This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

WinZip Registry Optimizer virus [Solved]

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi! This program appeared on my computer out of nowhere today and started running scans. I hadn't installed it so I googled it. Apparently there's a legitimate version and a virus version of the program. I figure it's a virus.

I followed the first two steps of this guide, basically just uninstalling it through control panel, but I did not want to mess around with the registry values like it said without some expert advice. I doubt all traces of the program have been completely erased.

Additionally spybot also keeps pulling up adware that it can't remove. I would really appreciate some help as my laptop has become a little slow as a result?

I have Windows Vista 64 bit on Sony Vaio

Here's the log from Hijack This:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:15:19 AM, on 6/9/2013
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18928)
Boot mode: Normal

Running processes:
C:\Program Files\Sony\VAIO Care\listener.exe
C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Mohammad\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll
R3 - URLSearchHook: AF-HSS Toolbar - {f0381dbd-e018-4e07-ae40-d96ab15083f0} - C:\Program Files (x86)\AF-HSS\prxtbAF-H.dll
F2 - REG:system.ini: UserInit=userinit.exe,
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll
O2 - BHO: AF-HSS - {f0381dbd-e018-4e07-ae40-d96ab15083f0} - C:\Program Files (x86)\AF-HSS\prxtbAF-H.dll
O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: AF-HSS Toolbar - {f0381dbd-e018-4e07-ae40-d96ab15083f0} - C:\Program Files (x86)\AF-HSS\prxtbAF-H.dll
O4 - HKLM\..\Run: [RegistrationReminder] "C:\Program Files\Sony\First Experience\OOBEFcdRegistration.exe"
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre7\bin\jusched.exe"
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [Google Update] "C:\Users\Mohammad\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/dow…llerControl.cab
O16 - DPF: {02CF1781-EA91-4FA5-A200-646E8241987C} (VaioInfo.CMClass) - http://esupport.sony.com/VaioInfo.CAB
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {DAF7E6E6-D53A-439A-B28D-12271406B8A9} (RIM AxLoader) - http://mobileapps.blackberry.com/devicesoftware/AxLoader.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: Google Update Service (gupdate1c9e81a239f2659) (gupdate1c9e81a239f2659) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Hotspot Shield Service (hshld) - AnchorFree Inc. - C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe
O23 - Service: Hotspot Shield Routing Service (HssSrv) - AnchorFree Inc. - C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe
O23 - Service: Hotspot Shield Tray Service (HssTrayService) - Unknown owner - C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE
O23 - Service: Hotspot Shield Monitoring Service (HssWd) - Unknown owner - C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Ralink Registry Writer (RalinkRegistryWriter) - Ralink Technology, Corp. - C:\Program Files (x86)\PTCL\Common\RaRegistry.exe
O23 - Service: Ralink Registry Writer 64 (RalinkRegistryWriter64) - Ralink Technology, Corp. - C:\Program Files (x86)\PTCL\Common\RaRegistry64.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Intel® Sample Collector (SampleCollector) - Intel Corporation - C:\Program Files\Sony\VAIO Care\collsvc.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: VAIO Media plus Content Importer (SOHCImp) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe
O23 - Service: VAIO Media plus Database Manager (SOHDBSvr) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe
O23 - Service: VAIO Media plus Digital Media Server (SOHDms) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe
O23 - Service: VAIO Media plus Device Searcher (SOHDs) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe
O23 - Service: VAIO Media plus Playlist Manager (SOHPlMgr) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Power Management - Sony Corporation - C:\Program Files\Sony\VAIO Power Management\SPMService.exe
O23 - Service: VAIO Content Folder Watcher (VCFw) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XAudioService - Unknown owner - C:\Windows\system32\DRIVERS\xaudio64.exe (file missing)

–
End of file - 14653 bytes
Hi there,
my name is Marius and I will be assisting you with your Malware related problems.

Before we move on, please read the following points carefully.
  • First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while you are follow my instructions, Stop there and tell me the exact nature of your problem.
  • Do not run any other scans without instruction or Add/ Remove Software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
  • Post all Logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.




Download GMER Rootkit Scanner from here or here. Unzip it to your Desktop.

========================================================

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

========================================================


Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any "<— ROOKIT" entries unless advised by a trained Security Analyst


If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click Yes.
  • Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop.
If you do not receive notice about possible rootkit activity remain on the Rootkit/Malware tab & make sure the 'Show All' button is unticked.
  • Click the Scan button and let the program do its work. GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop.
Pleae attach the gmer.txt to your reply:
  • Click the[Manage Attachments] button under Additional Options > Attach Files on the post composition page, browse to where you saved the file, and
  • Click Upload.





Please download Farbar's Recovery Scan Tool to your desktop: FRST 32bit or FRST 64bit (If not sure: Start –> Computer (right click) –> properties)

  • Run FRST.
  • Don´t change one of the checkboxes and hit Scan.
  • Logfiles are created on your desktop.
  • Poste the FRST.txt and (after the first scan only!) the Addition.txt.
Hi Marius!
Thanks for your reply! :)

I followed your instructions and ran GMER. No rootkit activity was found and Show All was unchecked. So I hit scan.. when it was done I tried to save it but no window would pop up for some reason. I clicked the copy button then and copied the contents on to a .txt file which is attached.

Here is FRST.txt after the first scan:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-06-2013
Ran by [removed] (administrator) on 09-06-2013 21:16:39
Running from C:\Users\[removed]\Desktop
Windows Vista ™ Home Premium Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(AnchorFree Inc.) C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe
(Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AnchorFree Inc.) C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
() C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe
(InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\PTCL\Common\RaRegistry.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\PTCL\Common\RaRegistry64.exe
(Intel Corporation) C:\Program Files\Sony\VAIO Care\collsvc.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe
(ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe
(Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
(Conexant Systems, Inc.) C:\Windows\system32\DRIVERS\xaudio64.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
(Safer Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
(Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESGfxMgr.exe
(Intel Corporation) C:\Windows\system32\igfxext.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Sony Corporation) C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Program Files\Sony\VAIO Care\listener.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe

==================== Registry (Whitelisted) ==================

HKLM\…\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [6956576 2009-01-06] (Realtek Semiconductor)
HKLM\…\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1220392 2008-05-21] (Synaptics, Inc.)
HKCU\…\Run: [ISUSPM] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler [x]
MountPoints2: F - F:\AutoRun.exe
MountPoints2: {076fb6a0-714a-11e2-9917-001dbaf06e9b} - F:\urDrive.exe
MountPoints2: {243eb6eb-7bb1-11e0-bdf1-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {464e708f-aac4-11e0-b3dd-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {464e7093-aac4-11e0-b3dd-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {464e70d1-aac4-11e0-b3dd-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {464e70d3-aac4-11e0-b3dd-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {807975c6-d75c-11de-9ae1-001dbaf06e9b} - H:\LaunchU3.exe -a
MountPoints2: {80cd714b-cbab-11e0-9e09-001dbaf06e9b} - F:\Startme.exe
MountPoints2: {bc873d9d-cc3f-11e0-920a-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {bc873d9f-cc3f-11e0-920a-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {f56d0c52-ac3f-11e0-851b-806e6f6e6963} - F:\AutoRun.exe
HKLM-x32\…\Run: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe" [317288 2008-12-18] (Sony Corporation)
HKLM-x32\…\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49152 2007-10-14] (Hewlett-Packard)
HKLM-x32\…\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui [3451496 2011-02-23] (AVAST Software)
HKLM-x32\…\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot [202256 2010-08-09] (RealNetworks, Inc.)
HKLM-x32\…\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-01-28] (Apple Inc.)
HKLM-x32\…\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [946352 2012-12-19] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre7\bin\jusched.exe" [x]
HKU\Default\…\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter [2438656 2008-01-21] (Microsoft Corporation)
HKU\Default User\…\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter [2438656 2008-01-21] (Microsoft Corporation)
SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\System32\webcheck.dll (Microsoft Corporation)
SSODL-x32: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\SysWOW64\webcheck.dll (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

URLSearchHook: (No Name) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - No File
URLSearchHook: (No Name) - {f0381dbd-e018-4e07-ae40-d96ab15083f0} - No File
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={sea…ferrer:source?}
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={sea…ferrer:source?}
SearchScopes: HKLM-x32 - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2765711
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2765711
BHO: avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll ()
BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE_64.dll (AnchorFree Inc.)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited)
BHO-x32: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
BHO-x32: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
BHO-x32: AF-HSS Toolbar - {f0381dbd-e018-4e07-ae40-d96ab15083f0} - C:\Program Files (x86)\AF-HSS\prxtbAF-H.dll (Conduit Ltd.)
BHO-x32: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE.dll (AnchorFree Inc.)
BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll ()
Toolbar: HKLM-x32 - Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
Toolbar: HKLM-x32 - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
Toolbar: HKLM-x32 - AF-HSS Toolbar - {f0381dbd-e018-4e07-ae40-d96ab15083f0} - C:\Program Files (x86)\AF-HSS\prxtbAF-H.dll (Conduit Ltd.)
Toolbar: HKCU - No Name - {BA14329E-9550-4989-B3F2-9732E92D17CC} - No File
Toolbar: HKCU - No Name - {F0381DBD-E018-4E07-AE40-D96AB15083F0} - No File
DPF: HKLM-x32 {02CF1781-EA91-4FA5-A200-646E8241987C} http://esupport.sony.com/VaioInfo.CAB
DPF: HKLM-x32 {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab
DPF: HKLM-x32 {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
DPF: HKLM-x32 {DAF7E6E6-D53A-439A-B28D-12271406B8A9} http://mobileapps.blackberry.com/devicesoftware/AxLoader.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler-x32: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt

FireFox:
========
FF ProfilePath: C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default
FF Homepage: hxxp://search.conduit.com/?ctid=CT1572363&SearchSource;=13
FF NetworkProxy: "http", "localhost"
FF NetworkProxy: "http_port", 9666
FF NetworkProxy: "socks", "localhost"
FF NetworkProxy: "socks_port", 9050
FF NetworkProxy: "socks_remote_dns", true
FF NetworkProxy: "ssl", "localhost"
FF NetworkProxy: "ssl_port", 9666
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_171.dll ()
FF Plugin: @java.com/DTPlugin,version=10.13.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.13.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_171.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF Plugin-x32: @divx.com/DivX OVS Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.7.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.7.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\3.0.50106.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=6.0.12.775 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprjplug;version=1.0.3.775 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprphtml5videoshim;version=1.0.0.0 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpjplug;version=6.0.12.775 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Adblock Plus Pop-up Addon - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\[removed]
FF Extension: YouTube to MP3 - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\[removed]
FF Extension: Zotero - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\[removed]
FF Extension: Zotero Word for Windows Integration - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\[removed]
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF Extension: No Name - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{48e23fba-bb14-4745-b768-382150cd83fb}
FF Extension: No Name - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{5B52016C-D097-4aec-BE61-9F129D8FDDBA}
FF Extension: Orthodox - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{6d677280-ddfe-11dc-95ff-0800200c9a66}
FF Extension: NoScript - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
FF Extension: Zynga Toolbar - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
FF Extension: No Name - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
FF Extension: No Name - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}
FF Extension: AF-HSS - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{f0381dbd-e018-4e07-ae40-d96ab15083f0}

Chrome:
=======
CHR HomePage: hxxp://lums.edu.pk/
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (RealJukebox NS Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\nprjplug.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\nprpjplug.dll (RealNetworks, Inc.)
CHR Plugin: (Google Talk Plugin) - C:\Users\Mohammad\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
CHR Plugin: (Google Talk Plugin Video Accelerator) - C:\Users\Mohammad\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
CHR Plugin: (Google Talk Plugin Video Renderer) - C:\Users\Mohammad\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
CHR Plugin: (RIM Handheld Application Loader) - C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll No File
CHR Plugin: (DivX OVS Helper Plug-in) - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
CHR Plugin: (DivX Web Player) - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (Java™ Platform SE 7 U7) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Windows Live\u00AE Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (RealPlayer™ HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_171.dll ()
CHR Plugin: (Java Deployment Toolkit 7.0.70.11) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\3.0.50106.0\npctrl.dll ( Microsoft Corporation)
CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Extension: (Ge.tt) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdgghbbgmhcpidlmnepkbihehhkmjomc\0.99_0
CHR Extension: (NetCalc.org) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcfbbbolmblaajakigohdookklamneec\1_0
CHR Extension: (Facebook Nanny) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkpjofmdbabecniidggbbicfbcmfafmk\0.6.2_0
CHR Extension: (Dictionary Instant) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\hngaklbjlbjhmoilkegninbmpfigheol\1.0.22_0
CHR Extension: (WeatherBug) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihdkejbciahopmbagpnjmmkkdpfpaaak\2.0.5_0
CHR Extension: (PDF to Word Converter App) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\jclipofobaadknkadkpgggmjkebddjam\2.1_0
CHR Extension: (Any.DO) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdadialhpiikehpdeejjeiikopddkjem\1.0.3.3_0
CHR Extension: (Little Alchemy) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\knkapnclbofjjgicpkfoagdjohlfjhpd\0.0.15.7_0
CHR Extension: (Evernote Web) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol\1.0.7_0
CHR Extension: (Dropbox) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndbkiaijfjjjbejhcbcpkcpkcffjckga\1.0_0
CHR Extension: (Grooveshark Downloader) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\ooblpjoncpjmbncgocjlnannofkjjhnp\2.9.2_0
CHR Extension: (Gmail) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0

==================== Services (Whitelisted) =================

S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [42184 2011-02-23] (AVAST Software)
S2 gupdate1c9e81a239f2659; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [133104 2009-06-08] (Google Inc.)
R2 hshld; C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe [534824 2013-01-23] (AnchorFree Inc.)
S3 HssTrayService; C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE [78512 2013-01-20] ()
R2 HssWd; C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe [389928 2013-01-23] ()
S3 PACSPTISVR; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\PACSPTISVR.exe [114688 2009-01-08] (Sony Corporation)
R2 RalinkRegistryWriter; C:\Program Files (x86)\PTCL\Common\RaRegistry.exe [185632 2009-10-26] (Ralink Technology, Corp.)
R2 RalinkRegistryWriter64; C:\Program Files (x86)\PTCL\Common\RaRegistry64.exe [211232 2009-10-26] (Ralink Technology, Corp.)
R2 SampleCollector; C:\Program Files\Sony\VAIO Care\collsvc.exe [167424 2008-09-30] (Intel Corporation)
R2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
R2 SOHDBSvr; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [70952 2009-01-20] (Sony Corporation)
R2 SOHPlMgr; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [91432 2009-01-20] (Sony Corporation)
R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.)
S3 VAIO Entertainment TV Device Arbitration Service; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [69632 2009-01-21] (Sony Corporation)
R3 Vcsw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [313264 2009-01-21] (Sony Corporation)
R2 VzCdbSvc; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [192512 2009-01-21] (Sony Corporation)
S3 msiserver; %systemroot%\system32\msiexec /V [x]
S2 RoxLiveShare9; "C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe" [x]

==================== Drivers (Whitelisted) ====================

R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2008-04-25] (ArcSoft, Inc.)
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [22360 2011-02-23] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [64344 2011-02-23] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswRdr.sys [31064 2011-02-23] (AVAST Software)
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [505176 2011-02-23] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [280408 2011-02-23] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [53592 2011-02-23] (AVAST Software)
S3 dgderdrv; C:\Windows\System32\drivers\dgderdrv.sys [20568 2009-12-22] (Devguru Co., Ltd)
S1 DMICall; C:\Windows\SysWow64\DRIVERS\DMICall.sys [10216 2008-11-25] (Sony Corporation)
R1 HssDRV6; C:\Windows\System32\DRIVERS\hssdrv6.sys [42696 2013-01-20] (AnchorFree Inc.)
S3 RimVSerPort; C:\Windows\System32\DRIVERS\RimSerial_AMD64.sys [31744 2009-01-09] (Research in Motion Ltd)
R2 risdptsk; C:\Windows\System32\DRIVERS\risdsn64.sys [76288 2008-10-23] (REDC)
S3 s0016bus; C:\Windows\System32\DRIVERS\s0016bus.sys [115240 2008-05-16] (MCCI Corporation)
S3 s0016mdfl; C:\Windows\System32\DRIVERS\s0016mdfl.sys [19496 2008-05-16] (MCCI Corporation)
S3 s0016mdm; C:\Windows\System32\DRIVERS\s0016mdm.sys [158760 2008-05-16] (MCCI Corporation)
S3 s0016mgmt; C:\Windows\System32\DRIVERS\s0016mgmt.sys [137256 2008-05-16] (MCCI Corporation)
S3 s0016nd5; C:\Windows\System32\DRIVERS\s0016nd5.sys [34344 2008-05-16] (MCCI Corporation)
S3 s0016obex; C:\Windows\System32\DRIVERS\s0016obex.sys [136744 2008-05-16] (MCCI Corporation)
S3 s0016unic; C:\Windows\System32\DRIVERS\s0016unic.sys [151592 2008-05-16] (MCCI Corporation)
R3 seehcri; C:\Windows\System32\DRIVERS\seehcri.sys [34032 2008-01-09] (Sony Ericsson Mobile Communications)
R3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42328 2013-01-05] (Anchorfree Inc.)
R3 tapSF0901; C:\Windows\System32\DRIVERS\tapSF0901.sys [39104 2013-05-29] (Spotflux, Inc.)
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 Normandy; No ImagePath
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S3 RimUsb; System32\Drivers\RimUsb_AMD64.sys [x]
U3 aglyqkow; \??\C:\Users\Mohammad\AppData\Local\Temp\aglyqkow.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-06-09 21:16 - 2013-06-09 21:16 - 00000000 ____D C:\FRST
2013-06-09 21:15 - 2013-06-09 21:15 - 00526368 ____A C:\Users\Mohammad\Desktop\GMER.txt
2013-06-09 18:38 - 2013-06-09 19:54 - 00000578 ____A C:\Users\Mohammad\Desktop\Emad.html
2013-06-09 18:20 - 2013-06-09 18:20 - 00000000 ____D C:\Users\Mohammad\Desktop\Juris proj
2013-06-09 17:16 - 2013-06-09 17:16 - 00000000 ____D C:\Users\Mohammad\AppData\Local\Apple Computer
2013-06-09 17:16 - 2013-06-09 17:16 - 00000000 ____D C:\Users\Mohammad\AppData\Local\Apple
2013-06-09 16:55 - 2013-06-09 16:55 - 00002058 ____A C:\Users\Mohammad\Desktop\instructions.txt
2013-06-09 16:52 - 2013-06-09 17:41 - 00000000 ____D C:\Users\Mohammad\AppData\Local\Adobe
2013-06-09 16:51 - 2013-06-09 16:52 - 01919210 ____A (Farbar) C:\Users\Mohammad\Desktop\FRST64.exe
2013-06-09 16:51 - 2013-04-04 09:55 - 00377856 ____A C:\Users\Mohammad\Desktop\gmer.exe
2013-06-09 16:50 - 2013-06-09 16:51 - 00368554 ____A C:\Users\Mohammad\Desktop\gmer.zip
2013-06-09 03:13 - 2013-06-09 03:13 - 00000770 ____A C:\Users\Public\Desktop\CCleaner.lnk
2013-06-09 03:12 - 2013-06-09 03:13 - 00000000 ____D C:\Program Files\CCleaner
2013-06-09 02:08 - 2013-06-09 02:08 - 00602112 ____A (OldTimer Tools) C:\Users\Mohammad\Desktop\OTL.exe
2013-06-09 01:15 - 2013-06-09 01:15 - 00014655 ____A C:\Users\Mohammad\Desktop\hijackthis.log
2013-06-09 01:04 - 2013-06-09 01:05 - 00388608 ____A (Trend Micro Inc.) C:\Users\Mohammad\Desktop\HiJackThis.exe
2013-06-09 00:47 - 2013-06-09 00:47 - 00000000 ____D C:\Program Files (x86)\ESET
2013-06-09 00:46 - 2013-06-09 00:46 - 02347384 ____A (ESET) C:\Users\Mohammad\Desktop\esetsmartinstaller_enu.exe
2013-06-08 14:59 - 2013-06-08 23:56 - 00000000 ____D C:\Users\Mohammad\AppData\Roaming\Nico Mak Computing
2013-06-08 14:59 - 2013-06-08 23:05 - 00000310 ____A C:\Windows\Tasks\Registry Optimizer_UPDATES.job
2013-06-08 14:59 - 2013-06-08 15:01 - 00000302 ____A C:\Windows\Tasks\Registry Optimizer_DEFAULT.job
2013-06-08 14:59 - 2013-02-13 11:07 - 00019840 ____A (WinZip Computing, S.L.(WinZip Computing)) C:\Windows\System32\roboot64.exe
2013-06-08 14:58 - 2013-06-08 14:58 - 05594104 ____A C:\Users\Mohammad\Downloads\spotflux-latestPC (1).exe
2013-06-08 14:58 - 2013-06-08 14:58 - 00000000 ____D C:\Program Files (x86)\Spotflux
2013-06-08 14:26 - 2013-06-08 14:26 - 00287208 ____A C:\Users\Mohammad\Downloads\GroovesharkDownloader.crx
2013-06-08 01:33 - 2013-06-08 01:33 - 02000488 ____A C:\Users\Mohammad\Downloads\U1301.exe
2013-06-07 11:34 - 2013-06-08 14:55 - 00000000 ____D C:\Users\Mohammad\Downloads\utmp
2013-05-29 04:12 - 2013-05-29 04:12 - 00039104 ____A (Spotflux, Inc.) C:\Windows\System32\Drivers\tapSF0901.sys
2013-05-18 23:00 - 2013-05-18 23:00 - 00001882 ____A C:\Users\Public\Desktop\Adobe Reader XI.lnk
2013-05-18 22:52 - 2013-05-18 22:55 - 50363976 ____A (Adobe Systems Incorporated) C:\Users\Mohammad\Downloads\AdbeRdr11002_en_US.exe

==================== One Month Modified Files and Folders =======

2013-06-09 21:17 - 2011-05-06 19:30 - 00000920 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2874463723-3708051865-952906006-1000UA.job
2013-06-09 21:16 - 2013-06-09 21:16 - 00000000 ____D C:\FRST
2013-06-09 21:15 - 2013-06-09 21:15 - 00526368 ____A C:\Users\Mohammad\Desktop\GMER.txt
2013-06-09 21:07 - 2009-07-02 02:06 - 01838093 ____A C:\Windows\WindowsUpdate.log
2013-06-09 20:45 - 2011-11-23 16:31 - 00000940 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2874463723-3708051865-952906006-1000UA.job
2013-06-09 20:40 - 2006-11-02 20:22 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-09 20:40 - 2006-11-02 20:22 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-09 20:38 - 2009-10-12 22:47 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-09 19:54 - 2013-06-09 18:38 - 00000578 ____A C:\Users\Mohammad\Desktop\Emad.html
2013-06-09 19:44 - 2013-02-13 23:53 - 00000000 ____D C:\Users\Mohammad\AppData\Roaming\.spotflux
2013-06-09 18:38 - 2009-10-12 22:47 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-09 18:20 - 2013-06-09 18:20 - 00000000 ____D C:\Users\Mohammad\Desktop\Juris proj
2013-06-09 17:41 - 2013-06-09 16:52 - 00000000 ____D C:\Users\Mohammad\AppData\Local\Adobe
2013-06-09 17:16 - 2013-06-09 17:16 - 00000000 ____D C:\Users\Mohammad\AppData\Local\Apple Computer
2013-06-09 17:16 - 2013-06-09 17:16 - 00000000 ____D C:\Users\Mohammad\AppData\Local\Apple
2013-06-09 16:55 - 2013-06-09 16:55 - 00002058 ____A C:\Users\Mohammad\Desktop\instructions.txt
2013-06-09 16:52 - 2013-06-09 16:51 - 01919210 ____A (Farbar) C:\Users\Mohammad\Desktop\FRST64.exe
2013-06-09 16:51 - 2013-06-09 16:50 - 00368554 ____A C:\Users\Mohammad\Desktop\gmer.zip
2013-06-09 03:48 - 2012-10-21 16:33 - 00000000 ____D C:\Users\Mohammad\AppData\Roaming\Dropbox
2013-06-09 03:43 - 2012-10-21 16:40 - 00000000 ___RD C:\Users\Mohammad\Dropbox
2013-06-09 03:35 - 2006-11-02 20:42 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-09 03:13 - 2013-06-09 03:13 - 00000770 ____A C:\Users\Public\Desktop\CCleaner.lnk
2013-06-09 03:13 - 2013-06-09 03:12 - 00000000 ____D C:\Program Files\CCleaner
2013-06-09 02:08 - 2013-06-09 02:08 - 00602112 ____A (OldTimer Tools) C:\Users\Mohammad\Desktop\OTL.exe
2013-06-09 01:17 - 2011-05-06 19:30 - 00000868 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2874463723-3708051865-952906006-1000Core.job
2013-06-09 01:15 - 2013-06-09 01:15 - 00014655 ____A C:\Users\Mohammad\Desktop\hijackthis.log
2013-06-09 01:08 - 2008-01-21 08:26 - 00282188 ____A C:\Windows\PFRO.log
2013-06-09 01:05 - 2013-06-09 01:04 - 00388608 ____A (Trend Micro Inc.) C:\Users\Mohammad\Desktop\HiJackThis.exe
2013-06-09 00:47 - 2013-06-09 00:47 - 00000000 ____D C:\Program Files (x86)\ESET
2013-06-09 00:46 - 2013-06-09 00:46 - 02347384 ____A (ESET) C:\Users\Mohammad\Desktop\esetsmartinstaller_enu.exe
2013-06-08 23:56 - 2013-06-08 14:59 - 00000000 ____D C:\Users\Mohammad\AppData\Roaming\Nico Mak Computing
2013-06-08 23:42 - 2006-11-02 20:42 - 00032552 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-06-08 23:05 - 2013-06-08 14:59 - 00000310 ____A C:\Windows\Tasks\Registry Optimizer_UPDATES.job
2013-06-08 15:01 - 2013-06-08 14:59 - 00000302 ____A C:\Windows\Tasks\Registry Optimizer_DEFAULT.job
2013-06-08 14:58 - 2013-06-08 14:58 - 05594104 ____A C:\Users\Mohammad\Downloads\spotflux-latestPC (1).exe
2013-06-08 14:58 - 2013-06-08 14:58 - 00000000 ____D C:\Program Files (x86)\Spotflux
2013-06-08 14:55 - 2013-06-07 11:34 - 00000000 ____D C:\Users\Mohammad\Downloads\utmp
2013-06-08 14:48 - 2010-05-26 02:26 - 00000600 ____A C:\Users\Mohammad\PUTTY.RND
2013-06-08 14:47 - 2009-10-18 21:51 - 00000000 ____D C:\Users\Mohammad\AppData\Roaming\Mozilla
2013-06-08 14:26 - 2013-06-08 14:26 - 00287208 ____A C:\Users\Mohammad\Downloads\GroovesharkDownloader.crx
2013-06-08 01:33 - 2013-06-08 01:33 - 02000488 ____A C:\Users\Mohammad\Downloads\U1301.exe
2013-06-07 23:45 - 2011-11-23 16:31 - 00000918 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2874463723-3708051865-952906006-1000Core.job
2013-06-07 11:35 - 2012-09-22 22:07 - 00000213 ____A C:\Users\Mohammad\Downloads\u.ini
2013-06-07 00:28 - 2009-10-12 09:27 - 00000000 ____D C:\users\Mohammad
2013-05-29 04:12 - 2013-05-29 04:12 - 00039104 ____A (Spotflux, Inc.) C:\Windows\System32\Drivers\tapSF0901.sys
2013-05-27 02:28 - 2009-10-12 09:27 - 00079232 ____A C:\Users\Mohammad\AppData\Local\GDIPFONTCACHEV1.DAT
2013-05-27 02:27 - 2006-11-02 20:21 - 00330256 ____A C:\Windows\System32\FNTCACHE.DAT
2013-05-26 18:54 - 2009-10-12 10:16 - 00167936 ____A C:\Users\Mohammad\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-05-26 18:48 - 2009-04-10 08:49 - 00000000 ____D C:\Program Files (x86)\Java
2013-05-26 17:57 - 2010-08-27 18:30 - 00000000 ____D C:\Users\Mohammad\AppData\Roaming\Barnes & Noble
2013-05-26 17:57 - 2010-08-27 18:30 - 00000000 ____D C:\Program Files (x86)\Barnes & Noble
2013-05-26 17:55 - 2010-01-20 00:04 - 00000000 ____D C:\ProgramData\Roxio
2013-05-26 17:55 - 2009-06-08 15:16 - 00000000 ____D C:\Program Files (x86)\Roxio
2013-05-26 17:47 - 2010-01-19 21:03 - 00000000 ____D C:\Users\Mohammad\AppData\Roaming\Research In Motion
2013-05-18 23:03 - 2009-06-08 14:28 - 00000000 ____D C:\ProgramData\Adobe
2013-05-18 23:01 - 2009-10-12 22:50 - 00000000 ____D C:\Users\Mohammad\AppData\Roaming\Adobe
2013-05-18 23:00 - 2013-05-18 23:00 - 00001882 ____A C:\Users\Public\Desktop\Adobe Reader XI.lnk
2013-05-18 22:59 - 2009-06-08 14:28 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-05-18 22:55 - 2013-05-18 22:52 - 50363976 ____A (Adobe Systems Incorporated) C:\Users\Mohammad\Downloads\AdbeRdr11002_en_US.exe
2013-05-15 22:32 - 2011-04-11 12:34 - 00044840 ____A C:\Windows\System32\spsys.log
2013-05-11 01:00 - 2011-07-11 16:07 - 01573503 ____A C:\Users\Mohammad\Downloads\DashboardInstaller.rar
2013-05-11 00:57 - 2012-10-21 15:58 - 00000000 ___SD C:\Users\Mohammad\Google Drive

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-06-09 03:45

==================== End Of Log ============================







And here is Addition.txt after the first scan:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-06-2013
Ran by [removed] at 2013-06-09 21:17:37 Run:
Running from C:\Users\[removed]\Desktop
Boot Mode: Normal
==========================================================


==================== Installed Programs =======================

Update for Microsoft Office 2007 (KB2508958)
µTorrent (Version: 2.0.2)
64 Bit HP CIO Components Installer (Version: 1.0.0)
Acrobat.com (Version: 0.0.0)
Acrobat.com (Version: 1.1.377)
Adobe AIR (Version: 1.0.4990)
Adobe AIR (Version: 1.0.8.4990)
Adobe Flash Player 10 ActiveX (Version: 10.1.53.64)
Adobe Flash Player 11 Plugin (Version: 11.6.602.171)
Adobe Reader XI (11.0.02) (Version: 11.0.02)
Adobe Shockwave Player 12.0 (Version: 12.0.0.112)
AF-HSS Toolbar (Version: 6.10.3.27)
Apache Tomcat 7.0.27
Apple Application Support (Version: 2.3.3)
Apple Mobile Device Support (Version: 6.1.0.13)
Apple Software Update (Version: 2.1.3.127)
Applian FLV Player (Version: 2.0.24)
Application Manager for VAIO
ArcSoft Magic-i Visual Effects 2 (Version: 2.0.1.39)
ArcSoft WebCam Companion 2
avast! Free Antivirus (Version: 6.0.1000.0)
Bonjour (Version: 3.0.0.10)
BufferChm (Version: 100.0.170.000)
CCleaner (Version: 4.02)
Cisco EAP-FAST Module (Version: 2.1.6)
Cisco LEAP Module (Version: 1.0.12)
Cisco PEAP Module (Version: 1.0.13)
Click to Disc (Version: 1.2.60.13210)
Click to Disc Editor (Version: 2.0.00)
Combined Community Codec Pack 2009-09-09 (Version: 2009.09.09.0)
Compatibility Pack for the 2007 Office system (Version: 12.0.6425.1000)
Copy (Version: 100.0.170.000)
Destination Component (Version: 100.0.0.0)
DeviceDiscovery (Version: 100.0.190.000)
DeviceManagementQFolder (Version: 1.00.0000)
DivX Setup (Version: 2.2.1.2)
DJ_AIO_03_F2200_ProductContext (Version: 100.0.215.000)
DJ_AIO_03_F2200_Software (Version: 100.0.206.000)
DJ_AIO_03_F2200_Software_Min (Version: 100.0.239.000)
DocProc (Version: 10.0.0.0)
DocProcQFolder (Version: 1.00.0000)
Dropbox (Version: 1.4.17)
DVDVideoMedia Free Video Converter 2.1 (Version: 2.1)
ESET Online Scanner v3
eSupportQFolder (Version: 1.00.0000)
F2200 (Version: 100.0.206.000)
F2200_Help (Version: 100.0.206.000)
Facebook Video Calling 1.2.0.287 (Version: 1.2.287)
GlassFish Server Open Source Edition [removed]
Google Chrome (Version: 27.0.1453.110)
Google Drive (Version: 1.9.4536.8202)
Google Earth Plug-in (Version: 7.0.3.8542)
Google Talk Plugin (Version: 4.0.1.13525)
Google Update Helper (Version: 1.3.21.145)
GPBaseService (Version: 100.0.187.000)
HDAUDIO SoftV92 Data Fax Modem with SmartCP
Hotspot Shield 2.84 (Version: 2.84)
HP Deskjet F2200 All-In-One Driver Software 10.0 Rel .3 (Version: 10.0)
HP Imaging Device Functions 10.0 (Version: 10.0)
HP Smart Web Printing (Version: 3.5)
HP Solution Center 10.0 (Version: 10.0)
HPProductAssistant (Version: 100.0.170.000)
Intel® Graphics Media Accelerator Driver
iTunes (Version: 11.0.2.26)
Java 7 Update 13 (64-bit) (Version: 7.0.130)
Java 7 Update 7 (Version: 7.0.70)
Java Auto Updater (Version: 2.1.9.0)
Java SE Development Kit 7 Update 13 (64-bit) (Version: 1.7.0.130)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Choice Guard (Version: 2.0.48.0)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007 (Version: 12.0.6425.1000)
Microsoft Office Home and Student 2007 (Version: 12.0.6425.1000)
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6425.1000)
Microsoft Office OneNote MUI (English) 2007 (Version: 12.0.6425.1000)
Microsoft Office PowerPoint MUI (English) 2007 (Version: 12.0.6425.1000)
Microsoft Office PowerPoint Viewer 2007 (English) (Version: 12.0.6425.1000)
Microsoft Office Proof (English) 2007 (Version: 12.0.6425.1000)
Microsoft Office Proof (French) 2007 (Version: 12.0.6425.1000)
Microsoft Office Proof (Spanish) 2007 (Version: 12.0.6425.1000)
Microsoft Office Proofing (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Shared 64-bit MUI (English) 2007 (Version: 12.0.6425.1000)
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 (Version: 12.0.6425.1000)
Microsoft Office Shared MUI (English) 2007 (Version: 12.0.6425.1000)
Microsoft Office Shared Setup Metadata MUI (English) 2007 (Version: 12.0.6425.1000)
Microsoft Office Suite Activation Assistant (Version: 2.9)
Microsoft Office Word MUI (English) 2007 (Version: 12.0.6425.1000)
Microsoft Silverlight (Version: 3.0.50106.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.50727.42)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Works (Version: 9.7.0621)
Mozilla Firefox (3.6.25) (Version: 3.6.25 (en-US))
MSVCRT (Version: 14.0.1468.721)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
MSXML 4.0 SP2 Parser and SDK (Version: 4.20.9818.0)
Music Transfer (Version: 1.3.01.13160)
NetBeans IDE 7.2.1 (Version: 7.2.1)
OCR Software by I.R.I.S. 10.0 (Version: 10.0)
Octoshape add-in for Adobe Flash Player
OpenMG Secure Module 5.3.00 (Version: 5.3.00.13080)
PDFCreator (Version: 0.9.8)
Picasa 3 (Version: 3.9)
Plants vs Zombies (Version: 1.0.0.1051)
Primo (Version: 1.00.0000)
PTCL PTCL Wireless LAN Card (Version: 1.5.4.0)
Python 3.3.0 (64-bit) (Version: 3.3.150)
QuickTime (Version: 7.68.75.0)
RealPlayer
Realtek High Definition Audio Driver (Version: 6.0.1.5759)
RealUpgrade 1.0 (Version: 1.0.0)
Roxio Central Audio (Version: 3.7.0)
Roxio Central Copy (Version: 3.7.0)
Roxio Central Core (Version: 3.7.0)
Roxio Central Data (Version: 3.7.0)
Roxio Central Tools (Version: 3.7.0)
Roxio Easy Media Creator 10 LJ (Version: 10.1)
Roxio Easy Media Creator Home (Version: 10.1.311)
Runtime (Version: 1.00.0000)
Samsung Printer Live Update (Version: 1.01.00.04)
Scan (Version: 10.1.0.0)
Setting Utility Series (Version: 4.3.0.14120)
Skype™ 5.5 (Version: 5.5.117)
SmartWebPrintingOC (Version: 100.0.189.000)
SmartWi Connection Utility (Version: 4.7.4.20090305.1964)
SolutionCenter (Version: 100.0.175.000)
Sony Home Network Library (Version: 1.4.0.13200)
Sony Picture Utility (Version: 4.2.12.14260)
Sony Video Shared Library (Version: 3.5.00)
Spotflux (Version: 2.9.10)
Spybot - Search & Destroy (Version: 1.6.2)
Status (Version: 100.0.175.000)
SupportSoft Assisted Service (Version: 15)
swMSM (Version: 12.0.0.1)
Synaptics Pointing Device Driver (Version: 10.2.7.0)
Toolbox (Version: 100.0.170.000)
TrayApp (Version: 100.0.170.000)
UnloadSupport (Version: 10.0.0)
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
VAIO Care (Version: 2.01.1031)
VAIO Content Folder Setting (Version: 2.3.0.12220)
VAIO Content Folder Watcher (Version: 1.1.0.13140)
VAIO Content Metadata Intelligent Analyzing Manager (Version: 3.4.0.13192)
VAIO Content Metadata Manager Setting (Version: 3.4.0.13160)
VAIO Content Metadata XML Interface Library (Version: 3.4.0.13160)
VAIO Control Center (Version: 3.3.0.12240)
VAIO Data Restore Tool (Version: 1.1.00.13080)
VAIO DVD Menu Data Basic (Version: 1.0.00.08130)
VAIO Entertainment Platform (Version: 3.4.0.13210)
VAIO Event Service (Version: 4.3.0.13190)
VAIO Help and Support (Version: 8.00.0403.NS)
VAIO Launcher (Version: 2.3.0.15090)
VAIO Media plus (Version: 1.4.0.13200)
VAIO Media plus Opening Movie (Version: 1.2.0.09050)
VAIO Movie Story (Version: 1.4.00.13080)
VAIO Movie Story Template Data (Version: 1.4.00.13080)
VAIO MusicBox (Version: 2.2.0.13091)
VAIO MusicBox Sample Music (Version: 1.1.00.14140)
VAIO My Memory Center (Version: 3.00.0317)
VAIO OOBE and Welcome Center (Version: 8.00.0327.ENUS)
VAIO Original Function Setting (Version: 1.5.01.10310)
VAIO Power Management (Version: 3.3.0.12190)
VAIO Presentation Support (Version: 1.2.0.12240)
VAIO Startup Assistant (Version: 5.00.0410)
VAIO Survey (Version: 6.00.0722)
VAIO Update 4 (Version: 4.1.0.12180)
VAIO Wallpaper Contents (Version: 1.3.0.10310)
VC80CRTRedist - 8.0.50727.4053 (Version: 1.1.0)
Vuze_Remote Toolbar (Version: )
WebReg (Version: 100.0.170.000)
Windows Live Communications Platform (Version: 14.0.8117.416)
Windows Live Essentials (Version: 14.0.8117.0416)
Windows Live Essentials (Version: 14.0.8117.416)
Windows Live Movie Maker (Version: 14.0.8117.0416)
Windows Live Photo Gallery (Version: 14.0.8117.416)
Windows Live Sign-in Assistant (Version: 5.000.818.5)
Windows Live Upload Tool (Version: 14.0.8014.1029)
WinDVD for VAIO (Version: 8.0-B9.726)
WinRAR archiver
Wireless Broadband (Version: 16.001.06.04.476)
XPS2OneNote (Version: 1.1.0)
YTD YouTube Downloader & Converter 3.6

==================== Restore Points =========================

09-05-2013 16:16:44 Scheduled Checkpoint
10-05-2013 19:00:02 Scheduled Checkpoint
11-05-2013 20:06:21 Scheduled Checkpoint
12-05-2013 19:00:02 Scheduled Checkpoint
15-05-2013 18:14:18 Scheduled Checkpoint
15-05-2013 19:27:09 VAIO Care Automatic Restore Point
16-05-2013 20:01:02 Scheduled Checkpoint
18-05-2013 17:57:46 Installed Adobe Reader XI.
20-05-2013 00:33:23 Scheduled Checkpoint
20-05-2013 20:13:14 Scheduled Checkpoint
21-05-2013 21:32:02 Scheduled Checkpoint
24-05-2013 15:25:25 Scheduled Checkpoint
26-05-2013 12:40:57 Device Driver Package Install: Research In Motion Universal Serial Bus controllers
26-05-2013 12:43:08 Device Driver Package Install: Research In Motion Universal Serial Bus controllers
26-05-2013 12:47:42 Removed Roxio Media Manager
26-05-2013 13:47:17 Removed Java™ SE Runtime Environment 6
26-05-2013 13:48:20 Removed Java™ 6 Update 17
04-06-2013 19:59:37 Scheduled Checkpoint
06-06-2013 19:27:14 Device Driver Package Install: Spotflux, Inc. Network adapters
08-06-2013 21:37:15 OTL Restore Point - 6/9/2013 2:37:15 AM
08-06-2013 22:19:28 OTL Restore Point - 6/9/2013 3:19:28 AM

==================== Hosts content: ==========================

::1 localhost

127.0.0.1 localhost


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (06/09/2013 05:19:32 PM) (Source: Windows Search Service) (User: )
Description: The entry in the hash map cannot be updated.

Context: Application, SystemIndex Catalog


Details:
A device attached to the system is not functioning. (0x8007001f)

Error: (06/09/2013 05:19:32 PM) (Source: Windows Search Service) (User: )
Description: The entry in the hash map cannot be updated.

Context: Application, SystemIndex Catalog


Details:
A device attached to the system is not functioning. (0x8007001f)

Error: (06/09/2013 04:40:01 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 43646475

Error: (06/09/2013 04:40:01 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 43646475

Error: (06/09/2013 04:40:01 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (06/09/2013 04:40:00 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 43645336

Error: (06/09/2013 04:40:00 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 43645336

Error: (06/09/2013 04:40:00 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (06/09/2013 04:39:59 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 43644213

Error: (06/09/2013 04:39:59 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 43644213


System errors:
=============
Error: (04/07/2013 03:32:28 PM) (Source: EventLog) (User: )
Description: The previous system shutdown at 7:21:06 PM on 4/4/2013 was unexpected.

Error: (04/07/2013 03:32:21 PM) (Source: Application Popup) (User: )
Description: \SystemRoot\SysWow64\DRIVERS\DMICall.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

Error: (04/03/2013 04:00:01 PM) (Source: Dhcp) (User: )
Description: The IP address lease [removed] for the Network Card with network address 00FF4894D3CA has been denied by the DHCP server [removed] (The DHCP Server sent a DHCPNACK message).

Error: (04/03/2013 00:12:53 PM) (Source: Dhcp) (User: )
Description: The IP address lease 192.168.1.8 for the Network Card with network address 00242BF15876 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).

Error: (04/03/2013 00:10:52 PM) (Source: Service Control Manager) (User: )
Description: DMICall

Error: (04/03/2013 00:10:51 PM) (Source: Service Control Manager) (User: )
Description: HP CUE DeviceDiscovery Service

Error: (04/03/2013 00:08:20 PM) (Source: Service Control Manager) (User: )
Description: VAIO Power Management%%1053

Error: (04/03/2013 00:08:20 PM) (Source: Service Control Manager) (User: )
Description: 30000VAIO Power Management

Error: (04/03/2013 00:08:20 PM) (Source: Service Control Manager) (User: )
Description: 30000Roxio Hard Drive Watcher 9

Error: (04/03/2013 11:20:29 AM) (Source: HTTP) (User: )
Description: \Device\Http\ReqQueueKerberos


Microsoft Office Sessions:
=========================
Error: (02/04/2012 05:44:37 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6425.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 218 seconds with 60 seconds of active time. This session ended with a crash.

Error: (02/04/2012 05:40:52 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6425.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 1947 seconds with 480 seconds of active time. This session ended with a crash.


CodeIntegrity Errors:
===================================
Date: 2013-06-09 21:17:12.762
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

Date: 2013-06-09 21:17:12.613
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

Date: 2013-06-09 21:17:12.506
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

Date: 2013-06-09 21:17:12.398
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

Date: 2013-06-09 21:17:12.277
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

Date: 2013-06-09 21:17:12.164
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

Date: 2013-06-09 21:17:12.054
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

Date: 2013-06-09 21:17:11.933
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

Date: 2013-06-09 21:17:06.986
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\aswSP.sys because the set of per-page image hashes could not be found on the system.

Date: 2013-06-09 21:17:06.868
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\aswSP.sys because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Percentage of memory in use: 51%
Total physical RAM: 2938.25 MB
Available physical RAM: 1414.56 MB
Total Pagefile: 6088.79 MB
Available Pagefile: 4294.3 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:287.91 GB) (Free:94.77 GB) NTFS (Disk=0 Partition=2) ==>[Drive with boot components (obtained from BCD)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 298 GB) (Disk ID: 46334274)
Partition 1: (Not Active) - (Size=10 GB) - (Type=27)
Partition 2: (Active) - (Size=288 GB) - (Type=07 NTFS)

==================== End Of Log ============================

Attachments:

Please download Malwarebytes Anti-Rootkit from here Malwarebytes : Malwarebytes Anti-Rootkit and save it to your desktop.

Be sure to print out and follow the instructions provided on that same page.

Caution: This is a beta version so please be sure to read the disclaimer and back up any important data before using.

  • Double click the mbar.zip file to open it, then 'Extract all files'.
  • Double click the mbar folder to open it, then double click mbar.exe to start the tool.
Check for Updates, then Scan your system for malware

If malware is found, do NOT press the Cleanup button yet. Click EXIT.

I'd like to see the log first so I can see what it sees. You'll find the log in that mbar folder as MBAR-log-***.txt . Please attach that to your next reply.
Run another scan with mbar.exe and click the CleanUp button. It will require a reboot.

When it has rebooted, run another scan with mbar.exe and click CleanUp again if necessary.

Send the mbar-log.txt along with an update on machine behavior.




Please download Farbar's Recovery Scan Tool to your desktop: FRST 32bit or FRST 64bit (If not sure: Start –> Computer (right click) –> properties)

  • Run FRST.
  • Don´t change one of the checkboxes and hit Scan.
  • Logfiles are created on your desktop.
  • Poste the FRST.txt and (after the first scan only!) the Addition.txt.
Hey here's the log file from mbar :)

Malwarebytes Anti-Rootkit BETA 1.06.0.1003
www.malwarebytes.org

Database version: v2013.06.09.04

Windows Vista Service Pack 1 x64 NTFS
Internet Explorer 8.0.6001.18928
Mohammad :: MOHAMMAD-PC [administrator]

6/10/2013 3:02:38 AM
mbar-log-2013-06-10 (03-02-38).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUM | P2P
Scan options disabled: Deep Anti-Rootkit Scan | PUP
Objects scanned: 241217
Time elapsed: 29 minute(s), 38 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)


Here's FRST.txt after the first scan

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-06-2013
Ran by [removed] (administrator) on 09-06-2013 21:22:29
Running from C:\Users\[removed]\Desktop
Windows Vista ™ Home Premium Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(AnchorFree Inc.) C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe
(Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AnchorFree Inc.) C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
() C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe
(InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\PTCL\Common\RaRegistry.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\PTCL\Common\RaRegistry64.exe
(Intel Corporation) C:\Program Files\Sony\VAIO Care\collsvc.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe
(ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe
(Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
(Conexant Systems, Inc.) C:\Windows\system32\DRIVERS\xaudio64.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
(Safer Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
(Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESGfxMgr.exe
(Intel Corporation) C:\Windows\system32\igfxext.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Sony Corporation) C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Program Files\Sony\VAIO Care\listener.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe

==================== Registry (Whitelisted) ==================

HKLM\…\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [6956576 2009-01-06] (Realtek Semiconductor)
HKLM\…\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1220392 2008-05-21] (Synaptics, Inc.)
HKCU\…\Run: [ISUSPM] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler [x]
MountPoints2: F - F:\AutoRun.exe
MountPoints2: {076fb6a0-714a-11e2-9917-001dbaf06e9b} - F:\urDrive.exe
MountPoints2: {243eb6eb-7bb1-11e0-bdf1-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {464e708f-aac4-11e0-b3dd-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {464e7093-aac4-11e0-b3dd-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {464e70d1-aac4-11e0-b3dd-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {464e70d3-aac4-11e0-b3dd-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {807975c6-d75c-11de-9ae1-001dbaf06e9b} - H:\LaunchU3.exe -a
MountPoints2: {80cd714b-cbab-11e0-9e09-001dbaf06e9b} - F:\Startme.exe
MountPoints2: {bc873d9d-cc3f-11e0-920a-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {bc873d9f-cc3f-11e0-920a-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {f56d0c52-ac3f-11e0-851b-806e6f6e6963} - F:\AutoRun.exe
HKLM-x32\…\Run: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe" [317288 2008-12-18] (Sony Corporation)
HKLM-x32\…\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49152 2007-10-14] (Hewlett-Packard)
HKLM-x32\…\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui [3451496 2011-02-23] (AVAST Software)
HKLM-x32\…\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot [202256 2010-08-09] (RealNetworks, Inc.)
HKLM-x32\…\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-01-28] (Apple Inc.)
HKLM-x32\…\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [946352 2012-12-19] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre7\bin\jusched.exe" [x]
HKU\Default\…\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter [2438656 2008-01-21] (Microsoft Corporation)
HKU\Default User\…\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter [2438656 2008-01-21] (Microsoft Corporation)
SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\System32\webcheck.dll (Microsoft Corporation)
SSODL-x32: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\SysWOW64\webcheck.dll (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

URLSearchHook: (No Name) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - No File
URLSearchHook: (No Name) - {f0381dbd-e018-4e07-ae40-d96ab15083f0} - No File
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={sea…ferrer:source?}
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={sea…ferrer:source?}
SearchScopes: HKLM-x32 - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2765711
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2765711
BHO: avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll ()
BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE_64.dll (AnchorFree Inc.)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited)
BHO-x32: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
BHO-x32: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
BHO-x32: AF-HSS Toolbar - {f0381dbd-e018-4e07-ae40-d96ab15083f0} - C:\Program Files (x86)\AF-HSS\prxtbAF-H.dll (Conduit Ltd.)
BHO-x32: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE.dll (AnchorFree Inc.)
BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll ()
Toolbar: HKLM-x32 - Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
Toolbar: HKLM-x32 - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
Toolbar: HKLM-x32 - AF-HSS Toolbar - {f0381dbd-e018-4e07-ae40-d96ab15083f0} - C:\Program Files (x86)\AF-HSS\prxtbAF-H.dll (Conduit Ltd.)
Toolbar: HKCU - No Name - {BA14329E-9550-4989-B3F2-9732E92D17CC} - No File
Toolbar: HKCU - No Name - {F0381DBD-E018-4E07-AE40-D96AB15083F0} - No File
DPF: HKLM-x32 {02CF1781-EA91-4FA5-A200-646E8241987C} http://esupport.sony.com/VaioInfo.CAB
DPF: HKLM-x32 {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab
DPF: HKLM-x32 {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
DPF: HKLM-x32 {DAF7E6E6-D53A-439A-B28D-12271406B8A9} http://mobileapps.blackberry.com/devicesoftware/AxLoader.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler-x32: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt

FireFox:
========
FF ProfilePath: C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default
FF Homepage: hxxp://search.conduit.com/?ctid=CT1572363&SearchSource;=13
FF NetworkProxy: "http", "localhost"
FF NetworkProxy: "http_port", 9666
FF NetworkProxy: "socks", "localhost"
FF NetworkProxy: "socks_port", 9050
FF NetworkProxy: "socks_remote_dns", true
FF NetworkProxy: "ssl", "localhost"
FF NetworkProxy: "ssl_port", 9666
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_171.dll ()
FF Plugin: @java.com/DTPlugin,version=10.13.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.13.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_171.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF Plugin-x32: @divx.com/DivX OVS Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.7.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.7.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\3.0.50106.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=6.0.12.775 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprjplug;version=1.0.3.775 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprphtml5videoshim;version=1.0.0.0 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpjplug;version=6.0.12.775 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Adblock Plus Pop-up Addon - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\[removed]
FF Extension: YouTube to MP3 - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\[removed]
FF Extension: Zotero - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\[removed]
FF Extension: Zotero Word for Windows Integration - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\[removed]
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF Extension: No Name - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{48e23fba-bb14-4745-b768-382150cd83fb}
FF Extension: No Name - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{5B52016C-D097-4aec-BE61-9F129D8FDDBA}
FF Extension: Orthodox - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{6d677280-ddfe-11dc-95ff-0800200c9a66}
FF Extension: NoScript - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
FF Extension: Zynga Toolbar - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
FF Extension: No Name - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
FF Extension: No Name - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}
FF Extension: AF-HSS - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{f0381dbd-e018-4e07-ae40-d96ab15083f0}

Chrome:
=======
CHR HomePage: hxxp://lums.edu.pk/
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (RealJukebox NS Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\nprjplug.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\nprpjplug.dll (RealNetworks, Inc.)
CHR Plugin: (Google Talk Plugin) - C:\Users\Mohammad\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
CHR Plugin: (Google Talk Plugin Video Accelerator) - C:\Users\Mohammad\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
CHR Plugin: (Google Talk Plugin Video Renderer) - C:\Users\Mohammad\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
CHR Plugin: (RIM Handheld Application Loader) - C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll No File
CHR Plugin: (DivX OVS Helper Plug-in) - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
CHR Plugin: (DivX Web Player) - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (Java™ Platform SE 7 U7) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Windows Live\u00AE Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (RealPlayer™ HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_171.dll ()
CHR Plugin: (Java Deployment Toolkit 7.0.70.11) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\3.0.50106.0\npctrl.dll ( Microsoft Corporation)
CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Extension: (Ge.tt) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdgghbbgmhcpidlmnepkbihehhkmjomc\0.99_0
CHR Extension: (NetCalc.org) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcfbbbolmblaajakigohdookklamneec\1_0
CHR Extension: (Facebook Nanny) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkpjofmdbabecniidggbbicfbcmfafmk\0.6.2_0
CHR Extension: (Dictionary Instant) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\hngaklbjlbjhmoilkegninbmpfigheol\2.0.0_0
CHR Extension: (WeatherBug) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihdkejbciahopmbagpnjmmkkdpfpaaak\2.0.5_0
CHR Extension: (PDF to Word Converter App) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\jclipofobaadknkadkpgggmjkebddjam\2.1_0
CHR Extension: (Any.DO) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdadialhpiikehpdeejjeiikopddkjem\1.0.3.3_0
CHR Extension: (Little Alchemy) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\knkapnclbofjjgicpkfoagdjohlfjhpd\0.0.15.7_0
CHR Extension: (Evernote Web) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol\1.0.7_0
CHR Extension: (Dropbox) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndbkiaijfjjjbejhcbcpkcpkcffjckga\1.0_0
CHR Extension: (Grooveshark Downloader) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\ooblpjoncpjmbncgocjlnannofkjjhnp\2.9.2_0
CHR Extension: (Gmail) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0

==================== Services (Whitelisted) =================

S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [42184 2011-02-23] (AVAST Software)
S2 gupdate1c9e81a239f2659; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [133104 2009-06-08] (Google Inc.)
R2 hshld; C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe [534824 2013-01-23] (AnchorFree Inc.)
S3 HssTrayService; C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE [78512 2013-01-20] ()
R2 HssWd; C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe [389928 2013-01-23] ()
S3 PACSPTISVR; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\PACSPTISVR.exe [114688 2009-01-08] (Sony Corporation)
R2 RalinkRegistryWriter; C:\Program Files (x86)\PTCL\Common\RaRegistry.exe [185632 2009-10-26] (Ralink Technology, Corp.)
R2 RalinkRegistryWriter64; C:\Program Files (x86)\PTCL\Common\RaRegistry64.exe [211232 2009-10-26] (Ralink Technology, Corp.)
R2 SampleCollector; C:\Program Files\Sony\VAIO Care\collsvc.exe [167424 2008-09-30] (Intel Corporation)
R2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
R2 SOHDBSvr; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [70952 2009-01-20] (Sony Corporation)
R2 SOHPlMgr; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [91432 2009-01-20] (Sony Corporation)
R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.)
S3 VAIO Entertainment TV Device Arbitration Service; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [69632 2009-01-21] (Sony Corporation)
R3 Vcsw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [313264 2009-01-21] (Sony Corporation)
R2 VzCdbSvc; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [192512 2009-01-21] (Sony Corporation)
S3 msiserver; %systemroot%\system32\msiexec /V [x]
S2 RoxLiveShare9; "C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe" [x]

==================== Drivers (Whitelisted) ====================

R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2008-04-25] (ArcSoft, Inc.)
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [22360 2011-02-23] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [64344 2011-02-23] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswRdr.sys [31064 2011-02-23] (AVAST Software)
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [505176 2011-02-23] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [280408 2011-02-23] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [53592 2011-02-23] (AVAST Software)
S3 dgderdrv; C:\Windows\System32\drivers\dgderdrv.sys [20568 2009-12-22] (Devguru Co., Ltd)
S1 DMICall; C:\Windows\SysWow64\DRIVERS\DMICall.sys [10216 2008-11-25] (Sony Corporation)
R1 HssDRV6; C:\Windows\System32\DRIVERS\hssdrv6.sys [42696 2013-01-20] (AnchorFree Inc.)
S3 RimVSerPort; C:\Windows\System32\DRIVERS\RimSerial_AMD64.sys [31744 2009-01-09] (Research in Motion Ltd)
R2 risdptsk; C:\Windows\System32\DRIVERS\risdsn64.sys [76288 2008-10-23] (REDC)
S3 s0016bus; C:\Windows\System32\DRIVERS\s0016bus.sys [115240 2008-05-16] (MCCI Corporation)
S3 s0016mdfl; C:\Windows\System32\DRIVERS\s0016mdfl.sys [19496 2008-05-16] (MCCI Corporation)
S3 s0016mdm; C:\Windows\System32\DRIVERS\s0016mdm.sys [158760 2008-05-16] (MCCI Corporation)
S3 s0016mgmt; C:\Windows\System32\DRIVERS\s0016mgmt.sys [137256 2008-05-16] (MCCI Corporation)
S3 s0016nd5; C:\Windows\System32\DRIVERS\s0016nd5.sys [34344 2008-05-16] (MCCI Corporation)
S3 s0016obex; C:\Windows\System32\DRIVERS\s0016obex.sys [136744 2008-05-16] (MCCI Corporation)
S3 s0016unic; C:\Windows\System32\DRIVERS\s0016unic.sys [151592 2008-05-16] (MCCI Corporation)
R3 seehcri; C:\Windows\System32\DRIVERS\seehcri.sys [34032 2008-01-09] (Sony Ericsson Mobile Communications)
R3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42328 2013-01-05] (Anchorfree Inc.)
R3 tapSF0901; C:\Windows\System32\DRIVERS\tapSF0901.sys [39104 2013-05-29] (Spotflux, Inc.)
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 Normandy; No ImagePath
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S3 RimUsb; System32\Drivers\RimUsb_AMD64.sys [x]
U3 aglyqkow; \??\C:\Users\Mohammad\AppData\Local\Temp\aglyqkow.sys [x]

==================== NetSvcs (Whitelisted) ===================

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-06-2013
Ran by [removed] (administrator) on 10-06-2013 03:57:24
Running from C:\Users\[removed]\Downloads
Windows Vista ™ Home Premium Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(AnchorFree Inc.) C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe
(AnchorFree Inc.) C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe
() C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe
(InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\PTCL\Common\RaRegistry.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\PTCL\Common\RaRegistry64.exe
(Intel Corporation) C:\Program Files\Sony\VAIO Care\collsvc.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe
(ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe
(Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
(Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESGfxMgr.exe
(Intel Corporation) C:\Windows\system32\igfxext.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Intel Corporation) C:\Program Files\Sony\VAIO Care\listener.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
(Conexant Systems, Inc.) C:\Windows\system32\DRIVERS\xaudio64.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe
(Safer Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Sony Corporation) C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
() C:\Program Files (x86)\Hotspot Shield\bin\openvpn.exe
(AnchorFree Inc.) C:\Program Files (x86)\Hotspot Shield\bin\af_proxy_cmd.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_6_602_171.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_6_602_171.exe

==================== Registry (Whitelisted) ==================

HKLM\…\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [6956576 2009-01-06] (Realtek Semiconductor)
HKLM\…\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1220392 2008-05-21] (Synaptics, Inc.)
HKCU\…\Run: [ISUSPM] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler [x]
MountPoints2: F - F:\AutoRun.exe
MountPoints2: {076fb6a0-714a-11e2-9917-001dbaf06e9b} - F:\urDrive.exe
MountPoints2: {243eb6eb-7bb1-11e0-bdf1-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {464e708f-aac4-11e0-b3dd-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {464e7093-aac4-11e0-b3dd-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {464e70d1-aac4-11e0-b3dd-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {464e70d3-aac4-11e0-b3dd-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {807975c6-d75c-11de-9ae1-001dbaf06e9b} - H:\LaunchU3.exe -a
MountPoints2: {80cd714b-cbab-11e0-9e09-001dbaf06e9b} - F:\Startme.exe
MountPoints2: {bc873d9d-cc3f-11e0-920a-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {bc873d9f-cc3f-11e0-920a-001dbaf06e9b} - F:\AutoRun.exe
MountPoints2: {f56d0c52-ac3f-11e0-851b-806e6f6e6963} - F:\AutoRun.exe
HKLM-x32\…\Run: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe" [317288 2008-12-18] (Sony Corporation)
HKLM-x32\…\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49152 2007-10-14] (Hewlett-Packard)
HKLM-x32\…\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui [3451496 2011-02-23] (AVAST Software)
HKLM-x32\…\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot [202256 2010-08-09] (RealNetworks, Inc.)
HKLM-x32\…\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-01-28] (Apple Inc.)
HKLM-x32\…\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [946352 2012-12-19] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre7\bin\jusched.exe" [x]
HKU\Default\…\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter [2438656 2008-01-21] (Microsoft Corporation)
HKU\Default User\…\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter [2438656 2008-01-21] (Microsoft Corporation)
SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\System32\webcheck.dll (Microsoft Corporation)
SSODL-x32: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\SysWOW64\webcheck.dll (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

URLSearchHook: (No Name) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - No File
URLSearchHook: (No Name) - {f0381dbd-e018-4e07-ae40-d96ab15083f0} - No File
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={sea…ferrer:source?}
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={sea…ferrer:source?}
SearchScopes: HKLM-x32 - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2765711
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2765711
BHO: avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll ()
BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE_64.dll (AnchorFree Inc.)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited)
BHO-x32: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
BHO-x32: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
BHO-x32: AF-HSS Toolbar - {f0381dbd-e018-4e07-ae40-d96ab15083f0} - C:\Program Files (x86)\AF-HSS\prxtbAF-H.dll (Conduit Ltd.)
BHO-x32: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE.dll (AnchorFree Inc.)
BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll ()
Toolbar: HKLM-x32 - Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
Toolbar: HKLM-x32 - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
Toolbar: HKLM-x32 - AF-HSS Toolbar - {f0381dbd-e018-4e07-ae40-d96ab15083f0} - C:\Program Files (x86)\AF-HSS\prxtbAF-H.dll (Conduit Ltd.)
Toolbar: HKCU - No Name - {BA14329E-9550-4989-B3F2-9732E92D17CC} - No File
Toolbar: HKCU - No Name - {F0381DBD-E018-4E07-AE40-D96AB15083F0} - No File
DPF: HKLM-x32 {02CF1781-EA91-4FA5-A200-646E8241987C} http://esupport.sony.com/VaioInfo.CAB
DPF: HKLM-x32 {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab
DPF: HKLM-x32 {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
DPF: HKLM-x32 {DAF7E6E6-D53A-439A-B28D-12271406B8A9} http://mobileapps.blackberry.com/devicesoftware/AxLoader.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler-x32: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 8.8.8.8

FireFox:
========
FF ProfilePath: C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_171.dll ()
FF Plugin: @java.com/DTPlugin,version=10.13.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.13.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_171.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF Plugin-x32: @divx.com/DivX OVS Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.7.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.7.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\3.0.50106.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=6.0.12.775 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprjplug;version=1.0.3.775 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprphtml5videoshim;version=1.0.0.0 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpjplug;version=6.0.12.775 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Adblock Plus Pop-up Addon - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\[removed]
FF Extension: YouTube to MP3 - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\[removed]
FF Extension: Zotero - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\[removed]
FF Extension: Zotero Word for Windows Integration - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\[removed]
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF Extension: No Name - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{48e23fba-bb14-4745-b768-382150cd83fb}
FF Extension: No Name - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{5B52016C-D097-4aec-BE61-9F129D8FDDBA}
FF Extension: Orthodox - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{6d677280-ddfe-11dc-95ff-0800200c9a66}
FF Extension: Zynga Toolbar - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
FF Extension: No Name - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}
FF Extension: AF-HSS - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{f0381dbd-e018-4e07-ae40-d96ab15083f0}
FF Extension: No Name - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi

Chrome:
=======
CHR HomePage: hxxp://lums.edu.pk/
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (RealJukebox NS Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\nprjplug.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\nprpjplug.dll (RealNetworks, Inc.)
CHR Plugin: (Google Talk Plugin) - C:\Users\Mohammad\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
CHR Plugin: (Google Talk Plugin Video Accelerator) - C:\Users\Mohammad\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
CHR Plugin: (Google Talk Plugin Video Renderer) - C:\Users\Mohammad\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
CHR Plugin: (RIM Handheld Application Loader) - C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll No File
CHR Plugin: (DivX OVS Helper Plug-in) - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
CHR Plugin: (DivX Web Player) - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (Java™ Platform SE 7 U7) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Windows Live\u00AE Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (RealPlayer™ HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_171.dll ()
CHR Plugin: (Java Deployment Toolkit 7.0.70.11) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\3.0.50106.0\npctrl.dll ( Microsoft Corporation)
CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Extension: (Ge.tt) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdgghbbgmhcpidlmnepkbihehhkmjomc\0.99_0
CHR Extension: (NetCalc.org) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcfbbbolmblaajakigohdookklamneec\1_0
CHR Extension: (Facebook Nanny) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkpjofmdbabecniidggbbicfbcmfafmk\0.6.2_0
CHR Extension: (Dictionary Instant) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\hngaklbjlbjhmoilkegninbmpfigheol\2.0.0_0
CHR Extension: (WeatherBug) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihdkejbciahopmbagpnjmmkkdpfpaaak\2.0.5_0
CHR Extension: (PDF to Word Converter App) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\jclipofobaadknkadkpgggmjkebddjam\2.1_0
CHR Extension: (Any.DO) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdadialhpiikehpdeejjeiikopddkjem\1.0.3.3_0
CHR Extension: (Little Alchemy) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\knkapnclbofjjgicpkfoagdjohlfjhpd\0.0.15.7_0
CHR Extension: (Evernote Web) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol\1.0.7_0
CHR Extension: (Dropbox) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndbkiaijfjjjbejhcbcpkcpkcffjckga\1.0_0
CHR Extension: (Grooveshark Downloader) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\ooblpjoncpjmbncgocjlnannofkjjhnp\2.9.2_0
CHR Extension: (Gmail) - C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0

==================== Services (Whitelisted) =================

S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [42184 2011-02-23] (AVAST Software)
S2 gupdate1c9e81a239f2659; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [133104 2009-06-08] (Google Inc.)
R2 hshld; C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe [534824 2013-01-23] (AnchorFree Inc.)
S3 HssTrayService; C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE [78512 2013-01-20] ()
R2 HssWd; C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe [389928 2013-01-23] ()
S3 PACSPTISVR; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\PACSPTISVR.exe [114688 2009-01-08] (Sony Corporation)
R2 RalinkRegistryWriter; C:\Program Files (x86)\PTCL\Common\RaRegistry.exe [185632 2009-10-26] (Ralink Technology, Corp.)
R2 RalinkRegistryWriter64; C:\Program Files (x86)\PTCL\Common\RaRegistry64.exe [211232 2009-10-26] (Ralink Technology, Corp.)
R2 SampleCollector; C:\Program Files\Sony\VAIO Care\collsvc.exe [167424 2008-09-30] (Intel Corporation)
R2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
R2 SOHDBSvr; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [70952 2009-01-20] (Sony Corporation)
R2 SOHPlMgr; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [91432 2009-01-20] (Sony Corporation)
R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.)
S3 VAIO Entertainment TV Device Arbitration Service; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [69632 2009-01-21] (Sony Corporation)
R3 Vcsw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [313264 2009-01-21] (Sony Corporation)
R2 VzCdbSvc; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [192512 2009-01-21] (Sony Corporation)
S3 msiserver; %systemroot%\system32\msiexec /V [x]
S2 RoxLiveShare9; "C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe" [x]

==================== Drivers (Whitelisted) ====================

R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2008-04-25] (ArcSoft, Inc.)
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [22360 2011-02-23] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [64344 2011-02-23] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswRdr.sys [31064 2011-02-23] (AVAST Software)
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [505176 2011-02-23] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [280408 2011-02-23] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [53592 2011-02-23] (AVAST Software)
S3 dgderdrv; C:\Windows\System32\drivers\dgderdrv.sys [20568 2009-12-22] (Devguru Co., Ltd)
S1 DMICall; C:\Windows\SysWow64\DRIVERS\DMICall.sys [10216 2008-11-25] (Sony Corporation)
R1 HssDRV6; C:\Windows\System32\DRIVERS\hssdrv6.sys [42696 2013-01-20] (AnchorFree Inc.)
S3 RimVSerPort; C:\Windows\System32\DRIVERS\RimSerial_AMD64.sys [31744 2009-01-09] (Research in Motion Ltd)
R2 risdptsk; C:\Windows\System32\DRIVERS\risdsn64.sys [76288 2008-10-23] (REDC)
S3 s0016bus; C:\Windows\System32\DRIVERS\s0016bus.sys [115240 2008-05-16] (MCCI Corporation)
S3 s0016mdfl; C:\Windows\System32\DRIVERS\s0016mdfl.sys [19496 2008-05-16] (MCCI Corporation)
S3 s0016mdm; C:\Windows\System32\DRIVERS\s0016mdm.sys [158760 2008-05-16] (MCCI Corporation)
S3 s0016mgmt; C:\Windows\System32\DRIVERS\s0016mgmt.sys [137256 2008-05-16] (MCCI Corporation)
S3 s0016nd5; C:\Windows\System32\DRIVERS\s0016nd5.sys [34344 2008-05-16] (MCCI Corporation)
S3 s0016obex; C:\Windows\System32\DRIVERS\s0016obex.sys [136744 2008-05-16] (MCCI Corporation)
S3 s0016unic; C:\Windows\System32\DRIVERS\s0016unic.sys [151592 2008-05-16] (MCCI Corporation)
R3 seehcri; C:\Windows\System32\DRIVERS\seehcri.sys [34032 2008-01-09] (Sony Ericsson Mobile Communications)
R3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42328 2013-01-05] (Anchorfree Inc.)
R3 tapSF0901; C:\Windows\System32\DRIVERS\tapSF0901.sys [39104 2013-05-29] (Spotflux, Inc.)
S1 DMICall; system32\DRIVERS\DMICall.sys [x]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
U4 mbamswissarmy;
S3 Normandy; No ImagePath
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S3 RimUsb; System32\Drivers\RimUsb_AMD64.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-06-10 03:56 - 2013-06-10 03:56 - 01919988 ____A (Farbar) C:\Users\Mohammad\Downloads\FRST64.exe
2013-06-10 01:32 - 2013-06-10 03:41 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-06-10 01:28 - 2013-06-10 03:41 - 00000000 ____D C:\Users\Mohammad\Desktop\mbar
2013-06-10 01:25 - 2013-06-10 01:27 - 13169742 ____A C:\Users\Mohammad\Downloads\mbar-1.06.0.1003.zip
2013-06-09 23:33 - 2013-06-09 23:33 - 00000000 ____D C:\Users\Mohammad\AppData\Local\Macromedia
2013-06-09 23:17 - 2013-06-09 23:17 - 00000000 ____D C:\ProgramData\Mozilla
2013-06-09 23:17 - 2013-06-09 23:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-06-09 21:16 - 2013-06-09 21:16 - 00000000 ____D C:\FRST
2013-06-09 18:20 - 2013-06-09 18:20 - 00000000 ____D C:\Users\Mohammad\Desktop\Juris proj
2013-06-09 17:16 - 2013-06-09 17:16 - 00000000 ____D C:\Users\Mohammad\AppData\Local\Apple Computer
2013-06-09 17:16 - 2013-06-09 17:16 - 00000000 ____D C:\Users\Mohammad\AppData\Local\Apple
2013-06-09 16:55 - 2013-06-10 01:26 - 00001205 ____A C:\Users\Mohammad\Desktop\instructions.txt
2013-06-09 16:52 - 2013-06-09 17:41 - 00000000 ____D C:\Users\Mohammad\AppData\Local\Adobe
2013-06-09 16:51 - 2013-06-09 16:52 - 01919210 ____A (Farbar) C:\Users\Mohammad\Desktop\FRST64.exe
2013-06-09 16:51 - 2013-04-04 09:55 - 00377856 ____A C:\Users\Mohammad\Desktop\gmer.exe
2013-06-09 16:50 - 2013-06-09 16:51 - 00368554 ____A C:\Users\Mohammad\Desktop\gmer.zip
2013-06-09 03:13 - 2013-06-09 03:13 - 00000770 ____A C:\Users\Public\Desktop\CCleaner.lnk
2013-06-09 03:12 - 2013-06-09 03:13 - 00000000 ____D C:\Program Files\CCleaner
2013-06-09 02:08 - 2013-06-09 02:08 - 00602112 ____A (OldTimer Tools) C:\Users\Mohammad\Desktop\OTL.exe
2013-06-09 01:04 - 2013-06-09 01:05 - 00388608 ____A (Trend Micro Inc.) C:\Users\Mohammad\Desktop\HiJackThis.exe
2013-06-09 00:47 - 2013-06-09 00:47 - 00000000 ____D C:\Program Files (x86)\ESET
2013-06-09 00:46 - 2013-06-09 00:46 - 02347384 ____A (ESET) C:\Users\Mohammad\Desktop\esetsmartinstaller_enu.exe
2013-06-08 14:59 - 2013-06-08 23:56 - 00000000 ____D C:\Users\Mohammad\AppData\Roaming\Nico Mak Computing
2013-06-08 14:59 - 2013-06-08 23:05 - 00000310 ____A C:\Windows\Tasks\Registry Optimizer_UPDATES.job
2013-06-08 14:59 - 2013-06-08 15:01 - 00000302 ____A C:\Windows\Tasks\Registry Optimizer_DEFAULT.job
2013-06-08 14:59 - 2013-02-13 11:07 - 00019840 ____A (WinZip Computing, S.L.(WinZip Computing)) C:\Windows\System32\roboot64.exe
2013-06-08 14:58 - 2013-06-08 14:58 - 05594104 ____A C:\Users\Mohammad\Downloads\spotflux-latestPC (1).exe
2013-06-08 14:58 - 2013-06-08 14:58 - 00000000 ____D C:\Program Files (x86)\Spotflux
2013-06-08 14:26 - 2013-06-08 14:26 - 00287208 ____A C:\Users\Mohammad\Downloads\GroovesharkDownloader.crx
2013-06-08 01:33 - 2013-06-08 01:33 - 02000488 ____A C:\Users\Mohammad\Downloads\U1301.exe
2013-06-07 11:34 - 2013-06-08 14:55 - 00000000 ____D C:\Users\Mohammad\Downloads\utmp
2013-05-29 04:12 - 2013-05-29 04:12 - 00039104 ____A (Spotflux, Inc.) C:\Windows\System32\Drivers\tapSF0901.sys
2013-05-18 23:00 - 2013-05-18 23:00 - 00001882 ____A C:\Users\Public\Desktop\Adobe Reader XI.lnk
2013-05-18 22:52 - 2013-05-18 22:55 - 50363976 ____A (Adobe Systems Incorporated) C:\Users\Mohammad\Downloads\AdbeRdr11002_en_US.exe

==================== One Month Modified Files and Folders =======

2013-06-10 03:56 - 2013-06-10 03:56 - 01919988 ____A (Farbar) C:\Users\Mohammad\Downloads\FRST64.exe
2013-06-10 03:41 - 2013-06-10 01:32 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-06-10 03:41 - 2013-06-10 01:28 - 00000000 ____D C:\Users\Mohammad\Desktop\mbar
2013-06-10 03:38 - 2009-10-12 22:47 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-10 03:17 - 2011-05-06 19:30 - 00000920 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2874463723-3708051865-952906006-1000UA.job
2013-06-10 03:08 - 2009-07-02 02:06 - 01877973 ____A C:\Windows\WindowsUpdate.log
2013-06-10 02:58 - 2009-10-12 22:47 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-10 02:58 - 2006-11-02 20:42 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-10 02:57 - 2006-11-02 20:22 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-10 02:57 - 2006-11-02 20:22 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-10 02:56 - 2006-11-02 20:42 - 00032552 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-06-10 02:55 - 2011-04-11 12:34 - 00045096 ____A C:\Windows\System32\spsys.log
2013-06-10 02:54 - 2008-01-21 08:26 - 00282782 ____A C:\Windows\PFRO.log
2013-06-10 02:51 - 2012-10-21 16:33 - 00000000 ____D C:\Users\Mohammad\AppData\Roaming\Dropbox
2013-06-10 02:45 - 2011-11-23 16:31 - 00000940 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2874463723-3708051865-952906006-1000UA.job
2013-06-10 01:27 - 2013-06-10 01:25 - 13169742 ____A C:\Users\Mohammad\Downloads\mbar-1.06.0.1003.zip
2013-06-10 01:26 - 2013-06-09 16:55 - 00001205 ____A C:\Users\Mohammad\Desktop\instructions.txt
2013-06-10 01:17 - 2011-05-06 19:30 - 00000868 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2874463723-3708051865-952906006-1000Core.job
2013-06-09 23:45 - 2011-11-23 16:31 - 00000918 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2874463723-3708051865-952906006-1000Core.job
2013-06-09 23:39 - 2012-10-21 16:40 - 00000000 ___RD C:\Users\Mohammad\Dropbox
2013-06-09 23:33 - 2013-06-09 23:33 - 00000000 ____D C:\Users\Mohammad\AppData\Local\Macromedia
2013-06-09 23:17 - 2013-06-09 23:17 - 00000000 ____D C:\ProgramData\Mozilla
2013-06-09 23:17 - 2013-06-09 23:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-06-09 23:17 - 2009-10-28 22:09 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-06-09 21:16 - 2013-06-09 21:16 - 00000000 ____D C:\FRST
2013-06-09 19:44 - 2013-02-13 23:53 - 00000000 ____D C:\Users\Mohammad\AppData\Roaming\.spotflux
2013-06-09 18:20 - 2013-06-09 18:20 - 00000000 ____D C:\Users\Mohammad\Desktop\Juris proj
2013-06-09 17:41 - 2013-06-09 16:52 - 00000000 ____D C:\Users\Mohammad\AppData\Local\Adobe
2013-06-09 17:16 - 2013-06-09 17:16 - 00000000 ____D C:\Users\Mohammad\AppData\Local\Apple Computer
2013-06-09 17:16 - 2013-06-09 17:16 - 00000000 ____D C:\Users\Mohammad\AppData\Local\Apple
2013-06-09 16:52 - 2013-06-09 16:51 - 01919210 ____A (Farbar) C:\Users\Mohammad\Desktop\FRST64.exe
2013-06-09 16:51 - 2013-06-09 16:50 - 00368554 ____A C:\Users\Mohammad\Desktop\gmer.zip
2013-06-09 03:13 - 2013-06-09 03:13 - 00000770 ____A C:\Users\Public\Desktop\CCleaner.lnk
2013-06-09 03:13 - 2013-06-09 03:12 - 00000000 ____D C:\Program Files\CCleaner
2013-06-09 02:08 - 2013-06-09 02:08 - 00602112 ____A (OldTimer Tools) C:\Users\Mohammad\Desktop\OTL.exe
2013-06-09 01:05 - 2013-06-09 01:04 - 00388608 ____A (Trend Micro Inc.) C:\Users\Mohammad\Desktop\HiJackThis.exe
2013-06-09 00:47 - 2013-06-09 00:47 - 00000000 ____D C:\Program Files (x86)\ESET
2013-06-09 00:46 - 2013-06-09 00:46 - 02347384 ____A (ESET) C:\Users\Mohammad\Desktop\esetsmartinstaller_enu.exe
2013-06-08 23:56 - 2013-06-08 14:59 - 00000000 ____D C:\Users\Mohammad\AppData\Roaming\Nico Mak Computing
2013-06-08 23:05 - 2013-06-08 14:59 - 00000310 ____A C:\Windows\Tasks\Registry Optimizer_UPDATES.job
2013-06-08 15:01 - 2013-06-08 14:59 - 00000302 ____A C:\Windows\Tasks\Registry Optimizer_DEFAULT.job
2013-06-08 14:58 - 2013-06-08 14:58 - 05594104 ____A C:\Users\Mohammad\Downloads\spotflux-latestPC (1).exe
2013-06-08 14:58 - 2013-06-08 14:58 - 00000000 ____D C:\Program Files (x86)\Spotflux
2013-06-08 14:55 - 2013-06-07 11:34 - 00000000 ____D C:\Users\Mohammad\Downloads\utmp
2013-06-08 14:48 - 2010-05-26 02:26 - 00000600 ____A C:\Users\Mohammad\PUTTY.RND
2013-06-08 14:47 - 2009-10-18 21:51 - 00000000 ____D C:\Users\Mohammad\AppData\Roaming\Mozilla
2013-06-08 14:26 - 2013-06-08 14:26 - 00287208 ____A C:\Users\Mohammad\Downloads\GroovesharkDownloader.crx
2013-06-08 01:33 - 2013-06-08 01:33 - 02000488 ____A C:\Users\Mohammad\Downloads\U1301.exe
2013-06-07 11:35 - 2012-09-22 22:07 - 00000213 ____A C:\Users\Mohammad\Downloads\u.ini
2013-06-07 00:28 - 2009-10-12 09:27 - 00000000 ____D C:\users\Mohammad
2013-05-29 04:12 - 2013-05-29 04:12 - 00039104 ____A (Spotflux, Inc.) C:\Windows\System32\Drivers\tapSF0901.sys
2013-05-27 02:28 - 2009-10-12 09:27 - 00079232 ____A C:\Users\Mohammad\AppData\Local\GDIPFONTCACHEV1.DAT
2013-05-27 02:27 - 2006-11-02 20:21 - 00330256 ____A C:\Windows\System32\FNTCACHE.DAT
2013-05-26 18:54 - 2009-10-12 10:16 - 00167936 ____A C:\Users\Mohammad\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-05-26 18:48 - 2009-04-10 08:49 - 00000000 ____D C:\Program Files (x86)\Java
2013-05-26 17:57 - 2010-08-27 18:30 - 00000000 ____D C:\Users\Mohammad\AppData\Roaming\Barnes & Noble
2013-05-26 17:57 - 2010-08-27 18:30 - 00000000 ____D C:\Program Files (x86)\Barnes & Noble
2013-05-26 17:55 - 2010-01-20 00:04 - 00000000 ____D C:\ProgramData\Roxio
2013-05-26 17:55 - 2009-06-08 15:16 - 00000000 ____D C:\Program Files (x86)\Roxio
2013-05-26 17:47 - 2010-01-19 21:03 - 00000000 ____D C:\Users\Mohammad\AppData\Roaming\Research In Motion
2013-05-18 23:03 - 2009-06-08 14:28 - 00000000 ____D C:\ProgramData\Adobe
2013-05-18 23:01 - 2009-10-12 22:50 - 00000000 ____D C:\Users\Mohammad\AppData\Roaming\Adobe
2013-05-18 23:00 - 2013-05-18 23:00 - 00001882 ____A C:\Users\Public\Desktop\Adobe Reader XI.lnk
2013-05-18 22:59 - 2009-06-08 14:28 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-05-18 22:55 - 2013-05-18 22:52 - 50363976 ____A (Adobe Systems Incorporated) C:\Users\Mohammad\Downloads\AdbeRdr11002_en_US.exe
2013-05-11 01:00 - 2011-07-11 16:07 - 01573503 ____A C:\Users\Mohammad\Downloads\DashboardInstaller.rar
2013-05-11 00:57 - 2012-10-21 15:58 - 00000000 ___SD C:\Users\Mohammad\Google Drive

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-06-10 03:36

==================== End Of Log ============================


There was no Addition.txt after the first scan :S
Seems to be the legitimate version.


Fix with FRST

  • Open notepad (Start =>All Programs => Accessories => Notepad).
  • Please copy the entire contents of the code box below.
    (To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
  • Save it to the same direction as frst.exe (or frst64.exe) as fixlist.txt.

    URLSearchHook: (No Name) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - No File
    URLSearchHook: (No Name) - {f0381dbd-e018-4e07-ae40-d96ab15083f0} - No File
    SearchScopes: HKLM-x32 - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2765711
    SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2765711
    BHO-x32: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
    BHO-x32: AF-HSS Toolbar - {f0381dbd-e018-4e07-ae40-d96ab15083f0} - C:\Program Files (x86)\AF-HSS\prxtbAF-H.dll (Conduit Ltd.)
    BHO-x32: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE.dll (AnchorFree Inc.)
    Toolbar: HKLM-x32 - Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
    Toolbar: HKLM-x32 - AF-HSS Toolbar - {f0381dbd-e018-4e07-ae40-d96ab15083f0} - C:\Program Files (x86)\AF-HSS\prxtbAF-H.dll (Conduit Ltd.)
    Toolbar: HKCU - No Name - {BA14329E-9550-4989-B3F2-9732E92D17CC} - No File
    Toolbar: HKCU - No Name - {F0381DBD-E018-4E07-AE40-D96AB15083F0} - No File
    
    C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE.dll
    C:\Windows\Tasks\Registry Optimizer_UPDATES.job
    C:\Windows\Tasks\Registry Optimizer_DEFAULT.job
    
    FF Homepage: hxxp://search.conduit.com/?ctid=CT1572363&SearchSource=13
    FF Extension: AF-HSS - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{f0381dbd-e018-4e07-ae40-d96ab15083f0}
    FF Extension: Zynga Toolbar - C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
  • Run frst.exe (on 64bit, run frst64.exe) and press the Fix button just once and wait.
  • The tool will make a log (Fixlog.txt) which you find where you saved FRST. Please post it to your reply.




Please go to here to run the online scannner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked
  • Click on Advanced Settings and ensure these options are ticked:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Click Scan
  • Wait for the scan to finish
  • If any threats were found, click the 'List of found threats' , then click Export to text file….
  • Save it to your desktop, then please copy and paste that log as a reply to this topic.
Here's the fixlog! Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 08-06-2013 Ran by [removed] at 2013-06-10 23:19:44 Run:1 Running from C:\Users\[removed]\Desktop Boot Mode: Normal ============================================== HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\\{ba14329e-9550-4989-b3f2-9732e92d17cc} => Value deleted successfully. HKCR\CLSID\{ba14329e-9550-4989-b3f2-9732e92d17cc} => Key not found. HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\\{f0381dbd-e018-4e07-ae40-d96ab15083f0} => Value deleted successfully. HKCR\CLSID\{f0381dbd-e018-4e07-ae40-d96ab15083f0} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => Key deleted successfully. HKCR\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{ba14329e-9550-4989-b3f2-9732e92d17cc} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f0381dbd-e018-4e07-ae40-d96ab15083f0} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{f0381dbd-e018-4e07-ae40-d96ab15083f0} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{ba14329e-9550-4989-b3f2-9732e92d17cc} => Value deleted successfully. HKCR\Wow6432Node\CLSID\{ba14329e-9550-4989-b3f2-9732e92d17cc} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{f0381dbd-e018-4e07-ae40-d96ab15083f0} => Value deleted successfully. HKCR\Wow6432Node\CLSID\{f0381dbd-e018-4e07-ae40-d96ab15083f0} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{BA14329E-9550-4989-B3F2-9732E92D17CC} => Value deleted successfully. HKCR\CLSID\{BA14329E-9550-4989-B3F2-9732E92D17CC} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{F0381DBD-E018-4E07-AE40-D96AB15083F0} => Value deleted successfully. HKCR\CLSID\{F0381DBD-E018-4E07-AE40-D96AB15083F0} => Key not found. C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE.dll => Moved successfully. C:\Windows\Tasks\Registry Optimizer_UPDATES.job => Moved successfully. C:\Windows\Tasks\Registry Optimizer_DEFAULT.job => Moved successfully. Firefox homepage deleted successfully. C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{f0381dbd-e018-4e07-ae40-d96ab15083f0} => Moved successfully. C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822} => Moved successfully. ==== End of Fixlog ==== Here are the threats ESET found: C:\Users\Mohammad\AppData\Roaming\.spotflux\updates\dist\install.exe a variant of Win32/Bunndle application C:\Users\Mohammad\Downloads\BBC_Horizon_The_Truth_About_Exercise_PDTV_XviD_AC3.exe Win32/Adware.1ClickDownload.G application C:\Users\Mohammad\Downloads\dvdvideomedia-free-video-converter.exe Win32/DeFile.Gen application C:\Users\Mohammad\Downloads\spotflux-latestPC (1).exe a variant of Win32/Bunndle application C:\Users\Mohammad\Downloads\u1203.exe Win32/UltraReach.AE application
The findings by ESET aren´t malware but contain security risks. Delete them without opening before.

Then we do the cleanup. If you are facing any issues, report immediately.


Scan with adwCleaner


Please download AdwCleaner to your desktop.


  • Run adwcleaner.exe.
  • Hit delete.
  • When the run is finished, it will open up a text file.
  • Please post its contents within your next reply.
  • You´ll find the log file at C:\AdwCleaner[S1].txt also.




SecurityCheck

Please download SecurityCheck: LINK1 LINK2

  • Save it to your desktop, start it and follow the instructions in the window.
  • After the scan finished the (checkup.txt) will open. Copy its content to your thread.
"Delete them without opening before." Do you mean I delete the ESET security risks from my computer before proceeding with adwcleaner?
I deleted the files that were security threats and ran adwCleaner. On restart command prompt opened as well as the report file.

Command prompt displayed this (I accidentally pressed "C" at the end when it opened):


C:\Windows\system32>rmdir /s /q "C:\ProgramData\Trymedia"
C:\ProgramData\Trymedia\data - Access is denied.
C:\ProgramData\Trymedia\licenses - Access is denied.
Access is denied.

C:\Windows\system32>rmdir /s /q "C:\Program Files (x86)\AF-HSS"
C:\Program Files (x86)\AF-HSS\AF-HSSToolbarHelper.exe - Access is denied.
C:\Program Files (x86)\AF-HSS\GottenAppsContextMenu.xml - Access is denied.
C:\Program Files (x86)\AF-HSS\ldrtbAF-H.dll - Access is denied.
C:\Program Files (x86)\AF-HSS\OtherAppsContextMenu.xml - Access is denied.
C:\Program Files (x86)\AF-HSS\prxtbAF-H.dll - Access is denied.
C:\Program Files (x86)\AF-HSS\SharedAppsContextMenu.xml - Access is denied.
C:\Program Files (x86)\AF-HSS\tbAF-H.dll - Access is denied.
C:\Program Files (x86)\AF-HSS\toolbar.cfg - Access is denied.
C:\Program Files (x86)\AF-HSS\ToolbarContextMenu.xml - Access is denied.
C:\Program Files (x86)\AF-HSS\uninstall.exe - Access is denied.
Access is denied.

C:\Windows\system32>rmdir /s /q "C:\Program Files (x86)\Conduit"
C:\Program Files (x86)\Conduit\COMMUN~1\Alert.dll - Access is denied.
C:\Program Files (x86)\Conduit\COMMUN~1 - Access is denied.
Access is denied.

C:\Windows\system32>rmdir /s /q "C:\Program Files (x86)\Mozilla Firefox\Extensio
ns\[removed]"
C:\Program Files (x86)\Mozilla Firefox\Extensions\[removed]\ch
rome\content\afurlhelper.js - Access is denied.
C:\Program Files (x86)\Mozilla Firefox\Extensions\[removed]\ch
rome\content\afurlhelper_comp.js - Access is denied.
C:\Program Files (x86)\Mozilla Firefox\Extensions\[removed]\ch
rome\content\overlay.js - Access is denied.
C:\Program Files (x86)\Mozilla Firefox\Extensions\[removed]\ch
rome\content\overlay.xul - Access is denied.
C:\Program Files (x86)\Mozilla Firefox\Extensions\[removed]\ch
rome\content - Access is denied.
C:\Program Files (x86)\Mozilla Firefox\Extensions\[removed]\ch
rome - Access is denied.
C:\Program Files (x86)\Mozilla Firefox\Extensions\[removed]\ch
rome.manifest - Access is denied.
C:\Program Files (x86)\Mozilla Firefox\Extensions\[removed]\CO
MPON~1\afurladvisor.dll - Access is denied.
C:\Program Files (x86)\Mozilla Firefox\Extensions\[removed]\CO
MPON~1\afurladvisor.xpt - Access is denied.
C:\Program Files (x86)\Mozilla Firefox\Extensions\[removed]\CO
MPON~1\afurladvisor12.dll - Access is denied.
C:\Program Files (x86)\Mozilla Firefox\Extensions\[removed]\CO
MPON~1 - Access is denied.
C:\Program Files (x86)\Mozilla Firefox\Extensions\[removed]\de
faults\PREFER~1\prefs.js - Access is denied.
C:\Program Files (x86)\Mozilla Firefox\Extensions\[removed]\de
faults\PREFER~1 - Access is denied.
C:\Program Files (x86)\Mozilla Firefox\Extensions\[removed]\de
faults - Access is denied.
C:\Program Files (x86)\Mozilla Firefox\Extensions\[removed]\in
stall.rdf - Access is denied.
C:\Program Files (x86)\Mozilla Firefox\Extensions\[removed]\lo
cale\en-US\overlay.dtd - Access is denied.
C:\Program Files (x86)\Mozilla Firefox\Extensions\[removed]\lo
cale\en-US - Access is denied.
C:\Program Files (x86)\Mozilla Firefox\Extensions\[removed]\lo
cale - Access is denied.
C:\Program Files (x86)\Mozilla Firefox\Extensions\[removed]\sk
in\overlay.css - Access is denied.
C:\Program Files (x86)\Mozilla Firefox\Extensions\[removed]\sk
in - Access is denied.
Access is denied.

C:\Windows\system32>rmdir /s /q "C:\Program Files (x86)\Vuze_Remote"
C:\Program Files (x86)\Vuze_Remote\INSTALL.LOG - Access is denied.
C:\Program Files (x86)\Vuze_Remote\tbVuze.dll - Access is denied.
C:\Program Files (x86)\Vuze_Remote\toolbar.cfg - Access is denied.
C:\Program Files (x86)\Vuze_Remote\UNWISE.EXE - Access is denied.
C:\Program Files (x86)\Vuze_Remote\Vuze_RemoteToolbarHelper.exe - Access is deni
ed.
Access is denied.

C:\Windows\system32>rmdir /s /q "C:\Program Files (x86)\Vuze_Remote"
C:\Program Files (x86)\Vuze_Remote\INSTALL.LOG - Access is denied.
C:\Program Files (x86)\Vuze_Remote\tbVuze.dll - Access is denied.
C:\Program Files (x86)\Vuze_Remote\toolbar.cfg - Access is denied.
C:\Program Files (x86)\Vuze_Remote\UNWISE.EXE - Access is denied.
C:\Program Files (x86)\Vuze_Remote\Vuze_RemoteToolbarHelper.exe - Access is deni
ed.
Access is denied.

C:\Windows\system32>rmdir /s /q "C:\Users\Mohammad\AppData\Local\Conduit"

C:\Windows\system32>rmdir /s /q "C:\Users\Mohammad\AppData\LocalLow\AF-HSS"

C:\Windows\system32>rmdir /s /q "C:\Users\Mohammad\AppData\LocalLow\Conduit"
^CTerminate batch job (Y/N)?



AdwCleaner[S1]. txt says:

# AdwCleaner v2.303 - Logfile created 06/11/2013 at 15:21:40
# Updated 08/06/2013 by Xplode
# Operating system : Windows ™ Vista Home Premium Service Pack 1 (64 bits)
# User : Mohammad - MOHAMMAD-PC
# Boot Mode : Normal
# Running from : C:\Users\Mohammad\Downloads\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Deleted on reboot : C:\Program Files (x86)\AF-HSS
Deleted on reboot : C:\Program Files (x86)\Conduit
Deleted on reboot : C:\Program Files (x86)\Mozilla Firefox\Extensions\[removed]
Deleted on reboot : C:\Program Files (x86)\Vuze_Remote
Deleted on reboot : C:\Program Files (x86)\Vuze_Remote
Deleted on reboot : C:\ProgramData\Trymedia
Deleted on reboot : C:\Users\Mohammad\AppData\Local\Conduit
Deleted on reboot : C:\Users\Mohammad\AppData\LocalLow\AF-HSS
Deleted on reboot : C:\Users\Mohammad\AppData\LocalLow\Conduit
Deleted on reboot : C:\Users\Mohammad\AppData\LocalLow\PriceGong
Deleted on reboot : C:\Users\Mohammad\AppData\LocalLow\Vuze_Remote
Deleted on reboot : C:\Users\Mohammad\AppData\LocalLow\Vuze_Remote
Deleted on reboot : C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Conduit
Deleted on reboot : C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Smartbar
File Deleted : C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\searchplugins\Conduit.xml

***** [Registry] *****

Key Deleted : HKCU\Software\AF-HSS
Key Deleted : HKCU\Software\AppDataLow\Software\AF-HSS
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\AppDataLow\Software\Vuze_Remote
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AF-HSS Toolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Vuze_Remote Toolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BA14329E-9550-4989-B3F2-9732E92D17CC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4260E0CC-0F75-462E-88A3-1E05C248BF4C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B7511D30-DDC0-4FDA-BD4D-58B20054DAC0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA14329E-9550-4989-B3F2-9732E92D17CC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKLM\Software\AF-HSS
Key Deleted : HKLM\SOFTWARE\Classes\InstallerControl.InstallerObject
Key Deleted : HKLM\SOFTWARE\Classes\InstallerControl.InstallerObject.1
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT1561552
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT1572363
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2504091
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2765711
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1D99FC84-31D3-4CA4-B2CD-39D9E24DAD78}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B7511D30-DDC0-4FDA-BD4D-58B20054DAC0}
Key Deleted : HKLM\Software\Vuze_Remote
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{1D99FC84-31D3-4CA4-B2CD-39D9E24DAD78}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4260E0CC-0F75-462E-88A3-1E05C248BF4C}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B7511D30-DDC0-4FDA-BD4D-58B20054DAC0}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{EEBEE8B9-660C-47EB-A650-7399B3ABC494}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CEFFD9D0-1828-4744-B920-CA1B04A87A3E}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F7028997-6BC2-46F2-A764-393E33FD4E45}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\AF-HSS Toolbar
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Vuze_Remote Toolbar
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4260E0CC-0F75-462E-88A3-1E05C248BF4C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{BA14329E-9550-4989-B3F2-9732E92D17CC}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{F0381DBD-E018-4E07-AE40-D96AB15083F0}]

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18928

[OK] Registry is clean.

-\\ Mozilla Firefox v12.0 (en-US)

File : C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\prefs.js

[OK] File is clean.

-\\ Google Chrome v27.0.1453.110

File : C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[S1].txt - [5619 octets] - [11/06/2013 15:21:40]

########## EOF - C:\AdwCleaner[S1].txt - [5679 octets] ##########




And finally the results of Security Check

Results of screen317's Security Check version 0.99.64
Windows Vista Service Pack 1 x64 (UAC is enabled)
Out of date service pack!!
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Windows Firewall Disabled!
avast! Antivirus
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Spybot - Search & Destroy
Java 7 Update 7
Java version out of Date!
Adobe Flash Player 10 Flash Player out of Date!
Adobe Flash Player 11.6.602.171
Adobe Reader XI
Mozilla Firefox 12.0 Firefox out of Date!
Google Chrome 27.0.1453.110
Google Chrome 27.0.1453.94
````````Process Check: objlist.exe by Laurent````````
Spybot Teatimer.exe is disabled!
AVAST Software Avast AvastSvc.exe
AVAST Software Avast AvastUI.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 2 % Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````
Be sure to be logged in as an administrator. Run adwcleaner.exe again and hit delete. Post up the log it opens.
I am logged in with the administrator, but since I have Vista, User Account Control is enabled. I did however click Run as Administrator this time. On reboot command prompt opened for a second and I could see "Access denied" written on some places but it closed itself before I could copy it. Here's the log: # AdwCleaner v2.303 - Logfile created 06/11/2013 at 17:20:22 # Updated 08/06/2013 by Xplode # Operating system : Windows ™ Vista Home Premium Service Pack 1 (64 bits) # User : Mohammad - MOHAMMAD-PC # Boot Mode : Normal # Running from : C:\Users\Mohammad\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** Deleted on reboot : C:\Program Files (x86)\Conduit Deleted on reboot : C:\Program Files (x86)\Mozilla Firefox\Extensions\[removed] Deleted on reboot : C:\Program Files (x86)\Vuze_Remote Deleted on reboot : C:\ProgramData\Trymedia Deleted on reboot : C:\Users\Mohammad\AppData\LocalLow\Conduit Deleted on reboot : C:\Users\Mohammad\AppData\LocalLow\PriceGong Deleted on reboot : C:\Users\Mohammad\AppData\LocalLow\Vuze_Remote Deleted on reboot : C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Conduit Deleted on reboot : C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\Smartbar ***** [Registry] ***** ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.6001.18928 [OK] Registry is clean. -\\ Mozilla Firefox v12.0 (en-US) File : C:\Users\Mohammad\AppData\Roaming\Mozilla\Firefox\Profiles\wzzo97kb.default\prefs.js [OK] File is clean. -\\ Google Chrome v27.0.1453.110 File : C:\Users\Mohammad\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[S1].txt - [5742 octets] - [11/06/2013 15:21:40] AdwCleaner[S2].txt - [1554 octets] - [11/06/2013 17:20:22] ########## EOF - C:\AdwCleaner[S2].txt - [1614 octets] ##########

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI