvtool.dll uRun: [Connectify] C:\Program Files (x86)\Connectify\Connectify.exe uRun: [DriverMax] "C:\Program Files (x86)\Innovative Solutions\DriverMax\drivermax.exe" -agent uRun: [Akamai NetSession Interface] "C:\Users\BigPapa\AppData\Local\Akamai\netsession_win.exe" uRun: [SearchProtect] C:\Users\BigPapa\AppData\Roaming\SearchProtect\bin\cltmng.exe uRun: [GoogleChromeAutoLaunch_89C113111C53352D1F68066DB33BEBDD] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" –no-startup-window uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" uRunOnce: [Application Restart #3] C:\Program Files (x86)\Google\Chrome\Application\chrome.exe –flag-switches-begin –flag-switches-end –flag-switches-begin –flag-switches-end –restore-last-session –flag-switches-begin –flag-switches-end –flag-switches-begin –flag-switches-end –flag-switches-begin –flag-switches-end –flag-switches-begin –flag-switches-end mRun: [Dell Registration] C:\Program Files (x86)\System Registration\prodreg.exe /boot mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [] mRun: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" mRun: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [AccuWeatherWidget] "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\start.umj" –startup mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe mRun: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [SearchProtectAll] C:\Program Files (x86)\SearchProtect\bin\cltmng.exe mRunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe dRun: [SearchProtect] \SearchProtect\bin\cltmng.exe mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105 IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll Trusted Zone: dell.com DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} - hxxp://support.dell.com/systemprofiler/DellSystemLite.CAB DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll mASetup: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\Installer\chrmstp.exe" –configure-user-settings –verbose-logging –system-level –multi-install –chrome BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL BHO-X64: URLRedirectionBHO - No File BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll TB-X64: {B920380D-FBE7-45C7-96AB-37E9870A566C} - No File EB-X64: {1A6FE369-F28C-4AD9-A3E6-2BCB50807CF1} - No File mRun-x64: [DellStage] "C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\start.umj" –startup mRun-x64: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" mRun-x64: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t mRun-x64: [cAudioFilterAgent] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe mRun-x64: [IgfxTray] C:\Windows\system32\igfxtray.exe mRun-x64: [HotKeysCmds] C:\Windows\system32\hkcmd.exe mRun-x64: [Persistence] C:\Windows\system32\igfxpers.exe . ============= SERVICES / DRIVERS =============== . R? AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service R? androidusb;SAMSUNG Android Composite ADB Interface Driver R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86 R? clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64 R? cphs;Intel® Content Protection HECI Service R? FLEXnet Licensing Service 64;FLEXnet Licensing Service 64 R? gupdate;Google Update Service (gupdate) R? gupdatem;Google Update Service (gupdatem) R? RdpVideoMiniport;Remote Desktop Video Miniport Driver R? RoxMediaDB12OEM;RoxMediaDB12OEM R? RoxWatch12;Roxio Hard Drive Watcher 12 R? SkypeUpdate;Skype Updater R? SwitchBoard;Adobe SwitchBoard R? TsUsbFlt;TsUsbFlt R? TsUsbGD;Remote Desktop Generic USB Device R? vwifimp;Microsoft Virtual WiFi Miniport Service R? WatAdminSvc;Windows Activation Technologies Service R? wlcrasvc;Windows Live Mesh remote connections service S? AdobeARMservice;Adobe Acrobat Update Service S? BHDrvx64;BHDrvx64 S? ccSet_N360;Norton 360 Settings Manager S? CltMngSvc;Search Protect by Conduit Updater S? cnnctfy2;Connectify LightWeight Filter S? Connectify;Connectify S? DefaultTabSearch;DefaultTabSearch S? DefaultTabUpdate;DefaultTabUpdate S? EraserUtilRebootDrv;EraserUtilRebootDrv S? IDSVia64;IDSVia64 S? IntcDAud;Intel® Display Audio S? MEIx64;Intel® Management Engine Interface S? N360;Norton 360 S? osppsvc;Office Software Protection Platform S? PxHlpa64;PxHlpa64 S? RTL8167;Realtek 8167 NT Driver S? SftService;SoftThinks Agent Service S? SymDS;Symantec Data Store S? SymEFA;Symantec Extended File Attributes S? SymIRON;Symantec Iron Driver S? SymNetS;Symantec Network Security WFP Driver S? vwififlt;Virtual WiFi Filter Driver . =============== Created Last 30 ================ . 2013-05-18 01:43:28 70144 —-a-w- C:\Windows\System32\appinfo.dll 2013-05-18 01:43:28 1930752 —-a-w- C:\Windows\System32\authui.dll 2013-05-18 01:43:28 1796096 —-a-w- C:\Windows\SysWow64\authui.dll 2013-05-18 01:43:28 111448 —-a-w- C:\Windows\System32\consent.exe 2013-05-17 23:31:24 983400 —-a-w- C:\Windows\System32\drivers\dxgkrnl.sys 2013-05-17 23:31:24 265064 —-a-w- C:\Windows\System32\drivers\dxgmms1.sys 2013-05-17 23:31:24 144384 —-a-w- C:\Windows\System32\cdd.dll 2013-05-17 23:22:21 48640 —-a-w- C:\Windows\System32\wwanprotdim.dll 2013-05-17 23:22:21 230400 —-a-w- C:\Windows\System32\wwansvc.dll 2013-05-17 23:22:19 3153920 —-a-w- C:\Windows\System32\win32k.sys 2013-05-14 03:45:48 ——– d—–w- C:\SearchProtect 2013-05-11 12:27:06 96768 —-a-w- C:\Windows\SysWow64\sspicli.dll 2013-05-11 12:27:06 458712 —-a-w- C:\Windows\System32\drivers\cng.sys 2013-05-11 12:27:06 340992 —-a-w- C:\Windows\System32\schannel.dll 2013-05-11 12:27:06 247808 —-a-w- C:\Windows\SysWow64\schannel.dll 2013-05-11 12:27:06 22016 —-a-w- C:\Windows\SysWow64\secur32.dll 2013-05-11 12:27:06 154480 —-a-w- C:\Windows\System32\drivers\ksecpkg.sys 2013-05-11 12:27:06 1448448 —-a-w- C:\Windows\System32\lsasrv.dll 2013-05-11 12:27:02 514560 —-a-w- C:\Windows\SysWow64\qdvd.dll 2013-05-11 12:27:02 366592 —-a-w- C:\Windows\System32\qdvd.dll 2013-05-07 20:05:33 796248 —-a-r- C:\Windows\System32\drivers\N360x64\1403010.016\srtsp64.sys 2013-05-07 20:05:33 493656 —-a-r- C:\Windows\System32\drivers\N360x64\1403010.016\SymDS64.sys 2013-05-07 20:05:33 432800 —-a-r- C:\Windows\System32\drivers\N360x64\1403010.016\symnets.sys 2013-05-07 20:05:33 36952 —-a-r- C:\Windows\System32\drivers\N360x64\1403010.016\srtspx64.sys 2013-05-07 20:05:33 23448 —-a-r- C:\Windows\System32\drivers\N360x64\1403010.016\SymELAM.sys 2013-05-07 20:05:33 224416 —-a-r- C:\Windows\System32\drivers\N360x64\1403010.016\Ironx64.sys 2013-05-07 20:05:33 168096 —-a-r- C:\Windows\System32\drivers\N360x64\1403010.016\ccSetx64.sys 2013-05-07 20:05:33 1139800 —-a-r- C:\Windows\System32\drivers\N360x64\1403010.016\SymEFA64.sys 2013-05-07 20:05:22 ——– d—–w- C:\Windows\System32\drivers\N360x64\1403010.016 2013-05-01 01:00:38 ——– d—–w- C:\Program Files (x86)\FFmpeg for Audacity 2013-04-30 19:57:00 ——– d—–w- C:\Program Files (x86)\Audacity 2013-04-30 07:06:08 9728 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-04-30 02:48:24 73728 —-a-w- C:\Windows\system\vdremote.dll 2013-04-30 02:48:24 65536 —-a-w- C:\Windows\system\vdsvrlnk.dll 2013-04-30 02:48:24 ——– d—–w- C:\VirtualDub-1.9.11 2013-04-29 22:51:09 ——– d—–w- C:\Program Files (x86)\Thugs at Bay 2013-04-28 15:34:26 ——– d—–w- C:\Users\BigPapa\AppData\Local\{9AC6A02F-2783-437B-8C28-D4B0CD91EFE9} 2013-04-28 15:34:26 ——– d—–w- C:\Users\BigPapa\AppData\Local\{068D4243-EC00-4741-B0A7-4353AC95E8B0} 2013-04-28 13:39:50 ——– d—–w- C:\Program Files (x86)\CamStudio 2013-04-28 13:39:13 ——– d—–w- C:\CamStudio . ==================== Find3M ==================== . 2013-05-07 20:06:23 177312 —-a-w- C:\Windows\System32\drivers\SYMEVENT64x86.SYS 2013-04-30 07:06:08 9728 —ha-w- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-04-13 05:49:23 135168 —-a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll 2013-04-13 05:49:19 350208 —-a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll 2013-04-13 05:49:19 308736 —-a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll 2013-04-13 05:49:19 111104 —-a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll 2013-04-13 04:45:16 474624 —-a-w- C:\Windows\apppatch\AcSpecfc.dll 2013-04-13 04:45:15 2176512 —-a-w- C:\Windows\apppatch\AcGenral.dll 2013-04-12 14:45:08 1656680 —-a-w- C:\Windows\System32\drivers\ntfs.sys 2013-04-11 14:22:56 770384 —-a-w- C:\Windows\SysWow64\msvcr100.dll 2013-04-11 14:22:56 421200 —-a-w- C:\Windows\SysWow64\msvcp100.dll 2013-04-05 06:52:14 2242048 —-a-w- C:\Windows\System32\wininet.dll 2013-04-05 06:50:36 3958784 —-a-w- C:\Windows\System32\jscript9.dll 2013-04-05 06:50:31 67072 —-a-w- C:\Windows\System32\iesetup.dll 2013-04-05 06:50:31 136704 —-a-w- C:\Windows\System32\iesysprep.dll 2013-04-05 05:28:24 1767424 —-a-w- C:\Windows\SysWow64\wininet.dll 2013-04-05 05:26:26 2877440 —-a-w- C:\Windows\SysWow64\jscript9.dll 2013-04-05 05:26:21 61440 —-a-w- C:\Windows\SysWow64\iesetup.dll 2013-04-05 05:26:21 109056 —-a-w- C:\Windows\SysWow64\iesysprep.dll 2013-04-05 04:43:00 2706432 —-a-w- C:\Windows\System32\mshtml.tlb 2013-04-05 04:29:45 2706432 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2013-04-05 03:51:11 89600 —-a-w- C:\Windows\System32\RegisterIEPKEYs.exe 2013-04-05 03:38:25 71680 —-a-w- C:\Windows\SysWow64\RegisterIEPKEYs.exe 2013-03-19 06:04:06 5550424 —-a-w- C:\Windows\System32\ntoskrnl.exe 2013-03-19 05:46:56 43520 —-a-w- C:\Windows\System32\csrsrv.dll 2013-03-19 05:04:13 3968856 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe 2013-03-19 05:04:10 3913560 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe 2013-03-19 04:47:50 6656 —-a-w- C:\Windows\SysWow64\apisetschema.dll 2013-03-19 03:06:33 112640 —-a-w- C:\Windows\System32\smss.exe 2013-03-01 16:08:26 71024 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2013-03-01 16:08:26 691568 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe . ============= FINISH: 10:32:27.93 ===============
Hi BnTheMan,

My name is OCD. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Copy and Paste logs directly into the reply window. DO NOT attach the logs unless specifically instructed to do so.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Important Note for Vista and Windows 7 & 8 users:

These tools MUST be run from the executable.(.exe) every time you run them with Admin Rights (Right click, choose "Run as Administrator")

Please stay with this topic until I let you know that your system appears to be "All Clear"

=========================

1. Security Check

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Right click SecurityCheck.exe, select "Run as Administrator" and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
=========================

2. aswMBR

Download aswMBR.exe and save it to your desktop.

Right click and select "Run as Administrator".
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
=========================

3. OTL

  • Download OTL to your desktop.
  • Make sure all other windows are closed and to let it run uninterrupted.

    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    services.exe
    /md5stop
    %systemroot%\*. /rp /s
    %systemdrive%\$Recycle.Bin|@;true;true;true
    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s >
    BASESERVICES
    DRIVES
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
    • You may need two posts to fit them both in.
=========================

In your next post please provide the following:
  • checkup.txt
  • aswMBR.txt
  • attach MBR.zip
  • OTL.txt
  • Extras.txt
  • Whay symptoms are you experiencing?
my symptoms are browser redirects to an infected flash update website and there are ads interrupting my work. Some of them appear as a sliding window below my screen, others are when you mouse over different things on a page sometimes I will get this is the best search we can find, or I will get embeded ad-words to text that are not original links but have become links to surveys or congratulations your the xxxxth customer bull-carp**. so here are my scans….

Results of screen317's Security Check version 0.99.64
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 10
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Norton 360
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
Java™ 6 Update 31
Java version out of Date!
Adobe Reader 10.1.7 Adobe Reader out of Date!
Google Chrome 26.0.1410.64
Google Chrome 27.0.1453.94
````````Process Check: objlist.exe by Laurent````````
Norton ccSvcHst.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 2%
````````````````````End of Log``````````````````````



aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-05-27 15:35:55
—————————–
15:35:55.496 OS Version: Windows x64 6.1.7601 Service Pack 1
15:35:55.497 Number of processors: 4 586 0x2A07
15:35:55.498 ComputerName: BIGPAPA-PC UserName: BigPapa
15:35:56.743 Initialize success
15:36:04.892 AVAST engine defs: 13052700
15:36:22.310 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
15:36:22.313 Disk 0 Vendor: ST31000524AS JC47 Size: 953869MB BusType: 3
15:36:22.392 Disk 0 MBR read successfully
15:36:22.395 Disk 0 MBR scan
15:36:22.400 Disk 0 Windows VISTA default MBR code
15:36:22.404 Disk 0 Partition 1 00 DE Dell Utility DELL 4.1 39 MB offset 63
15:36:22.412 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 12542 MB offset 81920
15:36:22.418 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 941286 MB offset 25767936
15:36:22.440 Disk 0 scanning C:\Windows\system32\drivers
15:36:31.358 Service scanning
15:36:49.537 Modules scanning
15:36:49.545 Disk 0 trace - called modules:
15:36:49.570 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS intelide.sys PCIIDEX.SYS hal.dll atapi.sys
15:36:49.892 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004d3a060]
15:36:49.899 3 CLASSPNP.SYS[fffff88001a6a43f] -> nt!IofCallDriver -> [0xfffffa80048f6520]
15:36:49.904 5 ACPI.sys[fffff88000fa57a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa80048f8060]
15:36:53.371 AVAST engine scan C:\Windows
15:36:56.063 AVAST engine scan C:\Windows\system32
15:39:32.852 AVAST engine scan C:\Windows\system32\drivers
15:39:47.845 AVAST engine scan C:\Users\BigPapa
15:45:01.222 AVAST engine scan C:\ProgramData
15:46:13.656 Scan finished successfully
15:46:57.275 Disk 0 MBR has been saved successfully to "C:\Users\BigPapa\Desktop\Checking 4 Virus 5-25-2013\MBR.dat"
15:46:57.278 The log file has been saved successfully to "C:\Users\BigPapa\Desktop\Checking 4 Virus 5-25-2013\aswMBR.txt"
OTL logfile created on: 5/27/2013 4:17:57 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\BigPapa\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16576)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.91 Gb Total Physical Memory | 1.90 Gb Available Physical Memory | 48.64% Memory free
7.83 Gb Paging File | 5.47 Gb Available in Paging File | 69.85% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 919.22 Gb Total Space | 829.05 Gb Free Space | 90.19% Space Free | Partition Type: NTFS

Computer Name: BIGPAPA-PC | User Name: BigPapa | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\BigPapa\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Users\BigPapa\AppData\Roaming\SearchProtect\bin\cltmng.exe (Conduit)
PRC - C:\Users\BigPapa\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe ()
PRC - C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe (Conduit)
PRC - C:\Program Files (x86)\Innovative Solutions\DriverMax\drivermax.exe (Innovative Solutions)
PRC - C:\Program Files (x86)\Norton 360\Engine\20.3.1.22\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe ()
PRC - C:\Program Files (x86)\Dell Stage\Dell Stage\stage_secondary.exe ()
PRC - C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe ()
PRC - C:\Program Files (x86)\Connectify\Connectify.exe (Connectify)
PRC - C:\Program Files (x86)\Connectify\Connectifyd.exe (Connectify)
PRC - C:\Program Files (x86)\Connectify\ConnectifyService.exe ()
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe (SoftThinks - Dell)
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe ()
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (SoftThinks SAS)
PRC - C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe ()
PRC - C:\Program Files (x86)\Notepad++\notepad++.exe (Don HO [removed])
PRC - C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\ppgooglenaclpluginchrome.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\PepperFlash\pepflashplayer.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\pdf.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\libglesv2.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\libegl.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\ffmpegsumo.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\1e8f7367eaa08c5057d78c093982f8f0\System.IdentityModel.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\e698a866fd16973a24ca6697218028ad\System.ServiceModel.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\3c2ed368e1f3889997dfb42a5ca77284\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\af525b4bec3b9941b7be8ffbf813da80\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\30e3a21202000677d0a9270572251477\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\7eac0dbe9aa20b55e37235f8ee030e6b\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\716959df79685a1eae0fc14275a32b0f\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\764f15e86c82662e977bd418bd6318c1\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\23673bbebe3c0ca7c894e614bb3ffd1a\System.Security.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\5ecf01964c70e453d71e5d7653912ff9\System.Web.ni.dll ()
MOD - C:\Program Files (x86)\Innovative Solutions\DriverMax\sync.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\1e04a5319c58010e945220af2751d34e\System.ServiceModel.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\2ad51da1b752b19c992fcefd56eb7c01\System.Runtime.Serialization.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\eb33bf977e97e97b12e82c18e36fbaee\SMDiagnostics.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\d7d20811a7ce7cc589153648cbb1ce5c\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\90b89f6e8032310e9ac72a309fd49e83\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Norton 360\Engine\20.3.1.22\wincfi39.dll ()
MOD - C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe ()
MOD - C:\Program Files (x86)\Dell Stage\Dell Stage\stage_secondary.exe ()
MOD - C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe ()
MOD - C:\Program Files (x86)\Dell Stage\Dell Stage\QtGui4.dll ()
MOD - C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\QtGui4.dll ()
MOD - C:\Program Files (x86)\Dell Stage\Dell Stage\QtCore4.dll ()
MOD - C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\QtCore4.dll ()
MOD - C:\Program Files (x86)\Connectify\Scannify.dll ()
MOD - C:\Program Files (x86)\Connectify\DriverLib.dll ()
MOD - C:\Program Files (x86)\Connectify\BuildProps.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe ()
MOD - C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe ()
MOD - C:\Program Files (x86)\Notepad++\plugins\NppFTP.dll ()
MOD - C:\Program Files (x86)\Notepad++\plugins\NppExport.dll ()
MOD - c:\Program Files (x86)\Common Files\Roxio Shared\DLLShared\SQLite352.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.WorkflowServices\3.5.0.0__31bf3856ad364e35\System.WorkflowServices.dll ()
MOD - C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()


========== Services (SafeList) ==========

SRV:64bit: - (HoudiniServer) – C:\WINDOWS\SysNative\hserver.exe (Side Effects Software Inc.)
SRV:64bit: - (FLEXnet Licensing Service 64) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe (Flexera Software, Inc.)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (DefaultTabUpdate) – C:\Users\BigPapa\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe ()
SRV - (CltMngSvc) – C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe (Conduit)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (DefaultTabSearch) – C:\Program Files (x86)\DefaultTab\DefaultTabSearch.exe ()
SRV - (N360) – C:\Program Files (x86)\Norton 360\Engine\20.3.1.22\ccSvcHst.exe (Symantec Corporation)
SRV - (cphs) – C:\WINDOWS\SysWOW64\IntelCpHeciSvc.exe (Intel Corporation)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (Connectify) – C:\Program Files (x86)\Connectify\ConnectifyService.exe ()
SRV - (SftService) – C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (SoftThinks SAS)
SRV - (RoxWatch12) – C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe (Sonic Solutions)
SRV - (RoxMediaDB12OEM) – C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe (Sonic Solutions)
SRV - (clr_optimization_v4.0.30319_32) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SwitchBoard) – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (clr_optimization_v2.0.50727_32) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (SymEvent) – C:\WINDOWS\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (SymNetS) – C:\WINDOWS\SysNative\drivers\N360x64\1403010.016\symnets.sys (Symantec Corporation)
DRV:64bit: - (SymEFA) – C:\WINDOWS\SysNative\drivers\N360x64\1403010.016\SymEFA64.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\WINDOWS\SysNative\drivers\N360x64\1403010.016\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) – C:\WINDOWS\SysNative\drivers\N360x64\1403010.016\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (SymDS) – C:\WINDOWS\SysNative\drivers\N360x64\1403010.016\SymDS64.sys (Symantec Corporation)
DRV:64bit: - (igfx) – C:\WINDOWS\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (SymIRON) – C:\WINDOWS\SysNative\drivers\N360x64\1403010.016\Ironx64.sys (Symantec Corporation)
DRV:64bit: - (ccSet_N360) – C:\WINDOWS\SysNative\drivers\N360x64\1403010.016\ccSetx64.sys (Symantec Corporation)
DRV:64bit: - (RdpVideoMiniport) – C:\WINDOWS\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbGD) – C:\WINDOWS\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\WINDOWS\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (cnnctfy2) – C:\WINDOWS\SysNative\drivers\cnnctfy2.sys (Connectify)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (RTL8167) – C:\WINDOWS\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (amdsata) – C:\WINDOWS\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\WINDOWS\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (CnxtHdAudService) – C:\WINDOWS\SysNative\drivers\CHDRT64.sys (Conexant Systems Inc.)
DRV:64bit: - (RMCAST) – C:\WINDOWS\SysNative\drivers\rmcast.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\WINDOWS\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (athr) – C:\WINDOWS\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (MEIx64) – C:\WINDOWS\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) – C:\WINDOWS\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (PxHlpa64) – C:\WINDOWS\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (androidusb) – C:\WINDOWS\SysNative\drivers\ssadadb.sys (Google Inc)
DRV:64bit: - (amdsbs) – C:\WINDOWS\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\WINDOWS\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\WINDOWS\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) – C:\WINDOWS\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\WINDOWS\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\WINDOWS\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\WINDOWS\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (WimFltr) – C:\WINDOWS\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\Definitions\VirusDefs\20130527.004\ex64.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\Definitions\VirusDefs\20130527.004\eng64.sys (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\Definitions\IPSDefs\20130524.001\IDSviA64.sys (Symantec Corporation)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\Definitions\BASHDefs\20130515.001\BHDrvx64.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (WIMMount) – C:\WINDOWS\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{49606DC7-976D-4030-A74E-9FB5C842FA68}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {b920380d-fbe7-45c7-96ab-37e9870a566c} - C:\Program Files (x86)\InternetHelper3\prxtbInte.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\..\SearchScopes\{49606DC7-976D-4030-A74E-9FB5C842FA68}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: {b920380d-fbe7-45c7-96ab-37e9870a566c} - C:\Program Files (x86)\InternetHelper3\prxtbInte.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {82B1E5B2-DCEA-484D-8E90-40FAD5BF7F01}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKCU\..\SearchScopes\{546E4570-96CF-443B-81D9-53CD7F0FAB65}: "URL" = http://search.conduit.com/Results.aspx?cti…q={searchTerms}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\..\SearchScopes\{82B1E5B2-DCEA-484D-8E90-40FAD5BF7F01}: "URL" = http://search.conduit.com/ResultsExt.aspx?…332582&UM;=2
IE - HKCU\..\SearchScopes\{E3F15D58-092E-47B8-AC12-4F1195C84251}: "URL" = http://www.google.com/search?q={searchTerm…1I7NDKB_enUS524
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@bestbuy.com/npBestBuyPcAppDetector,version=1.0: C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@bestbuy.com/npBestBuyPcAppDetector,version=1.0: C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll File not found
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\BigPapa\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\coFFPlgn\ [2013/05/27 15:16:12 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\IPSFFPlgn\ [2013/05/07 16:12:26 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - homepage: http://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 6 U31 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\BigPapa\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\BigPapa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\BigPapa\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: DefaultTab = C:\Users\BigPapa\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc\1.1.19_0\
CHR - Extension: Selection Links = C:\Users\BigPapa\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkmljcahgmhdlnhmnjiaakhkbbiapjkb\4.3_0\
CHR - Extension: Norton Identity Protection = C:\Users\BigPapa\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.3.3.19_0\
CHR - Extension: Gmail = C:\Users\BigPapa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\WINDOWS\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (Qwiklinx) - {3E7C8B5A-96AB-438F-BF9B-782400655440} - C:\Users\BigPapa\AppData\Roaming\Qwiklinx\Qwiklinx.dll (Qwiklinx, Inc.)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\20.3.1.22\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\20.3.1.22\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (DefaultTab Browser Helper) - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Users\BigPapa\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll (Search Results LLC.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Cartwheel) - {B50DF051-E1D4-439C-B94E-F4DE82B56542} - C:\Users\BigPapa\AppData\Roaming\Cartwheel\Cartwheel.dll (Cartwheel, Inc.)
O2 - BHO: (InternetHelper3 Toolbar) - {b920380d-fbe7-45c7-96ab-37e9870a566c} - C:\Program Files (x86)\InternetHelper3\prxtbInte.dll (Conduit Ltd.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\20.3.1.22\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (InternetHelper3 Toolbar) - {b920380d-fbe7-45c7-96ab-37e9870a566c} - C:\Program Files (x86)\InternetHelper3\prxtbInte.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (InternetHelper3 Toolbar) - {B920380D-FBE7-45C7-96AB-37E9870A566C} - C:\Program Files (x86)\InternetHelper3\prxtbInte.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [cAudioFilterAgent] C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe (Conexant Systems, Inc.)
O4:64bit: - HKLM..\Run: [DellStage] C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe ()
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\WINDOWS\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\WINDOWS\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe (Conexant Systems, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AccuWeatherWidget] C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Dell Registration] C:\Program Files (x86)\System Registration\prodreg.exe (Dell, Inc.)
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe (Sonic Solutions)
O4 - HKLM..\Run: [SearchProtectAll] C:\Program Files (x86)\SearchProtect\bin\cltmng.exe (Conduit)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [Akamai NetSession Interface] "C:\Users\BigPapa\AppData\Local\Akamai\netsession_win.exe" File not found
O4 - HKCU..\Run: [Connectify] C:\Program Files (x86)\Connectify\Connectify.exe (Connectify)
O4 - HKCU..\Run: [DriverMax] C:\Program Files (x86)\Innovative Solutions\DriverMax\drivermax.exe (Innovative Solutions)
O4 - HKCU..\Run: [GoogleChromeAutoLaunch_89C113111C53352D1F68066DB33BEBDD] C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
O4 - HKCU..\Run: [SearchProtect] C:\Users\BigPapa\AppData\Roaming\SearchProtect\bin\cltmng.exe (Conduit)
O4 - HKLM..\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe (Softthinks)
O4 - HKCU..\RunOnce: [Application Restart #3] C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
O4 - Startup: C:\Users\BigPapa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PdaNet Desktop.lnk = C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: dell.com ([]* in Trusted sites)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} http://support.dell.com/systemprofiler/DellSystemLite.CAB (DellSystemLite.Scanner)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9E1B8B58-55FD-45BC-A6A9-7BD5334B4140}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\WINDOWS\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\WINDOWS\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/05/27 16:08:49 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\BigPapa\Desktop\OTL.exe
[2013/05/25 10:38:28 | 000,000,000 | —D | C] – C:\Users\BigPapa\Desktop\Checking 4 Virus 5-25-2013
[2013/05/18 03:02:48 | 000,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/05/18 03:02:48 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/05/18 03:02:48 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/05/18 03:02:47 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/05/18 03:02:47 | 000,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/05/18 03:02:47 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/05/18 03:02:47 | 000,089,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/05/18 03:02:47 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/05/18 03:02:47 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/05/18 03:02:47 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/05/18 03:02:47 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/05/18 03:02:47 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/05/18 03:02:45 | 003,958,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/05/18 03:02:45 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/05/18 03:02:45 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/05/17 21:43:28 | 001,930,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\authui.dll
[2013/05/17 21:43:28 | 001,796,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\authui.dll
[2013/05/17 21:43:28 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\shdocvw.dll
[2013/05/17 21:43:28 | 000,111,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\consent.exe
[2013/05/17 19:31:24 | 000,265,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\dxgmms1.sys
[2013/05/17 19:31:24 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2013/05/17 19:22:21 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wwanprotdim.dll
[2013/05/13 23:45:48 | 000,000,000 | —D | C] – C:\SearchProtect
[2013/05/11 08:47:19 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RdpGroupPolicyExtension.dll
[2013/05/11 08:47:19 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbRedirectionGroupPolicyExtension.dll
[2013/05/11 08:47:19 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbRedirectionGroupPolicyControl.exe
[2013/05/11 08:47:15 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\TsUsbGD.sys
[2013/05/11 08:47:15 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\rdpvideominiport.sys
[2013/05/11 08:47:14 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\TsUsbFlt.sys
[2013/05/11 08:47:11 | 000,192,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rdpendp_winip.dll
[2013/05/11 08:47:11 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tsgqec.dll
[2013/05/11 08:47:11 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbGDCoInstaller.dll
[2013/05/11 08:47:11 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tsgqec.dll
[2013/05/11 08:47:11 | 000,018,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wksprtPS.dll
[2013/05/11 08:47:11 | 000,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wksprtPS.dll
[2013/05/11 08:47:10 | 000,384,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wksprt.exe
[2013/05/11 08:47:10 | 000,322,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\aaclient.dll
[2013/05/11 08:47:10 | 000,269,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\aaclient.dll
[2013/05/11 08:47:10 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpudd.dll
[2013/05/11 08:47:10 | 000,228,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpendp_winip.dll
[2013/05/11 08:47:10 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TSWbPrxy.exe
[2013/05/11 08:47:10 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MsRdpWebAccess.dll
[2013/05/11 08:47:10 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MsRdpWebAccess.dll
[2013/05/11 08:47:09 | 001,123,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstsc.exe
[2013/05/11 08:47:09 | 001,048,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstsc.exe
[2013/05/11 08:47:08 | 003,174,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorets.dll
[2013/05/11 08:47:07 | 004,916,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstscax.dll
[2013/05/11 08:47:06 | 005,773,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstscax.dll
[2013/05/11 08:27:06 | 001,448,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lsasrv.dll
[2013/05/11 08:27:02 | 000,514,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qdvd.dll
[2013/05/11 08:27:02 | 000,366,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qdvd.dll
[2013/05/07 16:08:47 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360
[2013/04/30 21:00:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\FFmpeg for Audacity
[2013/04/30 15:57:16 | 000,000,000 | —D | C] – C:\Users\BigPapa\AppData\Roaming\Audacity
[2013/04/30 15:57:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Audacity
[2013/04/30 03:10:57 | 001,054,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2013/04/30 03:10:57 | 000,719,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmlmedia.dll
[2013/04/30 03:10:57 | 000,226,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\elshyph.dll
[2013/04/30 03:10:57 | 000,185,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\elshyph.dll
[2013/04/30 03:10:57 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2013/04/30 03:10:57 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2013/04/30 03:10:57 | 000,138,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2013/04/30 03:10:57 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2013/04/30 03:10:57 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/04/30 03:10:57 | 000,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2013/04/30 03:10:56 | 001,441,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/04/30 03:10:56 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2013/04/30 03:10:56 | 000,629,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2013/04/30 03:10:56 | 000,361,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2013/04/30 03:10:56 | 000,232,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/04/30 03:10:56 | 000,137,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/04/30 03:10:56 | 000,125,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2013/04/30 03:10:56 | 000,117,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2013/04/30 03:10:56 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2013/04/30 03:10:56 | 000,073,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2013/04/30 03:10:56 | 000,069,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2013/04/30 03:10:56 | 000,061,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2013/04/30 03:10:56 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2013/04/30 03:10:56 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2013/04/30 03:10:56 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2013/04/30 03:10:55 | 001,509,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/04/30 03:10:55 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2013/04/30 03:10:55 | 000,905,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmlmedia.dll
[2013/04/30 03:10:55 | 000,762,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2013/04/30 03:10:55 | 000,599,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2013/04/30 03:10:55 | 000,452,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2013/04/30 03:10:55 | 000,441,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2013/04/30 03:10:55 | 000,281,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2013/04/30 03:10:55 | 000,235,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/04/30 03:10:55 | 000,216,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2013/04/30 03:10:55 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2013/04/30 03:10:55 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/04/30 03:10:55 | 000,167,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[2013/04/30 03:10:55 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2013/04/30 03:10:55 | 000,144,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2013/04/30 03:10:55 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2013/04/30 03:10:55 | 000,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2013/04/30 03:10:55 | 000,102,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2013/04/30 03:10:55 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/04/30 03:10:55 | 000,092,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2013/04/30 03:10:55 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2013/04/30 03:10:55 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2013/04/30 03:10:55 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2013/04/30 03:10:55 | 000,051,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2013/04/30 03:10:55 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2013/04/30 03:10:55 | 000,027,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2013/04/30 03:10:55 | 000,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2013/04/30 03:10:55 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2013/04/30 03:06:08 | 003,928,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2013/04/30 03:06:08 | 002,776,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msmpeg2vdec.dll
[2013/04/30 03:06:08 | 002,565,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10warp.dll
[2013/04/30 03:06:08 | 002,284,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msmpeg2vdec.dll
[2013/04/30 03:06:08 | 001,887,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d11.dll
[2013/04/30 03:06:08 | 001,682,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2013/04/30 03:06:08 | 001,643,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2013/04/30 03:06:08 | 001,504,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d11.dll
[2013/04/30 03:06:08 | 001,424,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecs.dll
[2013/04/30 03:06:08 | 001,238,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10.dll
[2013/04/30 03:06:08 | 001,158,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2013/04/30 03:06:08 | 000,648,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10level9.dll
[2013/04/30 03:06:08 | 000,522,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2013/04/30 03:06:08 | 000,465,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMPhoto.dll
[2013/04/30 03:06:08 | 000,417,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMPhoto.dll
[2013/04/30 03:06:08 | 000,364,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2013/04/30 03:06:08 | 000,363,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxgi.dll
[2013/04/30 03:06:08 | 000,333,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1core.dll
[2013/04/30 03:06:08 | 000,296,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10core.dll
[2013/04/30 03:06:08 | 000,245,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecsExt.dll
[2013/04/30 03:06:08 | 000,221,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UIAnimation.dll
[2013/04/30 03:06:08 | 000,194,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2013/04/30 03:06:08 | 000,187,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UIAnimation.dll
[2013/04/30 03:06:08 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/04/30 03:06:08 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/04/30 03:06:08 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/04/30 03:06:08 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/04/30 03:06:08 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/04/30 03:06:08 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/04/30 03:06:08 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/04/30 03:06:08 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/04/30 03:06:08 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/04/30 03:06:08 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/04/30 03:06:08 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/04/30 03:06:08 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/04/30 03:06:08 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
[2013/04/30 03:06:08 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-version-l1-1-0.dll
[2013/04/30 03:06:08 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/04/30 03:06:08 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/04/30 03:06:08 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/04/30 03:06:08 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/04/29 22:48:24 | 000,000,000 | —D | C] – C:\VirtualDub-1.9.11
[2013/04/29 18:52:25 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thugs at Bay
[2013/04/29 18:51:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\Thugs at Bay
[2013/04/28 11:34:26 | 000,000,000 | —D | C] – C:\Users\BigPapa\AppData\Local\{9AC6A02F-2783-437B-8C28-D4B0CD91EFE9}
[2013/04/28 11:34:26 | 000,000,000 | —D | C] – C:\Users\BigPapa\AppData\Local\{068D4243-EC00-4741-B0A7-4353AC95E8B0}
[2013/04/28 09:40:00 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CamStudio
[2013/04/28 09:39:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\CamStudio
[2013/04/28 09:39:13 | 000,000,000 | —D | C] – C:\CamStudio

========== Files - Modified Within 30 Days ==========

[2013/05/27 16:09:07 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\BigPapa\Desktop\OTL.exe
[2013/05/27 15:44:05 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/05/27 15:26:00 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/05/27 15:21:16 | 000,021,296 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/05/27 15:21:16 | 000,021,296 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/05/27 15:13:53 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/05/27 15:13:25 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/05/27 15:13:19 | 1637,965,791 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/05/27 15:13:16 | 3152,510,976 | -HS- | M] () – C:\hiberfil.sys
[2013/05/27 12:14:24 | 000,001,456 | —- | M] () – C:\Users\BigPapa\AppData\Local\Adobe Save for Web 12.0 Prefs
[2013/05/25 17:02:25 | 000,000,876 | —- | M] () – C:\Users\BigPapa\.recently-used.xbel
[2013/05/24 07:24:04 | 000,778,834 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/05/24 07:24:04 | 000,660,068 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/05/24 07:24:04 | 000,120,996 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/05/23 16:37:30 | 000,002,185 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/05/18 03:57:58 | 000,002,021 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[2013/05/18 03:32:28 | 004,953,816 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/05/18 03:31:53 | 001,842,244 | —- | M] () – C:\Windows\SysNative\drivers\N360x64\1403010.016\Cat.DB
[2013/05/07 16:08:48 | 000,002,321 | —- | M] () – C:\Users\Public\Desktop\Norton 360.lnk
[2013/05/07 16:06:23 | 000,177,312 | —- | M] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2013/05/07 16:06:23 | 000,007,466 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2013/05/07 16:06:23 | 000,000,855 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2013/04/30 15:57:09 | 000,001,009 | —- | M] () – C:\Users\BigPapa\Desktop\Audacity.lnk
[2013/04/30 03:10:57 | 001,054,720 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2013/04/30 03:10:57 | 000,719,360 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmlmedia.dll
[2013/04/30 03:10:57 | 000,226,304 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\elshyph.dll
[2013/04/30 03:10:57 | 000,185,344 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\elshyph.dll
[2013/04/30 03:10:57 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2013/04/30 03:10:57 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2013/04/30 03:10:57 | 000,138,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2013/04/30 03:10:57 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2013/04/30 03:10:57 | 000,079,872 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/04/30 03:10:57 | 000,057,344 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2013/04/30 03:10:56 | 001,441,280 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/04/30 03:10:56 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2013/04/30 03:10:56 | 000,629,248 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2013/04/30 03:10:56 | 000,361,984 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2013/04/30 03:10:56 | 000,232,960 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/04/30 03:10:56 | 000,137,216 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/04/30 03:10:56 | 000,125,440 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2013/04/30 03:10:56 | 000,117,248 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2013/04/30 03:10:56 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2013/04/30 03:10:56 | 000,073,728 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2013/04/30 03:10:56 | 000,069,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2013/04/30 03:10:56 | 000,061,952 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2013/04/30 03:10:56 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2013/04/30 03:10:56 | 000,025,185 | —- | M] () – C:\Windows\SysWow64\ieuinit.inf
[2013/04/30 03:10:56 | 000,023,040 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2013/04/30 03:10:56 | 000,011,776 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2013/04/30 03:10:55 | 001,509,376 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/04/30 03:10:55 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2013/04/30 03:10:55 | 000,905,728 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmlmedia.dll
[2013/04/30 03:10:55 | 000,762,368 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2013/04/30 03:10:55 | 000,599,552 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2013/04/30 03:10:55 | 000,452,096 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2013/04/30 03:10:55 | 000,441,856 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2013/04/30 03:10:55 | 000,281,600 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2013/04/30 03:10:55 | 000,235,008 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/04/30 03:10:55 | 000,216,064 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2013/04/30 03:10:55 | 000,197,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2013/04/30 03:10:55 | 000,173,568 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/04/30 03:10:55 | 000,167,424 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[2013/04/30 03:10:55 | 000,149,504 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2013/04/30 03:10:55 | 000,144,896 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2013/04/30 03:10:55 | 000,136,192 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2013/04/30 03:10:55 | 000,135,680 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2013/04/30 03:10:55 | 000,102,912 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2013/04/30 03:10:55 | 000,097,280 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/04/30 03:10:55 | 000,092,160 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2013/04/30 03:10:55 | 000,081,408 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2013/04/30 03:10:55 | 000,077,312 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2013/04/30 03:10:55 | 000,062,976 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2013/04/30 03:10:55 | 000,051,200 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2013/04/30 03:10:55 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2013/04/30 03:10:55 | 000,027,648 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2013/04/30 03:10:55 | 000,025,185 | —- | M] () – C:\Windows\SysNative\ieuinit.inf
[2013/04/30 03:10:55 | 000,013,824 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2013/04/30 03:10:55 | 000,012,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2013/04/30 03:06:08 | 003,928,064 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2013/04/30 03:06:08 | 002,776,576 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msmpeg2vdec.dll
[2013/04/30 03:06:08 | 002,565,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10warp.dll
[2013/04/30 03:06:08 | 002,284,544 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msmpeg2vdec.dll
[2013/04/30 03:06:08 | 001,887,232 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d11.dll
[2013/04/30 03:06:08 | 001,682,432 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2013/04/30 03:06:08 | 001,643,520 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2013/04/30 03:06:08 | 001,504,768 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\d3d11.dll
[2013/04/30 03:06:08 | 001,424,384 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecs.dll
[2013/04/30 03:06:08 | 001,238,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10.dll
[2013/04/30 03:06:08 | 001,158,144 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2013/04/30 03:06:08 | 000,648,192 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10level9.dll
[2013/04/30 03:06:08 | 000,522,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2013/04/30 03:06:08 | 000,465,920 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\WMPhoto.dll
[2013/04/30 03:06:08 | 000,417,792 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\WMPhoto.dll
[2013/04/30 03:06:08 | 000,364,544 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2013/04/30 03:06:08 | 000,363,008 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxgi.dll
[2013/04/30 03:06:08 | 000,333,312 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1core.dll
[2013/04/30 03:06:08 | 000,296,960 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10core.dll
[2013/04/30 03:06:08 | 000,245,248 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecsExt.dll
[2013/04/30 03:06:08 | 000,221,184 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\UIAnimation.dll
[2013/04/30 03:06:08 | 000,194,560 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2013/04/30 03:06:08 | 000,187,392 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\UIAnimation.dll
[2013/04/30 03:06:08 | 000,010,752 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/04/30 03:06:08 | 000,010,752 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/04/30 03:06:08 | 000,009,728 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/04/30 03:06:08 | 000,009,728 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/04/30 03:06:08 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/04/30 03:06:08 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/04/30 03:06:08 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/04/30 03:06:08 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/04/30 03:06:08 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/04/30 03:06:08 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/04/30 03:06:08 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/04/30 03:06:08 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/04/30 03:06:08 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
[2013/04/30 03:06:08 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-version-l1-1-0.dll
[2013/04/30 03:06:08 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/04/30 03:06:08 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/04/30 03:06:08 | 000,002,560 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/04/30 03:06:08 | 000,002,560 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/04/29 18:52:21 | 000,001,184 | —- | M] () – C:\Users\BigPapa\Desktop\Zwei-Stein.lnk
[2013/04/29 18:29:31 | 003,413,519 | —- | M] () – C:\Users\BigPapa\Desktop\zweifull.exe
[2013/04/28 09:40:01 | 000,001,016 | —- | M] () – C:\Users\Public\Desktop\CamStudio.lnk
[2013/04/28 09:15:41 | 000,072,329 | —- | M] () – C:\Users\BigPapa\Documents\test_microphone2.wma

========== Files Created - No Company Name ==========

[2013/05/25 17:02:25 | 000,000,876 | —- | C] () – C:\Users\BigPapa\.recently-used.xbel
[2013/04/30 15:57:08 | 000,001,009 | —- | C] () – C:\Users\BigPapa\Desktop\Audacity.lnk
[2013/04/30 15:57:06 | 000,001,021 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
[2013/04/30 03:10:56 | 000,025,185 | —- | C] () – C:\Windows\SysWow64\ieuinit.inf
[2013/04/30 03:10:55 | 000,025,185 | —- | C] () – C:\Windows\SysNative\ieuinit.inf
[2013/04/29 22:48:24 | 000,073,728 | —- | C] ( ) – C:\Windows\System\vdremote.dll
[2013/04/29 22:48:24 | 000,065,536 | —- | C] ( ) – C:\Windows\System\vdsvrlnk.dll
[2013/04/29 18:52:17 | 000,001,184 | —- | C] () – C:\Users\BigPapa\Desktop\Zwei-Stein.lnk
[2013/04/29 18:26:19 | 003,413,519 | —- | C] () – C:\Users\BigPapa\Desktop\zweifull.exe
[2013/04/28 09:40:01 | 000,001,016 | —- | C] () – C:\Users\Public\Desktop\CamStudio.lnk
[2013/04/28 09:15:25 | 000,072,329 | —- | C] () – C:\Users\BigPapa\Documents\test_microphone2.wma
[2013/04/21 15:02:15 | 000,000,258 | RHS- | C] () – C:\Users\BigPapa\ntuser.pol
[2013/02/09 20:00:38 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/02/09 20:00:38 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/02/09 20:00:38 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/02/09 20:00:38 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/02/09 20:00:38 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/12/14 02:42:30 | 000,963,452 | —- | C] () – C:\Windows\SysWow64\igcodeckrng600.bin
[2012/12/14 02:42:30 | 000,064,512 | —- | C] () – C:\Windows\SysWow64\igdde32.dll
[2012/12/14 02:42:28 | 000,272,928 | —- | C] () – C:\Windows\SysWow64\igvpkrng600.bin
[2012/08/08 23:31:23 | 000,001,456 | —- | C] () – C:\Users\BigPapa\AppData\Local\Adobe Save for Web 12.0 Prefs
[2012/07/16 00:01:04 | 000,000,132 | —- | C] () – C:\Users\BigPapa\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2012/06/03 18:48:08 | 000,000,056 | —- | C] () – C:\ProgramData\ezsidmv.dat
[2012/04/19 01:58:28 | 000,000,132 | —- | C] () – C:\Users\BigPapa\AppData\Roaming\Adobe Targa Format CS5 Prefs
[2012/02/14 18:47:06 | 000,963,912 | —- | C] () – C:\Windows\SysWow64\igkrng600.bin
[2012/02/14 18:47:06 | 000,261,208 | —- | C] () – C:\Windows\SysWow64\igfcg600m.bin
[2011/06/21 16:18:08 | 000,145,804 | —- | C] () – C:\Windows\SysWow64\igcompkrng600.bin

========== ZeroAccess Check ==========

[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\WINDOWS\SysNative\shell32.dll – [2013/02/27 01:52:56 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/27 00:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\WINDOWS\SysNative\wbem\fastprox.dll – [2009/07/13 21:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 23:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\WINDOWS\SysNative\wbem\wbemess.dll – [2009/07/13 21:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== Custom Scans ==========

< Results of screen317's Security Check version 0.99.64 >

< Windows 7 Service Pack 1 x64 (UAC is enabled) >

< Internet Explorer 10 >

< ``````````````Antivirus/Firewall Check:`````````````` >
Invalid Switch: b][]

< Windows Firewall Enabled! >

< Norton 360 >

< WMI entry may not exist for antivirus; attempting automatic update. >
Invalid Switch: size]

< `````````Anti-malware/Other Utilities Check:````````` >
Invalid Switch: b][]

< Java™ 6 Update 31 >

< Java version out of Date! >
Invalid Switch: color]

< Adobe Reader 10.1.7 Adobe Reader out of Date! >
Invalid Switch: color]

< Google Chrome 26.0.1410.64 >

< Google Chrome 27.0.1453.94 >

< ````````Process Check: objlist.exe by Laurent```````` >
Invalid Switch: b][]

< Norton ccSvcHst.exe >

< `````````````````System Health check````````````````` >
Invalid Switch: b][]

< Total Fragmentation on Drive C: 2% >

< ````````````````````End of Log`````````````````````` >
Invalid Switch: b][]

< >

< >

< >

< aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software >

< Run date: 2013-05-27 15:35:55 >

< —————————– >

< 15:35:55.496 OS Version: Windows x64 6.1.7601 Service Pack 1 >

< 15:35:55.497 Number of processors: 4 586 0x2A07 >

< 15:35:55.498 ComputerName: BIGPAPA-PC UserName: BigPapa >

< 15:35:56.743 Initialize success >

< 15:36:04.892 AVAST engine defs: 13052700 >

< 15:36:22.310 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 >

< 15:36:22.313 Disk 0 Vendor: ST31000524AS JC47 Size: 953869MB BusType: 3 >

< 15:36:22.392 Disk 0 MBR read successfully >

< 15:36:22.395 Disk 0 MBR scan >

< 15:36:22.400 Disk 0 Windows VISTA default MBR code >

< 15:36:22.404 Disk 0 Partition 1 00 DE Dell Utility DELL 4.1 39 MB offset 63 >

< 15:36:22.412 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 12542 MB offset 81920 >
Invalid Switch: NTFS NTFS 12542 MB offset 81920

< 15:36:22.418 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 941286 MB offset 25767936 >
Invalid Switch: NTFS NTFS 941286 MB offset 25767936

< 15:36:22.440 Disk 0 scanning C:\Windows\system32\drivers >

< 15:36:31.358 Service scanning >

< 15:36:49.537 Modules scanning >

< 15:36:49.545 Disk 0 trace - called modules: >

< 15:36:49.570 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS intelide.sys PCIIDEX.SYS hal.dll atapi.sys >

< 15:36:49.892 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004d3a060] >

< 15:36:49.899 3 CLASSPNP.SYS[fffff88001a6a43f] -> nt!IofCallDriver -> [0xfffffa80048f6520] >

< 15:36:49.904 5 ACPI.sys[fffff88000fa57a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa80048f8060] >

< 15:36:53.371 AVAST engine scan C:\Windows >

< 15:36:56.063 AVAST engine scan C:\Windows\system32 >

< 15:39:32.852 AVAST engine scan C:\Windows\system32\drivers >

< 15:39:47.845 AVAST engine scan C:\Users\BigPapa >

< 15:45:01.222 AVAST engine scan C:\ProgramData >

< 15:46:13.656 Scan finished successfully >

< 15:46:57.275 Disk 0 MBR has been saved successfully to "C:\Users\BigPapa\Desktop\Checking 4 Virus 5-25-2013\MBR.dat" >

< 15:46:57.278 The log file has been saved successfully to "C:\Users\BigPapa\Desktop\Checking 4 Virus 5-25-2013\aswMBR.txt" >

< >

< >

< >

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2011/02/26 01:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\WINDOWS\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\WINDOWS\erdnt\cache86\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\WINDOWS\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\WINDOWS\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 02:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\WINDOWS\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 23:24:25 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\WINDOWS\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\WINDOWS\SysWOW64\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\WINDOWS\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/11/20 23:24:11 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\WINDOWS\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

< MD5 for: SERVICES.EXE >
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\WINDOWS\erdnt\cache64\services.exe
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\WINDOWS\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SVCHOST.EXE >
[2009/07/13 21:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\WINDOWS\erdnt\cache86\svchost.exe
[2009/07/13 21:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\WINDOWS\SysWOW64\svchost.exe
[2009/07/13 21:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\WINDOWS\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009/07/13 21:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\WINDOWS\erdnt\cache64\svchost.exe
[2009/07/13 21:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\SysNative\svchost.exe
[2009/07/13 21:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\WINDOWS\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 23:23:55 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\WINDOWS\erdnt\cache86\userinit.exe
[2010/11/20 23:23:55 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\WINDOWS\SysWOW64\userinit.exe
[2010/11/20 23:23:55 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\WINDOWS\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010/11/20 23:24:28 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\WINDOWS\erdnt\cache64\userinit.exe
[2010/11/20 23:24:28 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\SysNative\userinit.exe
[2010/11/20 23:24:28 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\WINDOWS\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010/11/20 23:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\WINDOWS\erdnt\cache64\winlogon.exe
[2010/11/20 23:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 23:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\WINDOWS\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe

< %systemroot%\*. /rp /s >

< %systemdrive%\$Recycle.Bin|@;true;true;true >

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

========== Base Services ==========
SRV:64bit: - [2009/07/13 21:40:01 | 000,072,192 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\SysNative\aelupsvc.dll – (AeLookupSvc)
SRV:64bit: - [2013/02/27 01:47:10 | 000,070,144 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\SysNative\appinfo.dll – (Appinfo)
SRV:64bit: - [2009/07/13 21:38:55 | 000,079,360 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\SysNative\alg.exe – (ALG)
SRV:64bit: - [2010/11/20 23:23:51 | 000,849,920 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\SysNative\qmgr.dll – (BITS)
SRV:64bit: - [2010/11/20 23:24:00 | 000,705,024 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\SysNative\BFE.DLL – (BFE)
SRV:64bit: - [2011/11/17 02:33:55 | 000,031,232 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\SysNative\lsass.exe – (KeyIso)
SRV:64bit: - [2009/07/13 21:40:50 | 000,402,944 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\SysNative\es.dll – (EventSystem)
SRV - [2009/07/13 21:15:19 | 000,271,360 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\SysWOW64\es.dll – (EventSystem)
SRV:64bit: - [2012/07/04 18:13:27 | 000,136,704 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\SysNative\browser.dll – (Browser)
SRV:64bit: - [2012/06/02 01:41:28 | 000,184,320 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\SysNative\cryptsvc.dll – (CryptSvc)
SRV - [2012/06/02 00:36:29 | 000,140,288 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\SysWOW64\cryptsvc.dll – (CryptSvc)
SRV:64bit: - [2010/11/20 23:24:01 | 000,512,000 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\SysNative\rpcss.dll – (DcomLaunch)
SRV:64bit: - [2010/11/20 23:24:00 | 000,317,952 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\SysNative\dhcpcore.dll – (Dhcp)
SRV - [2010/11/20 23:24:09 | 000,254,464 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\SysWOW64\dhcpcore.dll – (Dhcp)
SRV:64bit: - [2011/06/21 16:30:52 | 000,183,296 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\SysNative\dnsrslvr.dll – (Dnscache)
SRV:64bit: - [2009/07/13 21:40:35 | 000,111,104 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\SysNative\eapsvc.dll – (EapHost)
SRV:64bit: - [2009/07/13 21:41:00 | 000,038,912 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\SysNative\hidserv.dll – (hidserv)
SRV - [2009/07/13 21:15:24 | 000,049,152 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\SysWOW64\hidserv.dll – (hidserv)
SRV:64bit: - [2009/07/13 21:41:10 | 000,359,424 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\SysNative\ipnathlp.dll – (SharedAccess)
SRV:64bit: - [2010/11/20 23:23:48 | 000,501,248 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\SysNative\IPSECSVC.DLL – (PolicyAgent)
No service found with a name of MsMpSvc
No service found with a name of NisSrv
SRV:64bit: - [2009/07/13 21:41:54 | 000,524,288 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\SysNative\swprv.dll – (swprv)
SRV:64bit: - [2009/07/13 21:41:26 | 000,067,584 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\WINDOWS\SysNative\mmcss.dll – (MMCSS)
SRV:64bit: - [2009/07/13 21:41:52 | 000,360,448 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\SysNative\netman.dll – (Netman)
SRV:64bit: - [2009/07/13 21:41:52 | 000,459,776 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\SysNative\netprofm.dll – (netprofm)
SRV - [2009/07/13 21:16:03 | 000,360,448 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\SysWOW64\netprofm.dll – (netprofm)
SRV:64bit: - [2012/10/03 13:44:21 | 000,303,104 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\SysNative\nlasvc.dll – (NlaSvc)
SRV:64bit: - [2009/07/13 21:41:53 | 000,025,600 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\SysNative\nsisvc.dll – (nsi)
SRV:64bit: - [2011/05/24 07:42:55 | 000,404,480 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\SysNative\umpnpmgr.dll – (PlugPlay)
SRV:64bit: - [2012/02/11 02:36:02 | 000,559,104 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\SysNative\spoolsv.exe – (Spooler)
SRV:64bit: - [2011/11/17 02:33:55 | 000,031,232 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\SysNative\lsass.exe – (ProtectedStorage)
No service found with a name of EMDMgmt
SRV:64bit: - [2009/07/13 21:41:53 | 000,099,328 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\SysNative\rasauto.dll – (RasAuto)
SRV:64bit: - [2010/11/20 23:24:17 | 000,344,064 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\SysNative\rasmans.dll – (RasMan)
SRV:64bit: - [2010/11/20 23:24:01 | 000,512,000 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\SysNative\rpcss.dll – (RpcSs)
SRV:64bit: - [2010/11/20 23:24:16 | 000,030,720 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\SysNative\seclogon.dll – (seclogon)
SRV:64bit: - [2011/11/17 02:33:55 | 000,031,232 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\SysNative\lsass.exe – (SamSs)
SRV:64bit: - [2009/07/13 21:41:58 | 000,097,280 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\SysNative\wscsvc.dll – (wscsvc)
SRV:64bit: - [2010/11/20 23:23:48 | 000,236,032 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\SysNative\srvsvc.dll – (LanmanServer)
SRV:64bit: - [2010/11/20 23:23:55 | 000,370,688 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\SysNative\shsvcs.dll – (ShellHWDetection)
SRV - [2010/11/20 23:24:03 | 000,328,192 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\SysWOW64\shsvcs.dll – (ShellHWDetection)
No service found with a name of slsvc
SRV:64bit: - [2010/11/20 23:24:16 | 001,110,016 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\SysNative\schedsvc.dll – (Schedule)
SRV:64bit: - [2010/11/20 23:24:32 | 000,316,928 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\SysNative\tapisrv.dll – (TapiSrv)
SRV - [2010/11/20 23:24:00 | 000,242,176 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\SysWOW64\tapisrv.dll – (TapiSrv)
SRV:64bit: - [2009/07/13 21:41:55 | 000,044,544 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\SysNative\themeservice.dll – (Themes)
SRV:64bit: - [2012/05/01 01:40:20 | 000,209,920 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\SysNative\profsvc.dll – (ProfSvc)
SRV:64bit: - [2010/11/20 23:23:55 | 001,600,512 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\SysNative\VSSVC.exe – (VSS)
SRV:64bit: - [2010/11/20 23:24:32 | 000,679,424 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\SysNative\audiosrv.dll – (AudioSrv)
SRV:64bit: - [2010/11/20 23:24:32 | 000,679,424 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\SysNative\audiosrv.dll – (AudioEndpointBuilder)
SRV:64bit: - [2010/11/20 23:25:06 | 000,170,496 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\SysNative\sdrsvc.dll – (SDRSVC)
SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2010/11/20 23:23:55 | 001,646,080 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\SysNative\wevtsvc.dll – (eventlog)
SRV:64bit: - [2010/11/20 23:24:28 | 000,828,416 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\SysNative\MPSSVC.dll – (MpsSvc)
SRV:64bit: - [2010/11/20 23:24:48 | 000,580,096 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\SysNative\wiaservc.dll – (stisvc)
SRV:64bit: - [2010/11/20 23:24:15 | 000,128,000 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\msiexec.exe – (msiserver)
SRV - [2010/11/20 23:24:28 | 000,073,216 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysWow64\msiexec.exe – (msiserver)
SRV:64bit: - [2009/07/13 21:41:56 | 000,242,688 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\SysNative\wbem\WMIsvc.dll – (Winmgmt)
SRV:64bit: - [2012/06/02 18:19:43 | 002,428,952 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\SysNative\wuaueng.dll – (wuauserv)
SRV:64bit: - [2010/11/20 23:24:09 | 000,252,416 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\SysNative\dot3svc.dll – (dot3svc)
SRV:64bit: - [2009/07/13 21:41:56 | 000,886,784 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\SysNative\wlansvc.dll – (Wlansvc)
SRV:64bit: - [2010/11/20 23:24:32 | 000,118,784 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\SysNative\wkssvc.dll – (LanmanWorkstation)

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: ST31000524AS ATA Device
Partitions: 3
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE1 -
Interface type: USB
Media Type:
Model: Generic- Multi-Card USB Device
Partitions: 0
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 39.00MB
Starting Offset: 32256
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 12.00GB
Starting Offset: 41943040
Hidden sectors: 0


DeviceID: Disk #0, Partition #2
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 919.00GB
Starting Offset: 13193183232
Hidden sectors: 0


< >

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 996 bytes -> C:\Users\BigPapa\AppData\Local\Temp:AOXaBQJ7tscq6Z15fNQRYx9gFQOe
@Alternate Data Stream - 1040 bytes -> C:\Users\BigPapa\AppData\Local\Temp:gbs3uYUkwcTpnTPBE

< End of report >


OTL Extras logfile created on: 5/27/2013 4:17:57 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\BigPapa\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16576)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.91 Gb Total Physical Memory | 1.90 Gb Available Physical Memory | 48.64% Memory free
7.83 Gb Paging File | 5.47 Gb Available in Paging File | 69.85% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 919.22 Gb Total Space | 829.05 Gb Free Space | 90.19% Space Free | Partition Type: NTFS

Computer Name: BIGPAPA-PC | User Name: BigPapa | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = ChromeHTML] – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = ChromeHTML] – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistHiDefMedia] – "C:\Program Files (x86)\HiDefMedia\HiDefMedia\HiDefMedia.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithHiDefMedia] – "C:\Program Files (x86)\HiDefMedia\HiDefMedia\HiDefMedia.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistHiDefMedia] – "C:\Program Files (x86)\HiDefMedia\HiDefMedia\HiDefMedia.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithHiDefMedia] – "C:\Program Files (x86)\HiDefMedia\HiDefMedia\HiDefMedia.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – Reg Error: Value error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0607DB13-268C-4EDF-BD60-5FF7B6F5A384}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{0614CC7C-E551-494F-BE1F-C403E1631413}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{0ADAB0CC-22CA-4D1B-9C3D-1712CE4A11E7}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{0D0B99CB-9FB1-437B-81BE-FFA115EF13CA}" = lport=139 | protocol=6 | dir=in | app=system |
"{0ED7C053-4E1F-4785-941F-58A272774768}" = lport=547 | protocol=17 | dir=in | app=c:\windows\system32\svchost.exe |
"{11404A20-58C2-4553-9888-3EB1ABECFACE}" = lport=10243 | protocol=6 | dir=in | app=system |
"{15878FA5-3EB5-4B17-B65C-A74535EF7D90}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{1F1C1C53-2990-40A6-97B3-EA7204901905}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{1F276872-E11A-43BE-A35A-48CFB4E86E0D}" = rport=1900 | protocol=17 | dir=out | app=c:\windows\system32\svchost.exe |
"{2650C3F8-1E32-47D5-AF49-4C21C46C6261}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{288007FB-9486-45B5-B010-A758EC6FF57A}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{292251A4-6621-48A3-8500-18789C112FF2}" = lport=2869 | protocol=6 | dir=in | app=system |
"{2958AFF6-30B4-451A-90FE-6F9B09E896A9}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{36074F31-5DB4-45D9-93EC-AD31A6EA603E}" = lport=2869 | protocol=6 | dir=in | app=system |
"{3DE31478-E2D9-4566-8836-F75A2EB73C51}" = lport=137 | protocol=17 | dir=in | app=system |
"{435B0463-E9FF-4CDA-8B45-0BAB08D41F72}" = lport=1317 | protocol=17 | dir=in | app=c:\program files (x86)\connectify\connectifynetservices.exe |
"{43B033C0-8D06-4D1C-B396-617EDF8A2637}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{4473321E-DA05-41F0-9D6A-5C185AC5F91A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{48C8BC41-4F54-4C2A-83AD-2EFE10E611DA}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{5AC45808-A356-43DE-B922-4EFCFE407806}" = rport=2869 | protocol=6 | dir=out | app=system |
"{5C8A34F6-D940-47BC-86B0-D98388307E9F}" = rport=2869 | protocol=6 | dir=out | app=system |
"{5D21649E-E1D4-4060-A196-2125BB55AE01}" = lport=2869 | protocol=6 | dir=in | app=system |
"{61F289F3-F088-414D-8837-D46C4C0540DC}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{694C8CB3-10D5-4A2A-8A88-941CBAB97628}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{6C2CC718-AD5F-4659-B3F1-78CCE9AC80B6}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe |
"{6FAE9F93-F765-4953-9341-CABE18E5A7E5}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{7814A0E0-A8EC-41C9-B96F-C68EEEB24CE4}" = lport=1900 | protocol=17 | dir=in | app=c:\windows\system32\svchost.exe |
"{785FC4ED-BE6A-48D2-89C8-58ABFA5C2025}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{7AC1D8C9-5E18-4539-8C6B-3986BD7061AD}" = rport=138 | protocol=17 | dir=out | app=system |
"{7DED8404-6A3A-4703-A27E-A63218EEFEF4}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{7E33BDFA-DD25-4ABE-BFDD-55D75A646DB4}" = rport=137 | protocol=17 | dir=out | app=system |
"{828D5C0C-690F-4F76-A251-FD3B8330D685}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{82C1DFFA-B424-4BF2-AB61-CBBD4A672769}" = lport=1303 | protocol=17 | dir=in | app=c:\program files (x86)\connectify\connectifynetservices.exe |
"{853B27DD-4C7D-4686-B513-6705E2E141F6}" = lport=445 | protocol=6 | dir=in | app=system |
"{89ED850E-721C-4957-A7F7-19883A74CD02}" = lport=53 | protocol=17 | dir=in | app=c:\program files (x86)\connectify\connectifynetservices.exe |
"{8E4CC97A-A57C-4D93-85EA-AF87C262586F}" = lport=68 | protocol=17 | dir=in | app=c:\program files (x86)\connectify\connectifynetservices.exe |
"{8F596EEE-60E0-40B1-A6E3-FBADB414CCA0}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{91F1C8CE-4DF2-4168-81F6-19171B1130D5}" = lport=2869 | protocol=6 | dir=in | app=system |
"{9E435AF2-6C1E-48FD-A90B-A6376668E13B}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{A005B64C-1A63-4539-9B31-46ECC5D56F13}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{B10D34F9-F00D-440B-B083-D21B9F990A60}" = rport=2869 | protocol=6 | dir=out | app=system |
"{B7345FCA-0FF6-4246-84A5-B5C311F884BB}" = rport=139 | protocol=6 | dir=out | app=system |
"{BBCA9BAF-822D-46C8-852F-0A40FADF6132}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{C9D9F5D7-06DD-4D5E-9D9D-8A446832EBBF}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{CA706AB1-A305-4BD3-BAA8-F585C0640F12}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{CC8898C2-9569-47FC-A743-17639E61F14E}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{CCB52CA9-4BE3-47E1-8A2C-97DC83B8C8EF}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{CF115FB5-7770-4F79-9D4E-CE2BBBB71CDC}" = lport=138 | protocol=17 | dir=in | app=system |
"{D0315000-7F39-498F-A403-08829B6C61EB}" = lport=2869 | protocol=6 | dir=in | app=system |
"{D16269D1-33AA-4A98-A666-06E0C5D8C0A7}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{D564F873-262E-4447-A85A-3BCEFEF953C2}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{D71EA4CC-076F-4526-B078-17A56227D7E2}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D7F99C2E-DBBF-4E9B-83DD-AF316F8EF55C}" = rport=445 | protocol=6 | dir=out | app=system |
"{DA2E678A-1FC8-4D8E-818A-69044D43B765}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{DD057556-2D21-4435-ACAA-162038C06D44}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{DD8CE842-DF87-460E-9285-3D3C2A88C266}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{E93DC8AE-B4B1-434F-B302-0D5C0D5DACC5}" = lport=67 | protocol=17 | dir=in | app=c:\program files (x86)\connectify\connectifynetservices.exe |
"{E971DF21-9AA5-4296-9772-DA03DF2A2B25}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{ECF5CDC9-94F5-4CD7-8C92-B0327BCD53BC}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{F024FFD3-FEAA-420C-8DD7-525FB7B42AD5}" = rport=10243 | protocol=6 | dir=out | app=system |
"{FC454CB8-C54E-4E2A-BEB3-32EC6141D5EC}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01AD3B9A-ADCB-431E-9A18-6CFDB6204E27}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{048241D4-207A-4844-BF9E-C6BEE08D9A0B}" = protocol=17 | dir=in | app=c:\program files (x86)\autodesk\backburner\monitor.exe |
"{10BDE695-455E-4859-AF1E-FC0B803BFFA1}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{11A5A541-AB32-4838-B4BD-E098C3327826}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{12F34F76-87F5-48EA-B323-4706B8FDF733}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{144A31CB-D0E5-403B-A995-5522FF099B26}" = protocol=58 | dir=in | name=internet connection sharing (router solicitation-in) |
"{1646524C-2DBE-4039-A6DD-B4AAA2760EEA}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{2352E266-994D-40A6-B55C-1BA011DF5C90}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{24FAEF55-B633-4CE2-B850-BE774882043A}" = protocol=6 | dir=in | app=c:\udk\udk-2012-10\binaries\win64\udk.exe |
"{3646DA2F-29D2-48E3-B01B-46AC6CF11D10}" = protocol=6 | dir=out | app=%systemroot%\system32\wudfhost.exe |
"{36CF658C-27EE-4AB5-B3AF-C510D8AFB24B}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{38DC1D35-F9EF-4E26-8CEA-313E5A21D1AC}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{4212CAD5-2D7C-4C3B-B63D-F8F2110B8CCE}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{4BDA0FA0-798D-485A-9450-9279E5786772}" = protocol=17 | dir=in | app=c:\program files (x86)\autodesk\backburner\manager.exe |
"{4D8FF5DC-502C-485E-BC7C-A1EF50660DAD}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{5009E2B4-4437-41B8-AD01-A3B5444513AB}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{564A1666-F3A9-4B2E-A7FD-8E406F53ABC2}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{5811674A-4405-4E34-93C3-1B48648A0BE6}" = protocol=6 | dir=out | app=system |
"{634BCE36-7ED4-4E7C-9D1E-AEAD5EAC9D0C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{661974BF-1322-4275-91FF-17C497CB6D19}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{724074AC-23A0-4919-9B3C-B5A23DBF8C29}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{75B39D1A-700A-45FE-A27C-A933A0DA569F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{7DA3768B-6643-4705-83F4-A54AF0277ACF}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 |
"{7EF71112-E30C-4C9B-AD3B-AD815A6AC2B5}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{8147E265-EFC1-4E08-950C-ABD1613FDD9F}" = protocol=17 | dir=in | app=c:\udk\udk-2012-10\binaries\win64\udk.exe |
"{81AAE21D-E417-48C5-9A1B-2EBEADF6D32B}" = protocol=6 | dir=out | app=c:\windows\system32\svchost.exe |
"{83290696-E83D-445B-BC2C-2B7B38BE0F48}" = protocol=17 | dir=in | app=c:\udk\udk-2012-10\binaries\win32\udk.exe |
"{83FC6523-5182-4443-956B-31D1C0C0CDB9}" = protocol=6 | dir=in | app=c:\udk\udk-2012-10\binaries\win32\udk.exe |
"{843D0F62-9B70-4320-8A7F-33A1B467B61F}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{861E5884-7EF8-4B59-913A-27BA12F7116F}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{89F46317-2239-45D8-8299-E90B3B120AC9}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{8CC9B278-D012-44FF-BE50-3E2990DCC113}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{91BD945D-F42E-4043-A376-7DC40372ABE3}" = protocol=6 | dir=in | app=c:\program files (x86)\autodesk\backburner\manager.exe |
"{92268B8A-F599-4EA7-AB2A-AFC4FD48E9F3}" = protocol=6 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{927C8CBF-FA44-406C-86AE-450DF1CE83D8}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{99F956EC-D429-4394-BA94-0AFDF77430B4}" = dir=in | app=c:\program files (x86)\dell\videostage\videostage.exe |
"{9A9DC434-B380-401B-88BC-7FC316DFD1A2}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{A265CFD2-2EAF-4D20-AB28-D19D25114C41}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A5EF2AEF-93B4-4ADD-93A6-E96F2E510AE5}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{A642A2BC-27E6-4088-95B9-543D2E5A54A4}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 |
"{AB84003A-2363-4EB9-BBA7-B3F8AADAC9E2}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{AEFEDC8C-A242-4BCF-A598-781DF0F2784D}" = protocol=17 | dir=in | app=c:\program files\7-zip\7zfm.exe |
"{B56A8560-5DBB-4261-8F5B-49462D337F8F}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{C1D3DD71-C8B0-46F6-A5CD-A1119BD6529C}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{C4086B3B-DE6F-4C2F-B817-8420117AEEF1}" = protocol=6 | dir=in | app=c:\program files\7-zip\7zfm.exe |
"{CC07ABFC-5E84-42E0-AE91-3671E934AB3F}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{CF30AE50-822A-42D1-BAFB-6386B814DF62}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{DAE46B93-D365-4C03-954C-7C6FAC6FE7DA}" = protocol=6 | dir=in | app=c:\program files (x86)\autodesk\backburner\server.exe |
"{DB27A5F3-9F57-460E-AE82-6A88BF45C5EF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{E2C2DFEC-1046-410C-A772-25F29344F636}" = protocol=6 | dir=in | app=c:\program files (x86)\autodesk\backburner\monitor.exe |
"{E73ECFA0-6330-4285-8461-F3842508CE38}" = protocol=17 | dir=in | app=c:\program files (x86)\autodesk\backburner\server.exe |
"{F113AA3C-5A6C-4984-A3CF-59E74C227003}" = dir=out | app=c:\windows\system32\svchost.exe |
"TCP Query User{852CC61F-0719-4E03-AFFE-6AC59D28FF43}C:\program files\autodesk\maya2012\bin\maya.exe" = protocol=6 | dir=in | app=c:\program files\autodesk\maya2012\bin\maya.exe |
"TCP Query User{C7EF4817-F0B3-4F5D-B5E6-0DE4A7E3333E}C:\users\bigpapa\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\bigpapa\appdata\local\akamai\netsession_win.exe |
"UDP Query User{2C9FD82F-E4CB-4052-BAA7-38D97C3FF3DC}C:\users\bigpapa\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\bigpapa\appdata\local\akamai\netsession_win.exe |
"UDP Query User{322CFA43-E72C-45AA-83AE-2421C6925D2C}C:\program files\autodesk\maya2012\bin\maya.exe" = protocol=17 | dir=in | app=c:\program files\autodesk\maya2012\bin\maya.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{24aab420-4e30-4496-9739-3e216f3de6af}" = Python 2.6.2 (64-bit)
"{26A24AE4-039D-4CA4-87B4-2F86416024FF}" = Java™ 6 Update 24 (64-bit)
"{4529F749-C362-4119-AFA0-0A3F1CA924AB}" = Autodesk MatchMover 2012 64-bit
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}" = Roxio File Backup
"{6151cf20-0bd8-4023-a4a0-6a86dcfe58e6}" = Python 2.6.6 (64-bit)
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}" = Dell Edoc Viewer
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{90BF0360-A1DB-4599-A643-95AB90A52C1E}" = Microsoft_VC90_MFCLOC_x86_x64
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9D6DFAD6-09E5-445E-A4B5-A388FEEBD90D}" = RBVirtualFolder64Inst
"{9E6BB4E4-0B20-4922-AA37-260FA5ACFBA5}" = Autodesk Maya 2012 64-bit
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{A597FB4B-9113-4E22-8726-EDFAB0C67E9C}" = Maya 2012 Bonus Tools (64-bit)
"{AC3E3746-8F18-4F8A-9521-1493022C6E0A}" = Autodesk DirectConnect 2012 64-bit
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{EA234BC3-39FE-4734-B72F-076086889F6D}" = Composite 2012 64-bit
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FBBC4667-2521-4E78-B1BD-8706F774549B}" = Best Buy pc app
"{FC4AD39F-9DCE-4BD0-B7D0-7C81CEB9F04B}" = NVIDIA PhysX Plug-in for Autodesk Maya 2012 64 bit
"Autodesk DirectConnect 2012 64-bit" = Autodesk DirectConnect 2012 64-bit
"Autodesk Maya 2012 64-bit" = Autodesk Maya 2012 64-bit
"Blender" = Blender
"CNXT_AUDIO_HDA" = Conexant HD Audio
"Connectify" = Connectify
"Houdini 12.1.185" = Houdini 12.1.185
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"UDK-7b9bb08d-8771-4752-ad79-485cc4e16fde" = Unreal Development Kit: 2012-10

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{0ED7EE95-6A97-47AA-AD73-152C08A15B04}" = Dell DataSafe Local Backup
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java™ 6 Update 31
"{28E82311-8616-11E1-BEB0-B8AC6F97B88E}" = Google Earth
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2A0F2CC5-3065-492C-8380-B03AA7106B1A}" = Dell Product Registration
"{2E497885-E60B-420A-832D-0148B392E058}_is1" = Qwiklinx
"{3250260C-7A95-4632-893B-89657EB5545B}" = PhotoShowExpress
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3521BDBD-D453-5D9F-AA55-44B75D214629}" = Adobe Community Help
"{3D347E6D-5A03-4342-B5BA-6A771885F379}" = Autodesk Backburner 2012.0.0
"{44EF9917-8C1B-43D0-9A1F-D5DE5F363795}" = Adobe Setup
"{468D22C0-8080-11E2-B86E-B8AC6F98CCE3}" = Google Earth
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5A06423A-210C-49FB-950E-CB0EB8C5CEC7}" = Roxio BackOnTrack
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{63E29D1A-D6B5-4295-BFAC-967606232411}_is1" = Cartwheel Shopping
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}" = Roxio Creator Starter
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7746BFAA-2B5D-4FFD-A0E8-4558F4668105}" = Roxio Burn
"{779D8CA1-03DD-4AD4-B21F-3E20BFE7BEDE}" = SketchUp 8
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0409-1000-0000000FF1CE}_Office14.SingleImage_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.SingleImage_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0116-0409-1000-0000000FF1CE}_Office14.SingleImage_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{9158FF30-78D7-40EF-B83E-451AC5334640}" = Adobe Photoshop CS5.1
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9A00EC4E-27E1-42C4-98DD-662F32AC8870}" = Sonic CinePlayer Decoder Pack
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A121EEDE-C68F-461D-91AA-D48BA226AF1C}" = Roxio Activation Module
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9668246-FB70-4103-A1E3-66C9BC2EFB49}" = Dell DataSafe Local Backup - Support Software
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-FFFF-7B44-AA0000000001}" = Adobe Reader X (10.1.7) MUI
"{AF9E97C1-7431-426D-A8D5-ABE40995C0B1}" = DirectX 9 Runtime
"{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}" = Dell VideoStage
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E4335E82-17B3-460F-9E70-39D9BC269DB3}" = Dell PhotoStage
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{EF56258E-0326-48C5-A86C-3BAC26FC15DF}" = Roxio Creator Starter
"{F06B5C4C-8D2E-4B24-9D43-7A45EEC6C878}" = Roxio Creator Starter
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Processor Graphics
"{F336F89D-8C5A-432C-8EA9-DA19377AD591}" = Dell MusicStage
"{F62FA646-0693-43D2-9B48-E58B8635FB55}" = Adobe Director 11.5
"{FACF1CAE-8996-4FA9-BE83-654B312E59C4}" = Autodesk Maya 2012 English Documentation
"{FBBC4667-2521-4E78-B1BD-8706F774549B}" = Best Buy pc app
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FE182796-F6BA-486A-8590-89B7E8D1D60F}" = Dell Stage
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Adobe_46f17ca4f5daa9524ac09ba8d50e980" = Adobe Director 11.5
"Audacity_is1" = Audacity 2.0.3
"Blender" = Blender (remove only)
"CamStudio" = CamStudio
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"CityEngine TRIAL" = Esri CityEngine TRIAL 2011
"DefaultTab" = DefaultTab
"DMX5_is1" = DriverMax 6
"EarthSculptor_is1" = EarthSculptor 1.11
"ESET Online Scanner" = ESET Online Scanner v3
"FFmpeg for Audacity on Windows_is1" = FFmpeg for Audacity on Windows
"Google Chrome" = Google Chrome
"HiDef Media Player" = HiDef Media Player 1.1.12
"InstallShield_{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}" = Dell VideoStage
"InternetHelper3 Toolbar" = InternetHelper3 Toolbar
"N360" = Norton 360
"Notepad++" = Notepad++
"Office14.SingleImage" = Microsoft Office Home and Student 2010
"OSM" = JOSM 5608
"PdaNet_is1" = PdaNet for Android 3.02
"SearchProtect" = Search Protect by conduit
"sl-cb" = SelectionLinks
"Unity" = Unity
"vfd-adk" = VideoFileDownload
"VLC media player" = VLC media player 2.0.1
"WinGimp-2.0_is1" = GIMP 2.6.10
"WinLiveSuite" = Windows Live Essentials
"Zwei-Stein_is1" = Zwei-Stein Video Compositor 3.01 (Beta 2).

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"9204f5692a8faf3b" = Dell System Detect
"bd4d3a0508d364f5" = Dell Driver Download Manager

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 5/26/2013 6:55:35 AM | Computer Name = BigPapa-PC | Source = Application Error | ID = 1000
Description = Faulting application name: DefaultTabSearch.exe, version: 0.0.0.0,
time stamp: 0x511246e7 Faulting module name: unknown, version: 0.0.0.0, time stamp:
0x00000000 Exception code: 0xc0000005 Fault offset: 0x00000000 Faulting process id:
0x5cc Faulting application start time: 0x01ce55d0cf2e9e9e Faulting application path:
C:\Program Files (x86)\DefaultTab\DefaultTabSearch.exe Faulting module path: unknown
Report
Id: ca2fb580-c5f2-11e2-b981-f04da2f75aa5

Error - 5/26/2013 12:05:05 PM | Computer Name = BigPapa-PC | Source = Application Error | ID = 1000
Description = Faulting application name: kompozer.exe, version: 0.0.0.0, time stamp:
0x46d89a8a Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0x108b0845 Faulting process id: 0x2cd8 Faulting application
start time: 0x01ce5a17b85abf59 Faulting application path: C:\Program Files (x86)\kompozer-0.7.10-win32\KompoZer
0.7.10\kompozer.exe Faulting module path: unknown Report Id: 06fbf544-c61e-11e2-b981-f04da2f75aa5

Error - 5/26/2013 12:17:31 PM | Computer Name = BigPapa-PC | Source = Application Error | ID = 1000
Description = Faulting application name: kompozer.exe, version: 0.0.0.0, time stamp:
0x46d89a8a Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0xfffb288b Faulting process id: 0x39fc Faulting application
start time: 0x01ce5a2b0792d58f Faulting application path: C:\Program Files (x86)\kompozer-0.7.10-win32\KompoZer
0.7.10\kompozer.exe Faulting module path: unknown Report Id: c3894ba5-c61f-11e2-b981-f04da2f75aa5

Error - 5/26/2013 4:01:32 PM | Computer Name = BigPapa-PC | Source = Application Error | ID = 1000
Description = Faulting application name: kompozer.exe, version: 0.0.0.0, time stamp:
0x46d89a8a Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0x00000080 Faulting process id: 0x3994 Faulting application
start time: 0x01ce5a308c446526 Faulting application path: C:\Program Files (x86)\kompozer-0.7.10-win32\KompoZer
0.7.10\kompozer.exe Faulting module path: unknown Report Id: 0eecf36c-c63f-11e2-b981-f04da2f75aa5

Error - 5/27/2013 1:02:34 PM | Computer Name = BigPapa-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Program Files\Autodesk\Composite
2012\python\lib\distutils\command\wininst-8_d.exe". Dependent Assembly Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 5/27/2013 1:03:45 PM | Computer Name = BigPapa-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Python26\Lib\distutils\command\wininst-8_d.exe".
Dependent
Assembly Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 5/27/2013 1:05:35 PM | Computer Name = BigPapa-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "c:\program files (x86)\innovative
solutions\drivermax\DPInst\ia64\dpinst.exe". Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="ia64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 5/27/2013 1:05:36 PM | Computer Name = BigPapa-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "c:\program files (x86)\ESET\eset
online scanner\ESETSmartInstaller.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error - 5/27/2013 3:13:59 PM | Computer Name = BigPapa-PC | Source = Application Error | ID = 1000
Description = Faulting application name: DefaultTabSearch.exe, version: 0.0.0.0,
time stamp: 0x511246e7 Faulting module name: DefaultTabSearch.exe, version: 0.0.0.0,
time stamp: 0x511246e7 Exception code: 0xc0000005 Fault offset: 0x00002c60 Faulting
process id: 0x5f0 Faulting application start time: 0x01ce5b0e4c32f4f8 Faulting application
path: C:\Program Files (x86)\DefaultTab\DefaultTabSearch.exe Faulting module path:
C:\Program Files (x86)\DefaultTab\DefaultTabSearch.exe Report Id: 94e845af-c701-11e2-b9a8-f04da2f75aa5

Error - 5/27/2013 3:14:33 PM | Computer Name = BigPapa-PC | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 5/27/2013 9:18:01 AM | Computer Name = BigPapa-PC | Source = ipnathlp | ID = 31004
Description =

Error - 5/27/2013 9:18:03 AM | Computer Name = BigPapa-PC | Source = ipnathlp | ID = 31004
Description =

Error - 5/27/2013 3:13:26 PM | Computer Name = BigPapa-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 3:11:35 PM on ?5/?27/?2013 was unexpected.

Error - 5/27/2013 3:13:35 PM | Computer Name = BigPapa-PC | Source = BugCheck | ID = 1001
Description =

Error - 5/27/2013 3:14:03 PM | Computer Name = BigPapa-PC | Source = Service Control Manager | ID = 7034
Description = The DefaultTabSearch service terminated unexpectedly. It has done
this 1 time(s).

Error - 5/27/2013 3:14:21 PM | Computer Name = BigPapa-PC | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the SftService service.

Error - 5/27/2013 3:14:51 PM | Computer Name = BigPapa-PC | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the SftService service.

Error - 5/27/2013 3:14:51 PM | Computer Name = BigPapa-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Windows
Presentation Foundation Font Cache 3.0.0.0 service to connect.

Error - 5/27/2013 3:14:51 PM | Computer Name = BigPapa-PC | Source = Service Control Manager | ID = 7000
Description = The Windows Presentation Foundation Font Cache 3.0.0.0 service failed
to start due to the following error: %%1053

Error - 5/27/2013 3:15:24 PM | Computer Name = BigPapa-PC | Source = ipnathlp | ID = 31004
Description =


< End of report >
Hi BnTheMan,

1. Uninstall via Programs and Features

Click Start > Control Panel > Programs and Features. Locate and select the following that are present on the list and click the Remove button:
  • DefaultTab
  • SearchProtect
=========================

2. Run OTL.exe

Windows Vista and Windows 7 users Right Click and select "Run as Administrator"
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    PRC - C:\Users\BigPapa\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe ()
    PRC - C:\Users\BigPapa\AppData\Roaming\SearchProtect\bin\cltmng.exe (Conduit)
    PRC - C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe (Conduit)
    IE - HKCU\..\SearchScopes\{546E4570-96CF-443B-81D9-53CD7F0FAB65}: "URL" = http://search.conduit.com/Results.aspx?cti…q={searchTerms}
    IE - HKCU\..\SearchScopes\{82B1E5B2-DCEA-484D-8E90-40FAD5BF7F01}: "URL" = http://search.conduit.com/ResultsExt.aspx?…332582&UM=2
    CHR - Extension: DefaultTab = C:\Users\BigPapa\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc\1.1.19_0\
    O2 - BHO: (Qwiklinx) - {3E7C8B5A-96AB-438F-BF9B-782400655440} - C:\Users\BigPapa\AppData\Roaming\Qwiklinx\Qwiklinx.dll (Qwiklinx, Inc.)
    O2 - BHO: (DefaultTab Browser Helper) - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Users\BigPapa\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll (Search Results LLC.)
    O2 - BHO: (Cartwheel) - {B50DF051-E1D4-439C-B94E-F4DE82B56542} - C:\Users\BigPapa\AppData\Roaming\Cartwheel\Cartwheel.dll (Cartwheel, Inc.)
    O2 - BHO: (InternetHelper3 Toolbar) - {b920380d-fbe7-45c7-96ab-37e9870a566c} - C:\Program Files (x86)\InternetHelper3\prxtbInte.dll (Conduit Ltd.)
    O3 - HKCU\..\Toolbar\WebBrowser: (InternetHelper3 Toolbar) - {B920380D-FBE7-45C7-96AB-37E9870A566C} - C:\Program Files (x86)\InternetHelper3\prxtbInte.dll (Conduit Ltd.)
    O4 - HKLM..\Run: [SearchProtectAll] C:\Program Files (x86)\SearchProtect\bin\cltmng.exe (Conduit)
    O4 - HKCU..\Run: [SearchProtect] C:\Users\BigPapa\AppData\Roaming\SearchProtect\bin\cltmng.exe (Conduit)
    O15 - HKCU\..Trusted Domains: dell.com ([]* in Trusted sites)
    [2013/05/13 23:45:48 | 000,000,000 | —D | C] – C:\SearchProtect
    @Alternate Data Stream - 996 bytes -> C:\Users\BigPapa\AppData\Local\Temp:AOXaBQJ7tscq6Z15fNQRYx9gFQOe
    @Alternate Data Stream - 1040 bytes -> C:\Users\BigPapa\AppData\Local\Temp:gbs3uYUkwcTpnTPBE
    
    :Files
    C:\Users\BigPapa\AppData\Roaming\DefaultTab
    
    :Services
    DefaultTabUpdate
    
    
    :Commands
    [purity]
    [createrestorepoint]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
=========================

3. AdwCleaner

Download AdwCleaner to your desktop.

Right click and select "Run as Administrator".
  • Run AdwCleaner and select Delete
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply
=========================

1. Re-run OTL (it should be located on your desktop).

Windows Vista and Windows 7 & 8 users Right Click and select "Run as Administrator" on the icon to run it.
  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Uncheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open one notepad window. OTL.Txt. (No Extras.txt will be produced)
    Note:The log can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of the file, and post it with your next reply.
=========================

In your next post please provide the following:
  • AdwCleraner[S1].txt
  • Fresh OTL.txt
  • Hows the computer running?
did what you said
but atleast with the ads, I am still getting them
I attached an image to show you


# AdwCleaner v2.301 - Logfile created 05/27/2013 at 20:16:10
# Updated 16/05/2013 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : BigPapa - BIGPAPA-PC
# Boot Mode : Normal
# Running from : C:\Users\BigPapa\Downloads\AdwCleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

File Deleted : C:\END
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\InternetHelper3
Folder Deleted : C:\Program Files (x86)\OApps
Folder Deleted : C:\Program Files (x86)\Qwiklinx
Folder Deleted : C:\ProgramData\boost_interprocess
Folder Deleted : C:\Users\BigPapa\AppData\Local\Conduit
Folder Deleted : C:\Users\BigPapa\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\BigPapa\AppData\LocalLow\InternetHelper3
Folder Deleted : C:\Users\BigPapa\AppData\Roaming\Qwiklinx

***** [Registry] *****

Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\InternetHelper3
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B920380D-FBE7-45C7-96AB-37E9870A566C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B920380D-FBE7-45C7-96AB-37E9870A566C}
Key Deleted : HKCU\Software\Qwiklinx
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
Key Deleted : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
Key Deleted : HKLM\SOFTWARE\Classes\QwiklinxBHO
Key Deleted : HKLM\SOFTWARE\Classes\QwiklinxBHO.1
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3277370
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{204C0025-C26A-43E2-853C-D8A8EB1BCE51}
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\InternetHelper3
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6F89054E-27B3-45BB-A3D6-E26D00838F00}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{6F89054E-27B3-45BB-A3D6-E26D00838F00}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E2C1A522-B8E1-45D1-B316-F5625004A28C}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6E84ACAA-78F4-4A89-B629-CD990A61810B}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EE93EAF9-32AF-4D58-8F16-F0C9B8D0A3CC}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2E497885-E60B-420A-832D-0148B392E058}_is1
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\InternetHelper3 Toolbar
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E2C1A522-B8E1-45D1-B316-F5625004A28C}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{B920380D-FBE7-45C7-96AB-37E9870A566C}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{B920380D-FBE7-45C7-96AB-37E9870A566C}]
Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{B920380D-FBE7-45C7-96AB-37E9870A566C}]

***** [Internet Browsers] *****

-\\ Internet Explorer v10.0.9200.16576

[OK] Registry is clean.

-\\ Google Chrome v27.0.1453.94

File : C:\Users\BigPapa\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[S1].txt - [5100 octets] - [09/02/2013 09:42:01]
AdwCleaner[S2].txt - [3901 octets] - [27/05/2013 20:16:10]

########## EOF - C:\AdwCleaner[S2].txt - [3961 octets] ##########


OTL logfile created on: 5/27/2013 8:30:10 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\BigPapa\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16576)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.91 Gb Total Physical Memory | 2.01 Gb Available Physical Memory | 51.37% Memory free
7.83 Gb Paging File | 5.44 Gb Available in Paging File | 69.47% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 919.22 Gb Total Space | 828.69 Gb Free Space | 90.15% Space Free | Partition Type: NTFS

Computer Name: BIGPAPA-PC | User Name: BigPapa | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\BigPapa\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Innovative Solutions\DriverMax\drivermax.exe (Innovative Solutions)
PRC - C:\Program Files (x86)\Norton 360\Engine\20.3.1.22\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe ()
PRC - C:\Program Files (x86)\Dell Stage\Dell Stage\stage_secondary.exe ()
PRC - C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe ()
PRC - C:\Program Files (x86)\Connectify\Connectify.exe (Connectify)
PRC - C:\Program Files (x86)\Connectify\Connectifyd.exe (Connectify)
PRC - C:\Program Files (x86)\Connectify\ConnectifyService.exe ()
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe (SoftThinks - Dell)
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe ()
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (SoftThinks SAS)
PRC - C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe ()
PRC - C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\ppgooglenaclpluginchrome.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\PepperFlash\pepflashplayer.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\pdf.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\libglesv2.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\libegl.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\ffmpegsumo.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\1e8f7367eaa08c5057d78c093982f8f0\System.IdentityModel.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\e698a866fd16973a24ca6697218028ad\System.ServiceModel.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\3c2ed368e1f3889997dfb42a5ca77284\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\af525b4bec3b9941b7be8ffbf813da80\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\30e3a21202000677d0a9270572251477\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\7eac0dbe9aa20b55e37235f8ee030e6b\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\716959df79685a1eae0fc14275a32b0f\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\764f15e86c82662e977bd418bd6318c1\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\23673bbebe3c0ca7c894e614bb3ffd1a\System.Security.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\5ecf01964c70e453d71e5d7653912ff9\System.Web.ni.dll ()
MOD - C:\Program Files (x86)\Innovative Solutions\DriverMax\sync.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\1e04a5319c58010e945220af2751d34e\System.ServiceModel.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\2ad51da1b752b19c992fcefd56eb7c01\System.Runtime.Serialization.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\eb33bf977e97e97b12e82c18e36fbaee\SMDiagnostics.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\d7d20811a7ce7cc589153648cbb1ce5c\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\90b89f6e8032310e9ac72a309fd49e83\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Norton 360\Engine\20.3.1.22\wincfi39.dll ()
MOD - C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe ()
MOD - C:\Program Files (x86)\Dell Stage\Dell Stage\stage_secondary.exe ()
MOD - C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe ()
MOD - C:\Program Files (x86)\Dell Stage\Dell Stage\QtGui4.dll ()
MOD - C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\QtGui4.dll ()
MOD - C:\Program Files (x86)\Dell Stage\Dell Stage\QtCore4.dll ()
MOD - C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\QtCore4.dll ()
MOD - C:\Program Files (x86)\Connectify\Scannify.dll ()
MOD - C:\Program Files (x86)\Connectify\DriverLib.dll ()
MOD - C:\Program Files (x86)\Connectify\BuildProps.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe ()
MOD - C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe ()
MOD - C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\zlib1.dll ()
MOD - c:\Program Files (x86)\Common Files\Roxio Shared\DLLShared\SQLite352.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.WorkflowServices\3.5.0.0__31bf3856ad364e35\System.WorkflowServices.dll ()
MOD - C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()


========== Services (SafeList) ==========

SRV:64bit: - (HoudiniServer) – C:\WINDOWS\SysNative\hserver.exe (Side Effects Software Inc.)
SRV:64bit: - (FLEXnet Licensing Service 64) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe (Flexera Software, Inc.)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (N360) – C:\Program Files (x86)\Norton 360\Engine\20.3.1.22\ccSvcHst.exe (Symantec Corporation)
SRV - (cphs) – C:\WINDOWS\SysWOW64\IntelCpHeciSvc.exe (Intel Corporation)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (Connectify) – C:\Program Files (x86)\Connectify\ConnectifyService.exe ()
SRV - (SftService) – C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (SoftThinks SAS)
SRV - (RoxWatch12) – C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe (Sonic Solutions)
SRV - (RoxMediaDB12OEM) – C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe (Sonic Solutions)
SRV - (clr_optimization_v4.0.30319_32) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SwitchBoard) – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (clr_optimization_v2.0.50727_32) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (SymEvent) – C:\WINDOWS\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (SymNetS) – C:\WINDOWS\SysNative\drivers\N360x64\1403010.016\symnets.sys (Symantec Corporation)
DRV:64bit: - (SymEFA) – C:\WINDOWS\SysNative\drivers\N360x64\1403010.016\SymEFA64.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\WINDOWS\SysNative\drivers\N360x64\1403010.016\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) – C:\WINDOWS\SysNative\drivers\N360x64\1403010.016\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (SymDS) – C:\WINDOWS\SysNative\drivers\N360x64\1403010.016\SymDS64.sys (Symantec Corporation)
DRV:64bit: - (igfx) – C:\WINDOWS\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (SymIRON) – C:\WINDOWS\SysNative\drivers\N360x64\1403010.016\Ironx64.sys (Symantec Corporation)
DRV:64bit: - (ccSet_N360) – C:\WINDOWS\SysNative\drivers\N360x64\1403010.016\ccSetx64.sys (Symantec Corporation)
DRV:64bit: - (RdpVideoMiniport) – C:\WINDOWS\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbGD) – C:\WINDOWS\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\WINDOWS\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (cnnctfy2) – C:\WINDOWS\SysNative\drivers\cnnctfy2.sys (Connectify)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (RTL8167) – C:\WINDOWS\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (amdsata) – C:\WINDOWS\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\WINDOWS\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (CnxtHdAudService) – C:\WINDOWS\SysNative\drivers\CHDRT64.sys (Conexant Systems Inc.)
DRV:64bit: - (RMCAST) – C:\WINDOWS\SysNative\drivers\rmcast.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\WINDOWS\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (athr) – C:\WINDOWS\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (MEIx64) – C:\WINDOWS\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) – C:\WINDOWS\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (PxHlpa64) – C:\WINDOWS\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (androidusb) – C:\WINDOWS\SysNative\drivers\ssadadb.sys (Google Inc)
DRV:64bit: - (amdsbs) – C:\WINDOWS\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\WINDOWS\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\WINDOWS\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) – C:\WINDOWS\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\WINDOWS\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\WINDOWS\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\WINDOWS\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (WimFltr) – C:\WINDOWS\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\Definitions\VirusDefs\20130527.004\ex64.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\Definitions\VirusDefs\20130527.004\eng64.sys (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\Definitions\IPSDefs\20130524.001\IDSviA64.sys (Symantec Corporation)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\Definitions\BASHDefs\20130515.001\BHDrvx64.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (WIMMount) – C:\WINDOWS\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{49606DC7-976D-4030-A74E-9FB5C842FA68}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{49606DC7-976D-4030-A74E-9FB5C842FA68}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\..\SearchScopes\{E3F15D58-092E-47B8-AC12-4F1195C84251}: "URL" = http://www.google.com/search?q={searchTerm…1I7NDKB_enUS524
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@bestbuy.com/npBestBuyPcAppDetector,version=1.0: C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@bestbuy.com/npBestBuyPcAppDetector,version=1.0: C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll File not found
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\BigPapa\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\coFFPlgn\ [2013/05/27 20:21:05 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\IPSFFPlgn\ [2013/05/07 16:12:26 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - homepage: http://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 6 U31 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\BigPapa\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\BigPapa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\BigPapa\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Selection Links = C:\Users\BigPapa\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkmljcahgmhdlnhmnjiaakhkbbiapjkb\4.3_0\
CHR - Extension: Norton Identity Protection = C:\Users\BigPapa\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.3.3.19_0\
CHR - Extension: Gmail = C:\Users\BigPapa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\WINDOWS\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\20.3.1.22\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\20.3.1.22\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\20.3.1.22\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [cAudioFilterAgent] C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe (Conexant Systems, Inc.)
O4:64bit: - HKLM..\Run: [DellStage] C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe ()
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\WINDOWS\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\WINDOWS\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe (Conexant Systems, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AccuWeatherWidget] C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Dell Registration] C:\Program Files (x86)\System Registration\prodreg.exe (Dell, Inc.)
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe (Sonic Solutions)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [Akamai NetSession Interface] "C:\Users\BigPapa\AppData\Local\Akamai\netsession_win.exe" File not found
O4 - HKCU..\Run: [Connectify] C:\Program Files (x86)\Connectify\Connectify.exe (Connectify)
O4 - HKCU..\Run: [DriverMax] C:\Program Files (x86)\Innovative Solutions\DriverMax\drivermax.exe (Innovative Solutions)
O4 - HKCU..\Run: [GoogleChromeAutoLaunch_89C113111C53352D1F68066DB33BEBDD] C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
O4 - HKLM..\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe (Softthinks)
O4 - HKCU..\RunOnce: [Application Restart #3] C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
O4 - Startup: C:\Users\BigPapa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PdaNet Desktop.lnk = C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} http://support.dell.com/systemprofiler/DellSystemLite.CAB (DellSystemLite.Scanner)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9E1B8B58-55FD-45BC-A6A9-7BD5334B4140}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\WINDOWS\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\WINDOWS\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/05/27 20:02:59 | 000,000,000 | —D | C] – C:\_OTL
[2013/05/27 16:08:49 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\BigPapa\Desktop\OTL.exe
[2013/05/25 10:38:28 | 000,000,000 | —D | C] – C:\Users\BigPapa\Desktop\Checking 4 Virus 5-25-2013
[2013/05/18 03:02:48 | 000,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/05/18 03:02:48 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/05/18 03:02:48 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/05/18 03:02:47 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/05/18 03:02:47 | 000,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/05/18 03:02:47 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/05/18 03:02:47 | 000,089,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/05/18 03:02:47 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/05/18 03:02:47 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/05/18 03:02:47 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/05/18 03:02:47 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/05/18 03:02:47 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/05/18 03:02:45 | 003,958,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/05/18 03:02:45 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/05/18 03:02:45 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/05/17 21:43:28 | 001,930,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\authui.dll
[2013/05/17 21:43:28 | 001,796,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\authui.dll
[2013/05/17 21:43:28 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\shdocvw.dll
[2013/05/17 21:43:28 | 000,111,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\consent.exe
[2013/05/17 19:31:24 | 000,265,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\dxgmms1.sys
[2013/05/17 19:31:24 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2013/05/17 19:22:21 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wwanprotdim.dll
[2013/05/11 08:47:19 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RdpGroupPolicyExtension.dll
[2013/05/11 08:47:19 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbRedirectionGroupPolicyExtension.dll
[2013/05/11 08:47:19 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbRedirectionGroupPolicyControl.exe
[2013/05/11 08:47:15 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\TsUsbGD.sys
[2013/05/11 08:47:15 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\rdpvideominiport.sys
[2013/05/11 08:47:14 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\TsUsbFlt.sys
[2013/05/11 08:47:11 | 000,192,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rdpendp_winip.dll
[2013/05/11 08:47:11 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tsgqec.dll
[2013/05/11 08:47:11 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbGDCoInstaller.dll
[2013/05/11 08:47:11 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tsgqec.dll
[2013/05/11 08:47:11 | 000,018,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wksprtPS.dll
[2013/05/11 08:47:11 | 000,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wksprtPS.dll
[2013/05/11 08:47:10 | 000,384,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wksprt.exe
[2013/05/11 08:47:10 | 000,322,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\aaclient.dll
[2013/05/11 08:47:10 | 000,269,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\aaclient.dll
[2013/05/11 08:47:10 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpudd.dll
[2013/05/11 08:47:10 | 000,228,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpendp_winip.dll
[2013/05/11 08:47:10 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TSWbPrxy.exe
[2013/05/11 08:47:10 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MsRdpWebAccess.dll
[2013/05/11 08:47:10 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MsRdpWebAccess.dll
[2013/05/11 08:47:09 | 001,123,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstsc.exe
[2013/05/11 08:47:09 | 001,048,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstsc.exe
[2013/05/11 08:47:08 | 003,174,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorets.dll
[2013/05/11 08:47:07 | 004,916,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstscax.dll
[2013/05/11 08:47:06 | 005,773,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstscax.dll
[2013/05/11 08:27:06 | 001,448,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lsasrv.dll
[2013/05/11 08:27:02 | 000,514,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qdvd.dll
[2013/05/11 08:27:02 | 000,366,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qdvd.dll
[2013/05/07 16:08:47 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360
[2013/04/30 21:00:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\FFmpeg for Audacity
[2013/04/30 15:57:16 | 000,000,000 | —D | C] – C:\Users\BigPapa\AppData\Roaming\Audacity
[2013/04/30 15:57:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Audacity
[2013/04/30 03:10:57 | 001,054,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2013/04/30 03:10:57 | 000,719,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmlmedia.dll
[2013/04/30 03:10:57 | 000,226,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\elshyph.dll
[2013/04/30 03:10:57 | 000,185,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\elshyph.dll
[2013/04/30 03:10:57 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2013/04/30 03:10:57 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2013/04/30 03:10:57 | 000,138,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2013/04/30 03:10:57 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2013/04/30 03:10:57 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/04/30 03:10:57 | 000,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2013/04/30 03:10:56 | 001,441,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/04/30 03:10:56 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2013/04/30 03:10:56 | 000,629,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2013/04/30 03:10:56 | 000,361,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2013/04/30 03:10:56 | 000,232,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/04/30 03:10:56 | 000,137,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/04/30 03:10:56 | 000,125,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2013/04/30 03:10:56 | 000,117,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2013/04/30 03:10:56 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2013/04/30 03:10:56 | 000,073,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2013/04/30 03:10:56 | 000,069,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2013/04/30 03:10:56 | 000,061,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2013/04/30 03:10:56 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2013/04/30 03:10:56 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2013/04/30 03:10:56 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2013/04/30 03:10:55 | 001,509,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/04/30 03:10:55 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2013/04/30 03:10:55 | 000,905,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmlmedia.dll
[2013/04/30 03:10:55 | 000,762,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2013/04/30 03:10:55 | 000,599,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2013/04/30 03:10:55 | 000,452,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2013/04/30 03:10:55 | 000,441,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2013/04/30 03:10:55 | 000,281,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2013/04/30 03:10:55 | 000,235,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/04/30 03:10:55 | 000,216,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2013/04/30 03:10:55 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2013/04/30 03:10:55 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/04/30 03:10:55 | 000,167,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[2013/04/30 03:10:55 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2013/04/30 03:10:55 | 000,144,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2013/04/30 03:10:55 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2013/04/30 03:10:55 | 000,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2013/04/30 03:10:55 | 000,102,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2013/04/30 03:10:55 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/04/30 03:10:55 | 000,092,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2013/04/30 03:10:55 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2013/04/30 03:10:55 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2013/04/30 03:10:55 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2013/04/30 03:10:55 | 000,051,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2013/04/30 03:10:55 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2013/04/30 03:10:55 | 000,027,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2013/04/30 03:10:55 | 000,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2013/04/30 03:10:55 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2013/04/30 03:06:08 | 003,928,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2013/04/30 03:06:08 | 002,776,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msmpeg2vdec.dll
[2013/04/30 03:06:08 | 002,565,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10warp.dll
[2013/04/30 03:06:08 | 002,284,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msmpeg2vdec.dll
[2013/04/30 03:06:08 | 001,887,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d11.dll
[2013/04/30 03:06:08 | 001,682,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2013/04/30 03:06:08 | 001,643,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2013/04/30 03:06:08 | 001,504,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d11.dll
[2013/04/30 03:06:08 | 001,424,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecs.dll
[2013/04/30 03:06:08 | 001,238,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10.dll
[2013/04/30 03:06:08 | 001,158,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2013/04/30 03:06:08 | 000,648,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10level9.dll
[2013/04/30 03:06:08 | 000,522,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2013/04/30 03:06:08 | 000,465,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMPhoto.dll
[2013/04/30 03:06:08 | 000,417,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMPhoto.dll
[2013/04/30 03:06:08 | 000,364,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2013/04/30 03:06:08 | 000,363,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxgi.dll
[2013/04/30 03:06:08 | 000,333,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1core.dll
[2013/04/30 03:06:08 | 000,296,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10core.dll
[2013/04/30 03:06:08 | 000,245,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecsExt.dll
[2013/04/30 03:06:08 | 000,221,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UIAnimation.dll
[2013/04/30 03:06:08 | 000,194,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2013/04/30 03:06:08 | 000,187,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UIAnimation.dll
[2013/04/30 03:06:08 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/04/30 03:06:08 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/04/30 03:06:08 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/04/30 03:06:08 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/04/30 03:06:08 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/04/30 03:06:08 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/04/30 03:06:08 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/04/30 03:06:08 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/04/30 03:06:08 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/04/30 03:06:08 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/04/30 03:06:08 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/04/30 03:06:08 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/04/30 03:06:08 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
[2013/04/30 03:06:08 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-version-l1-1-0.dll
[2013/04/30 03:06:08 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/04/30 03:06:08 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/04/30 03:06:08 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/04/30 03:06:08 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/04/29 22:48:24 | 000,000,000 | —D | C] – C:\VirtualDub-1.9.11
[2013/04/29 18:52:25 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thugs at Bay
[2013/04/29 18:51:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\Thugs at Bay
[2013/04/28 11:34:26 | 000,000,000 | —D | C] – C:\Users\BigPapa\AppData\Local\{9AC6A02F-2783-437B-8C28-D4B0CD91EFE9}
[2013/04/28 11:34:26 | 000,000,000 | —D | C] – C:\Users\BigPapa\AppData\Local\{068D4243-EC00-4741-B0A7-4353AC95E8B0}
[2013/04/28 09:40:00 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CamStudio
[2013/04/28 09:39:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\CamStudio
[2013/04/28 09:39:13 | 000,000,000 | —D | C] – C:\CamStudio

========== Files - Modified Within 30 Days ==========

[2013/05/27 20:28:03 | 000,001,456 | —- | M] () – C:\Users\BigPapa\AppData\Local\Adobe Save for Web 12.0 Prefs
[2013/05/27 20:26:00 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/05/27 20:25:21 | 000,021,296 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/05/27 20:25:21 | 000,021,296 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/05/27 20:18:15 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/05/27 20:17:43 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/05/27 20:17:31 | 3152,510,976 | -HS- | M] () – C:\hiberfil.sys
[2013/05/27 20:14:37 | 000,001,503 | —- | M] () – C:\Users\BigPapa\Desktop\AdwCleaner.exe - Shortcut.lnk
[2013/05/27 19:49:11 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/05/27 16:09:07 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\BigPapa\Desktop\OTL.exe
[2013/05/27 15:13:19 | 1637,965,791 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/05/25 17:02:25 | 000,000,876 | —- | M] () – C:\Users\BigPapa\.recently-used.xbel
[2013/05/24 07:24:04 | 000,778,834 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/05/24 07:24:04 | 000,660,068 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/05/24 07:24:04 | 000,120,996 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/05/23 16:37:30 | 000,002,185 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/05/18 03:57:58 | 000,002,021 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[2013/05/18 03:32:28 | 004,953,816 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/05/18 03:31:53 | 001,842,244 | —- | M] () – C:\Windows\SysNative\drivers\N360x64\1403010.016\Cat.DB
[2013/05/07 16:08:48 | 000,002,321 | —- | M] () – C:\Users\Public\Desktop\Norton 360.lnk
[2013/05/07 16:06:23 | 000,177,312 | —- | M] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2013/05/07 16:06:23 | 000,007,466 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2013/05/07 16:06:23 | 000,000,855 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2013/04/30 15:57:09 | 000,001,009 | —- | M] () – C:\Users\BigPapa\Desktop\Audacity.lnk
[2013/04/30 03:10:57 | 001,054,720 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2013/04/30 03:10:57 | 000,719,360 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmlmedia.dll
[2013/04/30 03:10:57 | 000,226,304 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\elshyph.dll
[2013/04/30 03:10:57 | 000,185,344 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\elshyph.dll
[2013/04/30 03:10:57 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2013/04/30 03:10:57 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2013/04/30 03:10:57 | 000,138,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2013/04/30 03:10:57 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2013/04/30 03:10:57 | 000,079,872 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/04/30 03:10:57 | 000,057,344 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2013/04/30 03:10:56 | 001,441,280 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/04/30 03:10:56 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2013/04/30 03:10:56 | 000,629,248 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2013/04/30 03:10:56 | 000,361,984 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2013/04/30 03:10:56 | 000,232,960 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/04/30 03:10:56 | 000,137,216 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/04/30 03:10:56 | 000,125,440 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2013/04/30 03:10:56 | 000,117,248 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2013/04/30 03:10:56 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2013/04/30 03:10:56 | 000,073,728 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2013/04/30 03:10:56 | 000,069,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2013/04/30 03:10:56 | 000,061,952 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2013/04/30 03:10:56 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2013/04/30 03:10:56 | 000,025,185 | —- | M] () – C:\Windows\SysWow64\ieuinit.inf
[2013/04/30 03:10:56 | 000,023,040 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2013/04/30 03:10:56 | 000,011,776 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2013/04/30 03:10:55 | 001,509,376 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/04/30 03:10:55 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2013/04/30 03:10:55 | 000,905,728 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmlmedia.dll
[2013/04/30 03:10:55 | 000,762,368 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2013/04/30 03:10:55 | 000,599,552 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2013/04/30 03:10:55 | 000,452,096 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2013/04/30 03:10:55 | 000,441,856 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2013/04/30 03:10:55 | 000,281,600 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2013/04/30 03:10:55 | 000,235,008 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/04/30 03:10:55 | 000,216,064 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2013/04/30 03:10:55 | 000,197,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2013/04/30 03:10:55 | 000,173,568 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/04/30 03:10:55 | 000,167,424 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[2013/04/30 03:10:55 | 000,149,504 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2013/04/30 03:10:55 | 000,144,896 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2013/04/30 03:10:55 | 000,136,192 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2013/04/30 03:10:55 | 000,135,680 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2013/04/30 03:10:55 | 000,102,912 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2013/04/30 03:10:55 | 000,097,280 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/04/30 03:10:55 | 000,092,160 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2013/04/30 03:10:55 | 000,081,408 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2013/04/30 03:10:55 | 000,077,312 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2013/04/30 03:10:55 | 000,062,976 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2013/04/30 03:10:55 | 000,051,200 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2013/04/30 03:10:55 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2013/04/30 03:10:55 | 000,027,648 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2013/04/30 03:10:55 | 000,025,185 | —- | M] () – C:\Windows\SysNative\ieuinit.inf
[2013/04/30 03:10:55 | 000,013,824 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2013/04/30 03:10:55 | 000,012,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2013/04/30 03:06:08 | 003,928,064 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2013/04/30 03:06:08 | 002,776,576 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msmpeg2vdec.dll
[2013/04/30 03:06:08 | 002,565,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10warp.dll
[2013/04/30 03:06:08 | 002,284,544 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msmpeg2vdec.dll
[2013/04/30 03:06:08 | 001,887,232 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d11.dll
[2013/04/30 03:06:08 | 001,682,432 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2013/04/30 03:06:08 | 001,643,520 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2013/04/30 03:06:08 | 001,504,768 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\d3d11.dll
[2013/04/30 03:06:08 | 001,424,384 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecs.dll
[2013/04/30 03:06:08 | 001,238,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10.dll
[2013/04/30 03:06:08 | 001,158,144 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2013/04/30 03:06:08 | 000,648,192 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10level9.dll
[2013/04/30 03:06:08 | 000,522,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2013/04/30 03:06:08 | 000,465,920 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\WMPhoto.dll
[2013/04/30 03:06:08 | 000,417,792 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\WMPhoto.dll
[2013/04/30 03:06:08 | 000,364,544 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2013/04/30 03:06:08 | 000,363,008 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxgi.dll
[2013/04/30 03:06:08 | 000,333,312 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1core.dll
[2013/04/30 03:06:08 | 000,296,960 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10core.dll
[2013/04/30 03:06:08 | 000,245,248 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecsExt.dll
[2013/04/30 03:06:08 | 000,221,184 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\UIAnimation.dll
[2013/04/30 03:06:08 | 000,194,560 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2013/04/30 03:06:08 | 000,187,392 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\UIAnimation.dll
[2013/04/30 03:06:08 | 000,010,752 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/04/30 03:06:08 | 000,010,752 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/04/30 03:06:08 | 000,009,728 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/04/30 03:06:08 | 000,009,728 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/04/30 03:06:08 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/04/30 03:06:08 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/04/30 03:06:08 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/04/30 03:06:08 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/04/30 03:06:08 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/04/30 03:06:08 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/04/30 03:06:08 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/04/30 03:06:08 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/04/30 03:06:08 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
[2013/04/30 03:06:08 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-version-l1-1-0.dll
[2013/04/30 03:06:08 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/04/30 03:06:08 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/04/30 03:06:08 | 000,002,560 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/04/30 03:06:08 | 000,002,560 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/04/29 18:52:21 | 000,001,184 | —- | M] () – C:\Users\BigPapa\Desktop\Zwei-Stein.lnk
[2013/04/29 18:29:31 | 003,413,519 | —- | M] () – C:\Users\BigPapa\Desktop\zweifull.exe
[2013/04/28 09:40:01 | 000,001,016 | —- | M] () – C:\Users\Public\Desktop\CamStudio.lnk
[2013/04/28 09:15:41 | 000,072,329 | —- | M] () – C:\Users\BigPapa\Documents\test_microphone2.wma

========== Files Created - No Company Name ==========

[2013/05/27 20:14:37 | 000,001,503 | —- | C] () – C:\Users\BigPapa\Desktop\AdwCleaner.exe - Shortcut.lnk
[2013/05/25 17:02:25 | 000,000,876 | —- | C] () – C:\Users\BigPapa\.recently-used.xbel
[2013/04/30 15:57:08 | 000,001,009 | —- | C] () – C:\Users\BigPapa\Desktop\Audacity.lnk
[2013/04/30 15:57:06 | 000,001,021 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
[2013/04/30 03:10:56 | 000,025,185 | —- | C] () – C:\Windows\SysWow64\ieuinit.inf
[2013/04/30 03:10:55 | 000,025,185 | —- | C] () – C:\Windows\SysNative\ieuinit.inf
[2013/04/29 22:48:24 | 000,073,728 | —- | C] ( ) – C:\Windows\System\vdremote.dll
[2013/04/29 22:48:24 | 000,065,536 | —- | C] ( ) – C:\Windows\System\vdsvrlnk.dll
[2013/04/29 18:52:17 | 000,001,184 | —- | C] () – C:\Users\BigPapa\Desktop\Zwei-Stein.lnk
[2013/04/29 18:26:19 | 003,413,519 | —- | C] () – C:\Users\BigPapa\Desktop\zweifull.exe
[2013/04/28 09:40:01 | 000,001,016 | —- | C] () – C:\Users\Public\Desktop\CamStudio.lnk
[2013/04/28 09:15:25 | 000,072,329 | —- | C] () – C:\Users\BigPapa\Documents\test_microphone2.wma
[2013/04/21 15:02:15 | 000,000,258 | RHS- | C] () – C:\Users\BigPapa\ntuser.pol
[2013/02/09 20:00:38 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/02/09 20:00:38 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/02/09 20:00:38 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/02/09 20:00:38 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/02/09 20:00:38 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/12/14 02:42:30 | 000,963,452 | —- | C] () – C:\Windows\SysWow64\igcodeckrng600.bin
[2012/12/14 02:42:30 | 000,064,512 | —- | C] () – C:\Windows\SysWow64\igdde32.dll
[2012/12/14 02:42:28 | 000,272,928 | —- | C] () – C:\Windows\SysWow64\igvpkrng600.bin
[2012/08/08 23:31:23 | 000,001,456 | —- | C] () – C:\Users\BigPapa\AppData\Local\Adobe Save for Web 12.0 Prefs
[2012/07/16 00:01:04 | 000,000,132 | —- | C] () – C:\Users\BigPapa\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2012/06/03 18:48:08 | 000,000,056 | —- | C] () – C:\ProgramData\ezsidmv.dat
[2012/04/19 01:58:28 | 000,000,132 | —- | C] () – C:\Users\BigPapa\AppData\Roaming\Adobe Targa Format CS5 Prefs
[2012/02/14 18:47:06 | 000,963,912 | —- | C] () – C:\Windows\SysWow64\igkrng600.bin
[2012/02/14 18:47:06 | 000,261,208 | —- | C] () – C:\Windows\SysWow64\igfcg600m.bin
[2011/06/21 16:18:08 | 000,145,804 | —- | C] () – C:\Windows\SysWow64\igcompkrng600.bin

========== ZeroAccess Check ==========

[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\WINDOWS\SysNative\shell32.dll – [2013/02/27 01:52:56 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/27 00:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\WINDOWS\SysNative\wbem\fastprox.dll – [2009/07/13 21:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 23:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\WINDOWS\SysNative\wbem\wbemess.dll – [2009/07/13 21:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

< End of report >
Hi BnTheMan,

Have you run ComboFix in the past? If so, delete the copy you have and download a fresh copy.

=========================

1. RogueKiller

Download to your desktop RogueKiller (by tigzy)

Right click and select "Run as Administrator"
  • Quit all programs
  • Wait until Prescan has finished …
  • Click on Scan, Do Not Fix Anything at this point.
  • Click the Report button, save the report to your desktop
=========================

2. ComboFix

Refer to the ComboFix User's Guide

  • Download ComboFix from the following location:

    Link

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.
    ———————————————————————————————
NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.

=========================

In your next post please provide the following:
  • RKreport[1].txt
  • Combofix.txt
I will actually need a little bit more time. The downloads took a little more time than usual, and by the time I had completed both scans it was 3AM. However I have both logs ready, so hopefully tonight will be an easier night and I can post my logs. I just wanted to keep you informed so that this thread does not close. Thanks for being patient and understanding.
So for once I actually was able to get home early. BTW I am not about the ad pop-ups but I still get the Flash redirect that points to a malicius file. So here are my reports from last night….


RogueKiller V8.5.4 _x64_ [Mar 18 2013] by Tigzy
mail : tigzyRKgmailcom
Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : BigPapa [Admin rights]
Mode : Scan – Date : 05/29/2013 00:36:13
| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 2 ¤¤¤
[HJPOL] HKLM\[…]\System : DisableRegistryTools (0) -> FOUND
[HJPOL] HKLM\[…]\Wow6432Node\System : DisableRegistryTools (0) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [NOT LOADED] ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
–> C:\Windows\system32\drivers\etc\hosts



¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: ST31000524AS ATA Device +++++
— User —
[MBR] c29b3b753579bc576ee4cac2e0ea2dee
[BSP] 2dd105e2d820589e1f67ea6df5630ae8 : Windows Vista MBR Code
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 39 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 81920 | Size: 12542 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 25767936 | Size: 941286 Mo
User = LL1 … OK!
User = LL2 … OK!

Finished : << RKreport[4]_S_05292013_02d0036.txt >>
RKreport[1]_S_02082013_02d1416.txt ; RKreport[2]_D_02082013_02d1417.txt ; RKreport[3]_SC_02082013_02d1419.txt ; RKreport[4]_S_05292013_02d0036.txt



ComboFix 13-05-29.01 - BigPapa 05/29/2013 3:16.2.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4009.2678 [GMT -4:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
AV: Norton 360 *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton 360 *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Public\sdelevURL.tmp
.
.
((((((((((((((((((((((((( Files Created from 2013-04-28 to 2013-05-29 )))))))))))))))))))))))))))))))
.
.
2013-05-29 07:21 . 2013-05-29 07:21 ——– d—–w- c:\users\User2\AppData\Local\temp
2013-05-29 07:21 . 2013-05-29 07:21 ——– d—–w- c:\users\RNeilen\AppData\Local\temp
2013-05-29 07:21 . 2013-05-29 07:21 ——– d—–w- c:\users\Public\AppData\Local\temp
2013-05-29 07:21 . 2013-05-29 07:21 ——– d—–w- c:\users\Default\AppData\Local\temp
2013-05-29 02:32 . 2013-05-29 02:32 ——– d—–w- c:\programdata\boost_interprocess
2013-05-28 00:02 . 2013-05-28 00:02 ——– d—–w- C:\_OTL
2013-05-18 01:43 . 2013-02-27 05:52 14172672 —-a-w- c:\windows\system32\shell32.dll
2013-05-18 01:43 . 2013-02-27 06:02 111448 —-a-w- c:\windows\system32\consent.exe
2013-05-18 01:43 . 2013-02-27 05:52 197120 —-a-w- c:\windows\system32\shdocvw.dll
2013-05-18 01:43 . 2013-02-27 05:48 1930752 —-a-w- c:\windows\system32\authui.dll
2013-05-18 01:43 . 2013-02-27 05:47 70144 —-a-w- c:\windows\system32\appinfo.dll
2013-05-18 01:43 . 2013-02-27 04:49 1796096 —-a-w- c:\windows\SysWow64\authui.dll
2013-05-17 23:31 . 2013-04-10 06:01 265064 —-a-w- c:\windows\system32\drivers\dxgmms1.sys
2013-05-17 23:31 . 2013-04-10 06:01 983400 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-05-17 23:31 . 2011-02-03 11:25 144384 —-a-w- c:\windows\system32\cdd.dll
2013-05-17 23:22 . 2013-03-19 05:53 48640 —-a-w- c:\windows\system32\wwanprotdim.dll
2013-05-17 23:22 . 2013-03-19 05:53 230400 —-a-w- c:\windows\system32\wwansvc.dll
2013-05-17 23:22 . 2013-04-10 03:30 3153920 —-a-w- c:\windows\system32\win32k.sys
2013-05-11 12:48 . 2013-05-18 07:07 75016696 —-a-w- c:\windows\system32\MRT.exe
2013-05-11 12:27 . 2012-08-24 18:13 154480 —-a-w- c:\windows\system32\drivers\ksecpkg.sys
2013-05-11 12:27 . 2012-08-24 18:09 458712 —-a-w- c:\windows\system32\drivers\cng.sys
2013-05-11 12:27 . 2012-08-24 18:05 340992 —-a-w- c:\windows\system32\schannel.dll
2013-05-11 12:27 . 2012-08-24 18:03 1448448 —-a-w- c:\windows\system32\lsasrv.dll
2013-05-11 12:27 . 2012-08-24 16:57 247808 —-a-w- c:\windows\SysWow64\schannel.dll
2013-05-11 12:27 . 2012-08-24 16:57 22016 —-a-w- c:\windows\SysWow64\secur32.dll
2013-05-11 12:27 . 2012-08-24 16:53 96768 —-a-w- c:\windows\SysWow64\sspicli.dll
2013-05-11 12:27 . 2012-05-04 11:00 366592 —-a-w- c:\windows\system32\qdvd.dll
2013-05-11 12:27 . 2012-05-04 09:59 514560 —-a-w- c:\windows\SysWow64\qdvd.dll
2013-05-07 20:05 . 2013-05-07 21:26 ——– d—–w- c:\windows\system32\drivers\N360x64\1403010.016
2013-05-01 01:00 . 2013-05-01 01:00 ——– d—–w- c:\program files (x86)\FFmpeg for Audacity
2013-04-30 19:57 . 2013-05-07 19:58 ——– d—–w- c:\users\BigPapa\AppData\Roaming\Audacity
2013-04-30 19:57 . 2013-04-30 19:57 ——– d—–w- c:\program files (x86)\Audacity
2013-04-30 07:06 . 2013-04-30 07:06 9728 —ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-04-30 02:48 . 2013-04-30 02:48 ——– d—–w- C:\VirtualDub-1.9.11
2013-04-30 02:48 . 2010-12-24 17:18 73728 —-a-w- c:\windows\system\vdremote.dll
2013-04-30 02:48 . 2010-12-24 17:17 65536 —-a-w- c:\windows\system\vdsvrlnk.dll
2013-04-29 22:51 . 2013-04-29 22:51 ——– d—–w- c:\program files (x86)\Thugs at Bay
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-05-07 20:06 . 2012-04-17 19:34 177312 —-a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS
2013-04-13 05:49 . 2013-05-18 01:17 135168 —-a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2013-04-13 05:49 . 2013-05-18 01:17 350208 —-a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2013-04-13 05:49 . 2013-05-18 01:17 308736 —-a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll
2013-04-13 05:49 . 2013-05-18 01:17 111104 —-a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll
2013-04-13 04:45 . 2013-05-18 01:17 474624 —-a-w- c:\windows\apppatch\AcSpecfc.dll
2013-04-13 04:45 . 2013-05-18 01:17 2176512 —-a-w- c:\windows\apppatch\AcGenral.dll
2013-04-12 14:45 . 2013-04-23 19:46 1656680 —-a-w- c:\windows\system32\drivers\ntfs.sys
2013-04-11 14:22 . 2011-06-11 06:58 770384 —-a-w- c:\windows\SysWow64\msvcr100.dll
2013-04-11 14:22 . 2011-06-11 06:58 421200 —-a-w- c:\windows\SysWow64\msvcp100.dll
2013-03-19 06:04 . 2013-04-11 02:37 5550424 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-03-19 05:46 . 2013-04-11 02:37 43520 —-a-w- c:\windows\system32\csrsrv.dll
2013-03-19 05:04 . 2013-04-11 02:37 3968856 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe
2013-03-19 05:04 . 2013-04-11 02:37 3913560 —-a-w- c:\windows\SysWow64\ntoskrnl.exe
2013-03-19 04:47 . 2013-04-11 02:37 6656 —-a-w- c:\windows\SysWow64\apisetschema.dll
2013-03-19 03:06 . 2013-04-11 02:37 112640 —-a-w- c:\windows\system32\smss.exe
2013-03-01 16:08 . 2012-04-12 05:59 71024 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-03-01 16:08 . 2012-04-12 05:59 691568 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Connectify"="c:\program files (x86)\Connectify\Connectify.exe" [2011-09-29 2967368]
"DriverMax"="c:\program files (x86)\Innovative Solutions\DriverMax\drivermax.exe" [2013-01-16 11325304]
"GoogleChromeAutoLaunch_89C113111C53352D1F68066DB33BEBDD"="c:\program files (x86)\Google\Chrome\Application\chrome.exe" [2013-05-23 825808]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2013-02-19 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Dell Registration"="c:\program files (x86)\System Registration\prodreg.exe" [2010-11-10 4144448]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2013-05-10 37960]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [2010-11-25 240112]
"Desktop Disc Tool"="c:\program files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" [2010-11-17 514544]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"AccuWeatherWidget"="c:\program files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" [2012-02-01 968048]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-11 421888]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\program files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe" [2011-08-01 165184]
.
c:\users\BigPapa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
PdaNet Desktop.lnk - c:\program files (x86)\PdaNet for Android\PdaNetPC.exe [2012-3-10 480880]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944]
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys [2010-01-06 36256]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-03-02 1431888]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]
R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656]
R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-05-28 1255736]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2010-03-19 55856]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360x64\1403010.016\SYMDS64.SYS [2013-01-22 493656]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360x64\1403010.016\SYMEFA64.SYS [2013-01-31 1139800]
S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\Definitions\BASHDefs\20130515.001\BHDrvx64.sys [2013-05-03 1390680]
S1 ccSet_N360;Norton 360 Settings Manager;c:\windows\system32\drivers\N360x64\1403010.016\ccSetx64.sys [2012-11-16 168096]
S1 cnnctfy2;Connectify LightWeight Filter;c:\windows\system32\DRIVERS\cnnctfy2.sys [2012-03-11 31344]
S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\Definitions\IPSDefs\20130528.001\IDSvia64.sys [2013-05-05 513184]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360x64\1403010.016\Ironx64.SYS [2012-11-16 224416]
S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\N360x64\1403010.016\SYMNETS.SYS [2013-01-31 432800]
S2 Connectify;Connectify;c:\program files (x86)\Connectify\ConnectifyService.exe [2011-09-29 69632]
S2 N360;Norton 360;c:\program files (x86)\Norton 360\Engine\20.3.1.22\ccSvcHst.exe [2012-12-24 144520]
S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2011-08-18 1692480]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-08-10 138912]
S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-15 317440]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-05-23 20:37 1165776 —-a-w- c:\program files (x86)\Google\Chrome\Application\27.0.1453.94\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-05-29 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-12 16:08]
.
2013-05-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-09-06 01:15]
.
2013-05-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-09-06 01:15]
.
.
——— X64 Entries ———–
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellStage"="c:\program files (x86)\Dell Stage\Dell Stage\stage_primary.exe" [2012-02-01 2195824]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608]
"SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2011-03-03 309376]
"cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2011-02-25 519296]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-12-14 172144]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-12-14 399984]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-12-14 441968]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService
FontCache
.
——- Supplementary Scan ——-
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride =
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.1
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKCU-Run-Akamai NetSession Interface - c:\users\BigPapa\AppData\Local\Akamai\netsession_win.exe
Wow6432Node-HKLM-Run- - (no file)
Wow6432Node-HKU-Default-Run-SearchProtect - \SearchProtect\bin\cltmng.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
AddRemove-Adobe Flash Player ActiveX - c:\windows\SysWOW64\Macromed\Flash\FlashUtil32_11_6_602_171_ActiveX.exe
AddRemove-sl-cb - c:\program files (x86)\OApps\sl-cb_uninstall.exe
AddRemove-vfd-adk - c:\program files (x86)\OApps\vfd-adk_uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\N360]
"ImagePath"="\"c:\program files (x86)\Norton 360\Engine\20.3.1.22\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files (x86)\Norton 360\Engine\20.3.1.22\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_171_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_171_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_171_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_171_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_171.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_171.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_171.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_171.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-05-29 03:24:10
ComboFix-quarantined-files.txt 2013-05-29 07:24
ComboFix2.txt 2013-02-10 00:13
.
Pre-Run: 888,155,869,184 bytes free
Post-Run: 887,844,446,208 bytes free
.
- - End Of File - - B9A7F6A28EEFE2A5CAF4C6AE82C48E54
Hi BnTheMan,

Please be sure to place these tools on the Desktop for them to run properly.

=========================

1. SystemLook

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Right click SystemLook.exe and select "Run as Administrator" to run it.
  • Copy the content of the following code-box into the main text-field:
    :dir
    C:\ProgramData\boost_interprocess
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

=========================

2. TDSSKiller

Please download TDSSKiller.zip
  • Extract it to your desktop
  • TDSSKiller.exe - Right click and select "Run as Administrator".
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
=========================

In your next post please provide the following:
  • SystemLook.txt
  • TDSSKiller log
this is starting to worry me. Do you see anything. Just even seeing some of the applications that are on my hard drive I do not even recall installing, yet tdskiller did not find anything???? However, if I do recall, RogueKiller did find 2 objects. should I kill it? here are my logs… SystemLook 30.07.11 by jpshortstuff Log created at 22:24 on 29/05/2013 by BigPapa Administrator - Elevation successful WARNING: SystemLook running under WOW64. Use SystemLook_x64 for accurate results. ========== dir ========== C:\ProgramData\boost_interprocess - Parameters: "(none)" —Files— None found. —Folders— 5FCC385BFA5BCE01 d—— [02:32 29/05/2013] -= EOF =- 22:32:19.0789 6828 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42 22:32:21.0369 6828 ============================================================ 22:32:21.0369 6828 Current date / time: 2013/05/29 22:32:21.0369 22:32:21.0369 6828 SystemInfo: 22:32:21.0369 6828 22:32:21.0369 6828 OS Version: 6.1.7601 ServicePack: 1.0 22:32:21.0369 6828 Product type: Workstation 22:32:21.0369 6828 ComputerName: BIGPAPA-PC 22:32:21.0369 6828 UserName: BigPapa 22:32:21.0369 6828 Windows directory: C:\Windows 22:32:21.0369 6828 System windows directory: C:\Windows 22:32:21.0369 6828 Running under WOW64 22:32:21.0369 6828 Processor architecture: Intel x64 22:32:21.0369 6828 Number of processors: 4 22:32:21.0369 6828 Page size: 0x1000 22:32:21.0369 6828 Boot type: Normal boot 22:32:21.0369 6828 ============================================================ 22:32:23.0407 6828 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 22:32:23.0424 6828 ============================================================ 22:32:23.0424 6828 \Device\Harddisk0\DR0: 22:32:23.0424 6828 MBR partitions: 22:32:23.0424 6828 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x14000, BlocksNum 0x187F000 22:32:23.0424 6828 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1893000, BlocksNum 0x72E73000 22:32:23.0424 6828 ============================================================ 22:32:23.0459 6828 C: <-> \Device\Harddisk0\DR0\Partition2 22:32:23.0459 6828 ============================================================ 22:32:23.0459 6828 Initialize success 22:32:23.0459 6828 ============================================================ 22:32:26.0669 6292 ============================================================ 22:32:26.0669 6292 Scan started 22:32:26.0669 6292 Mode: Manual; 22:32:26.0669 6292 ============================================================ 22:32:27.0367 6292 ================ Scan system memory ======================== 22:32:27.0367 6292 System memory - ok 22:32:27.0368 6292 ================ Scan services ============================= 22:32:27.0468 6292 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys 22:32:27.0471 6292 1394ohci - ok 22:32:27.0486 6292 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys 22:32:27.0491 6292 ACPI - ok 22:32:27.0499 6292 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 22:32:27.0500 6292 AcpiPmi - ok 22:32:27.0570 6292 [ ADDA5E1951B90D3D23C56D3CF0622ADC ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 22:32:27.0572 6292 AdobeARMservice - ok 22:32:27.0673 6292 [ 9942DC4CC265CDA00486504444EF521D ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 22:32:27.0676 6292 AdobeFlashPlayerUpdateSvc - ok 22:32:27.0704 6292 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys 22:32:27.0710 6292 adp94xx - ok 22:32:27.0736 6292 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\drivers\adpahci.sys 22:32:27.0741 6292 adpahci - ok 22:32:27.0753 6292 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\drivers\adpu320.sys 22:32:27.0756 6292 adpu320 - ok 22:32:27.0775 6292 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 22:32:27.0776 6292 AeLookupSvc - ok 22:32:27.0810 6292 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys 22:32:27.0814 6292 AFD - ok 22:32:27.0822 6292 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys 22:32:27.0824 6292 agp440 - ok 22:32:27.0831 6292 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe 22:32:27.0832 6292 ALG - ok 22:32:27.0841 6292 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys 22:32:27.0843 6292 aliide - ok 22:32:27.0855 6292 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys 22:32:27.0856 6292 amdide - ok 22:32:27.0867 6292 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys 22:32:27.0869 6292 AmdK8 - ok 22:32:27.0878 6292 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\drivers\amdppm.sys 22:32:27.0880 6292 AmdPPM - ok 22:32:27.0903 6292 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys 22:32:27.0905 6292 amdsata - ok 22:32:27.0910 6292 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\drivers\amdsbs.sys 22:32:27.0913 6292 amdsbs - ok 22:32:27.0922 6292 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys 22:32:27.0923 6292 amdxata - ok 22:32:27.0948 6292 [ 27466E519371C6FC3A39B1F7B8A297FC ] androidusb C:\Windows\system32\Drivers\ssadadb.sys 22:32:27.0950 6292 androidusb - ok 22:32:27.0962 6292 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys 22:32:27.0963 6292 AppID - ok 22:32:27.0970 6292 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll 22:32:27.0972 6292 AppIDSvc - ok 22:32:28.0006 6292 [ 9D2A2369AB4B08A4905FE72DB104498F ] Appinfo C:\Windows\System32\appinfo.dll 22:32:28.0009 6292 Appinfo - ok 22:32:28.0024 6292 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\drivers\arc.sys 22:32:28.0026 6292 arc - ok 22:32:28.0034 6292 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\drivers\arcsas.sys 22:32:28.0037 6292 arcsas - ok 22:32:28.0108 6292 [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe 22:32:28.0110 6292 aspnet_state - ok 22:32:28.0132 6292 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 22:32:28.0133 6292 AsyncMac - ok 22:32:28.0146 6292 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys 22:32:28.0146 6292 atapi - ok 22:32:28.0203 6292 [ 96ABF88241F90FF647E55C934C55C2F1 ] athr C:\Windows\system32\DRIVERS\athrx.sys 22:32:28.0256 6292 athr - ok 22:32:28.0278 6292 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 22:32:28.0282 6292 AudioEndpointBuilder - ok 22:32:28.0290 6292 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll 22:32:28.0293 6292 AudioSrv - ok 22:32:28.0313 6292 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll 22:32:28.0315 6292 AxInstSV - ok 22:32:28.0326 6292 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys 22:32:28.0331 6292 b06bdrv - ok 22:32:28.0352 6292 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys 22:32:28.0355 6292 b57nd60a - ok 22:32:28.0363 6292 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll 22:32:28.0365 6292 BDESVC - ok 22:32:28.0373 6292 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys 22:32:28.0375 6292 Beep - ok 22:32:28.0405 6292 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll 22:32:28.0412 6292 BFE - ok 22:32:28.0632 6292 [ 7B56A40EAAACF1867FF178501D3EA185 ] BHDrvx64 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\Definitions\BASHDefs\20130515.001\BHDrvx64.sys 22:32:28.0657 6292 BHDrvx64 - ok 22:32:28.0685 6292 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\system32\qmgr.dll 22:32:28.0693 6292 BITS - ok 22:32:28.0701 6292 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys 22:32:28.0702 6292 blbdrive - ok 22:32:28.0715 6292 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 22:32:28.0717 6292 bowser - ok 22:32:28.0724 6292 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys 22:32:28.0725 6292 BrFiltLo - ok 22:32:28.0730 6292 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys 22:32:28.0730 6292 BrFiltUp - ok 22:32:28.0737 6292 [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys 22:32:28.0739 6292 BridgeMP - ok 22:32:28.0770 6292 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll 22:32:28.0772 6292 Browser - ok 22:32:28.0788 6292 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys 22:32:28.0792 6292 Brserid - ok 22:32:28.0801 6292 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys 22:32:28.0803 6292 BrSerWdm - ok 22:32:28.0810 6292 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys 22:32:28.0812 6292 BrUsbMdm - ok 22:32:28.0816 6292 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys 22:32:28.0817 6292 BrUsbSer - ok 22:32:28.0833 6292 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys 22:32:28.0835 6292 BTHMODEM - ok 22:32:28.0850 6292 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll 22:32:28.0852 6292 bthserv - ok 22:32:28.0891 6292 catchme - ok 22:32:28.0967 6292 [ 248C952C82DF1E23775432774CBB20F1 ] ccSet_N360 C:\Windows\system32\drivers\N360x64\1403010.016\ccSetx64.sys 22:32:28.0969 6292 ccSet_N360 - ok 22:32:28.0980 6292 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 22:32:28.0982 6292 cdfs - ok 22:32:29.0001 6292 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys 22:32:29.0003 6292 cdrom - ok 22:32:29.0019 6292 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll 22:32:29.0022 6292 CertPropSvc - ok 22:32:29.0041 6292 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\drivers\circlass.sys 22:32:29.0043 6292 circlass - ok 22:32:29.0056 6292 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys 22:32:29.0060 6292 CLFS - ok 22:32:29.0100 6292 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 22:32:29.0102 6292 clr_optimization_v2.0.50727_32 - ok 22:32:29.0129 6292 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 22:32:29.0132 6292 clr_optimization_v2.0.50727_64 - ok 22:32:29.0169 6292 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 22:32:29.0172 6292 clr_optimization_v4.0.30319_32 - ok 22:32:29.0197 6292 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 22:32:29.0200 6292 clr_optimization_v4.0.30319_64 - ok 22:32:29.0214 6292 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\drivers\CmBatt.sys 22:32:29.0215 6292 CmBatt - ok 22:32:29.0229 6292 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys 22:32:29.0230 6292 cmdide - ok 22:32:29.0269 6292 [ AAFCB52FE0037207FB6FBEA070D25EFE ] CNG C:\Windows\system32\Drivers\cng.sys 22:32:29.0275 6292 CNG - ok 22:32:29.0306 6292 [ 040FF3B09F26926A3792E047DB0F47DD ] cnnctfy2 C:\Windows\system32\DRIVERS\cnnctfy2.sys 22:32:29.0308 6292 cnnctfy2 - ok 22:32:29.0349 6292 [ 5C855932E4DF00B1B6F5F6F57E82B6C5 ] CnxtHdAudService C:\Windows\system32\drivers\CHDRT64.sys 22:32:29.0375 6292 CnxtHdAudService - ok 22:32:29.0388 6292 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\drivers\compbatt.sys 22:32:29.0389 6292 Compbatt - ok 22:32:29.0399 6292 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys 22:32:29.0400 6292 CompositeBus - ok 22:32:29.0403 6292 COMSysApp - ok 22:32:29.0468 6292 [ 452D0996F0BBF20DD6C142662B748E37 ] Connectify C:\Program Files (x86)\Connectify\ConnectifyService.exe 22:32:29.0470 6292 Connectify - ok 22:32:29.0558 6292 [ 815F3180B5117E42E422188E9CCC89C6 ] cphs C:\Windows\SysWow64\IntelCpHeciSvc.exe 22:32:29.0562 6292 cphs - ok 22:32:29.0575 6292 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys 22:32:29.0576 6292 crcdisk - ok 22:32:29.0611 6292 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\Windows\system32\cryptsvc.dll 22:32:29.0612 6292 CryptSvc - ok 22:32:29.0643 6292 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll 22:32:29.0651 6292 DcomLaunch - ok 22:32:29.0681 6292 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll 22:32:29.0685 6292 defragsvc - ok 22:32:29.0693 6292 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys 22:32:29.0695 6292 DfsC - ok 22:32:29.0708 6292 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll 22:32:29.0728 6292 Dhcp - ok 22:32:29.0741 6292 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys 22:32:29.0742 6292 discache - ok 22:32:29.0763 6292 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\drivers\disk.sys 22:32:29.0765 6292 Disk - ok 22:32:29.0775 6292 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll 22:32:29.0778 6292 Dnscache - ok 22:32:29.0791 6292 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll 22:32:29.0795 6292 dot3svc - ok 22:32:29.0807 6292 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll 22:32:29.0809 6292 DPS - ok 22:32:29.0817 6292 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 22:32:29.0818 6292 drmkaud - ok 22:32:29.0861 6292 [ AF2E16242AA723F68F461B6EAE2EAD3D ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 22:32:29.0874 6292 DXGKrnl - ok 22:32:29.0905 6292 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll 22:32:29.0907 6292 EapHost - ok 22:32:29.0967 6292 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\drivers\evbda.sys 22:32:30.0008 6292 ebdrv - ok 22:32:30.0073 6292 [ 4353FF94D47A0A9D52B89ECCF0CDB013 ] eeCtrl C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys 22:32:30.0079 6292 eeCtrl - ok 22:32:30.0116 6292 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe 22:32:30.0118 6292 EFS - ok 22:32:30.0170 6292 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe 22:32:30.0179 6292 ehRecvr - ok 22:32:30.0193 6292 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe 22:32:30.0195 6292 ehSched - ok 22:32:30.0213 6292 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\drivers\elxstor.sys 22:32:30.0218 6292 elxstor - ok 22:32:30.0267 6292 [ C5BCCB378D0A896304A3E71BE7215983 ] EraserUtilRebootDrv C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 22:32:30.0269 6292 EraserUtilRebootDrv - ok 22:32:30.0280 6292 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys 22:32:30.0281 6292 ErrDev - ok 22:32:30.0298 6292 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll 22:32:30.0304 6292 EventSystem - ok 22:32:30.0316 6292 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys 22:32:30.0319 6292 exfat - ok 22:32:30.0332 6292 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys 22:32:30.0334 6292 fastfat - ok 22:32:30.0372 6292 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe 22:32:30.0381 6292 Fax - ok 22:32:30.0389 6292 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\drivers\fdc.sys 22:32:30.0391 6292 fdc - ok 22:32:30.0410 6292 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll 22:32:30.0411 6292 fdPHost - ok 22:32:30.0416 6292 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll 22:32:30.0417 6292 FDResPub - ok 22:32:30.0425 6292 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 22:32:30.0426 6292 FileInfo - ok 22:32:30.0431 6292 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 22:32:30.0432 6292 Filetrace - ok 22:32:30.0472 6292 [ 1F63900E2EB00101B9ACA2B7A870704E ] FLEXnet Licensing Service C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe 22:32:30.0481 6292 FLEXnet Licensing Service - ok 22:32:30.0559 6292 [ 5CEE6CD43AE5844C49300EA0B1E557EE ] FLEXnet Licensing Service 64 C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe 22:32:30.0585 6292 FLEXnet Licensing Service 64 - ok 22:32:30.0600 6292 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\drivers\flpydisk.sys 22:32:30.0601 6292 flpydisk - ok 22:32:30.0617 6292 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 22:32:30.0620 6292 FltMgr - ok 22:32:30.0673 6292 [ C4C183E6551084039EC862DA1C945E3D ] FontCache C:\Windows\system32\FntCache.dll 22:32:30.0698 6292 FontCache - ok 22:32:30.0733 6292 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 22:32:30.0735 6292 FontCache3.0.0.0 - ok 22:32:30.0749 6292 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 22:32:30.0751 6292 FsDepends - ok 22:32:30.0783 6292 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 22:32:30.0784 6292 Fs_Rec - ok 22:32:30.0824 6292 [ 8F6322049018354F45F05A2FD2D4E5E0 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 22:32:30.0827 6292 fvevol - ok 22:32:30.0847 6292 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys 22:32:30.0849 6292 gagp30kx - ok 22:32:30.0873 6292 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll 22:32:30.0884 6292 gpsvc - ok 22:32:30.0980 6292 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 22:32:30.0982 6292 gupdate - ok 22:32:30.0987 6292 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 22:32:30.0988 6292 gupdatem - ok 22:32:31.0037 6292 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe 22:32:31.0040 6292 gusvc - ok 22:32:31.0051 6292 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys 22:32:31.0052 6292 hcw85cir - ok 22:32:31.0063 6292 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys 22:32:31.0065 6292 HDAudBus - ok 22:32:31.0077 6292 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\drivers\HidBatt.sys 22:32:31.0078 6292 HidBatt - ok 22:32:31.0089 6292 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\drivers\hidbth.sys 22:32:31.0091 6292 HidBth - ok 22:32:31.0097 6292 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\drivers\hidir.sys 22:32:31.0098 6292 HidIr - ok 22:32:31.0107 6292 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\System32\hidserv.dll 22:32:31.0108 6292 hidserv - ok 22:32:31.0132 6292 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys 22:32:31.0133 6292 HidUsb - ok 22:32:31.0170 6292 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll 22:32:31.0172 6292 hkmsvc - ok 22:32:31.0183 6292 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll 22:32:31.0187 6292 HomeGroupListener - ok 22:32:31.0288 6292 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 22:32:31.0292 6292 HomeGroupProvider - ok 22:32:31.0369 6292 [ D7EBC37319C0A25C88CE477E7F814AAC ] HoudiniServer C:\Windows\system32\hserver.exe 22:32:31.0405 6292 HoudiniServer - ok 22:32:31.0414 6292 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 22:32:31.0415 6292 HpSAMD - ok 22:32:31.0453 6292 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys 22:32:31.0462 6292 HTTP - ok 22:32:31.0476 6292 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 22:32:31.0476 6292 hwpolicy - ok 22:32:31.0489 6292 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys 22:32:31.0490 6292 i8042prt - ok 22:32:31.0527 6292 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 22:32:31.0531 6292 iaStorV - ok 22:32:31.0577 6292 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 22:32:31.0588 6292 idsvc - ok 22:32:31.0789 6292 [ A48928D4CCA6F8B731989DB08CF2C0AB ] IDSVia64 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\Definitions\IPSDefs\20130528.001\IDSvia64.sys 22:32:31.0796 6292 IDSVia64 - ok 22:32:31.0900 6292 [ 348214F96642FD4FEF630DE021BA3540 ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys 22:32:31.0987 6292 igfx - ok 22:32:31.0997 6292 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\drivers\iirsp.sys 22:32:31.0998 6292 iirsp - ok 22:32:32.0023 6292 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll 22:32:32.0031 6292 IKEEXT - ok 22:32:32.0060 6292 [ FC727061C0F47C8059E88E05D5C8E381 ] IntcDAud C:\Windows\system32\DRIVERS\IntcDAud.sys 22:32:32.0063 6292 IntcDAud - ok 22:32:32.0074 6292 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys 22:32:32.0075 6292 intelide - ok 22:32:32.0082 6292 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 22:32:32.0083 6292 intelppm - ok 22:32:32.0095 6292 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll 22:32:32.0098 6292 IPBusEnum - ok 22:32:32.0106 6292 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 22:32:32.0108 6292 IpFilterDriver - ok 22:32:32.0138 6292 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 22:32:32.0146 6292 iphlpsvc - ok 22:32:32.0162 6292 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys 22:32:32.0164 6292 IPMIDRV - ok 22:32:32.0174 6292 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys 22:32:32.0176 6292 IPNAT - ok 22:32:32.0190 6292 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys 22:32:32.0191 6292 IRENUM - ok 22:32:32.0198 6292 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys 22:32:32.0199 6292 isapnp - ok 22:32:32.0216 6292 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys 22:32:32.0219 6292 iScsiPrt - ok 22:32:32.0234 6292 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys 22:32:32.0235 6292 kbdclass - ok 22:32:32.0254 6292 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys 22:32:32.0256 6292 kbdhid - ok 22:32:32.0264 6292 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe 22:32:32.0265 6292 KeyIso - ok 22:32:32.0303 6292 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 22:32:32.0305 6292 KSecDD - ok 22:32:32.0335 6292 [ 7EFB9333E4ECCE6AE4AE9D777D9E553E ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 22:32:32.0337 6292 KSecPkg - ok 22:32:32.0351 6292 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys 22:32:32.0353 6292 ksthunk - ok 22:32:32.0374 6292 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll 22:32:32.0380 6292 KtmRm - ok 22:32:32.0397 6292 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\System32\srvsvc.dll 22:32:32.0402 6292 LanmanServer - ok 22:32:32.0422 6292 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 22:32:32.0424 6292 LanmanWorkstation - ok 22:32:32.0449 6292 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 22:32:32.0451 6292 lltdio - ok 22:32:32.0467 6292 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll 22:32:32.0472 6292 lltdsvc - ok 22:32:32.0483 6292 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll 22:32:32.0486 6292 lmhosts - ok 22:32:32.0505 6292 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys 22:32:32.0507 6292 LSI_FC - ok 22:32:32.0515 6292 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys 22:32:32.0517 6292 LSI_SAS - ok 22:32:32.0528 6292 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys 22:32:32.0530 6292 LSI_SAS2 - ok 22:32:32.0537 6292 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys 22:32:32.0540 6292 LSI_SCSI - ok 22:32:32.0550 6292 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys 22:32:32.0552 6292 luafv - ok 22:32:32.0564 6292 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 22:32:32.0566 6292 Mcx2Svc - ok 22:32:32.0579 6292 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\drivers\megasas.sys 22:32:32.0580 6292 megasas - ok 22:32:32.0586 6292 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys 22:32:32.0589 6292 MegaSR - ok 22:32:32.0613 6292 [ A6518DCC42F7A6E999BB3BEA8FD87567 ] MEIx64 C:\Windows\system32\DRIVERS\HECIx64.sys 22:32:32.0614 6292 MEIx64 - ok 22:32:32.0639 6292 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll 22:32:32.0641 6292 MMCSS - ok 22:32:32.0653 6292 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys 22:32:32.0655 6292 Modem - ok 22:32:32.0690 6292 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys 22:32:32.0690 6292 monitor - ok 22:32:32.0700 6292 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys 22:32:32.0701 6292 mouclass - ok 22:32:32.0721 6292 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 22:32:32.0722 6292 mouhid - ok 22:32:32.0729 6292 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 22:32:32.0731 6292 mountmgr - ok 22:32:32.0743 6292 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys 22:32:32.0745 6292 mpio - ok 22:32:32.0751 6292 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 22:32:32.0752 6292 mpsdrv - ok 22:32:32.0777 6292 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll 22:32:32.0785 6292 MpsSvc - ok 22:32:32.0798 6292 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 22:32:32.0800 6292 MRxDAV - ok 22:32:32.0834 6292 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 22:32:32.0836 6292 mrxsmb - ok 22:32:32.0850 6292 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 22:32:32.0854 6292 mrxsmb10 - ok 22:32:32.0868 6292 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 22:32:32.0870 6292 mrxsmb20 - ok 22:32:32.0898 6292 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys 22:32:32.0899 6292 msahci - ok 22:32:32.0909 6292 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys 22:32:32.0912 6292 msdsm - ok 22:32:32.0923 6292 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe 22:32:32.0927 6292 MSDTC - ok 22:32:32.0943 6292 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys 22:32:32.0946 6292 Msfs - ok 22:32:32.0966 6292 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 22:32:32.0968 6292 mshidkmdf - ok 22:32:32.0974 6292 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 22:32:32.0975 6292 msisadrv - ok 22:32:33.0000 6292 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 22:32:33.0003 6292 MSiSCSI - ok 22:32:33.0007 6292 msiserver - ok 22:32:33.0026 6292 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 22:32:33.0028 6292 MSKSSRV - ok 22:32:33.0034 6292 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 22:32:33.0035 6292 MSPCLOCK - ok 22:32:33.0041 6292 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 22:32:33.0041 6292 MSPQM - ok 22:32:33.0057 6292 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 22:32:33.0061 6292 MsRPC - ok 22:32:33.0070 6292 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys 22:32:33.0071 6292 mssmbios - ok 22:32:33.0073 6292 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 22:32:33.0074 6292 MSTEE - ok 22:32:33.0083 6292 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\drivers\MTConfig.sys 22:32:33.0084 6292 MTConfig - ok 22:32:33.0093 6292 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys 22:32:33.0094 6292 Mup - ok 22:32:33.0177 6292 [ 241BD3019FB31E812A51B31B06906335 ] N360 C:\Program Files (x86)\Norton 360\Engine\20.3.1.22\ccSvcHst.exe 22:32:33.0178 6292 N360 - ok 22:32:33.0195 6292 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll 22:32:33.0202 6292 napagent - ok 22:32:33.0230 6292 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 22:32:33.0235 6292 NativeWifiP - ok 22:32:33.0292 6292 [ 56540E526B46E379A476FB5BC381B290 ] NAVENG C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\Definitions\VirusDefs\20130528.032\ENG64.SYS 22:32:33.0294 6292 NAVENG - ok 22:32:33.0338 6292 [ 8A19D3991F9F14B885CDE8BC640F6B68 ] NAVEX15 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\Definitions\VirusDefs\20130528.032\EX64.SYS 22:32:33.0381 6292 NAVEX15 - ok 22:32:33.0441 6292 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys 22:32:33.0453 6292 NDIS - ok 22:32:33.0470 6292 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 22:32:33.0472 6292 NdisCap - ok 22:32:33.0483 6292 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 22:32:33.0484 6292 NdisTapi - ok 22:32:33.0490 6292 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 22:32:33.0492 6292 Ndisuio - ok 22:32:33.0505 6292 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 22:32:33.0508 6292 NdisWan - ok 22:32:33.0521 6292 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 22:32:33.0522 6292 NDProxy - ok 22:32:33.0531 6292 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 22:32:33.0533 6292 NetBIOS - ok 22:32:33.0542 6292 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 22:32:33.0544 6292 NetBT - ok 22:32:33.0554 6292 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe 22:32:33.0555 6292 Netlogon - ok 22:32:33.0586 6292 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll 22:32:33.0592 6292 Netman - ok 22:32:33.0636 6292 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 22:32:33.0639 6292 NetMsmqActivator - ok 22:32:33.0644 6292 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 22:32:33.0645 6292 NetPipeActivator - ok 22:32:33.0664 6292 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll 22:32:33.0670 6292 netprofm - ok 22:32:33.0673 6292 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 22:32:33.0674 6292 NetTcpActivator - ok 22:32:33.0677 6292 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 22:32:33.0678 6292 NetTcpPortSharing - ok 22:32:33.0687 6292 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys 22:32:33.0688 6292 nfrd960 - ok 22:32:33.0724 6292 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll 22:32:33.0729 6292 NlaSvc - ok 22:32:33.0737 6292 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys 22:32:33.0738 6292 Npfs - ok 22:32:33.0747 6292 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll 22:32:33.0750 6292 nsi - ok 22:32:33.0760 6292 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 22:32:33.0760 6292 nsiproxy - ok 22:32:33.0811 6292 [ B98F8C6E31CD07B2E6F71F7F648E38C0 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 22:32:33.0846 6292 Ntfs - ok 22:32:33.0855 6292 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys 22:32:33.0856 6292 Null - ok 22:32:33.0893 6292 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys 22:32:33.0896 6292 nvraid - ok 22:32:33.0909 6292 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys 22:32:33.0912 6292 nvstor - ok 22:32:33.0930 6292 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 22:32:33.0932 6292 nv_agp - ok 22:32:33.0947 6292 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys 22:32:33.0949 6292 ohci1394 - ok 22:32:34.0010 6292 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE 22:32:34.0012 6292 ose - ok 22:32:34.0139 6292 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 22:32:34.0213 6292 osppsvc - ok 22:32:34.0232 6292 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 22:32:34.0236 6292 p2pimsvc - ok 22:32:34.0250 6292 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll 22:32:34.0255 6292 p2psvc - ok 22:32:34.0264 6292 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\drivers\parport.sys 22:32:34.0266 6292 Parport - ok 22:32:34.0298 6292 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys 22:32:34.0300 6292 partmgr - ok 22:32:34.0311 6292 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll 22:32:34.0315 6292 PcaSvc - ok 22:32:34.0330 6292 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys 22:32:34.0332 6292 pci - ok 22:32:34.0344 6292 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys 22:32:34.0345 6292 pciide - ok 22:32:34.0355 6292 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\drivers\pcmcia.sys 22:32:34.0357 6292 pcmcia - ok 22:32:34.0367 6292 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys 22:32:34.0368 6292 pcw - ok 22:32:34.0386 6292 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys 22:32:34.0393 6292 PEAUTH - ok 22:32:34.0450 6292 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe 22:32:34.0452 6292 PerfHost - ok 22:32:34.0487 6292 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll 22:32:34.0513 6292 pla - ok 22:32:34.0555 6292 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll 22:32:34.0560 6292 PlugPlay - ok 22:32:34.0568 6292 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 22:32:34.0570 6292 PNRPAutoReg - ok 22:32:34.0576 6292 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 22:32:34.0579 6292 PNRPsvc - ok 22:32:34.0604 6292 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 22:32:34.0608 6292 PolicyAgent - ok 22:32:34.0624 6292 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll 22:32:34.0627 6292 Power - ok 22:32:34.0650 6292 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 22:32:34.0652 6292 PptpMiniport - ok 22:32:34.0664 6292 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\drivers\processr.sys 22:32:34.0665 6292 Processor - ok 22:32:34.0704 6292 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll 22:32:34.0707 6292 ProfSvc - ok 22:32:34.0720 6292 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe 22:32:34.0722 6292 ProtectedStorage - ok 22:32:34.0743 6292 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys 22:32:34.0745 6292 Psched - ok 22:32:34.0771 6292 [ 87B04878A6D59D6C79251DC960C674C1 ] PxHlpa64 C:\Windows\system32\Drivers\PxHlpa64.sys 22:32:34.0773 6292 PxHlpa64 - ok 22:32:34.0806 6292 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\drivers\ql2300.sys 22:32:34.0828 6292 ql2300 - ok 22:32:34.0841 6292 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\drivers\ql40xx.sys 22:32:34.0843 6292 ql40xx - ok 22:32:34.0858 6292 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll 22:32:34.0862 6292 QWAVE - ok 22:32:34.0869 6292 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 22:32:34.0870 6292 QWAVEdrv - ok 22:32:34.0883 6292 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 22:32:34.0884 6292 RasAcd - ok 22:32:34.0911 6292 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 22:32:34.0913 6292 RasAgileVpn - ok 22:32:34.0923 6292 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll 22:32:34.0925 6292 RasAuto - ok 22:32:34.0938 6292 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 22:32:34.0940 6292 Rasl2tp - ok 22:32:34.0966 6292 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll 22:32:34.0972 6292 RasMan - ok 22:32:34.0984 6292 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 22:32:34.0987 6292 RasPppoe - ok 22:32:34.0996 6292 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 22:32:34.0998 6292 RasSstp - ok 22:32:35.0010 6292 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 22:32:35.0013 6292 rdbss - ok 22:32:35.0025 6292 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\drivers\rdpbus.sys 22:32:35.0026 6292 rdpbus - ok 22:32:35.0035 6292 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 22:32:35.0035 6292 RDPCDD - ok 22:32:35.0043 6292 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 22:32:35.0044 6292 RDPENCDD - ok 22:32:35.0053 6292 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys 22:32:35.0053 6292 RDPREFMP - ok 22:32:35.0109 6292 [ 313F68E1A3E6345A4F47A36B07062F34 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys 22:32:35.0110 6292 RdpVideoMiniport - ok 22:32:35.0151 6292 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 22:32:35.0155 6292 RDPWD - ok 22:32:35.0169 6292 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 22:32:35.0173 6292 rdyboost - ok 22:32:35.0190 6292 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll 22:32:35.0194 6292 RemoteAccess - ok 22:32:35.0208 6292 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll 22:32:35.0210 6292 RemoteRegistry - ok 22:32:35.0225 6292 [ CAF88D6573D21CD2AA27001DDBFDC74D ] RMCAST C:\Windows\system32\DRIVERS\RMCAST.sys 22:32:35.0227 6292 RMCAST - ok 22:32:35.0310 6292 [ 3C957189B31C34D3AD21967B12B6AED7 ] RoxMediaDB12OEM C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe 22:32:35.0337 6292 RoxMediaDB12OEM - ok 22:32:35.0353 6292 [ 2B73088CC2CA757A172B425C9398E5BC ] RoxWatch12 C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe 22:32:35.0356 6292 RoxWatch12 - ok 22:32:35.0365 6292 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 22:32:35.0367 6292 RpcEptMapper - ok 22:32:35.0386 6292 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe 22:32:35.0388 6292 RpcLocator - ok 22:32:35.0402 6292 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\System32\rpcss.dll 22:32:35.0405 6292 RpcSs - ok 22:32:35.0411 6292 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 22:32:35.0413 6292 rspndr - ok 22:32:35.0443 6292 [ EE082E06A82FF630351D1E0EBBD3D8D0 ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys 22:32:35.0450 6292 RTL8167 - ok 22:32:35.0461 6292 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe 22:32:35.0462 6292 SamSs - ok 22:32:35.0473 6292 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 22:32:35.0474 6292 sbp2port - ok 22:32:35.0488 6292 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll 22:32:35.0490 6292 SCardSvr - ok 22:32:35.0496 6292 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 22:32:35.0498 6292 scfilter - ok 22:32:35.0556 6292 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll 22:32:35.0583 6292 Schedule - ok 22:32:35.0605 6292 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll 22:32:35.0606 6292 SCPolicySvc - ok 22:32:35.0622 6292 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll 22:32:35.0625 6292 SDRSVC - ok 22:32:35.0633 6292 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys 22:32:35.0634 6292 secdrv - ok 22:32:35.0643 6292 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll 22:32:35.0646 6292 seclogon - ok 22:32:35.0663 6292 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\system32\sens.dll 22:32:35.0665 6292 SENS - ok 22:32:35.0675 6292 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll 22:32:35.0677 6292 SensrSvc - ok 22:32:35.0684 6292 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\drivers\serenum.sys 22:32:35.0685 6292 Serenum - ok 22:32:35.0699 6292 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\drivers\serial.sys 22:32:35.0700 6292 Serial - ok 22:32:35.0714 6292 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\drivers\sermouse.sys 22:32:35.0716 6292 sermouse - ok 22:32:35.0726 6292 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll 22:32:35.0728 6292 SessionEnv - ok 22:32:35.0737 6292 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 22:32:35.0738 6292 sffdisk - ok 22:32:35.0744 6292 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 22:32:35.0745 6292 sffp_mmc - ok 22:32:35.0754 6292 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 22:32:35.0765 6292 sffp_sd - ok 22:32:35.0779 6292 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys 22:32:35.0780 6292 sfloppy - ok 22:32:35.0836 6292 [ 74EC60E20516AAA573BE74F31175270F ] SftService C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE 22:32:35.0871 6292 SftService - ok 22:32:35.0897 6292 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll 22:32:35.0900 6292 SharedAccess - ok 22:32:35.0914 6292 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll 22:32:35.0918 6292 ShellHWDetection - ok 22:32:35.0929 6292 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys 22:32:35.0930 6292 SiSRaid2 - ok 22:32:35.0943 6292 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys 22:32:35.0944 6292 SiSRaid4 - ok 22:32:35.0980 6292 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe 22:32:35.0983 6292 SkypeUpdate - ok 22:32:36.0006 6292 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys 22:32:36.0008 6292 Smb - ok 22:32:36.0027 6292 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe 22:32:36.0030 6292 SNMPTRAP - ok 22:32:36.0040 6292 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys 22:32:36.0041 6292 spldr - ok 22:32:36.0074 6292 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe 22:32:36.0083 6292 Spooler - ok 22:32:36.0147 6292 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe 22:32:36.0206 6292 sppsvc - ok 22:32:36.0218 6292 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll 22:32:36.0221 6292 sppuinotify - ok 22:32:36.0312 6292 [ 378A0748DE5ADF90BF9DB897DA8564E6 ] SRTSP C:\Windows\System32\Drivers\N360x64\1403010.016\SRTSP64.SYS 22:32:36.0322 6292 SRTSP - ok 22:32:36.0337 6292 [ 0E76CEF892C45734F7AED09FDDF35D4D ] SRTSPX C:\Windows\system32\drivers\N360x64\1403010.016\SRTSPX64.SYS 22:32:36.0338 6292 SRTSPX - ok 22:32:36.0377 6292 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys 22:32:36.0383 6292 srv - ok 22:32:36.0393 6292 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 22:32:36.0398 6292 srv2 - ok 22:32:36.0409 6292 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 22:32:36.0411 6292 srvnet - ok 22:32:36.0434 6292 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 22:32:36.0437 6292 SSDPSRV - ok 22:32:36.0449 6292 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll 22:32:36.0452 6292 SstpSvc - ok 22:32:36.0457 6292 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\drivers\stexstor.sys 22:32:36.0458 6292 stexstor - ok 22:32:36.0492 6292 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll 22:32:36.0501 6292 stisvc - ok 22:32:36.0539 6292 [ 7731F46EC0D687A931CBA063E8F90EF0 ] stllssvr C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe 22:32:36.0540 6292 stllssvr - ok 22:32:36.0554 6292 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\DRIVERS\swenum.sys 22:32:36.0556 6292 swenum - ok 22:32:36.0664 6292 [ F577910A133A592234EBAAD3F3AFA258 ] SwitchBoard C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe 22:32:36.0671 6292 SwitchBoard - ok 22:32:36.0692 6292 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll 22:32:36.0699 6292 swprv - ok 22:32:36.0707 6292 [ E174C8BC572E93AEEE1036DEDAC5F225 ] SymDS C:\Windows\system32\drivers\N360x64\1403010.016\SYMDS64.SYS 22:32:36.0712 6292 SymDS - ok 22:32:36.0741 6292 [ 599872BAD7CFB45C7CE47CDED4B726D8 ] SymEFA C:\Windows\system32\drivers\N360x64\1403010.016\SYMEFA64.SYS 22:32:36.0759 6292 SymEFA - ok 22:32:36.0792 6292 [ F5D6D3B7468C46EA2DDC1D19D2A6DA0F ] SymEvent C:\Windows\system32\Drivers\SYMEVENT64x86.SYS 22:32:36.0795 6292 SymEvent - ok 22:32:36.0809 6292 [ ADF37F1A715D6C56C8E065FD8569A9A4 ] SymIRON C:\Windows\system32\drivers\N360x64\1403010.016\Ironx64.SYS 22:32:36.0812 6292 SymIRON - ok 22:32:36.0820 6292 [ 1605EBD8CB86AFC4430116065995279A ] SymNetS C:\Windows\System32\Drivers\N360x64\1403010.016\SYMNETS.SYS 22:32:36.0824 6292 SymNetS - ok 22:32:36.0862 6292 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll 22:32:36.0891 6292 SysMain - ok 22:32:36.0900 6292 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll 22:32:36.0903 6292 TabletInputService - ok 22:32:36.0915 6292 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll 22:32:36.0919 6292 TapiSrv - ok 22:32:36.0931 6292 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll 22:32:36.0933 6292 TBS - ok 22:32:36.0996 6292 [ B62A953F2BF3922C8764A29C34A22899 ] Tcpip C:\Windows\system32\drivers\tcpip.sys 22:32:37.0024 6292 Tcpip - ok 22:32:37.0071 6292 [ B62A953F2BF3922C8764A29C34A22899 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 22:32:37.0086 6292 TCPIP6 - ok 22:32:37.0117 6292 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 22:32:37.0119 6292 tcpipreg - ok 22:32:37.0129 6292 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 22:32:37.0131 6292 TDPIPE - ok 22:32:37.0166 6292 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 22:32:37.0167 6292 TDTCP - ok 22:32:37.0193 6292 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 22:32:37.0196 6292 tdx - ok 22:32:37.0209 6292 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys 22:32:37.0211 6292 TermDD - ok 22:32:37.0223 6292 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll 22:32:37.0230 6292 TermService - ok 22:32:37.0243 6292 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll 22:32:37.0245 6292 Themes - ok 22:32:37.0268 6292 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll 22:32:37.0270 6292 THREADORDER - ok 22:32:37.0292 6292 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll 22:32:37.0296 6292 TrkWks - ok 22:32:37.0331 6292 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 22:32:37.0334 6292 TrustedInstaller - ok 22:32:37.0343 6292 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 22:32:37.0345 6292 tssecsrv - ok 22:32:37.0356 6292 [ 17C6B51CBCCDED95B3CC14E22791F85E ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 22:32:37.0358 6292 TsUsbFlt - ok 22:32:37.0385 6292 [ AD64450A4ABE076F5CB34CC08EEACB07 ] TsUsbGD C:\Windows\system32\drivers\TsUsbGD.sys 22:32:37.0387 6292 TsUsbGD - ok 22:32:37.0407 6292 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 22:32:37.0409 6292 tunnel - ok 22:32:37.0418 6292 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\drivers\uagp35.sys 22:32:37.0420 6292 uagp35 - ok 22:32:37.0431 6292 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 22:32:37.0434 6292 udfs - ok 22:32:37.0446 6292 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe 22:32:37.0449 6292 UI0Detect - ok 22:32:37.0456 6292 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 22:32:37.0458 6292 uliagpkx - ok 22:32:37.0468 6292 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\DRIVERS\umbus.sys 22:32:37.0469 6292 umbus - ok 22:32:37.0479 6292 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\drivers\umpass.sys 22:32:37.0480 6292 UmPass - ok 22:32:37.0494 6292 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll 22:32:37.0498 6292 upnphost - ok 22:32:37.0565 6292 [ 82E8F44688E6FAC57B5B7C6FC7ADBC2A ] usbaudio C:\Windows\system32\drivers\usbaudio.sys 22:32:37.0568 6292 usbaudio - ok 22:32:37.0595 6292 [ 19AD7990C0B67E48DAC5B26F99628223 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 22:32:37.0598 6292 usbccgp - ok 22:32:37.0620 6292 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys 22:32:37.0623 6292 usbcir - ok 22:32:37.0636 6292 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\drivers\usbehci.sys 22:32:37.0638 6292 usbehci - ok 22:32:37.0668 6292 [ 8B892002D7B79312821169A14317AB86 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 22:32:37.0673 6292 usbhub - ok 22:32:37.0684 6292 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys 22:32:37.0685 6292 usbohci - ok 22:32:37.0691 6292 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\drivers\usbprint.sys 22:32:37.0692 6292 usbprint - ok 22:32:37.0706 6292 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 22:32:37.0708 6292 USBSTOR - ok 22:32:37.0714 6292 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys 22:32:37.0716 6292 usbuhci - ok 22:32:37.0722 6292 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll 22:32:37.0724 6292 UxSms - ok 22:32:37.0733 6292 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe 22:32:37.0734 6292 VaultSvc - ok 22:32:37.0742 6292 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 22:32:37.0744 6292 vdrvroot - ok 22:32:37.0759 6292 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe 22:32:37.0765 6292 vds - ok 22:32:37.0772 6292 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 22:32:37.0773 6292 vga - ok 22:32:37.0779 6292 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys 22:32:37.0780 6292 VgaSave - ok 22:32:37.0792 6292 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys 22:32:37.0794 6292 vhdmp - ok 22:32:37.0800 6292 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys 22:32:37.0801 6292 viaide - ok 22:32:37.0814 6292 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys 22:32:37.0816 6292 volmgr - ok 22:32:37.0832 6292 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 22:32:37.0835 6292 volmgrx - ok 22:32:37.0847 6292 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys 22:32:37.0850 6292 volsnap - ok 22:32:37.0858 6292 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys 22:32:37.0860 6292 vsmraid - ok 22:32:37.0890 6292 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe 22:32:37.0921 6292 VSS - ok 22:32:37.0929 6292 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys 22:32:37.0930 6292 vwifibus - ok 22:32:37.0953 6292 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys 22:32:37.0954 6292 vwififlt - ok 22:32:37.0969 6292 [ 6A638FC4BFDDC4D9B186C28C91BD1A01 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys 22:32:37.0971 6292 vwifimp - ok 22:32:37.0993 6292 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll 22:32:37.0999 6292 W32Time - ok 22:32:38.0011 6292 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\drivers\wacompen.sys 22:32:38.0012 6292 WacomPen - ok 22:32:38.0024 6292 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys 22:32:38.0025 6292 WANARP - ok 22:32:38.0028 6292 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 22:32:38.0029 6292 Wanarpv6 - ok 22:32:38.0073 6292 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe 22:32:38.0102 6292 WatAdminSvc - ok 22:32:38.0138 6292 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe 22:32:38.0173 6292 wbengine - ok 22:32:38.0199 6292 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 22:32:38.0204 6292 WbioSrvc - ok 22:32:38.0216 6292 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll 22:32:38.0223 6292 wcncsvc - ok 22:32:38.0233 6292 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 22:32:38.0235 6292 WcsPlugInService - ok 22:32:38.0238 6292 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\drivers\wd.sys 22:32:38.0239 6292 Wd - ok 22:32:38.0261 6292 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 22:32:38.0269 6292 Wdf01000 - ok 22:32:38.0277 6292 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll 22:32:38.0279 6292 WdiServiceHost - ok 22:32:38.0282 6292 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll 22:32:38.0283 6292 WdiSystemHost - ok 22:32:38.0295 6292 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll 22:32:38.0299 6292 WebClient - ok 22:32:38.0309 6292 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll 22:32:38.0313 6292 Wecsvc - ok 22:32:38.0320 6292 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll 22:32:38.0323 6292 wercplsupport - ok 22:32:38.0338 6292 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll 22:32:38.0341 6292 WerSvc - ok 22:32:38.0353 6292 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys 22:32:38.0354 6292 WfpLwf - ok 22:32:38.0384 6292 [ B14EF15BD757FA488F9C970EEE9C0D35 ] WimFltr C:\Windows\system32\DRIVERS\wimfltr.sys 22:32:38.0386 6292 WimFltr - ok 22:32:38.0396 6292 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys 22:32:38.0398 6292 WIMMount - ok 22:32:38.0407 6292 WinDefend - ok 22:32:38.0414 6292 WinHttpAutoProxySvc - ok 22:32:38.0448 6292 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 22:32:38.0451 6292 Winmgmt - ok 22:32:38.0483 6292 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll 22:32:38.0518 6292 WinRM - ok 22:32:38.0563 6292 [ FE88B288356E7B47B74B13372ADD906D ] WinUSB C:\Windows\system32\DRIVERS\WinUSB.sys 22:32:38.0565 6292 WinUSB - ok 22:32:38.0587 6292 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll 22:32:38.0600 6292 Wlansvc - ok 22:32:38.0647 6292 [ 06C8FA1CF39DE6A735B54D906BA791C6 ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe 22:32:38.0648 6292 wlcrasvc - ok 22:32:38.0720 6292 [ 7E47C328FC4768CB8BEAFBCFAFA70362 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 22:32:38.0756 6292 wlidsvc - ok 22:32:38.0766 6292 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys 22:32:38.0767 6292 WmiAcpi - ok 22:32:38.0792 6292 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 22:32:38.0794 6292 wmiApSrv - ok 22:32:38.0802 6292 WMPNetworkSvc - ok 22:32:38.0814 6292 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll 22:32:38.0816 6292 WPCSvc - ok 22:32:38.0821 6292 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 22:32:38.0823 6292 WPDBusEnum - ok 22:32:38.0843 6292 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 22:32:38.0843 6292 ws2ifsl - ok 22:32:38.0852 6292 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\system32\wscsvc.dll 22:32:38.0854 6292 wscsvc - ok 22:32:38.0857 6292 WSearch - ok 22:32:38.0915 6292 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll 22:32:38.0965 6292 wuauserv - ok 22:32:39.0001 6292 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 22:32:39.0003 6292 WudfPf - ok 22:32:39.0027 6292 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 22:32:39.0031 6292 WUDFRd - ok 22:32:39.0045 6292 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 22:32:39.0048 6292 wudfsvc - ok 22:32:39.0080 6292 [ FE90B750AB808FB9DD8FBB428B5FF83B ] WwanSvc C:\Windows\System32\wwansvc.dll 22:32:39.0084 6292 WwanSvc - ok 22:32:39.0091 6292 ================ Scan global =============================== 22:32:39.0112 6292 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll 22:32:39.0128 6292 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll 22:32:39.0138 6292 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll 22:32:39.0163 6292 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll 22:32:39.0179 6292 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe 22:32:39.0183 6292 [Global] - ok 22:32:39.0184 6292 ================ Scan MBR ================================== 22:32:39.0199 6292 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0 22:32:39.0375 6292 \Device\Harddisk0\DR0 - ok 22:32:39.0376 6292 ================ Scan VBR ================================== 22:32:39.0377 6292 [ 76432F9A01A553665396740C3D9EE6BF ] \Device\Harddisk0\DR0\Partition1 22:32:39.0379 6292 \Device\Harddisk0\DR0\Partition1 - ok 22:32:39.0403 6292 [ 3A8F08E671CC464C45C8AFC5838A3A2E ] \Device\Harddisk0\DR0\Partition2 22:32:39.0405 6292 \Device\Harddisk0\DR0\Partition2 - ok 22:32:39.0405 6292 ============================================================ 22:32:39.0405 6292 Scan finished 22:32:39.0405 6292 ============================================================ 22:32:39.0412 9120 Detected object count: 0 22:32:39.0412 9120 Actual detected object count: 0
Hello BnTheMan,

this is starting to worry me. Do you see anything. Just even seeing some of the applications that are on my hard drive I do not even recall installing, yet tdskiller did not find anything???? However, if I do recall, RogueKiller did find 2 objects. should I kill it?


Try not to worry, we must progress through the process in a step by step manner. Unfortunately, sometimes the process can be time consuming. The entries RogueKiller found do not require attention. Please do not remove anything unless I ask you to do so.

1. Run OTL.exe

Windows Vista and Windows 7 users Right Click and select "Run as Administrator"
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Commands
    [purity]
    [createrestorepoint]
    [emptyflash]
    [emptyjava]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then re-run OTL and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
=========================

In your next post please provide the following:
  • OTL.txt
  • Do you get the pop-ups while using other browsers?
OTL logfile created on: 5/30/2013 5:49:45 PM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\BigPapa\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16576)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.91 Gb Total Physical Memory | 2.27 Gb Available Physical Memory | 58.01% Memory free
7.83 Gb Paging File | 6.07 Gb Available in Paging File | 77.56% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 919.22 Gb Total Space | 827.15 Gb Free Space | 89.98% Space Free | Partition Type: NTFS

Computer Name: BIGPAPA-PC | User Name: BigPapa | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\BigPapa\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Innovative Solutions\DriverMax\drivermax.exe (Innovative Solutions)
PRC - C:\Program Files (x86)\Norton 360\Engine\20.3.1.22\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe ()
PRC - C:\Program Files (x86)\Dell Stage\Dell Stage\stage_secondary.exe ()
PRC - C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe ()
PRC - C:\Program Files (x86)\Connectify\Connectify.exe (Connectify)
PRC - C:\Program Files (x86)\Connectify\Connectifyd.exe (Connectify)
PRC - C:\Program Files (x86)\Connectify\ConnectifyService.exe ()
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe (SoftThinks - Dell)
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (SoftThinks SAS)
PRC - C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe ()
PRC - C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\ppgooglenaclpluginchrome.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\pdf.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\libglesv2.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\libegl.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\ffmpegsumo.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\1e8f7367eaa08c5057d78c093982f8f0\System.IdentityModel.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\e698a866fd16973a24ca6697218028ad\System.ServiceModel.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\3c2ed368e1f3889997dfb42a5ca77284\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\af525b4bec3b9941b7be8ffbf813da80\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\30e3a21202000677d0a9270572251477\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\7eac0dbe9aa20b55e37235f8ee030e6b\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\716959df79685a1eae0fc14275a32b0f\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\764f15e86c82662e977bd418bd6318c1\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\23673bbebe3c0ca7c894e614bb3ffd1a\System.Security.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\5ecf01964c70e453d71e5d7653912ff9\System.Web.ni.dll ()
MOD - C:\Program Files (x86)\Innovative Solutions\DriverMax\sync.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\1e04a5319c58010e945220af2751d34e\System.ServiceModel.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\2ad51da1b752b19c992fcefd56eb7c01\System.Runtime.Serialization.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\eb33bf977e97e97b12e82c18e36fbaee\SMDiagnostics.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\d7d20811a7ce7cc589153648cbb1ce5c\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\90b89f6e8032310e9ac72a309fd49e83\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Norton 360\Engine\20.3.1.22\wincfi39.dll ()
MOD - C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe ()
MOD - C:\Program Files (x86)\Dell Stage\Dell Stage\stage_secondary.exe ()
MOD - C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe ()
MOD - C:\Program Files (x86)\Dell Stage\Dell Stage\QtGui4.dll ()
MOD - C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\QtGui4.dll ()
MOD - C:\Program Files (x86)\Dell Stage\Dell Stage\QtCore4.dll ()
MOD - C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\QtCore4.dll ()
MOD - C:\Program Files (x86)\Connectify\Scannify.dll ()
MOD - C:\Program Files (x86)\Connectify\DriverLib.dll ()
MOD - C:\Program Files (x86)\Connectify\BuildProps.dll ()
MOD - C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe ()
MOD - c:\Program Files (x86)\Common Files\Roxio Shared\DLLShared\SQLite352.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.WorkflowServices\3.5.0.0__31bf3856ad364e35\System.WorkflowServices.dll ()
MOD - C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()


========== Services (SafeList) ==========

SRV:64bit: - (HoudiniServer) – C:\WINDOWS\SysNative\hserver.exe (Side Effects Software Inc.)
SRV:64bit: - (FLEXnet Licensing Service 64) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe (Flexera Software, Inc.)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (N360) – C:\Program Files (x86)\Norton 360\Engine\20.3.1.22\ccSvcHst.exe (Symantec Corporation)
SRV - (cphs) – C:\WINDOWS\SysWOW64\IntelCpHeciSvc.exe (Intel Corporation)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (Connectify) – C:\Program Files (x86)\Connectify\ConnectifyService.exe ()
SRV - (SftService) – C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (SoftThinks SAS)
SRV - (RoxWatch12) – C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe (Sonic Solutions)
SRV - (RoxMediaDB12OEM) – C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe (Sonic Solutions)
SRV - (clr_optimization_v4.0.30319_32) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SwitchBoard) – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (clr_optimization_v2.0.50727_32) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (SymEvent) – C:\WINDOWS\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (SymNetS) – C:\WINDOWS\SysNative\drivers\N360x64\1403010.016\symnets.sys (Symantec Corporation)
DRV:64bit: - (SymEFA) – C:\WINDOWS\SysNative\drivers\N360x64\1403010.016\SymEFA64.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\WINDOWS\SysNative\drivers\N360x64\1403010.016\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) – C:\WINDOWS\SysNative\drivers\N360x64\1403010.016\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (SymDS) – C:\WINDOWS\SysNative\drivers\N360x64\1403010.016\SymDS64.sys (Symantec Corporation)
DRV:64bit: - (igfx) – C:\WINDOWS\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (SymIRON) – C:\WINDOWS\SysNative\drivers\N360x64\1403010.016\Ironx64.sys (Symantec Corporation)
DRV:64bit: - (ccSet_N360) – C:\WINDOWS\SysNative\drivers\N360x64\1403010.016\ccSetx64.sys (Symantec Corporation)
DRV:64bit: - (RdpVideoMiniport) – C:\WINDOWS\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbGD) – C:\WINDOWS\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\WINDOWS\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (cnnctfy2) – C:\WINDOWS\SysNative\drivers\cnnctfy2.sys (Connectify)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (RTL8167) – C:\WINDOWS\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (amdsata) – C:\WINDOWS\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\WINDOWS\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (CnxtHdAudService) – C:\WINDOWS\SysNative\drivers\CHDRT64.sys (Conexant Systems Inc.)
DRV:64bit: - (RMCAST) – C:\WINDOWS\SysNative\drivers\rmcast.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\WINDOWS\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (athr) – C:\WINDOWS\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (MEIx64) – C:\WINDOWS\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) – C:\WINDOWS\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (PxHlpa64) – C:\WINDOWS\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (androidusb) – C:\WINDOWS\SysNative\drivers\ssadadb.sys (Google Inc)
DRV:64bit: - (amdsbs) – C:\WINDOWS\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\WINDOWS\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\WINDOWS\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) – C:\WINDOWS\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\WINDOWS\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\WINDOWS\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\WINDOWS\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (WimFltr) – C:\WINDOWS\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\Definitions\VirusDefs\20130528.032\ex64.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\Definitions\VirusDefs\20130528.032\eng64.sys (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\Definitions\IPSDefs\20130528.001\IDSviA64.sys (Symantec Corporation)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\Definitions\BASHDefs\20130515.001\BHDrvx64.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (WIMMount) – C:\WINDOWS\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{49606DC7-976D-4030-A74E-9FB5C842FA68}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{49606DC7-976D-4030-A74E-9FB5C842FA68}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\..\SearchScopes\{E3F15D58-092E-47B8-AC12-4F1195C84251}: "URL" = http://www.google.com/search?q={searchTerm…1I7NDKB_enUS524
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@bestbuy.com/npBestBuyPcAppDetector,version=1.0: C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@bestbuy.com/npBestBuyPcAppDetector,version=1.0: C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll File not found
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\BigPapa\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\coFFPlgn\ [2013/05/30 17:47:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\IPSFFPlgn\ [2013/05/07 16:12:26 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - homepage: http://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 6 U31 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\BigPapa\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\BigPapa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\BigPapa\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Selection Links = C:\Users\BigPapa\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkmljcahgmhdlnhmnjiaakhkbbiapjkb\4.3_0\
CHR - Extension: Norton Identity Protection = C:\Users\BigPapa\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.3.3.19_0\
CHR - Extension: Gmail = C:\Users\BigPapa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2013/05/29 03:22:00 | 000,000,027 | —- | M]) - C:\WINDOWS\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\20.3.1.22\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\20.3.1.22\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\20.3.1.22\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [cAudioFilterAgent] C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe (Conexant Systems, Inc.)
O4:64bit: - HKLM..\Run: [DellStage] C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe ()
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\WINDOWS\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\WINDOWS\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe (Conexant Systems, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AccuWeatherWidget] C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Dell Registration] C:\Program Files (x86)\System Registration\prodreg.exe (Dell, Inc.)
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe (Sonic Solutions)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [Connectify] C:\Program Files (x86)\Connectify\Connectify.exe (Connectify)
O4 - HKCU..\Run: [DriverMax] C:\Program Files (x86)\Innovative Solutions\DriverMax\drivermax.exe (Innovative Solutions)
O4 - HKCU..\Run: [GoogleChromeAutoLaunch_89C113111C53352D1F68066DB33BEBDD] C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
O4 - HKLM..\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe (Softthinks)
O4 - Startup: C:\Users\BigPapa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PdaNet Desktop.lnk = C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} http://support.dell.com/systemprofiler/DellSystemLite.CAB (DellSystemLite.Scanner)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9E1B8B58-55FD-45BC-A6A9-7BD5334B4140}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\WINDOWS\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\WINDOWS\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/05/30 17:45:34 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/05/29 22:26:14 | 002,237,968 | —- | C] (Kaspersky Lab ZAO) – C:\Users\BigPapa\Desktop\TDSSKiller.exe
[2013/05/29 03:24:12 | 000,000,000 | —D | C] – C:\Windows\temp
[2013/05/29 03:15:16 | 000,000,000 | —D | C] – C:\ComboFix
[2013/05/28 22:32:57 | 000,000,000 | —D | C] – C:\ProgramData\boost_interprocess
[2013/05/27 20:02:59 | 000,000,000 | —D | C] – C:\_OTL
[2013/05/27 16:08:49 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\BigPapa\Desktop\OTL.exe
[2013/05/25 10:38:28 | 000,000,000 | —D | C] – C:\Users\BigPapa\Desktop\Checking 4 Virus 5-25-2013
[2013/05/18 03:02:48 | 000,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/05/18 03:02:48 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/05/18 03:02:48 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/05/18 03:02:47 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/05/18 03:02:47 | 000,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/05/18 03:02:47 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/05/18 03:02:47 | 000,089,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/05/18 03:02:47 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/05/18 03:02:47 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/05/18 03:02:47 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/05/18 03:02:47 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/05/18 03:02:47 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/05/18 03:02:45 | 003,958,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/05/18 03:02:45 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/05/18 03:02:45 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/05/17 21:43:28 | 001,930,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\authui.dll
[2013/05/17 21:43:28 | 001,796,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\authui.dll
[2013/05/17 21:43:28 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\shdocvw.dll
[2013/05/17 21:43:28 | 000,111,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\consent.exe
[2013/05/17 19:31:24 | 000,265,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\dxgmms1.sys
[2013/05/17 19:31:24 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2013/05/17 19:22:21 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wwanprotdim.dll
[2013/05/11 08:47:19 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RdpGroupPolicyExtension.dll
[2013/05/11 08:47:19 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbRedirectionGroupPolicyExtension.dll
[2013/05/11 08:47:19 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbRedirectionGroupPolicyControl.exe
[2013/05/11 08:47:15 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\TsUsbGD.sys
[2013/05/11 08:47:15 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\rdpvideominiport.sys
[2013/05/11 08:47:14 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\TsUsbFlt.sys
[2013/05/11 08:47:11 | 000,192,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rdpendp_winip.dll
[2013/05/11 08:47:11 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tsgqec.dll
[2013/05/11 08:47:11 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbGDCoInstaller.dll
[2013/05/11 08:47:11 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tsgqec.dll
[2013/05/11 08:47:11 | 000,018,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wksprtPS.dll
[2013/05/11 08:47:11 | 000,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wksprtPS.dll
[2013/05/11 08:47:10 | 000,384,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wksprt.exe
[2013/05/11 08:47:10 | 000,322,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\aaclient.dll
[2013/05/11 08:47:10 | 000,269,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\aaclient.dll
[2013/05/11 08:47:10 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpudd.dll
[2013/05/11 08:47:10 | 000,228,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpendp_winip.dll
[2013/05/11 08:47:10 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TSWbPrxy.exe
[2013/05/11 08:47:10 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MsRdpWebAccess.dll
[2013/05/11 08:47:10 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MsRdpWebAccess.dll
[2013/05/11 08:47:09 | 001,123,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstsc.exe
[2013/05/11 08:47:09 | 001,048,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstsc.exe
[2013/05/11 08:47:08 | 003,174,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorets.dll
[2013/05/11 08:47:07 | 004,916,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstscax.dll
[2013/05/11 08:47:06 | 005,773,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstscax.dll
[2013/05/11 08:27:06 | 001,448,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lsasrv.dll
[2013/05/11 08:27:02 | 000,514,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qdvd.dll
[2013/05/11 08:27:02 | 000,366,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qdvd.dll
[2013/05/07 16:08:47 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360
[2013/04/30 21:00:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\FFmpeg for Audacity

========== Files - Modified Within 30 Days ==========

[2013/05/30 17:52:28 | 000,021,296 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/05/30 17:52:28 | 000,021,296 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/05/30 17:45:30 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/05/30 17:45:25 | 000,000,439 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts.ics
[2013/05/30 17:45:06 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/05/30 17:44:59 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/05/30 17:44:52 | 3152,510,976 | -HS- | M] () – C:\hiberfil.sys
[2013/05/30 17:35:01 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/05/29 22:19:59 | 000,139,264 | —- | M] () – C:\Users\BigPapa\Desktop\SystemLook.exe
[2013/05/29 03:22:00 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2013/05/29 00:25:49 | 000,001,166 | —- | M] () – C:\Users\BigPapa\Desktop\ComboFix.exe - Shortcut.lnk
[2013/05/28 22:46:18 | 000,791,040 | —- | M] () – C:\Users\BigPapa\Desktop\RogueKillerX64.exe
[2013/05/27 23:12:15 | 000,778,834 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/05/27 23:12:15 | 000,660,068 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/05/27 23:12:15 | 000,120,996 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/05/27 20:28:03 | 000,001,456 | —- | M] () – C:\Users\BigPapa\AppData\Local\Adobe Save for Web 12.0 Prefs
[2013/05/27 20:14:37 | 000,001,503 | —- | M] () – C:\Users\BigPapa\Desktop\AdwCleaner.exe - Shortcut.lnk
[2013/05/27 16:09:07 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\BigPapa\Desktop\OTL.exe
[2013/05/27 15:13:19 | 1637,965,791 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/05/25 17:02:25 | 000,000,876 | —- | M] () – C:\Users\BigPapa\.recently-used.xbel
[2013/05/23 16:37:30 | 000,002,185 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/05/18 03:57:58 | 000,002,021 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[2013/05/18 03:32:28 | 004,953,816 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/05/18 03:31:53 | 001,842,244 | —- | M] () – C:\Windows\SysNative\drivers\N360x64\1403010.016\Cat.DB
[2013/05/07 16:08:48 | 000,002,321 | —- | M] () – C:\Users\Public\Desktop\Norton 360.lnk
[2013/05/07 16:06:23 | 000,177,312 | —- | M] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2013/05/07 16:06:23 | 000,007,466 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2013/05/07 16:06:23 | 000,000,855 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF

========== Files Created - No Company Name ==========

[2013/05/29 22:19:57 | 000,139,264 | —- | C] () – C:\Users\BigPapa\Desktop\SystemLook.exe
[2013/05/29 00:25:49 | 000,001,166 | —- | C] () – C:\Users\BigPapa\Desktop\ComboFix.exe - Shortcut.lnk
[2013/05/28 22:45:53 | 000,791,040 | —- | C] () – C:\Users\BigPapa\Desktop\RogueKillerX64.exe
[2013/05/27 20:14:37 | 000,001,503 | —- | C] () – C:\Users\BigPapa\Desktop\AdwCleaner.exe - Shortcut.lnk
[2013/05/25 17:02:25 | 000,000,876 | —- | C] () – C:\Users\BigPapa\.recently-used.xbel
[2013/04/21 15:02:15 | 000,000,258 | RHS- | C] () – C:\Users\BigPapa\ntuser.pol
[2013/02/09 20:00:38 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/02/09 20:00:38 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/02/09 20:00:38 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/02/09 20:00:38 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/02/09 20:00:38 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/12/14 02:42:30 | 000,963,452 | —- | C] () – C:\Windows\SysWow64\igcodeckrng600.bin
[2012/12/14 02:42:30 | 000,064,512 | —- | C] () – C:\Windows\SysWow64\igdde32.dll
[2012/12/14 02:42:28 | 000,272,928 | —- | C] () – C:\Windows\SysWow64\igvpkrng600.bin
[2012/08/08 23:31:23 | 000,001,456 | —- | C] () – C:\Users\BigPapa\AppData\Local\Adobe Save for Web 12.0 Prefs
[2012/07/16 00:01:04 | 000,000,132 | —- | C] () – C:\Users\BigPapa\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2012/06/03 18:48:08 | 000,000,056 | —- | C] () – C:\ProgramData\ezsidmv.dat
[2012/04/19 01:58:28 | 000,000,132 | —- | C] () – C:\Users\BigPapa\AppData\Roaming\Adobe Targa Format CS5 Prefs
[2012/02/14 18:47:06 | 000,963,912 | —- | C] () – C:\Windows\SysWow64\igkrng600.bin
[2012/02/14 18:47:06 | 000,261,208 | —- | C] () – C:\Windows\SysWow64\igfcg600m.bin
[2011/06/21 16:18:08 | 000,145,804 | —- | C] () – C:\Windows\SysWow64\igcompkrng600.bin

========== ZeroAccess Check ==========

[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\WINDOWS\SysNative\shell32.dll – [2013/02/27 01:52:56 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/27 00:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\WINDOWS\SysNative\wbem\fastprox.dll – [2009/07/13 21:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 23:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\WINDOWS\SysNative\wbem\wbemess.dll – [2009/07/13 21:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI