Hey here's the log file from mbar
Malwarebytes Anti-Rootkit BETA 1.06.0.1003
www.malwarebytes.org
Database version: v2013.06.09.04
Windows Vista Service Pack 1 x64 NTFS
Internet Explorer 8.0.6001.18928
Mohammad :: MOHAMMAD-PC [administrator]
6/10/2013 3:02:38 AM
mbar-log-2013-06-10 (03-02-38).txt
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUM | P2P
Scan options disabled: Deep Anti-Rootkit Scan | PUP
Objects scanned: 241217
Time elapsed: 29 minute(s), 38 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
Physical Sectors Detected: 0
(No malicious items detected)
(end)
Here's FRST.txt after the first scan
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-06-2013
Ran by [removed] (administrator) on 09-06-2013 21:22:29
Running from C:\Users\[removed]\Desktop
Windows Vista ™ Home Premium Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(AnchorFree Inc.) C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe
(Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AnchorFree Inc.) C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
() C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe
(InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\PTCL\Common\RaRegistry.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\PTCL\Common\RaRegistry64.exe
(Intel Corporation) C:\Program Files\Sony\VAIO Care\collsvc.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe
(ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe
(Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
(Conexant Systems, Inc.) C:\Windows\system32\DRIVERS\xaudio64.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
(Safer Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
(Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESGfxMgr.exe
(Intel Corporation) C:\Windows\system32\igfxext.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Sony Corporation) C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Program Files\Sony\VAIO Care\listener.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
==================== Registry (Whitelisted) ==================
HKLM\…\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [6956576 2009-01-06] (Realtek Semiconductor)
HKLM\…\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1220392 2008-05-21] (Synaptics, Inc.)
HKCU\…\Run: [ISUSPM] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler [x]
MountPoints2: F - F:\AutoRun.exe
MountPoints2: {076fb6a0-714a-11e2-9917-001dbaf06e9b} - F:\urDrive.exe
MountPoints2: {243eb6eb-7bb1-11e0-bdf1-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {464e708f-aac4-11e0-b3dd-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {464e7093-aac4-11e0-b3dd-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {464e70d1-aac4-11e0-b3dd-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {464e70d3-aac4-11e0-b3dd-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {807975c6-d75c-11de-9ae1-001dbaf06e9b} - H:\LaunchU3.exe -a
MountPoints2: {80cd714b-cbab-11e0-9e09-001dbaf06e9b} - F:\Startme.exe
MountPoints2: {bc873d9d-cc3f-11e0-920a-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {bc873d9f-cc3f-11e0-920a-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {f56d0c52-ac3f-11e0-851b-806e6f6e6963} - F:\AutoRun.exe
HKLM-x32\…\Run: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe" [317288 2008-12-18] (Sony Corporation)
HKLM-x32\…\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49152 2007-10-14] (Hewlett-Packard)
HKLM-x32\…\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui [3451496 2011-02-23] (AVAST Software)
HKLM-x32\…\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot [202256 2010-08-09] (RealNetworks, Inc.)
HKLM-x32\…\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-01-28] (Apple Inc.)
HKLM-x32\…\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [946352 2012-12-19] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre7\bin\jusched.exe" [x]
HKU\Default\…\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter [2438656 2008-01-21] (Microsoft Corporation)
HKU\Default User\…\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter [2438656 2008-01-21] (Microsoft Corporation)
SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\System32\webcheck.dll (Microsoft Corporation)
SSODL-x32: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\SysWOW64\webcheck.dll (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
URLSearchHook: (No Name) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - No File
URLSearchHook: (No Name) - {f0381dbd-e018-4e07-ae40-d96ab15083f0} - No File
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={sea…ferrer:source?}
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={sea…ferrer:source?}
SearchScopes: HKLM-x32 - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL =
http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2765711
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL =
http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2765711
BHO: avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll ()
BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE_64.dll (AnchorFree Inc.)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited)
BHO-x32: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
BHO-x32: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
BHO-x32: AF-HSS Toolbar - {f0381dbd-e018-4e07-ae40-d96ab15083f0} - C:\Program Files (x86)\AF-HSS\prxtbAF-H.dll (Conduit Ltd.)
BHO-x32: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE.dll (AnchorFree Inc.)
BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll ()
Toolbar: HKLM-x32 - Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
Toolbar: HKLM-x32 - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
Toolbar: HKLM-x32 - AF-HSS Toolbar - {f0381dbd-e018-4e07-ae40-d96ab15083f0} - C:\Program Files (x86)\AF-HSS\prxtbAF-H.dll (Conduit Ltd.)
Toolbar: HKCU - No Name - {BA14329E-9550-4989-B3F2-9732E92D17CC} - No File
Toolbar: HKCU - No Name - {F0381DBD-E018-4E07-AE40-D96AB15083F0} - No File
DPF: HKLM-x32 {02CF1781-EA91-4FA5-A200-646E8241987C} http://esupport.sony.com/VaioInfo.CAB
DPF: HKLM-x32 {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab
DPF: HKLM-x32 {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
DPF: HKLM-x32 {DAF7E6E6-D53A-439A-B28D-12271406B8A9}
http://mobileapps.blackberry.com/devicesoftware/AxLoader.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler-x32: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
FireFox:
========
FF ProfilePath: C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default
FF Homepage: hxxp://search.conduit.com/?ctid=CT1572363&SearchSource;=13
FF NetworkProxy: "http", "localhost"
FF NetworkProxy: "http_port", 9666
FF NetworkProxy: "socks", "localhost"
FF NetworkProxy: "socks_port", 9050
FF NetworkProxy: "socks_remote_dns", true
FF NetworkProxy: "ssl", "localhost"
FF NetworkProxy: "ssl_port", 9666
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_171.dll ()
FF Plugin: @java.com/DTPlugin,version=10.13.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.13.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_171.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF Plugin-x32: @divx.com/DivX OVS Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.7.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.7.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\3.0.50106.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=6.0.12.775 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprjplug;version=1.0.3.775 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprphtml5videoshim;version=1.0.0.0 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpjplug;version=6.0.12.775 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Adblock Plus Pop-up Addon - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\[removed]
FF Extension: YouTube to MP3 - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\[removed]
FF Extension: Zotero - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\[removed]
FF Extension: Zotero Word for Windows Integration - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\[removed]
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF Extension: No Name - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{48e23fba-bb14-4745-b768-382150cd83fb}
FF Extension: No Name - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{5B52016C-D097-4aec-BE61-9F129D8FDDBA}
FF Extension: Orthodox - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{6d677280-ddfe-11dc-95ff-0800200c9a66}
FF Extension: NoScript - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
FF Extension: Zynga Toolbar - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
FF Extension: No Name - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
FF Extension: No Name - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}
FF Extension: AF-HSS - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{f0381dbd-e018-4e07-ae40-d96ab15083f0}
Chrome:
=======
CHR HomePage: hxxp://lums.edu.pk/
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (RealJukebox NS Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\nprjplug.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\nprpjplug.dll (RealNetworks, Inc.)
CHR Plugin: (Google Talk Plugin) - C:\Users\Mohammad\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
CHR Plugin: (Google Talk Plugin Video Accelerator) - C:\Users\Mohammad\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
CHR Plugin: (Google Talk Plugin Video Renderer) - C:\Users\Mohammad\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
CHR Plugin: (RIM Handheld Application Loader) - C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll No File
CHR Plugin: (DivX OVS Helper Plug-in) - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
CHR Plugin: (DivX Web Player) - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (Java™ Platform SE 7 U7) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Windows Live\u00AE Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (RealPlayer™ HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_171.dll ()
CHR Plugin: (Java Deployment Toolkit 7.0.70.11) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\3.0.50106.0\npctrl.dll ( Microsoft Corporation)
CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Extension: (Ge.tt) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdgghbbgmhcpidlmnepkbihehhkmjomc\0.99_0
CHR Extension: (NetCalc.org) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcfbbbolmblaajakigohdookklamneec\1_0
CHR Extension: (Facebook Nanny) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkpjofmdbabecniidggbbicfbcmfafmk\0.6.2_0
CHR Extension: (Dictionary Instant) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\hngaklbjlbjhmoilkegninbmpfigheol\2.0.0_0
CHR Extension: (WeatherBug) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihdkejbciahopmbagpnjmmkkdpfpaaak\2.0.5_0
CHR Extension: (PDF to Word Converter App) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\jclipofobaadknkadkpgggmjkebddjam\2.1_0
CHR Extension: (Any.DO) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdadialhpiikehpdeejjeiikopddkjem\1.0.3.3_0
CHR Extension: (Little Alchemy) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\knkapnclbofjjgicpkfoagdjohlfjhpd\0.0.15.7_0
CHR Extension: (Evernote Web) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol\1.0.7_0
CHR Extension: (Dropbox) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndbkiaijfjjjbejhcbcpkcpkcffjckga\1.0_0
CHR Extension: (Grooveshark Downloader) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\ooblpjoncpjmbncgocjlnannofkjjhnp\2.9.2_0
CHR Extension: (Gmail) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
==================== Services (Whitelisted) =================
S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [42184 2011-02-23] (AVAST Software)
S2 gupdate1c9e81a239f2659; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [133104 2009-06-08] (Google Inc.)
R2 hshld; C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe [534824 2013-01-23] (AnchorFree Inc.)
S3 HssTrayService; C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE [78512 2013-01-20] ()
R2 HssWd; C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe [389928 2013-01-23] ()
S3 PACSPTISVR; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\PACSPTISVR.exe [114688 2009-01-08] (Sony Corporation)
R2 RalinkRegistryWriter; C:\Program Files (x86)\PTCL\Common\RaRegistry.exe [185632 2009-10-26] (Ralink Technology, Corp.)
R2 RalinkRegistryWriter64; C:\Program Files (x86)\PTCL\Common\RaRegistry64.exe [211232 2009-10-26] (Ralink Technology, Corp.)
R2 SampleCollector; C:\Program Files\Sony\VAIO Care\collsvc.exe [167424 2008-09-30] (Intel Corporation)
R2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
R2 SOHDBSvr; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [70952 2009-01-20] (Sony Corporation)
R2 SOHPlMgr; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [91432 2009-01-20] (Sony Corporation)
R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.)
S3 VAIO Entertainment TV Device Arbitration Service; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [69632 2009-01-21] (Sony Corporation)
R3 Vcsw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [313264 2009-01-21] (Sony Corporation)
R2 VzCdbSvc; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [192512 2009-01-21] (Sony Corporation)
S3 msiserver; %systemroot%\system32\msiexec /V [x]
S2 RoxLiveShare9; "C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe" [x]
==================== Drivers (Whitelisted) ====================
R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2008-04-25] (ArcSoft, Inc.)
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [22360 2011-02-23] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [64344 2011-02-23] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswRdr.sys [31064 2011-02-23] (AVAST Software)
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [505176 2011-02-23] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [280408 2011-02-23] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [53592 2011-02-23] (AVAST Software)
S3 dgderdrv; C:\Windows\System32\drivers\dgderdrv.sys [20568 2009-12-22] (Devguru Co., Ltd)
S1 DMICall; C:\Windows\SysWow64\DRIVERS\DMICall.sys [10216 2008-11-25] (Sony Corporation)
R1 HssDRV6; C:\Windows\System32\DRIVERS\hssdrv6.sys [42696 2013-01-20] (AnchorFree Inc.)
S3 RimVSerPort; C:\Windows\System32\DRIVERS\RimSerial_AMD64.sys [31744 2009-01-09] (Research in Motion Ltd)
R2 risdptsk; C:\Windows\System32\DRIVERS\risdsn64.sys [76288 2008-10-23] (REDC)
S3 s0016bus; C:\Windows\System32\DRIVERS\s0016bus.sys [115240 2008-05-16] (MCCI Corporation)
S3 s0016mdfl; C:\Windows\System32\DRIVERS\s0016mdfl.sys [19496 2008-05-16] (MCCI Corporation)
S3 s0016mdm; C:\Windows\System32\DRIVERS\s0016mdm.sys [158760 2008-05-16] (MCCI Corporation)
S3 s0016mgmt; C:\Windows\System32\DRIVERS\s0016mgmt.sys [137256 2008-05-16] (MCCI Corporation)
S3 s0016nd5; C:\Windows\System32\DRIVERS\s0016nd5.sys [34344 2008-05-16] (MCCI Corporation)
S3 s0016obex; C:\Windows\System32\DRIVERS\s0016obex.sys [136744 2008-05-16] (MCCI Corporation)
S3 s0016unic; C:\Windows\System32\DRIVERS\s0016unic.sys [151592 2008-05-16] (MCCI Corporation)
R3 seehcri; C:\Windows\System32\DRIVERS\seehcri.sys [34032 2008-01-09] (Sony Ericsson Mobile Communications)
R3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42328 2013-01-05] (Anchorfree Inc.)
R3 tapSF0901; C:\Windows\System32\DRIVERS\tapSF0901.sys [39104 2013-05-29] (Spotflux, Inc.)
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 Normandy; No ImagePath
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S3 RimUsb; System32\Drivers\RimUsb_AMD64.sys [x]
U3 aglyqkow; \??\C:\Users\Mohammad\AppData\Local\Temp\aglyqkow.sys [x]
==================== NetSvcs (Whitelisted) ===================
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-06-2013
Ran by [removed] (administrator) on 10-06-2013 03:57:24
Running from C:\Users\[removed]\Downloads
Windows Vista ™ Home Premium Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(AnchorFree Inc.) C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe
(AnchorFree Inc.) C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe
() C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe
(InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\PTCL\Common\RaRegistry.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\PTCL\Common\RaRegistry64.exe
(Intel Corporation) C:\Program Files\Sony\VAIO Care\collsvc.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe
(ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe
(Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
(Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESGfxMgr.exe
(Intel Corporation) C:\Windows\system32\igfxext.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Intel Corporation) C:\Program Files\Sony\VAIO Care\listener.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
(Conexant Systems, Inc.) C:\Windows\system32\DRIVERS\xaudio64.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe
(Safer Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Sony Corporation) C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
() C:\Program Files (x86)\Hotspot Shield\bin\openvpn.exe
(AnchorFree Inc.) C:\Program Files (x86)\Hotspot Shield\bin\af_proxy_cmd.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_6_602_171.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_6_602_171.exe
==================== Registry (Whitelisted) ==================
HKLM\…\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [6956576 2009-01-06] (Realtek Semiconductor)
HKLM\…\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1220392 2008-05-21] (Synaptics, Inc.)
HKCU\…\Run: [ISUSPM] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler [x]
MountPoints2: F - F:\AutoRun.exe
MountPoints2: {076fb6a0-714a-11e2-9917-001dbaf06e9b} - F:\urDrive.exe
MountPoints2: {243eb6eb-7bb1-11e0-bdf1-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {464e708f-aac4-11e0-b3dd-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {464e7093-aac4-11e0-b3dd-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {464e70d1-aac4-11e0-b3dd-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {464e70d3-aac4-11e0-b3dd-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {807975c6-d75c-11de-9ae1-001dbaf06e9b} - H:\LaunchU3.exe -a
MountPoints2: {80cd714b-cbab-11e0-9e09-001dbaf06e9b} - F:\Startme.exe
MountPoints2: {bc873d9d-cc3f-11e0-920a-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {bc873d9f-cc3f-11e0-920a-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {f56d0c52-ac3f-11e0-851b-806e6f6e6963} - F:\AutoRun.exe
HKLM-x32\…\Run: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe" [317288 2008-12-18] (Sony Corporation)
HKLM-x32\…\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49152 2007-10-14] (Hewlett-Packard)
HKLM-x32\…\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui [3451496 2011-02-23] (AVAST Software)
HKLM-x32\…\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot [202256 2010-08-09] (RealNetworks, Inc.)
HKLM-x32\…\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-01-28] (Apple Inc.)
HKLM-x32\…\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [946352 2012-12-19] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre7\bin\jusched.exe" [x]
HKU\Default\…\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter [2438656 2008-01-21] (Microsoft Corporation)
HKU\Default User\…\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter [2438656 2008-01-21] (Microsoft Corporation)
SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\System32\webcheck.dll (Microsoft Corporation)
SSODL-x32: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\SysWOW64\webcheck.dll (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
URLSearchHook: (No Name) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - No File
URLSearchHook: (No Name) - {f0381dbd-e018-4e07-ae40-d96ab15083f0} - No File
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={sea…ferrer:source?}
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={sea…ferrer:source?}
SearchScopes: HKLM-x32 - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL =
http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2765711
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL =
http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2765711
BHO: avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll ()
BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE_64.dll (AnchorFree Inc.)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited)
BHO-x32: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
BHO-x32: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
BHO-x32: AF-HSS Toolbar - {f0381dbd-e018-4e07-ae40-d96ab15083f0} - C:\Program Files (x86)\AF-HSS\prxtbAF-H.dll (Conduit Ltd.)
BHO-x32: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE.dll (AnchorFree Inc.)
BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll ()
Toolbar: HKLM-x32 - Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
Toolbar: HKLM-x32 - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
Toolbar: HKLM-x32 - AF-HSS Toolbar - {f0381dbd-e018-4e07-ae40-d96ab15083f0} - C:\Program Files (x86)\AF-HSS\prxtbAF-H.dll (Conduit Ltd.)
Toolbar: HKCU - No Name - {BA14329E-9550-4989-B3F2-9732E92D17CC} - No File
Toolbar: HKCU - No Name - {F0381DBD-E018-4E07-AE40-D96AB15083F0} - No File
DPF: HKLM-x32 {02CF1781-EA91-4FA5-A200-646E8241987C} http://esupport.sony.com/VaioInfo.CAB
DPF: HKLM-x32 {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab
DPF: HKLM-x32 {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
DPF: HKLM-x32 {DAF7E6E6-D53A-439A-B28D-12271406B8A9}
http://mobileapps.blackberry.com/devicesoftware/AxLoader.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler-x32: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 8.8.8.8
FireFox:
========
FF ProfilePath: C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_171.dll ()
FF Plugin: @java.com/DTPlugin,version=10.13.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.13.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_171.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF Plugin-x32: @divx.com/DivX OVS Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.7.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.7.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\3.0.50106.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=6.0.12.775 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprjplug;version=1.0.3.775 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprphtml5videoshim;version=1.0.0.0 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpjplug;version=6.0.12.775 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Adblock Plus Pop-up Addon - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\[removed]
FF Extension: YouTube to MP3 - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\[removed]
FF Extension: Zotero - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\[removed]
FF Extension: Zotero Word for Windows Integration - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\[removed]
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF Extension: No Name - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{48e23fba-bb14-4745-b768-382150cd83fb}
FF Extension: No Name - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{5B52016C-D097-4aec-BE61-9F129D8FDDBA}
FF Extension: Orthodox - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{6d677280-ddfe-11dc-95ff-0800200c9a66}
FF Extension: Zynga Toolbar - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
FF Extension: No Name - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}
FF Extension: AF-HSS - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{f0381dbd-e018-4e07-ae40-d96ab15083f0}
FF Extension: No Name - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
Chrome:
=======
CHR HomePage: hxxp://lums.edu.pk/
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (RealJukebox NS Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\nprjplug.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\nprpjplug.dll (RealNetworks, Inc.)
CHR Plugin: (Google Talk Plugin) - C:\Users\Mohammad\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
CHR Plugin: (Google Talk Plugin Video Accelerator) - C:\Users\Mohammad\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
CHR Plugin: (Google Talk Plugin Video Renderer) - C:\Users\Mohammad\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
CHR Plugin: (RIM Handheld Application Loader) - C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll No File
CHR Plugin: (DivX OVS Helper Plug-in) - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
CHR Plugin: (DivX Web Player) - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (Java™ Platform SE 7 U7) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Windows Live\u00AE Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (RealPlayer™ HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_171.dll ()
CHR Plugin: (Java Deployment Toolkit 7.0.70.11) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\3.0.50106.0\npctrl.dll ( Microsoft Corporation)
CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Extension: (Ge.tt) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdgghbbgmhcpidlmnepkbihehhkmjomc\0.99_0
CHR Extension: (NetCalc.org) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcfbbbolmblaajakigohdookklamneec\1_0
CHR Extension: (Facebook Nanny) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkpjofmdbabecniidggbbicfbcmfafmk\0.6.2_0
CHR Extension: (Dictionary Instant) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\hngaklbjlbjhmoilkegninbmpfigheol\2.0.0_0
CHR Extension: (WeatherBug) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihdkejbciahopmbagpnjmmkkdpfpaaak\2.0.5_0
CHR Extension: (PDF to Word Converter App) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\jclipofobaadknkadkpgggmjkebddjam\2.1_0
CHR Extension: (Any.DO) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdadialhpiikehpdeejjeiikopddkjem\1.0.3.3_0
CHR Extension: (Little Alchemy) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\knkapnclbofjjgicpkfoagdjohlfjhpd\0.0.15.7_0
CHR Extension: (Evernote Web) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol\1.0.7_0
CHR Extension: (Dropbox) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndbkiaijfjjjbejhcbcpkcpkcffjckga\1.0_0
CHR Extension: (Grooveshark Downloader) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\ooblpjoncpjmbncgocjlnannofkjjhnp\2.9.2_0
CHR Extension: (Gmail) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
==================== Services (Whitelisted) =================
S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [42184 2011-02-23] (AVAST Software)
S2 gupdate1c9e81a239f2659; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [133104 2009-06-08] (Google Inc.)
R2 hshld; C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe [534824 2013-01-23] (AnchorFree Inc.)
S3 HssTrayService; C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE [78512 2013-01-20] ()
R2 HssWd; C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe [389928 2013-01-23] ()
S3 PACSPTISVR; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\PACSPTISVR.exe [114688 2009-01-08] (Sony Corporation)
R2 RalinkRegistryWriter; C:\Program Files (x86)\PTCL\Common\RaRegistry.exe [185632 2009-10-26] (Ralink Technology, Corp.)
R2 RalinkRegistryWriter64; C:\Program Files (x86)\PTCL\Common\RaRegistry64.exe [211232 2009-10-26] (Ralink Technology, Corp.)
R2 SampleCollector; C:\Program Files\Sony\VAIO Care\collsvc.exe [167424 2008-09-30] (Intel Corporation)
R2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
R2 SOHDBSvr; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [70952 2009-01-20] (Sony Corporation)
R2 SOHPlMgr; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [91432 2009-01-20] (Sony Corporation)
R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.)
S3 VAIO Entertainment TV Device Arbitration Service; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [69632 2009-01-21] (Sony Corporation)
R3 Vcsw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [313264 2009-01-21] (Sony Corporation)
R2 VzCdbSvc; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [192512 2009-01-21] (Sony Corporation)
S3 msiserver; %systemroot%\system32\msiexec /V [x]
S2 RoxLiveShare9; "C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe" [x]
==================== Drivers (Whitelisted) ====================
R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2008-04-25] (ArcSoft, Inc.)
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [22360 2011-02-23] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [64344 2011-02-23] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswRdr.sys [31064 2011-02-23] (AVAST Software)
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [505176 2011-02-23] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [280408 2011-02-23] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [53592 2011-02-23] (AVAST Software)
S3 dgderdrv; C:\Windows\System32\drivers\dgderdrv.sys [20568 2009-12-22] (Devguru Co., Ltd)
S1 DMICall; C:\Windows\SysWow64\DRIVERS\DMICall.sys [10216 2008-11-25] (Sony Corporation)
R1 HssDRV6; C:\Windows\System32\DRIVERS\hssdrv6.sys [42696 2013-01-20] (AnchorFree Inc.)
S3 RimVSerPort; C:\Windows\System32\DRIVERS\RimSerial_AMD64.sys [31744 2009-01-09] (Research in Motion Ltd)
R2 risdptsk; C:\Windows\System32\DRIVERS\risdsn64.sys [76288 2008-10-23] (REDC)
S3 s0016bus; C:\Windows\System32\DRIVERS\s0016bus.sys [115240 2008-05-16] (MCCI Corporation)
S3 s0016mdfl; C:\Windows\System32\DRIVERS\s0016mdfl.sys [19496 2008-05-16] (MCCI Corporation)
S3 s0016mdm; C:\Windows\System32\DRIVERS\s0016mdm.sys [158760 2008-05-16] (MCCI Corporation)
S3 s0016mgmt; C:\Windows\System32\DRIVERS\s0016mgmt.sys [137256 2008-05-16] (MCCI Corporation)
S3 s0016nd5; C:\Windows\System32\DRIVERS\s0016nd5.sys [34344 2008-05-16] (MCCI Corporation)
S3 s0016obex; C:\Windows\System32\DRIVERS\s0016obex.sys [136744 2008-05-16] (MCCI Corporation)
S3 s0016unic; C:\Windows\System32\DRIVERS\s0016unic.sys [151592 2008-05-16] (MCCI Corporation)
R3 seehcri; C:\Windows\System32\DRIVERS\seehcri.sys [34032 2008-01-09] (Sony Ericsson Mobile Communications)
R3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42328 2013-01-05] (Anchorfree Inc.)
R3 tapSF0901; C:\Windows\System32\DRIVERS\tapSF0901.sys [39104 2013-05-29] (Spotflux, Inc.)
S1 DMICall; system32\DRIVERS\DMICall.sys [x]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
U4 mbamswissarmy;
S3 Normandy; No ImagePath
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S3 RimUsb; System32\Drivers\RimUsb_AMD64.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-06-10 03:56 - 2013-06-10 03:56 - 01919988 ____A (Farbar) C:\Users\Mohammad\Downloads\FRST64.exe
2013-06-10 01:32 - 2013-06-10 03:41 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-06-10 01:28 - 2013-06-10 03:41 - 00000000 ____D C:\Users\Mohammad\Desktop\mbar
2013-06-10 01:25 - 2013-06-10 01:27 - 13169742 ____A C:\Users\Mohammad\Downloads\mbar-1.06.0.1003.zip
2013-06-09 23:33 - 2013-06-09 23:33 - 00000000 ____D C:\Users\Mohammad\AppData\Local\Macromedia
2013-06-09 23:17 - 2013-06-09 23:17 - 00000000 ____D C:\ProgramData\Mozilla
2013-06-09 23:17 - 2013-06-09 23:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-06-09 21:16 - 2013-06-09 21:16 - 00000000 ____D C:\FRST
2013-06-09 18:20 - 2013-06-09 18:20 - 00000000 ____D C:\Users\Mohammad\Desktop\Juris proj
2013-06-09 17:16 - 2013-06-09 17:16 - 00000000 ____D C:\Users\Mohammad\AppData\Local\Apple Computer
2013-06-09 17:16 - 2013-06-09 17:16 - 00000000 ____D C:\Users\Mohammad\AppData\Local\Apple
2013-06-09 16:55 - 2013-06-10 01:26 - 00001205 ____A C:\Users\Mohammad\Desktop\instructions.txt
2013-06-09 16:52 - 2013-06-09 17:41 - 00000000 ____D C:\Users\Mohammad\AppData\Local\Adobe
2013-06-09 16:51 - 2013-06-09 16:52 - 01919210 ____A (Farbar) C:\Users\Mohammad\Desktop\FRST64.exe
2013-06-09 16:51 - 2013-04-04 09:55 - 00377856 ____A C:\Users\Mohammad\Desktop\gmer.exe
2013-06-09 16:50 - 2013-06-09 16:51 - 00368554 ____A C:\Users\Mohammad\Desktop\gmer.zip
2013-06-09 03:13 - 2013-06-09 03:13 - 00000770 ____A C:\Users\Public\Desktop\CCleaner.lnk
2013-06-09 03:12 - 2013-06-09 03:13 - 00000000 ____D C:\Program Files\CCleaner
2013-06-09 02:08 - 2013-06-09 02:08 - 00602112 ____A (OldTimer Tools) C:\Users\Mohammad\Desktop\OTL.exe
2013-06-09 01:04 - 2013-06-09 01:05 - 00388608 ____A (Trend Micro Inc.) C:\Users\Mohammad\Desktop\HiJackThis.exe
2013-06-09 00:47 - 2013-06-09 00:47 - 00000000 ____D C:\Program Files (x86)\ESET
2013-06-09 00:46 - 2013-06-09 00:46 - 02347384 ____A (ESET) C:\Users\Mohammad\Desktop\esetsmartinstaller_enu.exe
2013-06-08 14:59 - 2013-06-08 23:56 - 00000000 ____D C:\Users\Mohammad\AppData\Roaming\Nico Mak Computing
2013-06-08 14:59 - 2013-06-08 23:05 - 00000310 ____A C:\Windows\Tasks\Registry Optimizer_UPDATES.job
2013-06-08 14:59 - 2013-06-08 15:01 - 00000302 ____A C:\Windows\Tasks\Registry Optimizer_DEFAULT.job
2013-06-08 14:59 - 2013-02-13 11:07 - 00019840 ____A (WinZip Computing, S.L.(WinZip Computing)) C:\Windows\System32\roboot64.exe
2013-06-08 14:58 - 2013-06-08 14:58 - 05594104 ____A C:\Users\Mohammad\Downloads\spotflux-latestPC (1).exe
2013-06-08 14:58 - 2013-06-08 14:58 - 00000000 ____D C:\Program Files (x86)\Spotflux
2013-06-08 14:26 - 2013-06-08 14:26 - 00287208 ____A C:\Users\Mohammad\Downloads\GroovesharkDownloader.crx
2013-06-08 01:33 - 2013-06-08 01:33 - 02000488 ____A C:\Users\Mohammad\Downloads\U1301.exe
2013-06-07 11:34 - 2013-06-08 14:55 - 00000000 ____D C:\Users\Mohammad\Downloads\utmp
2013-05-29 04:12 - 2013-05-29 04:12 - 00039104 ____A (Spotflux, Inc.) C:\Windows\System32\Drivers\tapSF0901.sys
2013-05-18 23:00 - 2013-05-18 23:00 - 00001882 ____A C:\Users\Public\Desktop\Adobe Reader XI.lnk
2013-05-18 22:52 - 2013-05-18 22:55 - 50363976 ____A (Adobe Systems Incorporated) C:\Users\Mohammad\Downloads\AdbeRdr11002_en_US.exe
==================== One Month Modified Files and Folders =======
2013-06-10 03:56 - 2013-06-10 03:56 - 01919988 ____A (Farbar) C:\Users\Mohammad\Downloads\FRST64.exe
2013-06-10 03:41 - 2013-06-10 01:32 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-06-10 03:41 - 2013-06-10 01:28 - 00000000 ____D C:\Users\Mohammad\Desktop\mbar
2013-06-10 03:38 - 2009-10-12 22:47 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-10 03:17 - 2011-05-06 19:30 - 00000920 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2874463723-3708051865-952906006-1000UA.job
2013-06-10 03:08 - 2009-07-02 02:06 - 01877973 ____A C:\Windows\WindowsUpdate.log
2013-06-10 02:58 - 2009-10-12 22:47 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-10 02:58 - 2006-11-02 20:42 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-10 02:57 - 2006-11-02 20:22 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-10 02:57 - 2006-11-02 20:22 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-10 02:56 - 2006-11-02 20:42 - 00032552 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-06-10 02:55 - 2011-04-11 12:34 - 00045096 ____A C:\Windows\System32\spsys.log
2013-06-10 02:54 - 2008-01-21 08:26 - 00282782 ____A C:\Windows\PFRO.log
2013-06-10 02:51 - 2012-10-21 16:33 - 00000000 ____D C:\Users\Mohammad\AppData\Roaming\Dropbox
2013-06-10 02:45 - 2011-11-23 16:31 - 00000940 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2874463723-3708051865-952906006-1000UA.job
2013-06-10 01:27 - 2013-06-10 01:25 - 13169742 ____A C:\Users\Mohammad\Downloads\mbar-1.06.0.1003.zip
2013-06-10 01:26 - 2013-06-09 16:55 - 00001205 ____A C:\Users\Mohammad\Desktop\instructions.txt
2013-06-10 01:17 - 2011-05-06 19:30 - 00000868 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2874463723-3708051865-952906006-1000Core.job
2013-06-09 23:45 - 2011-11-23 16:31 - 00000918 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2874463723-3708051865-952906006-1000Core.job
2013-06-09 23:39 - 2012-10-21 16:40 - 00000000 ___RD C:\Users\Mohammad\Dropbox
2013-06-09 23:33 - 2013-06-09 23:33 - 00000000 ____D C:\Users\Mohammad\AppData\Local\Macromedia
2013-06-09 23:17 - 2013-06-09 23:17 - 00000000 ____D C:\ProgramData\Mozilla
2013-06-09 23:17 - 2013-06-09 23:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-06-09 23:17 - 2009-10-28 22:09 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-06-09 21:16 - 2013-06-09 21:16 - 00000000 ____D C:\FRST
2013-06-09 19:44 - 2013-02-13 23:53 - 00000000 ____D C:\Users\Mohammad\AppData\Roaming\.spotflux
2013-06-09 18:20 - 2013-06-09 18:20 - 00000000 ____D C:\Users\Mohammad\Desktop\Juris proj
2013-06-09 17:41 - 2013-06-09 16:52 - 00000000 ____D C:\Users\Mohammad\AppData\Local\Adobe
2013-06-09 17:16 - 2013-06-09 17:16 - 00000000 ____D C:\Users\Mohammad\AppData\Local\Apple Computer
2013-06-09 17:16 - 2013-06-09 17:16 - 00000000 ____D C:\Users\Mohammad\AppData\Local\Apple
2013-06-09 16:52 - 2013-06-09 16:51 - 01919210 ____A (Farbar) C:\Users\Mohammad\Desktop\FRST64.exe
2013-06-09 16:51 - 2013-06-09 16:50 - 00368554 ____A C:\Users\Mohammad\Desktop\gmer.zip
2013-06-09 03:13 - 2013-06-09 03:13 - 00000770 ____A C:\Users\Public\Desktop\CCleaner.lnk
2013-06-09 03:13 - 2013-06-09 03:12 - 00000000 ____D C:\Program Files\CCleaner
2013-06-09 02:08 - 2013-06-09 02:08 - 00602112 ____A (OldTimer Tools) C:\Users\Mohammad\Desktop\OTL.exe
2013-06-09 01:05 - 2013-06-09 01:04 - 00388608 ____A (Trend Micro Inc.) C:\Users\Mohammad\Desktop\HiJackThis.exe
2013-06-09 00:47 - 2013-06-09 00:47 - 00000000 ____D C:\Program Files (x86)\ESET
2013-06-09 00:46 - 2013-06-09 00:46 - 02347384 ____A (ESET) C:\Users\Mohammad\Desktop\esetsmartinstaller_enu.exe
2013-06-08 23:56 - 2013-06-08 14:59 - 00000000 ____D C:\Users\Mohammad\AppData\Roaming\Nico Mak Computing
2013-06-08 23:05 - 2013-06-08 14:59 - 00000310 ____A C:\Windows\Tasks\Registry Optimizer_UPDATES.job
2013-06-08 15:01 - 2013-06-08 14:59 - 00000302 ____A C:\Windows\Tasks\Registry Optimizer_DEFAULT.job
2013-06-08 14:58 - 2013-06-08 14:58 - 05594104 ____A C:\Users\Mohammad\Downloads\spotflux-latestPC (1).exe
2013-06-08 14:58 - 2013-06-08 14:58 - 00000000 ____D C:\Program Files (x86)\Spotflux
2013-06-08 14:55 - 2013-06-07 11:34 - 00000000 ____D C:\Users\Mohammad\Downloads\utmp
2013-06-08 14:48 - 2010-05-26 02:26 - 00000600 ____A C:\Users\Mohammad\PUTTY.RND
2013-06-08 14:47 - 2009-10-18 21:51 - 00000000 ____D C:\Users\Mohammad\AppData\Roaming\Mozilla
2013-06-08 14:26 - 2013-06-08 14:26 - 00287208 ____A C:\Users\Mohammad\Downloads\GroovesharkDownloader.crx
2013-06-08 01:33 - 2013-06-08 01:33 - 02000488 ____A C:\Users\Mohammad\Downloads\U1301.exe
2013-06-07 11:35 - 2012-09-22 22:07 - 00000213 ____A C:\Users\Mohammad\Downloads\u.ini
2013-06-07 00:28 - 2009-10-12 09:27 - 00000000 ____D C:\users\Mohammad
2013-05-29 04:12 - 2013-05-29 04:12 - 00039104 ____A (Spotflux, Inc.) C:\Windows\System32\Drivers\tapSF0901.sys
2013-05-27 02:28 - 2009-10-12 09:27 - 00079232 ____A C:\Users\Mohammad\AppData\Local\GDIPFONTCACHEV1.DAT
2013-05-27 02:27 - 2006-11-02 20:21 - 00330256 ____A C:\Windows\System32\FNTCACHE.DAT
2013-05-26 18:54 - 2009-10-12 10:16 - 00167936 ____A C:\Users\Mohammad\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-05-26 18:48 - 2009-04-10 08:49 - 00000000 ____D C:\Program Files (x86)\Java
2013-05-26 17:57 - 2010-08-27 18:30 - 00000000 ____D C:\Users\Mohammad\AppData\Roaming\Barnes & Noble
2013-05-26 17:57 - 2010-08-27 18:30 - 00000000 ____D C:\Program Files (x86)\Barnes & Noble
2013-05-26 17:55 - 2010-01-20 00:04 - 00000000 ____D C:\ProgramData\Roxio
2013-05-26 17:55 - 2009-06-08 15:16 - 00000000 ____D C:\Program Files (x86)\Roxio
2013-05-26 17:47 - 2010-01-19 21:03 - 00000000 ____D C:\Users\Mohammad\AppData\Roaming\Research In Motion
2013-05-18 23:03 - 2009-06-08 14:28 - 00000000 ____D C:\ProgramData\Adobe
2013-05-18 23:01 - 2009-10-12 22:50 - 00000000 ____D C:\Users\Mohammad\AppData\Roaming\Adobe
2013-05-18 23:00 - 2013-05-18 23:00 - 00001882 ____A C:\Users\Public\Desktop\Adobe Reader XI.lnk
2013-05-18 22:59 - 2009-06-08 14:28 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-05-18 22:55 - 2013-05-18 22:52 - 50363976 ____A (Adobe Systems Incorporated) C:\Users\Mohammad\Downloads\AdbeRdr11002_en_US.exe
2013-05-11 01:00 - 2011-07-11 16:07 - 01573503 ____A C:\Users\Mohammad\Downloads\DashboardInstaller.rar
2013-05-11 00:57 - 2012-10-21 15:58 - 00000000 ___SD C:\Users\Mohammad\Google Drive
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-06-10 03:36
==================== End Of Log ============================
There was no Addition.txt after the first scan :S