This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Yahoo email compromised [Closed]

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

My yahoo account was recently compromised, sending spam while logged-in in Qatar. I have changed my password and ensured that my alternate email address has not been changed, nor seemingly compromised. I have run Spybot S&D, Avast a/v, and Advanced System Care removing anything detected. Do you guys seen anything remaining (or otherwise unnecessary) in the following logs? Any recommendations would be very appreciated!

TIA!
Steve

.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 9:11:15.36 on Wed 06/19/2013
Internet Explorer: 9.10.9200.16614 BrowserJavaVersion: 10.21.2
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.3037.2026 [GMT -4:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Enabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: IObit Malware Fighter *Disabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\IObit\Advanced SystemCare 6\ASCTray.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\SearchIndexer.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\wbem\wmiprvse.exe
C:\Users\Owner\Desktop\Utilities\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uInternet Settings,ProxyServer = localhost:21320
BHO: AVG Do Not Track: {31332eef-cb9f-458f-afeb-d30e9a66b6ba} - c:\program files\avg\avg2012\avgdtiex.dll
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GR469A~1.DLL
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre7\bin\ssv.dll
BHO: avast! Online Security: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Advanced SystemCare Browser Protection: {ba0c978d-d909-49b6-afe2-8bde245dc7e6} - c:\progra~1\iobit\advanc~1\brower~1\ASCPLU~1.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll
TB: avast! Online Security: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
uRun: [Advanced SystemCare 6] "c:\program files\iobit\advanced systemcare 6\ASCTray.exe" /AutoStart
mRun: [SDTray] "c:\program files\spybot - search & destroy 2\SDTray.exe"
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - c:\program files\avg\avg2012\avgdtiex.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
Trusted Zone: genieo.com\yahoo
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GRA32A~1.DLL
Notify: igfxcui - igfxdev.dll
Notify: SDWinLogon - SDWinLogon.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GR469A~1.DLL
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\39az9jpg.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.3.21.145\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\users\owner\appdata\local\google\update\1.3.21.145\npGoogleUpdate3.dll
FF - plugin: c:\users\owner\appdata\roaming\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\users\owner\appdata\roaming\mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: c:\users\owner\appdata\roaming\mozilla\plugins\npo1d.dll
FF - plugin: c:\windows\system32\adobe\director\np32dsw_1202122.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_7_700_224.dll
FF - plugin: c:\windows\system32\npDeployJava1.dll
FF - plugin: c:\windows\system32\npmproxy.dll
.
—- FIREFOX POLICIES —-
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: content.notify.ontimer - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.switch.threshold - 750000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;aswRvrt;c:\windows\system32\drivers\aswRvrt.sys [2013-6-16 49376]
R0 aswVmm;aswVmm;c:\windows\system32\drivers\aswVmm.sys [2013-6-16 174664]
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [2013-6-16 15672]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2013-6-16 765736]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2013-6-16 368944]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2013-6-16 29816]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-6-16 66336]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2013-6-16 46808]
R2 IMFservice;IMF Service;c:\program files\iobit\iobit malware fighter\IMFsrv.exe [2013-6-16 335168]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\spybot - search & destroy 2\SDFSSvc.exe [2013-6-16 1817560]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\spybot - search & destroy 2\SDUpdSvc.exe [2013-6-16 1033688]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\spybot - search & destroy 2\SDWSCSvc.exe [2013-6-16 171928]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2013-6-16 116648]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2013-6-16 116648]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2013-5-18 117144]
S3 NMgamingmsFltr;USB Optical Mouse;c:\windows\system32\drivers\NMgamingms.sys [2009-7-24 9472]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2013-6-5 14848]
S3 RegFilter;RegFilter;c:\program files\iobit\iobit malware fighter\drivers\win7_x86\RegFilter.sys [2013-6-16 31752]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2013-6-5 49664]
S3 UrlFilter;UrlFilter;c:\program files\iobit\iobit malware fighter\drivers\win7_x86\UrlFilter.sys [2013-6-16 20944]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2013-5-18 1343400]
S4 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2012-7-11 116608]
S4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-8-30 256904]
S4 AdvancedSystemCareService6;Advanced SystemCare Service 6;c:\program files\iobit\advanced systemcare 6\ASCService.exe [2013-5-19 574272]
S4 FileMonitor;FileMonitor;c:\program files\iobit\iobit malware fighter\drivers\win7_x86\FileMonitor.sys [2013-6-16 21480]
.
=============== Created Last 30 ================
.
2013-06-19 03:24:14 7016152 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\backup\mpengine.dll
2013-06-19 03:24:09 7068072 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\{ad71cbe4-a0d4-44f5-b010-0b0fe892be15}\mpengine.dll
2013-06-17 01:12:47 61680 —-a-w- c:\windows\system32\drivers\aswRdr2.sys
2013-06-17 01:12:46 765736 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2013-06-17 01:12:45 174664 —-a-w- c:\windows\system32\drivers\aswVmm.sys
2013-06-17 01:12:44 49376 —-a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-06-17 01:12:39 66336 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-06-17 01:11:48 41664 —-a-w- c:\windows\avastSS.scr
2013-06-17 01:11:33 ——– d—–w- c:\program files\AVAST Software
2013-06-17 01:10:24 ——– d—–w- c:\progra~2\AVAST Software
2013-06-17 00:17:28 ——– d—–w- c:\users\owner\appdata\roaming\TuneUp Software
2013-06-16 23:00:09 ——– d—–w- c:\progra~2\Spybot - Search & Destroy
2013-06-16 22:59:54 15224 —-a-w- c:\windows\system32\sdnclean.exe
2013-06-16 22:59:50 ——– d—–w- c:\program files\Spybot - Search & Destroy 2
2013-06-16 22:58:06 15672 —-a-w- c:\windows\system32\drivers\SmartDefragDriver.sys
2013-06-16 20:17:14 238872 ——w- c:\windows\system32\MpSigStub.exe
2013-06-13 20:23:33 3968872 —-a-w- c:\windows\system32\ntkrnlpa.exe
2013-06-13 20:23:33 3913576 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-06-13 13:24:06 2706432 —-a-w- c:\windows\system32\mshtml.tlb
2013-06-13 13:24:06 218112 —-a-w- c:\program files\internet explorer\sqmapi.dll
2013-06-13 13:22:01 61440 —-a-w- c:\windows\system32\iesetup.dll
2013-06-13 13:22:01 2877440 —-a-w- c:\windows\system32\jscript9.dll
2013-06-13 13:22:01 108032 —-a-w- c:\program files\internet explorer\jsdebuggeride.dll
2013-06-13 13:22:00 71680 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-06-13 13:22:00 257536 —-a-w- c:\program files\internet explorer\ieproxy.dll
2013-06-13 13:22:00 235520 —-a-w- c:\program files\internet explorer\IEShims.dll
2013-06-13 13:22:00 109056 —-a-w- c:\windows\system32\iesysprep.dll
2013-06-13 13:21:58 817664 —-a-w- c:\program files\common files\microsoft shared\vgx\VGX.dll
2013-06-13 13:21:58 1767936 —-a-w- c:\windows\system32\wininet.dll
2013-06-13 13:21:57 770648 —-a-w- c:\program files\internet explorer\iexplore.exe
2013-06-13 13:21:20 903168 —-a-w- c:\windows\system32\certutil.exe
2013-06-13 13:21:20 1160192 —-a-w- c:\windows\system32\crypt32.dll
2013-06-13 13:21:19 43008 —-a-w- c:\windows\system32\certenc.dll
2013-06-13 13:21:19 140288 —-a-w- c:\windows\system32\cryptsvc.dll
2013-06-13 13:21:19 103936 —-a-w- c:\windows\system32\cryptnet.dll
2013-06-13 13:21:16 492544 —-a-w- c:\windows\system32\win32spl.dll
2013-06-13 13:21:15 1293672 —-a-w- c:\windows\system32\drivers\tcpip.sys
2013-06-08 05:32:40 ——– d—–w- c:\program files\Mozilla Firefox Beta
2013-06-08 04:28:01 ——– d—–w- c:\program files\FileHippo.com
2013-06-08 03:25:25 ——– d—–w- c:\users\owner\appdata\roaming\USB Optical Mouse
2013-06-08 03:15:42 ——– d—–w- c:\program files\USB Optical Mouse
2013-06-05 05:15:59 40960 —-a-w- c:\windows\system32\wwanprotdim.dll
2013-06-05 05:15:59 186368 —-a-w- c:\windows\system32\wwansvc.dll
2013-06-05 05:15:21 196328 —-a-w- c:\windows\system32\drivers\fvevol.sys
2013-06-05 05:15:00 293376 —-a-w- c:\windows\system32\KernelBase.dll
2013-06-05 05:15:00 271360 —-a-w- c:\windows\system32\conhost.exe
2013-06-05 05:13:50 55296 —-a-w- c:\windows\system32\cero.rs
2013-06-05 05:12:49 44032 —-a-w- c:\windows\system32\dhcpcsvc6.dll
2013-06-05 05:11:33 1039360 —-a-w- c:\windows\system32\lsasrv.dll
2013-06-05 05:11:32 369856 —-a-w- c:\windows\system32\drivers\cng.sys
2013-06-05 05:11:32 247808 —-a-w- c:\windows\system32\schannel.dll
2013-06-05 05:11:32 136560 —-a-w- c:\windows\system32\drivers\ksecpkg.sys
2013-06-05 05:11:14 400896 —-a-w- c:\windows\system32\srcore.dll
2013-06-05 05:11:02 317440 —-a-w- c:\windows\system32\spoolsv.exe
2013-06-05 05:10:33 245760 —-a-w- c:\windows\system32\OxpsConverter.exe
2013-06-05 05:10:19 712048 —-a-w- c:\windows\system32\drivers\ndis.sys
2013-06-05 05:10:19 33280 —-a-w- c:\windows\system32\drivers\RNDISMP.sys
2013-06-05 05:10:06 514560 —-a-w- c:\windows\system32\qdvd.dll
2013-06-05 05:09:56 164352 —-a-w- c:\windows\system32\profsvc.dll
2013-06-05 05:09:44 2342400 —-a-w- c:\windows\system32\msi.dll
2013-06-05 05:09:31 442880 —-a-w- c:\windows\system32\ntshrui.dll
2013-06-05 05:09:14 478720 —-a-w- c:\windows\system32\timedate.cpl
2013-06-05 05:07:36 27008 —-a-w- c:\windows\system32\drivers\Diskdump.sys
2013-06-05 05:07:26 31232 —-a-w- c:\windows\system32\prevhost.exe
2013-06-05 05:07:10 2616320 —-a-w- c:\windows\explorer.exe
2013-06-05 05:06:33 23872 —-a-w- c:\windows\system32\RegistryDefragBootTime.exe
2013-06-03 23:01:03 866720 —-a-w- c:\windows\system32\npDeployJava1.dll
2013-06-03 23:00:55 94112 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-06-03 22:55:26 ——– d—–w- c:\progra~2\SUPERSetup
2013-06-03 22:54:15 ——– d—–w- c:\program files\VideoLAN
2013-06-03 22:47:26 ——– d—–w- c:\users\owner\appdata\roaming\uTorrent
2013-05-20 14:42:40 ——– d—–w- c:\users\owner\appdata\roaming\SUPERAntiSpyware.com
2013-05-20 14:42:15 ——– d—–w- c:\program files\SUPERAntiSpyware
2013-05-20 14:42:15 ——– d—–w- c:\progra~2\SUPERAntiSpyware.com
2013-05-20 14:17:24 ——– d—–w- c:\users\owner\appdata\roaming\Malwarebytes
2013-05-20 14:17:09 ——– d—–w- c:\progra~2\Malwarebytes
2013-05-20 14:17:08 22856 —-a-w- c:\windows\system32\drivers\mbam.sys
2013-05-20 14:17:08 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2013-05-20 14:16:45 ——– d—–w- c:\users\owner\appdata\local\Programs
.
==================== Find3M ====================
.
2013-06-13 20:11:08 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-06-13 20:11:08 692104 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-06-05 05:15:42 561664 —-a-w- c:\windows\apppatch\AcLayers.dll
2013-06-05 05:15:42 474624 —-a-w- c:\windows\apppatch\AcSpecfc.dll
2013-06-05 05:15:42 2176512 —-a-w- c:\windows\apppatch\AcGenral.dll
2013-06-05 05:13:50 51712 —-a-w- c:\windows\system32\esrb.rs
2013-06-05 05:12:49 193536 —-a-w- c:\windows\system32\dhcpcore6.dll
2013-06-05 05:08:49 74240 —-a-w- c:\windows\system32\fsutil.exe
2013-06-05 05:08:49 1699328 —-a-w- c:\windows\system32\esent.dll
2013-06-05 05:08:05 86528 —-a-w- c:\windows\system32\SearchFilterHost.exe
2013-06-05 05:08:05 666624 —-a-w- c:\windows\system32\mssvp.dll
2013-06-05 05:08:05 59392 —-a-w- c:\windows\system32\msscntrs.dll
2013-06-05 05:08:05 427520 —-a-w- c:\windows\system32\SearchIndexer.exe
2013-06-05 05:08:05 337408 —-a-w- c:\windows\system32\mssph.dll
2013-06-05 05:08:05 197120 —-a-w- c:\windows\system32\mssphtb.dll
2013-06-05 05:08:05 164352 —-a-w- c:\windows\system32\SearchProtocolHost.exe
2013-06-05 05:08:05 1549312 —-a-w- c:\windows\system32\tquery.dll
2013-06-05 05:08:05 1401344 —-a-w- c:\windows\system32\mssrch.dll
2013-06-03 23:00:39 788896 —-a-w- c:\windows\system32\deployJava1.dll
2013-05-19 03:05:52 9728 —ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-05-19 02:12:00 152576 —-a-w- c:\windows\system32\msclmd.dll
2013-04-10 03:14:06 2347520 —-a-w- c:\windows\system32\win32k.sys
2013-04-02 14:09:52 4550656 —-a-w- c:\windows\system32\GPhotos.scr
.
============= FINISH: 9:11:45.58 ===============



Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:09:47 AM, on 6/19/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16611)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\IObit\Advanced SystemCare 6\ASCTray.exe
C:\Users\Owner\Desktop\Utilities\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = localhost:21320
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AVG Do Not Track - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files\AVG\AVG2012\avgdtiex.dll (file missing)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\PROGRA~1\IObit\ADVANC~1\BROWER~1\ASCPLU~1.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKCU\..\Run: [Advanced SystemCare 6] "C:\Program Files\IObit\Advanced SystemCare 6\ASCTray.exe" /AutoStart
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://yahoo.genieo.com
O15 - Trusted IP range: 127.0.0.1
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GRA32A~1.DLL
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IMF Service (IMFservice) - IObit - C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe

–
End of file - 5270 bytes


OTL logfile created on: 6/19/2013 8:53:09 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Owner\Desktop\Utilities
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16614)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.97 Gb Total Physical Memory | 2.22 Gb Available Physical Memory | 74.82% Memory free
5.93 Gb Paging File | 5.10 Gb Available in Paging File | 86.01% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 93.06 Gb Total Space | 69.50 Gb Free Space | 74.69% Space Free | Partition Type: NTFS

Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Owner\Desktop\Utilities\OTL.exe (OldTimer Tools)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe (IObit)
PRC - C:\Program Files\IObit\Advanced SystemCare 6\ASCTray.exe (IObit)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
*

========== Modules (No Company Name) ==========

MOD - C:\Program Files\Spybot - Search & Destroy 2\snlFileFormats150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl ()
MOD - C:\Program Files\IObit\Advanced SystemCare 6\madexcept_.bpl ()
MOD - C:\Program Files\IObit\Advanced SystemCare 6\maddisAsm_.bpl ()
MOD - C:\Program Files\IObit\Advanced SystemCare 6\madbasic_.bpl ()
MOD - C:\Program Files\IObit\Advanced SystemCare 6\ASCExtMenu.dll ()


========== Services (SafeList) ==========

SRV - (SDWSCService) – C:\Program Files\Spybot File not found
SRV - (SDUpdateService) – C:\Program Files\Spybot File not found
SRV - (SDScannerService) – C:\Program Files\Spybot File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (IMFservice) – C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe (IObit)
SRV - (AdvancedSystemCareService6) – C:\Program Files\IObit\Advanced SystemCare 6\ASCService.exe (IObit)
SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (VGPU) – System32\drivers\rdvgkmd.sys File not found
DRV - (tsusbhub) – system32\drivers\tsusbhub.sys File not found
DRV - (Synth3dVsc) – System32\drivers\synth3dvsc.sys File not found
DRV - (AVGIDSShim) – system32\DRIVERS\avgidsshimx.sys File not found
DRV - (AVGIDSHX) – system32\DRIVERS\avgidshx.sys File not found
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (RdpVideoMiniport) – C:\Windows\System32\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV - (aswSnx) – C:\Windows\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswVmm) – C:\Windows\System32\drivers\aswVmm.sys ()
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr2.sys (AVAST Software)
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswRvrt) – C:\Windows\System32\drivers\aswRvrt.sys ()
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (UrlFilter) – C:\Program Files\IObit\IObit Malware Fighter\Drivers\win7_x86\UrlFilter.sys (IObit.com)
DRV - (RegFilter) – C:\Program Files\IObit\IObit Malware Fighter\Drivers\win7_x86\RegFilter.sys (IObit.com)
DRV - (FileMonitor) – C:\Program Files\IObit\IObit Malware Fighter\Drivers\win7_x86\FileMonitor.sys (IObit)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (SmartDefragDriver) – C:\Windows\System32\drivers\SmartDefragDriver.sys ()
DRV - (vmbus) – C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (L1E) – C:\Windows\System32\drivers\L1E62x86.sys (Atheros Communications, Inc.)
DRV - (NMgamingmsFltr) – C:\Windows\System32\drivers\NMgamingms.sys (Primax Ltd)
DRV - (MTsensor) – C:\Windows\System32\drivers\ATKACPI.sys (ATK0100)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\..\SearchScopes,DefaultScope = {BF5CDBD7-EC78-41F8-A1B1-01829572104D}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKCU\..\SearchScopes\{BF5CDBD7-EC78-41F8-A1B1-01829572104D}: "URL" = http://search.yahoo.com/search?fr=w3is&…p={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = localhost:21320

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledAddons: quicklaunch%40mozillaonline.com:1.0.1
FF - prefs.js..extensions.enabledAddons: isreaditlater%40ideashower.com:3.0.1
FF - prefs.js..extensions.enabledAddons: foxmarks%40kei.com:4.2.1
FF - prefs.js..extensions.enabledAddons: %7BAE93811A-5C9A-4d34-8462-F7B864FC4696%7D:4.16
FF - prefs.js..extensions.enabledAddons: downintab%40max.max:1.00
FF - prefs.js..extensions.enabledAddons: thumbnailZoom%40dadler.github.com:2.4.3
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:21.0
FF - prefs.js..network.proxy.type: 0


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Owner\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\Owner\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Owner\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Owner\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Owner\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files\AVG\AVG2012\Firefox\DoNotTrack\ [2012/08/30 14:15:35 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013/06/16 21:12:02 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Components: C:\Program Files\Mozilla Firefox Beta\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox Beta\plugins

[2012/01/03 18:21:27 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\mozilla\Extensions
[2013/06/08 01:30:26 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\mozilla\Firefox\Profiles\39az9jpg.default\extensions
[2013/05/19 01:31:51 | 000,000,000 | —D | M] (Advanced SystemCare Surfing Protection) – C:\Users\Owner\AppData\Roaming\mozilla\Firefox\Profiles\39az9jpg.default\extensions\[removed]
[2013/05/22 10:04:05 | 000,000,000 | —D | M] ("Xmarks") – C:\Users\Owner\AppData\Roaming\mozilla\Firefox\Profiles\39az9jpg.default\extensions\[removed]
[2013/06/07 23:57:47 | 000,018,856 | —- | M] () (No name found) – C:\Users\Owner\AppData\Roaming\mozilla\firefox\profiles\39az9jpg.default\extensions\[removed]
[2013/05/20 10:39:03 | 000,223,719 | —- | M] () (No name found) – C:\Users\Owner\AppData\Roaming\mozilla\firefox\profiles\39az9jpg.default\extensions\[removed]
[2013/05/18 22:51:16 | 000,111,371 | —- | M] () (No name found) – C:\Users\Owner\AppData\Roaming\mozilla\firefox\profiles\39az9jpg.default\extensions\[removed]
[2013/06/08 01:30:26 | 000,165,283 | —- | M] () (No name found) – C:\Users\Owner\AppData\Roaming\mozilla\firefox\profiles\39az9jpg.default\extensions\[removed]
[2013/05/24 08:54:22 | 000,377,738 | —- | M] () (No name found) – C:\Users\Owner\AppData\Roaming\mozilla\firefox\profiles\39az9jpg.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}.xpi
[2012/01/16 00:14:20 | 000,001,225 | —- | M] () – C:\Users\Owner\AppData\Roaming\mozilla\firefox\profiles\39az9jpg.default\searchplugins\my-homepage.xml
[2013/05/18 21:24:47 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2013/05/18 22:33:11 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\browser\extensions
[2013/05/18 22:33:11 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

O1 HOSTS File: ([2009/06/10 17:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files\AVG\AVG2012\avgdtiex.dll File not found
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Advanced SystemCare Browser Protection) - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\Program Files\IObit\Advanced SystemCare 6\BrowerProtect\ASCPlugin_Protection.dll (IObit)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [SDTray] C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [Advanced SystemCare 6] C:\Program Files\IObit\Advanced SystemCare 6\ASCTray.exe (IObit)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll File not found
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: genieo.com ([yahoo] http in Trusted sites)
O15 - HKCU\..Trusted Ranges: Range1 ([*]in Trusted sites)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 10.21.2)
O16 - DPF: {CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_21)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{85A36CE1-252B-4009-84F1-397C084C56C5}: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{927C92D6-C742-4CF9-9DEB-CED1FDF5C8CD}: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/06/19 07:59:45 | 000,000,000 | —D | C] – C:\Users\Owner\Desktop\Utilities
[2013/06/16 21:14:49 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
[2013/06/16 21:12:50 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2013/06/16 21:12:49 | 000,368,944 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswSP.sys
[2013/06/16 21:12:49 | 000,029,816 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2013/06/16 21:12:47 | 000,061,680 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswRdr2.sys
[2013/06/16 21:12:46 | 000,765,736 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswSnx.sys
[2013/06/16 21:12:46 | 000,056,080 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswTdi.sys
[2013/06/16 21:12:39 | 000,066,336 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2013/06/16 21:12:38 | 000,229,648 | —- | C] (AVAST Software) – C:\Windows\System32\aswBoot.exe
[2013/06/16 21:11:48 | 000,041,664 | —- | C] (AVAST Software) – C:\Windows\avastSS.scr
[2013/06/16 21:11:33 | 000,000,000 | —D | C] – C:\Program Files\AVAST Software
[2013/06/16 21:10:24 | 000,000,000 | —D | C] – C:\ProgramData\AVAST Software
[2013/06/16 20:17:28 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\TuneUp Software
[2013/06/16 19:55:58 | 000,000,000 | —D | C] – C:\Users\Owner\Documents\ProcAlyzer Dumps
[2013/06/16 19:00:09 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2013/06/16 18:59:58 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
[2013/06/16 18:59:54 | 000,015,224 | —- | C] (Safer Networking Limited) – C:\Windows\System32\sdnclean.exe
[2013/06/16 18:59:50 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy 2
[2013/06/16 18:58:05 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag 2
[2013/06/16 18:38:10 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter
[2013/06/16 16:17:14 | 000,238,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2013/06/13 16:23:33 | 003,968,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2013/06/13 16:23:33 | 003,913,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2013/06/13 09:24:06 | 002,706,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/06/13 09:24:06 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/06/13 09:22:01 | 002,877,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/06/13 09:22:01 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2013/06/13 09:22:01 | 000,039,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/06/13 09:22:00 | 000,493,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/06/13 09:22:00 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2013/06/13 09:22:00 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2013/06/13 09:22:00 | 000,042,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2013/06/13 09:22:00 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2013/06/13 09:21:20 | 000,903,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certutil.exe
[2013/06/13 09:21:19 | 000,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certenc.dll
[2013/06/08 01:32:40 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox Beta
[2013/06/08 00:28:01 | 000,000,000 | —D | C] – C:\Program Files\FileHippo.com
[2013/06/07 23:25:25 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\USB Optical Mouse
[2013/06/07 23:16:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\USB Optical Mouse
[2013/06/07 23:15:59 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\WinRAR
[2013/06/07 23:15:42 | 000,000,000 | -H-D | C] – C:\Program Files\InstallShield Installation Information
[2013/06/07 23:15:42 | 000,000,000 | —D | C] – C:\Program Files\USB Optical Mouse
[2013/06/07 23:15:14 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\InstallShield
[2013/06/05 01:15:59 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wwanprotdim.dll
[2013/06/05 01:15:00 | 000,271,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\conhost.exe
[2013/06/05 01:14:59 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
[2013/06/05 01:14:59 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
[2013/06/05 01:14:59 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
[2013/06/05 01:14:59 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
[2013/06/05 01:14:59 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/06/05 01:14:59 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
[2013/06/05 01:14:59 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
[2013/06/05 01:14:59 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
[2013/06/05 01:14:59 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
[2013/06/05 01:13:50 | 000,308,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Wpc.dll
[2013/06/05 01:13:50 | 000,055,296 | —- | C] (Microsoft) – C:\Windows\System32\cero.rs
[2013/06/05 01:13:50 | 000,051,712 | —- | C] (Microsoft) – C:\Windows\System32\esrb.rs
[2013/06/05 01:13:50 | 000,046,592 | —- | C] (Microsoft) – C:\Windows\System32\fpb.rs
[2013/06/05 01:13:50 | 000,045,568 | —- | C] (Microsoft) – C:\Windows\System32\oflc-nz.rs
[2013/06/05 01:13:50 | 000,044,544 | —- | C] (Microsoft) – C:\Windows\System32\pegibbfc.rs
[2013/06/05 01:13:50 | 000,043,520 | —- | C] (Microsoft) – C:\Windows\System32\csrr.rs
[2013/06/05 01:13:50 | 000,040,960 | —- | C] (Microsoft) – C:\Windows\System32\cob-au.rs
[2013/06/05 01:13:50 | 000,030,720 | —- | C] (Microsoft) – C:\Windows\System32\usk.rs
[2013/06/05 01:13:50 | 000,023,552 | —- | C] (Microsoft) – C:\Windows\System32\oflc.rs
[2013/06/05 01:13:50 | 000,021,504 | —- | C] (Microsoft) – C:\Windows\System32\grb.rs
[2013/06/05 01:13:50 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\System32\pegi-pt.rs
[2013/06/05 01:13:50 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\System32\pegi-fi.rs
[2013/06/05 01:13:50 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\System32\pegi.rs
[2013/06/05 01:13:50 | 000,015,360 | —- | C] (Microsoft) – C:\Windows\System32\djctq.rs
[2013/06/05 01:13:49 | 002,576,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gameux.dll
[2013/06/05 01:12:49 | 000,193,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dhcpcore6.dll
[2013/06/05 01:12:49 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dhcpcsvc6.dll
[2013/06/05 01:12:30 | 000,175,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netcorehc.dll
[2013/06/05 01:12:29 | 000,156,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ncsi.dll
[2013/06/05 01:12:29 | 000,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netevent.dll
[2013/06/05 01:12:01 | 002,739,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpcorets.dll
[2013/06/05 01:12:01 | 000,317,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wksprt.exe
[2013/06/05 01:12:01 | 000,269,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\aaclient.dll
[2013/06/05 01:12:01 | 000,221,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpudd.dll
[2013/06/05 01:12:01 | 000,192,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpendp_winip.dll
[2013/06/05 01:12:01 | 000,056,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\TSWbPrxy.exe
[2013/06/05 01:12:01 | 000,049,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\TsUsbFlt.sys
[2013/06/05 01:12:01 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MsRdpWebAccess.dll
[2013/06/05 01:12:01 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tsgqec.dll
[2013/06/05 01:12:01 | 000,032,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\TsUsbGDCoInstaller.dll
[2013/06/05 01:12:01 | 000,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wksprtPS.dll
[2013/06/05 01:12:01 | 000,014,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\rdpvideominiport.sys
[2013/06/05 01:12:01 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll
[2013/06/05 01:12:01 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RdpGroupPolicyExtension.dll
[2013/06/05 01:12:01 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe
[2013/06/05 01:11:14 | 000,400,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\srcore.dll
[2013/06/05 01:10:33 | 000,245,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\OxpsConverter.exe
[2013/06/05 01:10:19 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\RNDISMP.sys
[2013/06/05 01:10:06 | 000,514,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qdvd.dll
[2013/06/05 01:09:14 | 000,478,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\timedate.cpl
[2013/06/05 01:08:49 | 000,148,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\storport.sys
[2013/06/05 01:08:49 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fsutil.exe
[2013/06/05 01:08:19 | 000,284,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usbport.sys
[2013/06/05 01:08:19 | 000,005,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usbd.sys
[2013/06/05 01:08:05 | 001,549,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tquery.dll
[2013/06/05 01:08:05 | 001,401,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssrch.dll
[2013/06/05 01:08:05 | 000,666,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssvp.dll
[2013/06/05 01:08:05 | 000,337,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssph.dll
[2013/06/05 01:08:05 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssphtb.dll
[2013/06/05 01:08:05 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msscntrs.dll
[2013/06/05 01:07:36 | 000,027,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\Diskdump.sys
[2013/06/05 01:07:26 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\prevhost.exe
[2013/06/05 01:07:10 | 002,616,320 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2013/06/05 01:06:33 | 000,023,872 | —- | C] (IObit) – C:\Windows\System32\RegistryDefragBootTime.exe
[2013/06/03 19:01:17 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2013/06/03 19:01:16 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2013/06/03 19:01:03 | 000,866,720 | —- | C] (Oracle Corporation) – C:\Windows\System32\npDeployJava1.dll
[2013/06/03 19:01:03 | 000,263,584 | —- | C] (Oracle Corporation) – C:\Windows\System32\javaws.exe
[2013/06/03 19:00:55 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\System32\javaw.exe
[2013/06/03 19:00:55 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\System32\java.exe
[2013/06/03 19:00:55 | 000,094,112 | —- | C] (Oracle Corporation) – C:\Windows\System32\WindowsAccessBridge.dll
[2013/06/03 18:55:26 | 000,000,000 | —D | C] – C:\ProgramData\SUPERSetup
[2013/06/03 18:54:15 | 000,000,000 | —D | C] – C:\Program Files\VideoLAN
[2013/06/03 18:47:26 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\uTorrent
[2013/05/20 10:42:40 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\SUPERAntiSpyware.com
[2013/05/20 10:42:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2013/05/20 10:42:15 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2013/05/20 10:42:15 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2013/05/20 10:28:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2013/05/20 10:17:24 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\Malwarebytes
[2013/05/20 10:17:09 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/05/20 10:17:09 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/05/20 10:17:08 | 000,022,856 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2013/05/20 10:17:08 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2013/05/20 10:16:45 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\Programs

========== Files - Modified Within 30 Days ==========

[2013/06/19 08:52:42 | 000,014,192 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/06/19 08:52:42 | 000,014,192 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/06/19 08:50:29 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/06/19 08:49:42 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/06/19 08:49:36 | 2388,459,520 | -HS- | M] () – C:\hiberfil.sys
[2013/06/19 08:41:00 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2470835416-242634607-3998381889-1000UA.job
[2013/06/19 08:23:01 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/19 08:11:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/06/18 23:59:20 | 000,002,577 | —- | M] () – C:\Windows\System32\config.nt
[2013/06/18 23:12:25 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2470835416-242634607-3998381889-1000Core.job
[2013/06/16 21:12:50 | 000,002,075 | —- | M] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2013/06/16 21:09:48 | 000,615,360 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/06/16 21:09:48 | 000,103,702 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/06/16 18:59:58 | 000,002,119 | —- | M] () – C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
[2013/06/16 18:58:05 | 000,001,056 | —- | M] () – C:\Users\Public\Desktop\Smart Defrag 2.lnk
[2013/06/16 18:38:10 | 000,001,131 | —- | M] () – C:\Users\Public\Desktop\IObit Malware Fighter.lnk
[2013/06/13 16:11:08 | 000,692,104 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2013/06/13 16:11:08 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/06/08 07:40:02 | 000,391,168 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/06/08 07:13:19 | 002,706,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/06/08 01:32:44 | 000,001,140 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013/06/05 09:28:16 | 000,412,432 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2013/06/05 09:26:42 | 000,000,000 | —- | M] () – C:\asc_rdflag
[2013/06/05 01:15:59 | 000,040,960 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wwanprotdim.dll
[2013/06/05 01:15:00 | 000,271,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\conhost.exe
[2013/06/05 01:14:59 | 000,006,144 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
[2013/06/05 01:14:59 | 000,005,120 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
[2013/06/05 01:14:59 | 000,004,608 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
[2013/06/05 01:14:59 | 000,004,608 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
[2013/06/05 01:14:59 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/06/05 01:14:59 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
[2013/06/05 01:14:59 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
[2013/06/05 01:14:59 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
[2013/06/05 01:14:59 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
[2013/06/05 01:14:59 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
[2013/06/05 01:13:50 | 000,308,736 | —- | M] (Microsoft Corporation) – C:\Windows\System32\Wpc.dll
[2013/06/05 01:13:50 | 000,055,296 | —- | M] (Microsoft) – C:\Windows\System32\cero.rs
[2013/06/05 01:13:50 | 000,051,712 | —- | M] (Microsoft) – C:\Windows\System32\esrb.rs
[2013/06/05 01:13:50 | 000,046,592 | —- | M] (Microsoft) – C:\Windows\System32\fpb.rs
[2013/06/05 01:13:50 | 000,045,568 | —- | M] (Microsoft) – C:\Windows\System32\oflc-nz.rs
[2013/06/05 01:13:50 | 000,044,544 | —- | M] (Microsoft) – C:\Windows\System32\pegibbfc.rs
[2013/06/05 01:13:50 | 000,043,520 | —- | M] (Microsoft) – C:\Windows\System32\csrr.rs
[2013/06/05 01:13:50 | 000,040,960 | —- | M] (Microsoft) – C:\Windows\System32\cob-au.rs
[2013/06/05 01:13:50 | 000,030,720 | —- | M] (Microsoft) – C:\Windows\System32\usk.rs
[2013/06/05 01:13:50 | 000,023,552 | —- | M] (Microsoft) – C:\Windows\System32\oflc.rs
[2013/06/05 01:13:50 | 000,021,504 | —- | M] (Microsoft) – C:\Windows\System32\grb.rs
[2013/06/05 01:13:50 | 000,020,480 | —- | M] (Microsoft) – C:\Windows\System32\pegi-pt.rs
[2013/06/05 01:13:50 | 000,020,480 | —- | M] (Microsoft) – C:\Windows\System32\pegi-fi.rs
[2013/06/05 01:13:50 | 000,020,480 | —- | M] (Microsoft) – C:\Windows\System32\pegi.rs
[2013/06/05 01:13:50 | 000,015,360 | —- | M] (Microsoft) – C:\Windows\System32\djctq.rs
[2013/06/05 01:13:49 | 002,576,384 | —- | M] (Microsoft Corporation) – C:\Windows\System32\gameux.dll
[2013/06/05 01:12:49 | 000,193,536 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dhcpcore6.dll
[2013/06/05 01:12:49 | 000,044,032 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dhcpcsvc6.dll
[2013/06/05 01:12:30 | 000,175,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\netcorehc.dll
[2013/06/05 01:12:29 | 000,156,672 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ncsi.dll
[2013/06/05 01:12:29 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\Windows\System32\netevent.dll
[2013/06/05 01:12:01 | 002,739,712 | —- | M] (Microsoft Corporation) – C:\Windows\System32\rdpcorets.dll
[2013/06/05 01:12:01 | 000,317,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wksprt.exe
[2013/06/05 01:12:01 | 000,269,312 | —- | M] (Microsoft Corporation) – C:\Windows\System32\aaclient.dll
[2013/06/05 01:12:01 | 000,221,184 | —- | M] (Microsoft Corporation) – C:\Windows\System32\rdpudd.dll
[2013/06/05 01:12:01 | 000,192,000 | —- | M] (Microsoft Corporation) – C:\Windows\System32\rdpendp_winip.dll
[2013/06/05 01:12:01 | 000,056,320 | —- | M] (Microsoft Corporation) – C:\Windows\System32\TSWbPrxy.exe
[2013/06/05 01:12:01 | 000,049,664 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\TsUsbFlt.sys
[2013/06/05 01:12:01 | 000,046,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MsRdpWebAccess.dll
[2013/06/05 01:12:01 | 000,037,376 | —- | M] (Microsoft Corporation) – C:\Windows\System32\tsgqec.dll
[2013/06/05 01:12:01 | 000,032,768 | —- | M] (Microsoft Corporation) – C:\Windows\System32\TsUsbGDCoInstaller.dll
[2013/06/05 01:12:01 | 000,016,896 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wksprtPS.dll
[2013/06/05 01:12:01 | 000,014,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\rdpvideominiport.sys
[2013/06/05 01:12:01 | 000,013,312 | —- | M] (Microsoft Corporation) – C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll
[2013/06/05 01:12:01 | 000,012,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RdpGroupPolicyExtension.dll
[2013/06/05 01:12:01 | 000,012,288 | —- | M] (Microsoft Corporation) – C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe
[2013/06/05 01:12:01 | 000,003,072 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\en-US\tsusbflt.sys.mui
[2013/06/05 01:11:14 | 000,400,896 | —- | M] (Microsoft Corporation) – C:\Windows\System32\srcore.dll
[2013/06/05 01:10:34 | 000,245,760 | —- | M] (Microsoft Corporation) – C:\Windows\System32\OxpsConverter.exe
[2013/06/05 01:10:19 | 000,033,280 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\RNDISMP.sys
[2013/06/05 01:09:14 | 000,478,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\timedate.cpl
[2013/06/05 01:08:49 | 000,148,864 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\storport.sys
[2013/06/05 01:08:49 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\Windows\System32\fsutil.exe
[2013/06/05 01:08:19 | 000,284,672 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\usbport.sys
[2013/06/05 01:08:19 | 000,005,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\usbd.sys
[2013/06/05 01:08:05 | 001,549,312 | —- | M] (Microsoft Corporation) – C:\Windows\System32\tquery.dll
[2013/06/05 01:08:05 | 001,401,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mssrch.dll
[2013/06/05 01:08:05 | 000,666,624 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mssvp.dll
[2013/06/05 01:08:05 | 000,337,408 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mssph.dll
[2013/06/05 01:08:05 | 000,197,120 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mssphtb.dll
[2013/06/05 01:08:05 | 000,059,392 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msscntrs.dll
[2013/06/05 01:07:36 | 000,027,008 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\Diskdump.sys
[2013/06/05 01:07:26 | 000,031,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\prevhost.exe
[2013/06/05 01:07:10 | 002,616,320 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
[2013/06/03 19:00:42 | 000,094,112 | —- | M] (Oracle Corporation) – C:\Windows\System32\WindowsAccessBridge.dll
[2013/06/03 19:00:39 | 000,866,720 | —- | M] (Oracle Corporation) – C:\Windows\System32\npDeployJava1.dll
[2013/06/03 19:00:39 | 000,788,896 | —- | M] (Oracle Corporation) – C:\Windows\System32\deployJava1.dll
[2013/06/03 19:00:39 | 000,263,584 | —- | M] (Oracle Corporation) – C:\Windows\System32\javaws.exe
[2013/06/03 19:00:39 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\System32\javaw.exe
[2013/06/03 19:00:39 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\System32\java.exe
[2013/05/21 06:57:41 | 000,026,900 | —- | M] () – C:\Users\Owner\AppData\Local\dt.dat
[2013/05/21 06:57:38 | 000,001,407 | —- | M] () – C:\Users\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/05/21 00:23:44 | 000,000,632 | RHS- | M] () – C:\Users\Owner\ntuser.pol
[2013/05/20 10:28:19 | 000,002,170 | —- | M] () – C:\Users\Public\Desktop\Google Earth.lnk
[2013/05/20 10:17:09 | 000,001,091 | —- | M] () – C:\Users\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk

========== Files Created - No Company Name ==========

[2013/06/16 21:13:08 | 000,000,884 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/16 21:13:08 | 000,000,880 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/06/16 21:12:50 | 000,002,075 | —- | C] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2013/06/16 21:12:45 | 000,174,664 | —- | C] () – C:\Windows\System32\drivers\aswVmm.sys
[2013/06/16 21:12:44 | 000,049,376 | —- | C] () – C:\Windows\System32\drivers\aswRvrt.sys
[2013/06/16 18:59:58 | 000,002,131 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
[2013/06/16 18:59:58 | 000,002,119 | —- | C] () – C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
[2013/06/16 18:58:06 | 000,015,672 | —- | C] () – C:\Windows\System32\drivers\SmartDefragDriver.sys
[2013/06/16 18:58:05 | 000,001,056 | —- | C] () – C:\Users\Public\Desktop\Smart Defrag 2.lnk
[2013/06/16 18:38:10 | 000,001,131 | —- | C] () – C:\Users\Public\Desktop\IObit Malware Fighter.lnk
[2013/06/05 09:26:42 | 000,000,000 | —- | C] () – C:\asc_rdflag
[2013/05/21 06:57:41 | 000,026,900 | —- | C] () – C:\Users\Owner\AppData\Local\dt.dat
[2013/05/21 06:57:38 | 000,001,407 | —- | C] () – C:\Users\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/05/21 00:13:21 | 000,000,632 | RHS- | C] () – C:\Users\Owner\ntuser.pol
[2013/05/20 10:28:19 | 000,002,170 | —- | C] () – C:\Users\Public\Desktop\Google Earth.lnk
[2013/05/20 10:17:09 | 000,001,091 | —- | C] () – C:\Users\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2013/05/18 21:43:37 | 000,080,896 | —- | C] () – C:\Windows\System32\RDVGHelper.exe
[2013/05/18 21:41:51 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe

========== ZeroAccess Check ==========

[2009/07/14 00:42:31 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/27 00:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 08:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/13 21:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/08/29 16:49:06 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\.mono
[2012/01/03 18:21:17 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\AVG2012
[2013/06/16 18:58:07 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\IObit
[2013/05/18 21:33:40 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Pokémon Trading Card Game Online
[2013/06/16 20:17:28 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\TuneUp Software
[2013/06/07 23:25:25 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\USB Optical Mouse
[2013/06/16 18:34:06 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\uTorrent

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2009/07/13 22:07:10 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\PolicyDefinitions\en-US\Explorer.adml
[2009/07/13 22:07:10 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_22d6d5b5cba907ce\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 17:34:46 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\PolicyDefinitions\Explorer.admx
[2009/06/10 17:34:46 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\x86_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_1590ffd752297581\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2013/05/16 10:58:12 | 003,859,928 | —- | M] (Safer-Networking Ltd.) MD5=03250DB0886A23B1F6C077C5D9F152B0 – C:\Program Files\Spybot - Search & Destroy 2\explorer.exe
[2013/06/05 01:07:10 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2009/07/13 21:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2013/06/05 01:07:10 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe
[2009/10/31 01:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[2013/06/05 01:07:11 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe
[2010/11/20 08:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2013/06/05 01:07:10 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\explorer.exe
[2013/06/05 01:07:10 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
[2009/08/03 01:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2009/08/03 01:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2009/10/31 02:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2009/07/13 22:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\en-US\explorer.exe.mui
[2009/07/13 22:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_05c8dd40d4f56065\explorer.exe.mui

< MD5 for: EXPLORER.EXE-A80E4F97.PF >
[2013/06/18 23:13:03 | 000,160,466 | —- | M] () MD5=84D8A8F0A8E214529948C9A4D8867756 – C:\Windows\Prefetch\EXPLORER.EXE-A80E4F97.pf

< MD5 for: EXPLORER.ZIP >
[2006/03/06 23:48:08 | 000,020,394 | —- | M] () MD5=B469409C2B2A33C542190B720E11BD79 – C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip

< MD5 for: IEXPLORE.EXE >
[2013/03/04 00:49:09 | 000,672,928 | —- | M] (Microsoft Corporation) MD5=050A612C1CE0C7095CAD64EA32C570DB – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21484_none_b3cf7f6d9f39f5d6\iexplore.exe
[2013/05/16 22:32:12 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=07DFD28E57879554D054464EE4A5662D – C:\Program Files\Internet Explorer\iexplore.exe
[2013/05/16 22:32:12 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=07DFD28E57879554D054464EE4A5662D – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16614_none_ba6545dc65e543de\iexplore.exe
[2009/07/13 21:17:29 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=2C32E3E596CFE660353753EABEFB0540 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_b346f9b4861b55c2\iexplore.exe
[2013/05/16 21:57:28 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=3902E280F6117A468D5573343A7AA1F6 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20719_none_a38c5d6c7f953fa9\iexplore.exe
[2013/05/18 20:05:35 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=3F00BE80B9CEA20B7FE7363D15EDDB94 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16483_none_b0f72023c83af39d\iexplore.exe
[2013/03/02 01:06:58 | 000,672,912 | —- | M] (Microsoft Corporation) MD5=58D926F3B2113BF849162C9C26FE21DC – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17267_none_b35e817286096d08\iexplore.exe
[2013/05/18 23:06:57 | 000,770,608 | —- | M] (Microsoft Corporation) MD5=AAD90795E84E710543C6C7C2F7048E30 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16576_none_ba75e9f465d7f339\iexplore.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2010/11/20 08:22:51 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_b5780d7c8309d95c\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2013/05/18 20:05:35 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_aae2948effb95a30\iexplore.exe.mui
[2013/05/18 23:06:57 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2013/05/18 23:06:57 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_b41defe19d893548\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_acf38f2bbdc896a9\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_af24a2f3bab71a43\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-908C99F8.PF >
[2013/06/19 08:46:47 | 000,299,550 | —- | M] () MD5=60B999B78F14B17FC27084A7258542DC – C:\Windows\Prefetch\IEXPLORE.EXE-908C99F8.pf

< MD5 for: SERVICES >
[2009/06/10 17:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\System32\drivers\etc\services
[2009/06/10 17:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_045b589158ae90da\services

< MD5 for: SERVICES.EXE >
[2009/07/13 21:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\System32\services.exe
[2009/07/13 21:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2009/07/13 22:03:06 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 – C:\Windows\System32\en-US\services.exe.mui
[2009/07/13 22:03:06 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 – C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_69d39d3a8748c332\services.exe.mui

< MD5 for: SERVICES.LNK >
[2009/07/14 00:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 17:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\System32\wbem\services.mof
[2009/06/10 17:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.mof

< MD5 for: SERVICES.MSC >
[2009/07/13 22:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\en-US\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\services.msc
[2009/07/13 22:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009/07/13 16:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\System32\wdi\perftrack\Services.ptxml
[2009/07/13 16:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\Services.ptxml

< MD5 for: SERVICES.SBS >
[2011/03/01 00:00:00 | 000,034,818 | —- | M] () MD5=62AFD4B2025CE6D4706B36F4C4808F9B – C:\Program Files\Spybot - Search & Destroy 2\Includes\Services.sbs
[2011/03/01 03:58:46 | 000,034,818 | —- | M] () MD5=62AFD4B2025CE6D4706B36F4C4808F9B – C:\Program Files\Spybot - Search & Destroy 2\Updates\Extracts\Services.sbs

< MD5 for: SERVICES.SBS-20110301.CAB >
[2013/06/16 19:03:27 | 000,041,248 | —- | M] () MD5=149FF3413EED31253183D6E65E383138 – C:\Program Files\Spybot - Search & Destroy 2\Updates\Downloads\Services.sbs-20110301.cab

< MD5 for: WINLOGON.ADML >
[2009/07/13 22:05:00 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\PolicyDefinitions\en-US\WinLogon.adml
[2009/07/13 22:05:00 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_94da67ab3e358f3a\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 17:43:18 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\PolicyDefinitions\WinLogon.admx
[2009/06/10 17:43:18 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_7ae3b2e5da95d117\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2009/10/28 02:17:59 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009/10/28 01:52:08 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2010/11/20 08:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\System32\winlogon.exe
[2010/11/20 08:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2009/07/13 21:14:45 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2010/11/20 08:12:53 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=65C2C2EE8F334EE07F66876551DE1827 – C:\Windows\System32\en-US\winlogon.exe.mui
[2010/11/20 08:12:53 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=65C2C2EE8F334EE07F66876551DE1827 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_ccfffb7662588b45\winlogon.exe.mui
[2009/07/13 22:05:28 | 000,022,528 | —- | M] (Microsoft Corporation) MD5=DB61D28A59DEE68F77811B291D83AD1B – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7600.16385_en-us_cacee7ae656a07ab\winlogon.exe.mui

< MD5 for: WINLOGON.EXE-B020DC41.PF >
[2013/06/18 23:12:50 | 000,032,462 | —- | M] () MD5=5CAE2B3C48DE78ACE38BA3EE65892112 – C:\Windows\Prefetch\WINLOGON.EXE-B020DC41.pf

< MD5 for: WINLOGON.MFL >
[2009/07/13 22:09:40 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\System32\wbem\en-US\winlogon.mfl
[2009/07/13 22:09:40 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_2891397980a26140\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 16:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\System32\wbem\winlogon.mof
[2009/07/13 16:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_800f1ff3d73b72d9\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2012/01/16 00:15:36 | 000,000,063 | —- | M] () – C:\1.html
[2013/06/05 09:26:42 | 000,000,000 | —- | M] () – C:\asc_rdflag
[2009/06/10 17:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/06/10 17:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2013/06/19 08:49:36 | 2388,459,520 | -HS- | M] () – C:\hiberfil.sys
[2012/01/03 18:11:09 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2012/01/03 18:11:09 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2013/06/19 08:49:36 | 3184,615,424 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/14 00:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 17:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/13 21:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll
[2010/11/20 08:21:36 | 000,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2013/05/09 04:58:37 | 000,041,664 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2013/05/17 11:05:14 | 000,001,670 | -HS- | M] () – C:\Users\Owner\AppData\Roaming\Microsoft\LastFlashConfig.wfc

< %PROGRAMFILES%\*.* >
[2009/07/14 00:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C has no label.
Volume Serial Number is D4F3-5F44
Directory of C:\
07/14/2009 12:53 AM Documents and Settings [C:\Users]
0 File(s) 0 bytes
Directory of C:\ProgramData
07/14/2009 12:53 AM Application Data [C:\ProgramData]
07/14/2009 12:53 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 12:53 AM Documents [C:\Users\Public\Documents]
07/14/2009 12:53 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 12:53 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 12:53 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
07/14/2009 12:53 AM All Users [C:\ProgramData]
07/14/2009 12:53 AM Default User [C:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\Admin2
05/24/2013 09:05 AM Application Data [C:\Users\Admin2\AppData\Roaming]
05/24/2013 09:05 AM Cookies [C:\Users\Admin2\AppData\Roaming\Microsoft\Windows\Cookies]
05/24/2013 09:05 AM Local Settings [C:\Users\Admin2\AppData\Local]
05/24/2013 09:05 AM My Documents [C:\Users\Admin2\Documents]
05/24/2013 09:05 AM NetHood [C:\Users\Admin2\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
05/24/2013 09:05 AM PrintHood [C:\Users\Admin2\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
05/24/2013 09:05 AM Recent [C:\Users\Admin2\AppData\Roaming\Microsoft\Windows\Recent]
05/24/2013 09:05 AM SendTo [C:\Users\Admin2\AppData\Roaming\Microsoft\Windows\SendTo]
05/24/2013 09:05 AM Start Menu [C:\Users\Admin2\AppData\Roaming\Microsoft\Windows\Start Menu]
05/24/2013 09:05 AM Templates [C:\Users\Admin2\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Admin2\AppData\Local
05/24/2013 09:05 AM Application Data [C:\Users\Admin2\AppData\Local]
05/24/2013 09:05 AM History [C:\Users\Admin2\AppData\Local\Microsoft\Windows\History]
05/24/2013 09:05 AM Temporary Internet Files [C:\Users\Admin2\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Admin2\Documents
05/24/2013 09:05 AM My Music [C:\Users\Admin2\Music]
05/24/2013 09:05 AM My Pictures [C:\Users\Admin2\Pictures]
05/24/2013 09:05 AM My Videos [C:\Users\Admin2\Videos]
0 File(s) 0 bytes
Directory of C:\Users\All Users
07/14/2009 12:53 AM Application Data [C:\ProgramData]
07/14/2009 12:53 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 12:53 AM Documents [C:\Users\Public\Documents]
07/14/2009 12:53 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 12:53 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 12:53 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default
07/14/2009 12:53 AM Application Data [C:\Users\Default\AppData\Roaming]
07/14/2009 12:53 AM Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
07/14/2009 12:53 AM Local Settings [C:\Users\Default\AppData\Local]
07/14/2009 12:53 AM My Documents [C:\Users\Default\Documents]
07/14/2009 12:53 AM NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/14/2009 12:53 AM PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/14/2009 12:53 AM Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/14/2009 12:53 AM SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/14/2009 12:53 AM Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/14/2009 12:53 AM Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
07/14/2009 12:53 AM Application Data [C:\Users\Default\AppData\Local]
07/14/2009 12:53 AM History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009 12:53 AM Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
07/14/2009 12:53 AM My Music [C:\Users\Default\Music]
07/14/2009 12:53 AM My Pictures [C:\Users\Default\Pictures]
07/14/2009 12:53 AM My Videos [C:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Hannah
05/22/2013 05:35 PM Application Data [C:\Users\Hannah\AppData\Roaming]
05/22/2013 05:35 PM Cookies [C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Cookies]
05/22/2013 05:35 PM Local Settings [C:\Users\Hannah\AppData\Local]
05/22/2013 05:35 PM My Documents [C:\Users\Hannah\Documents]
05/22/2013 05:35 PM NetHood [C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
05/22/2013 05:35 PM PrintHood [C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
05/22/2013 05:35 PM Recent [C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Recent]
05/22/2013 05:35 PM SendTo [C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\SendTo]
05/22/2013 05:35 PM Start Menu [C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Start Menu]
05/22/2013 05:35 PM Templates [C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Hannah\AppData\Local
05/22/2013 05:35 PM Application Data [C:\Users\Hannah\AppData\Local]
05/22/2013 05:35 PM History [C:\Users\Hannah\AppData\Local\Microsoft\Windows\History]
05/22/2013 05:35 PM Temporary Internet Files [C:\Users\Hannah\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Hannah\Documents
05/22/2013 05:35 PM My Music [C:\Users\Hannah\Music]
05/22/2013 05:35 PM My Pictures [C:\Users\Hannah\Pictures]
05/22/2013 05:35 PM My Videos [C:\Users\Hannah\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Owner
01/03/2012 05:38 PM Application Data [C:\Users\Owner\AppData\Roaming]
01/03/2012 05:38 PM Cookies [C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Cookies]
01/03/2012 05:38 PM Local Settings [C:\Users\Owner\AppData\Local]
01/03/2012 05:38 PM My Documents [C:\Users\Owner\Documents]
01/03/2012 05:38 PM NetHood [C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
01/03/2012 05:38 PM PrintHood [C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
01/03/2012 05:38 PM Recent [C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Recent]
01/03/2012 05:38 PM SendTo [C:\Users\Owner\AppData\Roaming\Microsoft\Windows\SendTo]
01/03/2012 05:38 PM Start Menu [C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu]
01/03/2012 05:38 PM Templates [C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Owner\AppData\Local
01/03/2012 05:38 PM Application Data [C:\Users\Owner\AppData\Local]
01/03/2012 05:38 PM History [C:\Users\Owner\AppData\Local\Microsoft\Windows\History]
01/03/2012 05:38 PM Temporary Internet Files [C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Owner\Documents
01/03/2012 05:38 PM My Music [C:\Users\Owner\Music]
01/03/2012 05:38 PM My Pictures [C:\Users\Owner\Pictures]
01/03/2012 05:38 PM My Videos [C:\Users\Owner\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
07/14/2009 12:53 AM My Music [C:\Users\Public\Music]
07/14/2009 12:53 AM My Pictures [C:\Users\Public\Pictures]
07/14/2009 12:53 AM My Videos [C:\Users\Public\Videos]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
82 Dir(s) 74,610,958,336 bytes free

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2013/05/21 06:57:38 | 000,000,221 | -HS- | M] () – C:\Users\Owner\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-06-19 03:24:14

< End of report >

OTL Extras logfile created on: 6/19/2013 8:53:09 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Owner\Desktop\Utilities
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16614)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.97 Gb Total Physical Memory | 2.22 Gb Available Physical Memory | 74.82% Memory free
5.93 Gb Paging File | 5.10 Gb Available in Paging File | 86.01% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 93.06 Gb Total Space | 69.50 Gb Free Space | 74.69% Space Free | Partition Type: NTFS

Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon – (Safer-Networking Ltd.)
"C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service – (Safer-Networking Ltd.)
"C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater – (Safer-Networking Ltd.)
"C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service – (Safer-Networking Ltd.)


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0E6867FB-8A98-456F-A616-185FE36CD947}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{1ED199A5-9059-45FC-96F2-F9C8B92FE926}" = rport=10243 | protocol=6 | dir=out | app=system |
"{243D607C-C96D-446E-977E-B352803F1C89}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{30C7CE4D-C3DE-469C-B137-0B7E40E62D87}" = lport=137 | protocol=17 | dir=in | app=system |
"{326869CF-15C3-43C7-BE17-CAAE0C642D90}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{337DBAA6-2137-4AD8-B800-63B10583063E}" = lport=138 | protocol=17 | dir=in | app=system |
"{39EE6433-A833-4B98-A6BF-7EBF62176DB7}" = rport=445 | protocol=6 | dir=out | app=system |
"{42411BE3-4D10-4EF1-97A7-64AA7DC67EEB}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{47F5159C-4DE8-40AE-93F8-90C2BE0AF491}" = lport=2869 | protocol=6 | dir=in | app=system |
"{4A5247A9-535B-4C1E-8F37-6F3F80B84AA3}" = rport=139 | protocol=6 | dir=out | app=system |
"{5A821320-86C6-4D3A-BDC4-8524B11B9182}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{5FA18AAC-32A8-4158-8B65-0570FD2A35DA}" = lport=139 | protocol=6 | dir=in | app=system |
"{A384B1B4-6776-4FA5-BF08-CC6EA58F5656}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{A3BA930D-3C28-4E28-B341-53C45812EB5E}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{BA3FD4F0-A3EF-4579-9819-BB19A52D4A53}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{C9FB89EF-A328-4901-A0BA-1CF147101BEC}" = lport=10243 | protocol=6 | dir=in | app=system |
"{CEEA958A-FEB3-4A98-AE22-6F123CF55E27}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{D7C73B29-842D-4030-89D6-7345E495F4E4}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{E5E99EB1-083A-411D-A2DA-BF1DCC4D3E03}" = lport=445 | protocol=6 | dir=in | app=system |
"{E690E05C-A569-4A44-BE04-66134E55FE36}" = rport=138 | protocol=17 | dir=out | app=system |
"{E96DD998-2059-4B20-B0DB-C66C3BC89290}" = lport=1886 | protocol=6 | dir=in | name=genieo |
"{F7412692-AA14-47CA-8BFC-0E57508274B9}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{FC36A5D3-AB0A-441A-9CC6-640192FCEADA}" = rport=137 | protocol=17 | dir=out | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{03671173-E1D0-47D2-8EB6-C51F21CF9774}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{05D564C5-5711-486A-B534-6CABE3FB34C7}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{0B675597-5BBF-4A6A-BEB0-1FDB35C62494}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgdiagex.exe |
"{11DEF94E-FDBC-4F0C-B8AA-94E2237C3EAC}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{1CD839AA-1BB4-4AD8-BF9E-FDC00A84D5FF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{27DD98A9-A2FF-4E75-A5F4-82B3A81872E9}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{291463C4-055B-4145-8BF3-F1833FF9C854}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{29A4ECF0-C7E3-4DE9-95A6-F0103BBAD705}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{29A83817-B62A-4FCA-9AF7-AC74F9A42119}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgemcx.exe |
"{2B7F1A36-61D8-4A3F-BC1C-16CF05420357}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{34DE5739-6232-4BED-9E0D-79C81DB00AF4}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgnsx.exe |
"{3CED85B1-9F84-4340-AF2A-0586D45D97A0}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{5539C0E1-40FA-4876-ABCD-AF003A1A3798}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{55EFD4E1-E271-4652-ADD3-FF035DADF005}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{5A494684-6997-46FF-AAEE-9AB58D9FA9EE}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgemcx.exe |
"{5F079E5C-571F-4B72-B285-55D7DABDFD91}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{615C6E9B-679B-423D-AD21-583D52BF4872}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{6E143514-19D0-4D4C-BC9B-02FDDAE4EA58}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgnsx.exe |
"{77C369D5-F623-4BAC-BE61-5E3B31B214EF}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgmfapx.exe |
"{7C9037A1-DE70-4CED-BE89-E6A5D20559B8}" = protocol=6 | dir=out | app=system |
"{7FE645E8-106A-4889-B89B-FBA338080970}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgdiagex.exe |
"{9392DC5E-2972-461B-A221-C2CAF9CE61A6}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{93E97815-E919-4168-B2FA-4765F85E4C3A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{944B8B33-7AD1-4683-AB58-ED2CBBA34D99}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{951AD086-1743-43AB-801F-417D5C61E486}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgdiagex.exe |
"{97899B77-222B-476E-B4EE-F0A22D77C9FC}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgmfapx.exe |
"{97923075-2C6C-4D15-BFF0-21BD016FD88B}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgemcx.exe |
"{9D013B95-BDEE-4F9A-A464-76A00191229A}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A907953A-F63D-4E67-BE1C-C1E962142CE7}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgdiagex.exe |
"{B54FAE42-4174-4DD6-9A45-995BEB5F6F80}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgemcx.exe |
"{C6DB24D0-0E92-4EF5-B591-C636D5ED1C82}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{D59B31E8-4AB3-4CE1-B26F-427847B79F08}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgnsx.exe |
"{E3E7BB4D-2B0D-482A-8E5C-70BEC3926DB8}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgnsx.exe |
"{FCA59C5E-05EA-4E6E-BD56-C6DCD5DDD044}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"TCP Query User{6BC92DFA-68E2-4BAB-B1AB-24557ABFDC6E}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"UDP Query User{88F09A90-50D5-4EFF-968E-7664C45BB0E4}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0A844D8F-A965-11E2-9E77-B8AC6F98CCE3}" = Google Earth
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83217021FF}" = Java 7 Update 21
"{27979F37-AF9C-33DE-8437-76F7AEFAABAD}" = Google Talk Plugin
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{926CC8AE-8414-43DF-8EB4-CF26D9C3C663}" =
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{989FB5FD-9B00-4B32-8663-849CB1370DD1}" = Google Drive
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1" = Spybot - Search & Destroy
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{EEAE45EB-C1E3-4CCD-930D-D7B40F810063}" = USB Optical Mouse
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 12.0
"Advanced SystemCare 6_is1" = Advanced SystemCare 6
"avast" = avast! Free Antivirus
"ENTERPRISE" = Microsoft Office Enterprise 2007
"FreeBible" = FreeBible
"IObit Malware Fighter_is1" = IObit Malware Fighter
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"Mozilla Firefox 21.0 (x86 en-US)" = Mozilla Firefox 21.0 (x86 en-US)
"Mozilla Firefox 22.0 (x86 en-US)" = Mozilla Firefox 22.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Picasa 3" = Picasa 3
"Smart Defrag 2_is1" = Smart Defrag 2

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 6/7/2013 8:03:44 AM | Computer Name = Owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: firefox.exe, version: 21.0.0.4879, time
stamp: 0x518ec3cc Faulting module name: xul.dll, version: 21.0.0.4879, time stamp:
0x518ec306 Exception code: 0xc0000005 Fault offset: 0x001c9789 Faulting process id:
0xd14 Faulting application start time: 0x01ce637561510967 Faulting application path:
C:\Program Files\Mozilla Firefox\firefox.exe Faulting module path: C:\Program Files\Mozilla
Firefox\xul.dll Report Id: 4c712a87-cf6a-11e2-9078-20cf300c7762

Error - 6/7/2013 11:15:32 PM | Computer Name = Owner-PC | Source = VSS | ID = 8194
Description =

Error - 6/7/2013 11:41:28 PM | Computer Name = Owner-PC | Source = Application Hang | ID = 1002
Description = The program firefox.exe version 21.0.0.4879 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: cc0 Start
Time: 01ce63f7d4a5cb97 Termination Time: 53 Application Path: C:\Program Files\Mozilla
Firefox\firefox.exe Report Id: 4acc5c57-cfed-11e2-baad-20cf300c7762

Error - 6/8/2013 7:37:33 AM | Computer Name = Owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: firefox.exe, version: 21.0.0.4879, time
stamp: 0x518ec3cc Faulting module name: xul.dll, version: 21.0.0.4879, time stamp:
0x518ec306 Exception code: 0xc0000005 Fault offset: 0x001c9789 Faulting process id:
0x9dc Faulting application start time: 0x01ce6438082d0dd7 Faulting application path:
C:\Program Files\Mozilla Firefox\firefox.exe Faulting module path: C:\Program Files\Mozilla
Firefox\xul.dll Report Id: cea49407-d02f-11e2-985b-20cf300c7762

Error - 6/8/2013 1:33:15 PM | Computer Name = Owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: firefox.exe, version: 21.0.0.4879, time
stamp: 0x518ec3cc Faulting module name: xul.dll, version: 21.0.0.4879, time stamp:
0x518ec306 Exception code: 0xc0000005 Fault offset: 0x001c9789 Faulting process id:
0x1778 Faulting application start time: 0x01ce646e18e8187b Faulting application path:
C:\Program Files\Mozilla Firefox\firefox.exe Faulting module path: C:\Program Files\Mozilla
Firefox\xul.dll Report Id: 7f815c7d-d061-11e2-985b-20cf300c7762

Error - 6/11/2013 11:07:12 AM | Computer Name = Owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: firefox.exe, version: 21.0.0.4879, time
stamp: 0x518ec3cc Faulting module name: xul.dll, version: 21.0.0.4879, time stamp:
0x518ec306 Exception code: 0xc0000005 Fault offset: 0x001c9789 Faulting process id:
0xc44 Faulting application start time: 0x01ce66b3c433097a Faulting application path:
C:\Program Files\Mozilla Firefox\firefox.exe Faulting module path: C:\Program Files\Mozilla
Firefox\xul.dll Report Id: 97598f4d-d2a8-11e2-b5de-20cf300c7762

Error - 6/16/2013 6:20:28 PM | Computer Name = Owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: firefox.exe, version: 21.0.0.4879, time
stamp: 0x518ec3cc Faulting module name: xul.dll, version: 21.0.0.4879, time stamp:
0x518ec306 Exception code: 0xc0000005 Fault offset: 0x001c9789 Faulting process id:
0x8b4 Faulting application start time: 0x01ce6ade7e7b944b Faulting application path:
C:\Program Files\Mozilla Firefox\firefox.exe Faulting module path: C:\Program Files\Mozilla
Firefox\xul.dll Report Id: f24f1c63-d6d2-11e2-b1d0-20cf300c7762

Error - 6/16/2013 8:14:21 PM | Computer Name = Owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: SDTools.exe, version: 2.1.18.150, time
stamp: 0x51949fd7 Faulting module name: rtl150.bpl, version: 15.0.3953.35171, time
stamp: 0x4cca139f Exception code: 0xc0000005 Fault offset: 0x00005ebb Faulting process
id: 0x570 Faulting application start time: 0x01ce6aece4223ef4 Faulting application
path: C:\Program Files\Spybot - Search & Destroy 2\SDTools.exe Faulting module path:
C:\Program Files\Spybot - Search & Destroy 2\rtl150.bpl Report Id: db3edacb-d6e2-11e2-81c2-20cf300c7762

Error - 6/16/2013 8:18:01 PM | Computer Name = Owner-PC | Source = MsiInstaller | ID = 11922
Description =

Error - 6/16/2013 8:24:14 PM | Computer Name = Owner-PC | Source = MsiInstaller | ID = 11922
Description =

[ Media Center Events ]
Error - 8/25/2012 8:53:18 PM | Computer Name = Owner-PC | Source = MCUpdate | ID = 0
Description = 8:53:14 PM - Error connecting to the internet. 8:53:14 PM - Unable
to contact server..

[ System Events ]
Error - 6/5/2013 1:03:20 AM | Computer Name = Owner-PC | Source = DCOM | ID = 10010
Description =

Error - 6/5/2013 9:27:11 AM | Computer Name = Owner-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!

Error - 6/16/2013 9:02:22 PM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7043
Description = The AVGIDSAgent service did not shut down properly after receiving
a preshutdown control.

Error - 6/16/2013 9:03:34 PM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AVGIDSHX

Error - 6/18/2013 8:37:31 AM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7034
Description = The Google Update Service (gupdate) service terminated unexpectedly.
It has done this 1 time(s).

Error - 6/18/2013 8:38:01 AM | Computer Name = Owner-PC | Source = DCOM | ID = 10010
Description =

Error - 6/18/2013 11:12:21 PM | Computer Name = Owner-PC | Source = DCOM | ID = 10010
Description =

Error - 6/19/2013 8:50:34 AM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Spybot-S&D
2 Scanner Service service to connect.

Error - 6/19/2013 8:50:34 AM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7000
Description = The Spybot-S&D 2 Scanner Service service failed to start due to the
following error: %%1053

Error - 6/19/2013 8:50:39 AM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AVGIDSHX


< End of report >
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!

IOBit based in China has stolen and incorporated proprietary databases and intellectual property into their software in the past. This calls into question the reliability and safety of this program. I would suggest you use uninstall this program, but the decision is yours. You can read more about it here

It does look like you are being directed through a proxy for your internet, which is typically not a good thing unless you set it to do so, so let's go ahead and run a tool to do a deeper scan to look for and remove malware, and if it does not remove that, then we can do so with a fix.

This may be how someone was able to gain access to your credentials. When we are done cleaning, and you have the all clean from me, although you have done the recommended steps to protect your passwords, I'd recommend doing them once again - but not until we have this resolved.

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. 1. Do not mouse-click anywhere on the screen while it is running. That may cause it to stall. In fact, I suggest you do not do anything else on the computer while Combofix is running as it can cause it to stall. It may appear at times that it isn't doing anything but it is. Just let it run. It may also reboot the machine as a part of what it is doing and that is not unusual. (If your computer requires a login then you WILL need to fill in the login/password for it to continue. If your computer does not have a login then it will continue on it's own..) Then, just sit tight until it finishes. Sometimes it takes 10 minutes, sometimes it takes an hour. Just be patient until the log pops up. If it takes more than an hour and doesn't appear to be doing anything, you can stop it and come back and let me know.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

If you have a problem launching programs after running Combofix, please do not panic! Simply reboot the computer and all should be fine.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI