This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Netbook - Very slow performance [Solved]

42 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My daughter's Aspire One Netbook seems to have become seriously affected as the performance is terribly slow and pop-ups seem to have taken over the system.
The system itself runs with Vista, and has 1Gb memory, with 250 Gb HDD.
Please find the requested files attached.

Thank you in advance for any help.

OTL scan took about 30 seconds before it responded.

OTL.txt

OTL logfile created on: 19/06/2013 20:06:54 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\User\Desktop
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16618)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1013.09 Mb Total Physical Memory | 491.77 Mb Available Physical Memory | 48.54% Memory free
1.99 Gb Paging File | 1.04 Gb Available in Paging File | 52.19% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 215.79 Gb Total Space | 167.98 Gb Free Space | 77.85% Space Free | Partition Type: NTFS
Drive D: | 4.00 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: FAT32

Computer Name: USER-PC | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\User\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe (AVG Secure Search)
PRC - C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe ()
PRC - C:\Program Files\AVG\AVG2013\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - c:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil10x_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Launch Manager\dsiwmis.exe (Dritek System Inc.)
PRC - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated)
PRC - C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
PRC - C:\Program Files\Acer\Acer VCM\RS_Service.exe (Acer Incorporated)
PRC - C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Group)
PRC - C:\Program Files\Acer\Registration\GREGsvc.exe (Acer Incorporated)


========== Modules (No Company Name) ==========


========== Services (SafeList) ==========

SRV - (vToolbarUpdater15.2.0) – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe (AVG Secure Search)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (RealNetworks Downloader Resolver Service) – C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe ()
SRV - (NisSrv) – c:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (sftvsa) – C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (DsiWMIService) – C:\Program Files\Launch Manager\dsiwmis.exe (Dritek System Inc.)
SRV - (ePowerSvc) – C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated)
SRV - (IAStorDataMgrSvc) – C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (MWLService) – C:\Program Files\EgisTec MyWinLocker\x86\MWLService.exe (Egis Technology Inc.)
SRV - (RS_Service) – C:\Program Files\Acer\Acer VCM\RS_Service.exe (Acer Incorporated)
SRV - (Updater Service) – C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Group)
SRV - (GREGService) – C:\Program Files\Acer\Registration\GREGsvc.exe (Acer Incorporated)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (L1C) – system32\DRIVERS\L1C62x86.sys File not found
DRV - (GEARAspiWDM) – system32\DRIVERS\GEARAspiWDM.sys File not found
DRV - (avgtp) – C:\Windows\System32\drivers\avgtpx86.sys (AVG Technologies)
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avglogx) – C:\Windows\System32\drivers\avglogx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSHX) – C:\Windows\System32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\Windows\System32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (NisDrv) – C:\Windows\System32\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV - (Sftvol) – C:\Windows\System32\drivers\Sftvollh.sys (Microsoft Corporation)
DRV - (Sftredir) – C:\Windows\System32\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV - (Sftplay) – C:\Windows\System32\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV - (Sftfs) – C:\Windows\System32\drivers\Sftfslh.sys (Microsoft Corporation)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (EUCR) – C:\Windows\System32\drivers\EUCR6SK.sys (ENE Technology Inc.)
DRV - (hwdatacard) – C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (ZTEusbser6k) – C:\Windows\System32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbnmea) – C:\Windows\System32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) – C:\Windows\System32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (ZTEusbnet) – C:\Windows\System32\drivers\ZTEusbnet.sys (ZTE Corporation)
DRV - (mwlPSDVDisk) – C:\Windows\System32\drivers\mwlPSDVDisk.sys (Egis Technology Inc.)
DRV - (mwlPSDNServ) – C:\Windows\System32\drivers\mwlPSDNserv.sys (Egis Technology Inc.)
DRV - (mwlPSDFilter) – C:\Windows\System32\drivers\mwlPSDFilter.sys (Egis Technology Inc.)
DRV - (massfilter) – C:\Windows\System32\drivers\massfilter.sys (ZTE Incorporated)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKLM\..\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2269050

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com/
IE - HKCU\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD22}
IE - HKCU\..\SearchScopes\{37D5285D-E43C-4DF7-9108-533774FD7A78}: "URL" = http://websearch.ask.com/redirect?client=i…56-5309080391E3
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKCU\..\SearchScopes\{A531D99C-5A22-449b-83DA-872725C6D0ED}: "URL" = http://search.alot.com/web?q={searchTerms}…n=1.1.3001.0(B)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\15.2.0\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.2.32: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.2: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.2: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.2: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.2.32: C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\User\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\User\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FCE04E1F-9378-4f39-96F6-5689A9159E45}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2013/06/08 22:22:15 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013/06/08 22:22:15 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - default_search_provider: Search Results (Enabled)
CHR - default_search_provider: search_url = http://dts.search-results.com/sr?src=crb&a;…q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - homepage: http://search.conduit.com/?ctid=CT2269050&…amp;sspv=CHSB18
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\Application\27.0.1453.110\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\Application\27.0.1453.110\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\Application\27.0.1453.110\pdf.dll
CHR - plugin: registryAccess (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaaaooaijelonlmbcbjkocdnicdfmo\7.13.0.0_0\background/registryAccess.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.270.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U27 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~4\Office14\NPSPWRAP.DLL
CHR - plugin: MindSpark Toolbar Platform Plugin Stub (Enabled) = C:\Program Files\BetterCareerSearch_2b\bar\1.bin\NP2bStub.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Google Update (Enabled) = C:\Users\User\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - Extension: news.net = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmbbgcooaabknohabmoaikiakkoignai\1.0.12_0\
CHR - Extension: AVG Security Toolbar = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.2.0.5_0\

O1 HOSTS File: ([2013/06/17 01:30:43 | 000,449,637 | R— | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 123fporn.info
O1 - Hosts: 15435 more lines…
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found.
O2 - BHO: (MediaBar) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\PROGRA~1\BEARSH~1\MediaBar\Datamngr\ToolBar\bsdtxmltbpi.dll File not found
O2 - BHO: (DVDVideoSoft WebPageAdjuster Class) - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
O3 - HKLM\..\Toolbar: (no name) - !{2318C2B1-4965-11d4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - !{7ff70c81-f37a-4d7b-9d30-ba8ee8c80d5f} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - !{872b5b88-9db5-4310-bdd0-ac189557e5f5} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found.
O3 - HKLM\..\Toolbar: (MediaBar) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\PROGRA~1\BEARSH~1\MediaBar\Datamngr\ToolBar\bsdtxmltbpi.dll File not found
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4 - HKCU..\Run: [BreakingNews] C:\Program Files\BreakingNews\BreakingNews\DesktopContainer.exe File not found
O4 - HKCU..\Run: [MPOptimizer] "C:\Program Files\MaxPerforma Optimizer\MaxPerforma.exe" /scan File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Program Files\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm ()
O9 - Extra Button: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
O9 - Extra 'Tools' menuitem : Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{37096400-4D72-41DD-B37B-C84267CD79C6}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\15.2.0\ViProtocol.dll (AVG Secure Search)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{11bacb60-f4f8-11e0-b91d-18f46ac378bb}\Shell - "" = AutoRun
O33 - MountPoints2\{11bacb60-f4f8-11e0-b91d-18f46ac378bb}\Shell\AutoRun\command - "" = E:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{169b6e5a-5e4c-11e1-a61c-18f46ac378bb}\Shell - "" = AutoRun
O33 - MountPoints2\{169b6e5a-5e4c-11e1-a61c-18f46ac378bb}\Shell\AutoRun\command - "" = E:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{75e89618-ef1a-11e0-b73e-1c750835ad5b}\Shell - "" = AutoRun
O33 - MountPoints2\{75e89618-ef1a-11e0-b73e-1c750835ad5b}\Shell\AutoRun\command - "" = E:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{75e896b9-ef1a-11e0-b73e-1c750835ad5b}\Shell - "" = AutoRun
O33 - MountPoints2\{75e896b9-ef1a-11e0-b73e-1c750835ad5b}\Shell\AutoRun\command - "" = E:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\setup_vmc_lite.exe /checkApplicationPresence
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/06/19 19:50:07 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
[2013/06/19 19:27:12 | 000,000,000 | —D | C] – C:\Users\User\Documents\My Received Files
[2013/06/18 22:49:41 | 000,745,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MsSpellCheckingFacility.exe
[2013/06/18 22:49:41 | 000,185,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\elshyph.dll
[2013/06/18 22:49:40 | 000,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2013/06/18 22:49:40 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2013/06/18 22:49:39 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2013/06/18 22:49:39 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2013/06/18 22:49:39 | 000,138,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2013/06/18 22:49:39 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2013/06/18 22:49:39 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/06/18 22:49:38 | 002,706,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/06/18 22:49:38 | 000,493,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/06/18 22:49:38 | 000,137,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/06/18 22:49:37 | 000,117,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2013/06/18 22:49:37 | 000,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2013/06/18 22:49:37 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2013/06/18 22:49:37 | 000,038,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2013/06/18 22:49:37 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2013/06/18 22:49:36 | 002,877,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/06/18 22:49:36 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2013/06/18 22:49:36 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2013/06/18 22:49:36 | 000,073,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2013/06/18 22:49:36 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2013/06/18 22:49:35 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/06/18 22:49:35 | 000,361,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2013/06/18 22:49:35 | 000,226,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2013/06/18 22:49:34 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2013/06/18 22:49:34 | 000,719,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmlmedia.dll
[2013/06/18 22:49:34 | 000,629,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2013/06/18 22:49:34 | 000,357,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2013/06/18 22:49:34 | 000,242,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2013/06/18 22:49:34 | 000,232,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/06/18 22:49:34 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2013/06/18 22:49:34 | 000,042,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2013/06/18 22:49:34 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2013/06/18 22:49:33 | 001,441,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/06/18 22:49:33 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2013/06/18 22:47:25 | 002,284,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msmpeg2vdec.dll
[2013/06/18 22:47:25 | 001,158,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2013/06/18 22:47:25 | 000,364,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2013/06/18 22:47:25 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/06/18 22:47:25 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/06/18 22:47:25 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/06/18 22:47:25 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/06/18 22:47:25 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/06/18 22:47:25 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/06/18 22:47:25 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013/06/18 22:47:25 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/06/18 22:47:25 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/06/18 22:47:24 | 003,419,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2013/06/18 22:47:24 | 001,247,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2013/06/18 22:47:24 | 001,080,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/06/18 22:47:24 | 000,604,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/06/18 22:47:24 | 000,417,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2013/06/18 22:47:24 | 000,249,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2013/06/18 22:47:24 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/06/18 22:47:24 | 000,207,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2013/06/18 22:47:24 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2013/06/18 22:47:23 | 001,988,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2013/06/18 22:47:23 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2013/06/18 22:47:23 | 000,187,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAnimation.dll
[2013/06/17 20:54:50 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
[2013/06/17 20:54:47 | 000,000,000 | —D | C] – C:\Program Files\VS Revo Group
[2013/06/17 19:09:46 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\RNDISMP.sys
[2013/06/17 19:08:16 | 001,505,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d11.dll
[2013/06/17 19:05:54 | 000,245,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\OxpsConverter.exe
[2013/06/17 19:05:41 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wwanprotdim.dll
[2013/06/17 19:05:31 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cryptdlg.dll
[2013/06/17 19:04:36 | 002,347,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2013/06/17 19:04:22 | 000,903,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certutil.exe
[2013/06/17 19:04:18 | 000,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certenc.dll
[2013/06/17 19:03:14 | 000,156,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ncsi.dll
[2013/06/17 19:03:12 | 000,175,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netcorehc.dll
[2013/06/17 19:03:09 | 000,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netevent.dll
[2013/06/17 19:01:40 | 003,913,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2013/06/17 19:01:39 | 003,968,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2013/06/17 19:00:49 | 000,218,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\dxgmms1.sys
[2013/06/17 19:00:47 | 000,049,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskhost.exe
[2013/06/17 19:00:38 | 000,193,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dhcpcore6.dll
[2013/06/17 19:00:38 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dhcpcsvc6.dll
[2013/06/17 18:59:57 | 000,101,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\consent.exe
[2013/06/17 18:59:56 | 001,796,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\authui.dll
[2013/06/17 18:52:33 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\AVG2013
[2013/06/17 18:50:57 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\AVG Secure Search
[2013/06/17 18:50:10 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013/06/17 18:49:56 | 000,000,000 | —D | C] – C:\ProgramData\AVG Secure Search
[2013/06/17 18:49:16 | 000,037,664 | —- | C] (AVG Technologies) – C:\Windows\System32\drivers\avgtpx86.sys
[2013/06/17 18:49:00 | 000,000,000 | —D | C] – C:\Program Files\Common Files\AVG Secure Search
[2013/06/17 18:48:55 | 000,000,000 | —D | C] – C:\Program Files\AVG Secure Search
[2013/06/17 18:44:09 | 000,000,000 | -H-D | C] – C:\$AVG
[2013/06/17 18:44:09 | 000,000,000 | —D | C] – C:\ProgramData\AVG2013
[2013/06/17 18:42:08 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2013/06/17 18:36:05 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\MFAData
[2013/06/17 18:36:05 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2013/06/17 18:36:05 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Avg2013
[2013/06/17 06:47:45 | 000,000,000 | —D | C] – C:\9e856ef85da9b57ffd821680f163a2
[2013/06/17 05:47:58 | 000,295,424 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2013/06/17 05:47:57 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2013/06/17 05:19:38 | 000,000,000 | —D | C] – C:\Windows\System32\SPReview
[2013/06/17 05:18:04 | 000,000,000 | —D | C] – C:\Windows\System32\EventProviders
[2013/06/16 23:46:37 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2013/06/16 23:46:00 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2013/06/16 23:46:00 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2013/06/16 22:45:20 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2013/06/16 22:33:15 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2013/06/16 22:32:47 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\AVSoftware
[2013/06/14 12:58:13 | 000,047,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\WdfLdr.sys
[2013/06/14 12:58:13 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Wdfres.dll
[2013/06/14 12:57:16 | 000,131,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\aaclient.dll
[2013/06/14 12:57:16 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tsgqec.dll
[2013/06/14 12:56:41 | 000,172,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFPlatform.dll
[2013/06/14 12:56:39 | 000,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFx.dll
[2013/06/14 12:56:39 | 000,038,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFCoinstaller.dll
[2013/06/14 12:56:03 | 000,400,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\srcore.dll
[2013/06/14 12:56:03 | 000,262,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rstrui.exe
[2013/06/14 12:55:55 | 000,015,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usb8023.sys
[2013/06/14 12:55:20 | 000,376,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dpnet.dll
[2013/06/14 12:55:20 | 000,002,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dpnaddr.dll
[2013/06/14 12:54:48 | 000,038,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrsrv.dll
[2013/06/14 12:53:27 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msxml3r.dll
[2013/06/14 12:51:46 | 000,240,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\netio.sys
[2013/06/14 12:51:46 | 000,187,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\FWPKCLNT.SYS
[2013/06/14 12:51:38 | 000,271,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\conhost.exe
[2013/06/14 12:51:36 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
[2013/06/14 12:51:36 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
[2013/06/14 12:51:36 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
[2013/06/14 12:51:36 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
[2013/06/14 12:51:36 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/06/14 12:51:36 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
[2013/06/14 12:51:36 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
[2013/06/14 12:51:36 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
[2013/06/14 12:51:36 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
[2013/06/14 12:50:54 | 000,805,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cdosys.dll
[2013/06/14 12:32:03 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\browcli.dll
[2013/06/14 12:30:59 | 000,046,592 | —- | C] (Microsoft) – C:\Windows\System32\fpb.rs
[2013/06/14 12:30:59 | 000,045,568 | —- | C] (Microsoft) – C:\Windows\System32\oflc-nz.rs
[2013/06/14 12:30:59 | 000,044,544 | —- | C] (Microsoft) – C:\Windows\System32\pegibbfc.rs
[2013/06/14 12:30:59 | 000,043,520 | —- | C] (Microsoft) – C:\Windows\System32\csrr.rs
[2013/06/14 12:30:59 | 000,040,960 | —- | C] (Microsoft) – C:\Windows\System32\cob-au.rs
[2013/06/14 12:30:59 | 000,030,720 | —- | C] (Microsoft) – C:\Windows\System32\usk.rs
[2013/06/14 12:30:59 | 000,021,504 | —- | C] (Microsoft) – C:\Windows\System32\grb.rs
[2013/06/14 12:30:59 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\System32\pegi.rs
[2013/06/14 12:30:59 | 000,015,360 | —- | C] (Microsoft) – C:\Windows\System32\djctq.rs
[2013/06/14 12:30:58 | 002,576,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gameux.dll
[2013/06/14 12:30:58 | 000,308,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Wpc.dll
[2013/06/14 12:30:58 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\System32\pegi-pt.rs
[2013/06/14 12:30:56 | 000,055,296 | —- | C] (Microsoft) – C:\Windows\System32\cero.rs
[2013/06/14 12:30:56 | 000,051,712 | —- | C] (Microsoft) – C:\Windows\System32\esrb.rs
[2013/06/14 12:30:56 | 000,023,552 | —- | C] (Microsoft) – C:\Windows\System32\oflc.rs
[2013/06/14 12:30:56 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\System32\pegi-fi.rs
[2013/06/14 12:30:23 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ncrypt.dll
[2013/06/14 12:30:21 | 000,129,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpcorekmts.dll
[2013/06/14 12:30:21 | 000,058,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpwsx.dll
[2013/06/14 12:30:21 | 000,008,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdrmemptylst.exe
[2013/06/14 12:30:17 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\profprov.dll
[2013/06/14 12:30:16 | 000,078,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\synceng.dll
[2013/06/14 12:29:39 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2013/06/14 12:28:51 | 000,169,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsrv.dll
[2013/06/11 22:14:09 | 000,826,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpcore.dll
[2013/06/11 22:03:01 | 002,422,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wucltux.dll
[2013/06/11 22:03:01 | 000,045,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups2.dll
[2013/06/11 22:02:34 | 000,577,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapi.dll
[2013/06/11 22:02:34 | 000,088,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wudriver.dll
[2013/06/11 22:02:34 | 000,035,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups.dll
[2013/06/11 22:02:12 | 000,171,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuwebv.dll
[2013/06/11 22:02:12 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapp.exe
[2013/06/08 22:23:30 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Programs
[2013/06/08 22:23:13 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\RealNetworks
[2013/06/08 22:22:14 | 000,000,000 | —D | C] – C:\Program Files\RealNetworks
[2013/06/08 22:22:09 | 000,000,000 | —D | C] – C:\ProgramData\RealNetworks
[2013/06/08 22:21:46 | 000,000,000 | —D | C] – C:\Program Files\Common Files\xing shared
[2013/06/08 22:21:34 | 000,201,872 | —- | C] (RealNetworks, Inc.) – C:\Windows\System32\rmoc3260.dll
[2013/06/08 22:21:22 | 000,006,656 | —- | C] (RealNetworks, Inc.) – C:\Windows\System32\pndx5016.dll
[2013/06/08 22:21:22 | 000,005,632 | —- | C] (RealNetworks, Inc.) – C:\Windows\System32\pndx5032.dll
[2013/06/08 22:21:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealNetworks
[2013/06/08 22:21:18 | 000,272,896 | —- | C] (Progressive Networks) – C:\Windows\System32\pncrt.dll
[2013/06/08 22:20:56 | 000,000,000 | —D | C] – C:\Program Files\Real
[2013/06/08 22:20:28 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Real
[2013/06/08 22:20:27 | 000,000,000 | —D | C] – C:\Program Files\Google
[2013/06/08 22:17:21 | 000,000,000 | —D | C] – C:\ProgramData\Real
[2013/06/08 22:17:05 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DVDVideoSoft
[13 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/06/19 19:50:43 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
[2013/06/19 19:40:43 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/06/19 19:31:06 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1724070015-2864343876-1984321240-1000UA.job
[2013/06/19 19:31:05 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/19 19:24:49 | 000,000,878 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/06/19 19:17:26 | 000,009,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/06/19 19:17:26 | 000,009,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/06/19 19:10:36 | 796,729,344 | -HS- | M] () – C:\hiberfil.sys
[2013/06/18 22:49:41 | 000,745,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MsSpellCheckingFacility.exe
[2013/06/18 22:49:41 | 000,185,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\elshyph.dll
[2013/06/18 22:49:40 | 000,158,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2013/06/18 22:49:40 | 000,071,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2013/06/18 22:49:40 | 000,039,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/06/18 22:49:39 | 000,493,056 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/06/18 22:49:39 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2013/06/18 22:49:39 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2013/06/18 22:49:39 | 000,138,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2013/06/18 22:49:39 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2013/06/18 22:49:38 | 002,706,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/06/18 22:49:38 | 000,137,216 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/06/18 22:49:37 | 000,117,248 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2013/06/18 22:49:37 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2013/06/18 22:49:37 | 000,057,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2013/06/18 22:49:37 | 000,041,984 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2013/06/18 22:49:37 | 000,038,400 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2013/06/18 22:49:37 | 000,011,776 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2013/06/18 22:49:36 | 002,877,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/06/18 22:49:36 | 000,391,168 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/06/18 22:49:36 | 000,109,056 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2013/06/18 22:49:36 | 000,073,728 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2013/06/18 22:49:36 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2013/06/18 22:49:35 | 000,361,984 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2013/06/18 22:49:35 | 000,357,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2013/06/18 22:49:35 | 000,226,816 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2013/06/18 22:49:34 | 001,441,280 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/06/18 22:49:34 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2013/06/18 22:49:34 | 000,719,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmlmedia.dll
[2013/06/18 22:49:34 | 000,629,248 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2013/06/18 22:49:34 | 000,242,200 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2013/06/18 22:49:34 | 000,232,960 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/06/18 22:49:34 | 000,061,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2013/06/18 22:49:34 | 000,042,496 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2013/06/18 22:49:34 | 000,033,280 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2013/06/18 22:49:34 | 000,025,185 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2013/06/18 22:49:33 | 000,023,040 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2013/06/18 22:47:25 | 002,284,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msmpeg2vdec.dll
[2013/06/18 22:47:25 | 001,158,144 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2013/06/18 22:47:25 | 000,417,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2013/06/18 22:47:25 | 000,364,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2013/06/18 22:47:25 | 000,010,752 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/06/18 22:47:25 | 000,009,728 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/06/18 22:47:25 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/06/18 22:47:25 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/06/18 22:47:25 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/06/18 22:47:25 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/06/18 22:47:25 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013/06/18 22:47:25 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/06/18 22:47:25 | 000,002,560 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/06/18 22:47:24 | 003,419,136 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2013/06/18 22:47:24 | 001,988,096 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2013/06/18 22:47:24 | 001,247,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2013/06/18 22:47:24 | 001,080,832 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/06/18 22:47:24 | 000,604,160 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/06/18 22:47:24 | 000,249,856 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2013/06/18 22:47:24 | 000,220,160 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/06/18 22:47:24 | 000,207,872 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2013/06/18 22:47:24 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2013/06/18 22:47:23 | 000,293,376 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2013/06/18 22:47:23 | 000,187,392 | —- | M] (Microsoft Corporation) – C:\Windows\System32\UIAnimation.dll
[2013/06/18 22:31:01 | 000,000,852 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1724070015-2864343876-1984321240-1000Core.job
[2013/06/18 05:59:01 | 000,628,904 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/06/18 05:59:01 | 000,110,798 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/06/18 05:51:14 | 000,259,112 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2013/06/17 20:54:52 | 000,001,230 | —- | M] () – C:\Users\User\Desktop\Revo Uninstaller.lnk
[2013/06/17 18:50:10 | 000,000,939 | —- | M] () – C:\Users\Public\Desktop\AVG 2013.lnk
[2013/06/17 18:48:24 | 000,037,664 | —- | M] (AVG Technologies) – C:\Windows\System32\drivers\avgtpx86.sys
[2013/06/17 06:12:44 | 000,152,576 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msclmd.dll
[2013/06/17 01:30:43 | 000,449,637 | R— | M] () – C:\Windows\System32\drivers\etc\hosts
[2013/06/17 01:25:59 | 000,000,065 | —- | M] () – C:\Windows\wininit.ini
[2013/06/16 23:46:37 | 000,001,224 | —- | M] () – C:\Users\User\Desktop\Spybot - Search & Destroy.lnk
[2013/06/16 22:33:18 | 000,000,973 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2013/06/11 20:49:23 | 000,000,193 | —- | M] () – C:\Windows\WORDPAD.INI
[2013/06/11 20:49:10 | 000,003,439 | —- | M] () – C:\Users\User\Documents\Marks CV.rtf
[2013/06/08 22:54:21 | 000,002,329 | —- | M] () – C:\Users\User\Desktop\Google Chrome.lnk
[2013/06/08 22:22:23 | 000,001,242 | —- | M] () – C:\Users\Public\Desktop\RealPlayer.lnk
[2013/06/08 22:21:34 | 000,201,872 | —- | M] (RealNetworks, Inc.) – C:\Windows\System32\rmoc3260.dll
[2013/06/08 22:21:22 | 000,006,656 | —- | M] (RealNetworks, Inc.) – C:\Windows\System32\pndx5016.dll
[2013/06/08 22:21:22 | 000,005,632 | —- | M] (RealNetworks, Inc.) – C:\Windows\System32\pndx5032.dll
[2013/06/08 22:21:18 | 000,272,896 | —- | M] (Progressive Networks) – C:\Windows\System32\pncrt.dll
[13 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/06/18 22:49:34 | 000,025,185 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2013/06/17 20:54:52 | 000,001,230 | —- | C] () – C:\Users\User\Desktop\Revo Uninstaller.lnk
[2013/06/17 18:50:10 | 000,000,939 | —- | C] () – C:\Users\Public\Desktop\AVG 2013.lnk
[2013/06/17 01:25:59 | 000,000,065 | —- | C] () – C:\Windows\wininit.ini
[2013/06/16 23:46:37 | 000,001,224 | —- | C] () – C:\Users\User\Desktop\Spybot - Search & Destroy.lnk
[2013/06/16 23:34:06 | 000,161,736 | —- | C] () – C:\Program Files\2bres.dll
[2013/06/16 22:46:44 | 000,002,121 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2013/06/16 22:33:18 | 000,000,973 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2013/06/14 12:58:16 | 000,000,003 | —- | C] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2013/06/14 12:56:39 | 000,000,003 | —- | C] () – C:\Windows\System32\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2013/06/11 20:49:23 | 000,000,193 | —- | C] () – C:\Windows\WORDPAD.INI
[2013/06/11 20:49:10 | 000,003,439 | —- | C] () – C:\Users\User\Documents\Marks CV.rtf
[2013/06/08 22:22:23 | 000,001,242 | —- | C] () – C:\Users\Public\Desktop\RealPlayer.lnk
[2013/06/08 22:21:07 | 000,000,882 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/08 22:21:04 | 000,000,878 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/09/03 15:32:36 | 000,000,017 | —- | C] () – C:\Windows\System32\shortcut_ex.dat
[2012/01/13 23:37:54 | 000,004,096 | —- | C] () – C:\Windows\d3dx.dat
[2011/07/21 15:23:43 | 000,003,584 | —- | C] () – C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/19 19:46:28 | 000,001,940 | —- | C] () – C:\Users\User\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/05/15 21:00:39 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/09/17 10:24:14 | 000,131,984 | —- | C] () – C:\ProgramData\FullRemove.exe

========== ZeroAccess Check ==========

[2009/07/14 05:42:31 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/27 05:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 13:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/14 02:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013/06/17 18:52:33 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\AVG2013
[2013/06/16 22:32:47 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\AVSoftware
[2013/06/08 22:17:05 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\DVDVideoSoft
[2011/09/22 20:16:12 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\DVDVideoSoftIEHelpers
[2013/06/08 22:17:05 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\OpenCandy
[2011/12/21 18:39:41 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\PlayFirst
[2012/03/13 18:13:53 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\PriceGong
[2013/03/12 21:08:13 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\SoftGrid Client
[2012/08/13 18:00:02 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Tatara Systems
[2011/12/04 00:00:04 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Tific
[2011/12/04 15:08:47 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\TP
[2013/06/17 18:50:08 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\TuneUp Software
[2011/10/05 10:32:19 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Vodafone
[2011/04/30 15:36:33 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Windows Live Writer

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2009/07/14 03:07:10 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_22d6d5b5cba907ce\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 22:34:46 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\x86_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_1590ffd752297581\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2011/02/26 06:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2009/07/14 02:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2011/02/26 06:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe
[2010/07/14 12:01:28 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[2011/02/26 06:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe
[2010/11/20 13:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011/02/25 06:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\explorer.exe
[2011/02/25 06:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
[2010/02/04 10:56:31 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2010/02/04 10:56:31 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2010/07/14 12:01:28 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2009/07/14 03:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\en-US\explorer.exe.mui
[2009/07/14 03:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_05c8dd40d4f56065\explorer.exe.mui

< MD5 for: EXPLORER.EXE-03C49D11.PF >
[2013/06/17 18:19:08 | 000,119,350 | —- | M] () MD5=03C5E925FD20453367E3C82732E2FD98 – C:\Windows\Prefetch\EXPLORER.EXE-03C49D11.pf

< MD5 for: IEXPLORE.EXE >
[2009/07/14 02:17:29 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=2C32E3E596CFE660353753EABEFB0540 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_b346f9b4861b55c2\iexplore.exe
[2013/02/22 05:10:00 | 000,757,376 | —- | M] (Microsoft Corporation) MD5=32732CEDE2A1106B736EF3D84054EE04 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16476_none_b104f0edc83023b1\iexplore.exe
[2011/12/16 09:03:08 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=38668C6CADABC9487C683FADD3D165D0 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16930_none_b378134285f73a44\iexplore.exe
[2013/02/22 05:10:31 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=4145E2B5663F6FACC08EFDB17B658BB2 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20586_none_b183bdcce155df6c\iexplore.exe
[2011/08/20 05:35:15 | 000,673,024 | —- | M] (Microsoft Corporation) MD5=41FE5E37EFE0B587A688BA0E4FA41288 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16869_none_b360a432860774ff\iexplore.exe
[2011/04/22 20:29:16 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=64EFAF916C4009F1B84153D0BB491FB0 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16800_none_b398812085dee94a\iexplore.exe
[2013/05/17 00:34:33 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=67EE46FD4D3B56531C5DD1BDC149275A – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16490_none_b0e94f59c845c389\iexplore.exe
[2011/06/21 06:25:30 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=6BB506124872ACDFAC5BD912CA1334CE – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20992_none_b3c2cf339f43b73b\iexplore.exe
[2011/11/05 05:38:00 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=8ED7C19AEFA3673AADB0D6864B03FBCE – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16912_none_b38fb3ae85e53510\iexplore.exe
[2012/02/29 12:02:06 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_b135ff17c80c1949\iexplore.exe
[2011/06/21 06:37:00 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=A3AB0A260049BE22AB52E302D9220A92 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16839_none_b38113f685ef212c\iexplore.exe
[2013/05/16 23:27:11 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=A8732CEDB2C0EE7AFC08F867A47BB3EC – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20600_none_b1d43d56e11a6501\iexplore.exe
[2011/11/05 05:39:45 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=A8A14CD0CB499B80412F75D53996AE29 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21085_none_b3d0781f9f391a91\iexplore.exe
[2011/02/24 06:45:11 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=AB2BB40A5FE49AD236791AC22BD08869 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20908_none_b42a203b9ef553cc\iexplore.exe
[2011/12/16 10:19:51 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=C53E41F92B19EC97D987F968403BEC49 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21108_none_b429fa439ef58435\iexplore.exe
[2010/11/20 13:22:51 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_b5780d7c8309d95c\iexplore.exe
[2011/02/24 06:32:52 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C6697A46554E36541E81182B258A19D6 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16766_none_b35da16e860a2bd3\iexplore.exe
[2013/06/18 22:49:40 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=CEE28BCBC3251595396EE7FDA2B5F3CF – C:\Program Files\Internet Explorer\iexplore.exe
[2013/06/18 22:49:40 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=CEE28BCBC3251595396EE7FDA2B5F3CF – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16618_none_ba64eabc65e5aa62\iexplore.exe
[2011/04/22 20:11:29 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=F94877A94996B3C12BB31AD722840457 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20949_none_b3ffe0d59f14dce7\iexplore.exe
[2011/08/20 05:32:44 | 000,673,024 | —- | M] (Microsoft Corporation) MD5=FA623BE79902A7B49FF4F21117B63C83 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21033_none_b40487279f125c2e\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2012/02/29 12:02:08 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_aae2948effb95a30\iexplore.exe.mui
[2013/06/18 22:49:41 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2013/06/18 22:49:41 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_b41defe19d893548\iexplore.exe.mui
[2009/07/14 03:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_acf38f2bbdc896a9\iexplore.exe.mui
[2009/07/14 03:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_af24a2f3bab71a43\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-7A9337F2.PF >
[2013/06/19 19:56:08 | 000,249,762 | —- | M] () MD5=8A325275D92E5956A7CC5016563ECE01 – C:\Windows\Prefetch\IEXPLORE.EXE-7A9337F2.pf

< MD5 for: SERVICES >
[2009/06/10 22:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\System32\drivers\etc\services
[2009/06/10 22:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_045b589158ae90da\services

< MD5 for: SERVICES.EXE >
[2009/07/14 02:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\System32\services.exe
[2009/07/14 02:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2009/07/14 03:03:06 | 000,017,408 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\en-US\services.exe.mui
[2009/07/14 03:03:06 | 000,017,408 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_69d39d3a8748c332\services.exe.mui

< MD5 for: SERVICES.LNK >
[2009/07/14 05:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 05:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 22:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\System32\wbem\services.mof
[2009/06/10 22:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.mof

< MD5 for: SERVICES.MSC >
[2009/07/14 03:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\en-US\services.msc
[2009/06/10 22:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\services.msc
[2009/07/14 03:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 22:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009/07/13 21:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\System32\wdi\perftrack\Services.ptxml
[2009/07/13 21:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\Services.ptxml

< MD5 for: SERVICES.SBS >
[2011/03/01 08:58:44 | 000,034,818 | —- | M] () MD5=62AFD4B2025CE6D4706B36F4C4808F9B – C:\Program Files\Spybot - Search & Destroy\Includes\Services.sbs

< MD5 for: WINLOGON.ADML >
[2009/07/14 03:05:00 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_94da67ab3e358f3a\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 22:43:18 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_7ae3b2e5da95d117\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2010/07/14 12:01:28 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2010/07/14 12:01:28 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2010/11/20 13:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\System32\winlogon.exe
[2010/11/20 13:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2009/07/14 02:14:45 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2009/07/14 03:05:28 | 000,022,528 | —- | M] (Microsoft Corporation) MD5=DB61D28A59DEE68F77811B291D83AD1B – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7600.16385_en-us_cacee7ae656a07ab\winlogon.exe.mui
[2010/11/20 13:12:53 | 000,023,040 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\en-US\winlogon.exe.mui
[2010/11/20 13:12:53 | 000,023,040 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_ccfffb7662588b45\winlogon.exe.mui

< MD5 for: WINLOGON.EXE-0D9AB72B.PF >
[2013/01/05 00:31:59 | 000,036,434 | —- | M] () MD5=36D4E65B25B563CE3B7FD6829F636BE5 – C:\Windows\Prefetch\WINLOGON.EXE-0D9AB72B.pf

< MD5 for: WINLOGON.MFL >
[2009/07/14 03:09:40 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\System32\wbem\en-US\winlogon.mfl
[2009/07/14 03:09:40 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_2891397980a26140\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 21:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\System32\wbem\winlogon.mof
[2009/07/13 21:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_800f1ff3d73b72d9\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2009/06/10 22:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2010/09/17 10:42:19 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2009/06/10 22:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2013/06/19 19:10:36 | 796,729,344 | -HS- | M] () – C:\hiberfil.sys
[2013/06/19 19:10:36 | 1073,741,824 | -HS- | M] () – C:\pagefile.sys
[2010/09/17 10:16:12 | 000,002,089 | —- | M] () – C:\RHDSetup.log

< %systemroot%\Fonts\*.com >
[2009/07/14 05:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 05:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 05:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 05:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 22:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2010/11/20 13:21:36 | 000,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/04/17 01:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2011/10/04 08:48:57 | 000,161,736 | —- | M] () – C:\Program Files\2bres.dll
[2009/07/14 05:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C is Acer
Volume Serial Number is C0D2-1310
Directory of C:\
14/07/2009 05:53 Documents and Settings [C:\Users]
0 File(s) 0 bytes
Directory of C:\ProgramData
14/07/2009 05:53 Application Data [C:\ProgramData]
14/07/2009 05:53 Desktop [C:\Users\Public\Desktop]
14/07/2009 05:53 Documents [C:\Users\Public\Documents]
14/07/2009 05:53 Favorites [C:\Users\Public\Favorites]
14/07/2009 05:53 Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
14/07/2009 05:53 Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
14/07/2009 05:53 All Users [C:\ProgramData]
14/07/2009 05:53 Default User [C:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\All Users
14/07/2009 05:53 Application Data [C:\ProgramData]
14/07/2009 05:53 Desktop [C:\Users\Public\Desktop]
14/07/2009 05:53 Documents [C:\Users\Public\Documents]
14/07/2009 05:53 Favorites [C:\Users\Public\Favorites]
14/07/2009 05:53 Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
14/07/2009 05:53 Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default
14/07/2009 05:53 Application Data [C:\Users\Default\AppData\Roaming]
14/07/2009 05:53 Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
14/07/2009 05:53 Local Settings [C:\Users\Default\AppData\Local]
14/07/2009 05:53 My Documents [C:\Users\Default\Documents]
14/07/2009 05:53 NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
14/07/2009 05:53 PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
14/07/2009 05:53 Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
14/07/2009 05:53 SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
14/07/2009 05:53 Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
14/07/2009 05:53 Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
14/07/2009 05:53 Application Data [C:\Users\Default\AppData\Local]
14/07/2009 05:53 History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
14/07/2009 05:53 Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
14/07/2009 05:53 My Music [C:\Users\Default\Music]
14/07/2009 05:53 My Pictures [C:\Users\Default\Pictures]
14/07/2009 05:53 My Videos [C:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
14/07/2009 05:53 My Music [C:\Users\Public\Music]
14/07/2009 05:53 My Pictures [C:\Users\Public\Pictures]
14/07/2009 05:53 My Videos [C:\Users\Public\Videos]
0 File(s) 0 bytes
Directory of C:\Users\User
28/04/2011 15:53 Application Data [C:\Users\User\AppData\Roaming]
28/04/2011 15:53 Cookies [C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies]
28/04/2011 15:53 Local Settings [C:\Users\User\AppData\Local]
28/04/2011 15:53 My Documents [C:\Users\User\Documents]
28/04/2011 15:53 NetHood [C:\Users\User\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
28/04/2011 15:53 PrintHood [C:\Users\User\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
28/04/2011 15:53 Recent [C:\Users\User\AppData\Roaming\Microsoft\Windows\Recent]
28/04/2011 15:53 SendTo [C:\Users\User\AppData\Roaming\Microsoft\Windows\SendTo]
28/04/2011 15:53 Start Menu [C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu]
28/04/2011 15:53 Templates [C:\Users\User\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\User\AppData\Local
28/04/2011 15:53 Application Data [C:\Users\User\AppData\Local]
28/04/2011 15:53 History [C:\Users\User\AppData\Local\Microsoft\Windows\History]
28/04/2011 15:53 Temporary Internet Files [C:\Users\User\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\User\Documents
28/04/2011 15:53 My Music [C:\Users\User\Music]
28/04/2011 15:53 My Pictures [C:\Users\User\Pictures]
28/04/2011 15:53 My Videos [C:\Users\User\Videos]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
50 Dir(s) 180,227,072,000 bytes free

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/02/29 12:24:03 | 000,000,221 | -HS- | M] () – C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2013/06/19 19:50:43 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-06-18 21:57:24

========== Alternate Data Streams ==========

@Alternate Data Stream - 149 bytes -> C:\ProgramData\TEMP:93EB7685
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:CDFF58FE
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:E36F5B57
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:E1F04E8D
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:1A60DE96
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:798A3728

< End of report >

Extras.
OTL Extras logfile created on: 19/06/2013 20:06:54 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\User\Desktop
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16618)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1013.09 Mb Total Physical Memory | 491.77 Mb Available Physical Memory | 48.54% Memory free
1.99 Gb Paging File | 1.04 Gb Available in Paging File | 52.19% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 215.79 Gb Total Space | 167.98 Gb Free Space | 77.85% Space Free | Partition Type: NTFS
Drive D: | 4.00 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: FAT32

Computer Name: USER-PC | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{8D619BA9-CEB9-4CAF-A046-8D0996AFA3F7}" = lport=2869 | protocol=6 | dir=in | app=system |
"{93261F4F-6F49-4F05-BD31-EEC1957E037A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0D915D26-632E-4018-86D0-42E0CB68D960}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgnsx.exe |
"{13462FC8-47CF-4C6D-B4D8-DF6C74A5B01C}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{17166C8E-0410-4825-83C0-C63F83068A6E}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgnsx.exe |
"{1FC90693-891B-4627-BCAA-714A3A4036F8}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgdiagex.exe |
"{20A5C867-274F-42F1-9D16-16A2D07B9D9D}" = dir=in | app=c:\program files\acer\acer vcm\vc.exe |
"{4AE3F81D-6CFC-40C1-98A6-6B7F68688679}" = protocol=6 | dir=in | app=c:\program files\bearshare applications\mediabar\datamngr\toolbar\dtuser.exe |
"{62E76F29-2A2E-460F-A037-EDF06D25DC76}" = protocol=17 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"{7DD32618-6FCD-4636-A8C1-DB71EA48270B}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgmfapx.exe |
"{8846D206-31DA-4A63-BAEC-A071CBB2FAEC}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{9014FEEA-C54E-4606-9735-974B5DCF8E40}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgmfapx.exe |
"{9381D105-D510-47B3-89A1-973B571DF66F}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgdiagex.exe |
"{9E36EDD9-453A-479E-B839-8609260FB58E}" = protocol=17 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"{A3B8FCEA-C3E3-45E6-868E-2BCAF746C86C}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{B03276C1-EC25-475A-8CE0-B3269AE46F1B}" = protocol=6 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"{B94486ED-FC87-4682-9129-00E7ED1FC7F1}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgemcx.exe |
"{C3B8AE6C-76EF-4813-AD58-19A233FF5A1F}" = protocol=17 | dir=in | app=c:\program files\bearshare applications\mediabar\datamngr\toolbar\dtuser.exe |
"{D6007FF0-E302-4277-94AD-6649D4AC5171}" = dir=in | app=c:\program files\acer\acer vcm\rs_service.exe |
"{E08EBB58-1B16-4546-AEAA-67DC0D4E094A}" = protocol=6 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"{EDCC8F7A-6059-4E5C-BF8C-8E543F7AD143}" = protocol=6 | dir=in | app=c:\program files\frostwire 5\frostwire.exe |
"{F8D6D454-84E4-4981-A1B8-53ACDC531102}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgemcx.exe |
"{FC58E259-A97E-4DBA-8EAE-B628A73E6929}" = protocol=17 | dir=in | app=c:\program files\frostwire 5\frostwire.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{047F790A-7A2A-4B6A-AD02-38092BA63DAC}" = Acer VCM
"{0D7CD0D9-4A88-4A63-8F91-3F4E8F371768}" = MyWinLocker
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{20C44F68-5CC1-4EF2-AC9F-744166861406}" = O2 Connection Manager
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216027FF}" = Java™ 6 Update 27
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2AE79B77-E3FA-4F9C-93D7-4FC643516D6A}" = AVG 2013
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{390DD8BB-BB57-4942-A029-2D913E4E9D74}" = Microsoft Security Client
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3DB0448D-AD82-4923-B305-D001E521A964}" = Acer ePower Management
"{3DC873BB-FFE3-46BF-9701-26B9AE371F9F}" = RealDownloader
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{523281E5-91DD-49F5-9D85-954148F7596A}" = AndroidInstaller
"{58F4D244-314F-4D26-B5EF-C28AB32E22CB}_is1" = Acer GameZone Console
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{738BF5C3-AF7B-4BB0-B7EF-E505EFC756BE}" = MyWinLocker Suite
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112662477}" = Merriam Websters Spell Jam
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90140000-006D-0409-0000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010
"{90140011-0066-0409-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - English
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F479685-180E-4C05-9400-D59292A1B29C}" = Windows Live Movie Maker
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AAECF7BA-E83B-4A10-87EA-DE0B333F8734}" = RealNetworks - Microsoft Visual C++ 2010 Runtime
"{AC76BA86-7AD7-FFFF-7B44-A91000000001}" = Adobe Reader 9.1 MUI
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{C2695E83-CF1D-43D1-84FE-B3BEC561012A}" = Shredder
"{D0ACE89D-EC7F-470F-80BE-4C98ED366B32}" = Acer Crystal Eye webcam Ver:1.1.192.810
"{D774186B-031F-4186-BC4D-B256B9831B85}" = AVG 2013
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Acer Updater
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"3B29FD3CCF1F5B855DA0C521597413EBABE97DFB" = ENE USB Card Reader Driver
"Acer Registration" = Acer Registration
"Acer Screensaver" = Acer ScreenSaver
"Acer Welcome Center" = Welcome Center
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"AVG" = AVG 2013
"CCleaner" = CCleaner
"HDMI" = Intel® Graphics Media Accelerator Driver
"InstallShield_{523281E5-91DD-49F5-9D85-954148F7596A}" = AndroidInstaller
"InstallShield_{738BF5C3-AF7B-4BB0-B7EF-E505EFC756BE}" = MyWinLocker Suite
"LManager" = Launch Manager
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"Office14.Click2Run" = Microsoft Office Click-to-Run 2010
"RealPlayer 16.0" = RealPlayer
"Revo Uninstaller" = Revo Uninstaller 1.94
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"VLC media player" = VLC media player 1.1.11
"WinLiveSuite_Wave3" = Windows Live Essentials
"ZTE USB Driver" = ZTE USB Driver

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 16/06/2013 17:18:55 | Computer Name = User-PC | Source = CVHSVC | ID = 100
Description = Information only. (Patch task for {90140011-0066-0409-0000-0000000FF1CE}):
DownloadLatest Failed:

Error - 16/06/2013 17:18:55 | Computer Name = User-PC | Source = CVHSVC | ID = 100
Description = Information only. Error: Failed to make the SOAP Call HResult: 0x800c0005.
Exception caught while trying to report the Update Event

Error - 16/06/2013 17:50:22 | Computer Name = User-PC | Source = VMCService | ID = 0
Description = conflictManagerTypeValue

Error - 16/06/2013 18:07:53 | Computer Name = User-PC | Source = VSS | ID = 8194
Description =

Error - 16/06/2013 18:11:10 | Computer Name = User-PC | Source = VMCService | ID = 0
Description = conflictManagerTypeValue

Error - 16/06/2013 18:36:19 | Computer Name = User-PC | Source = VMCService | ID = 0
Description = conflictManagerTypeValue

Error - 16/06/2013 20:03:37 | Computer Name = User-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
of attribute "version" in element "assemblyIdentity" is invalid.

Error - 16/06/2013 20:09:10 | Computer Name = User-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program files\spybot
- search & destroy\DelZip179.dll" on line 8. The value "*" of attribute "language"
in element "assemblyIdentity" is invalid.

Error - 16/06/2013 20:09:41 | Computer Name = User-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{3DC873BB-FFE3-46BF-9701-26B9AE371F9F}\recordingmanager.exe".
Dependent
Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 17/06/2013 00:55:42 | Computer Name = User-PC | Source = VMCService | ID = 0
Description = conflictManagerTypeValue

[ System Events ]
Error - 19/01/2012 16:31:42 | Computer Name = User-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
BHDrvx86 cdrom

Error - 20/01/2012 07:40:13 | Computer Name = User-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
BHDrvx86

Error - 20/01/2012 10:10:54 | Computer Name = User-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
BHDrvx86

Error - 21/01/2012 10:16:54 | Computer Name = User-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
BHDrvx86 cdrom

Error - 22/01/2012 09:40:47 | Computer Name = User-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
BHDrvx86 cdrom

Error - 22/01/2012 16:19:30 | Computer Name = User-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
BHDrvx86 cdrom

Error - 22/01/2012 17:37:54 | Computer Name = User-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
BHDrvx86 cdrom

Error - 23/01/2012 13:46:01 | Computer Name = User-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
BHDrvx86 cdrom

Error - 24/01/2012 11:18:45 | Computer Name = User-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
BHDrvx86

Error - 25/01/2012 10:08:01 | Computer Name = User-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
BHDrvx86 cdrom


< End of report >


Hijack Reports and DDS to follow …
Hijack

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:52:28, on 19/06/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16618)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Acer\Acer VCM\AcerVCM.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\notepad.exe
C:\Windows\notepad.exe
C:\Windows\system32\taskhost.exe
C:\Users\User\Desktop\HiJackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
O2 - BHO: MediaBar - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\PROGRA~1\BEARSH~1\MediaBar\Datamngr\ToolBar\bsdtxmltbpi.dll (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: DVDVideoSoft.WebPageAdjuster - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
O3 - Toolbar: MediaBar - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\PROGRA~1\BEARSH~1\MediaBar\Datamngr\ToolBar\bsdtxmltbpi.dll (file missing)
O3 - Toolbar: (no name) - !{2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O3 - Toolbar: (no name) - !{7ff70c81-f37a-4d7b-9d30-ba8ee8c80d5f} - (no file)
O3 - Toolbar: (no name) - !{872b5b88-9db5-4310-bdd0-ac189557e5f5} - (no file)
O3 - Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
O4 - HKCU\..\Run: [Google Update] "C:\Users\User\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MPOptimizer] "C:\Program Files\MaxPerforma Optimizer\MaxPerforma.exe" /scan
O4 - HKCU\..\Run: [BreakingNews] C:\Program Files\BreakingNews\BreakingNews\DesktopContainer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O4 - Global Startup: Acer VCM.lnk = ?
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Program Files\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
O9 - Extra 'Tools' menuitem: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\15.2.0\ViProtocol.dll
O20 - AppInit_DLLs:
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgwdsvc.exe
O23 - Service: Dritek WMI Service (DsiWMIService) - Dritek System Inc. - C:\Program Files\Launch Manager\dsiwmis.exe
O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
O23 - Service: GREGService - Acer Incorporated - C:\Program Files\Acer\Registration\GREGsvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Intel® Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: MyWinLocker Service (MWLService) - Egis Technology Inc. - C:\Program Files\EgisTec MyWinLocker\x86\MWLService.exe
O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files\Acer\Acer VCM\RS_Service.exe
O23 - Service: Updater Service - Acer Group - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
O23 - Service: vToolbarUpdater15.2.0 - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe

–
End of file - 7091 bytes


The DDS tool crashed the system, but provided the below report at the second time.

.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 21:09:47.44 on 19/06/2013
Internet Explorer: 9.10.9200.16618
Microsoft Windows 7 Starter 6.1.7601.1.1252.44.1033.18.1013.325 [GMT 1:00]
.
AV: AVG AntiVirus Free Edition 2013 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AV: Microsoft Security Essentials *Enabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AVG AntiVirus Free Edition 2013 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
SP: Microsoft Security Essentials *Enabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
.
============== Running Processes ===============
.
C:\PROGRA~1\AVG\AVG2013\avgrsx.exe
C:\Program Files\AVG\AVG2013\avgcsrvx.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\AVG\AVG2013\avgidsagent.exe
C:\Program Files\AVG\AVG2013\avgwdsvc.exe
C:\Program Files\Launch Manager\dsiwmis.exe
C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
C:\Program Files\Acer\Registration\GREGsvc.exe
C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
C:\Program Files\Acer\Acer VCM\RS_Service.exe
C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Acer\Acer Updater\UpdaterService.exe
C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe
C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files\AVG\AVG2013\avgnsx.exe
C:\Program Files\AVG\AVG2013\avgemcx.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Acer\Acer VCM\AcerVCM.exe
C:\Windows\system32\SearchIndexer.exe
c:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Users\User\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uDefault_Page_URL = hxxp://acer.msn.com
uURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealNetworks Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\realnetworks\realdownloader\browserplugins\ie\rndlbrowserrecordplugin.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: {95B7759C-8C7F-4BF1-B163-73684A933233} - No File
BHO: MediaBar: {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - c:\progra~1\bearsh~1\mediabar\datamngr\toolbar\bsdtxmltbpi.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: DVDVideoSoft WebPageAdjuster Class: {ee932b49-d5c0-4d19-a3da-ce0849258de6} - c:\program files\common files\dvdvideosoft\bin\IEDownloadMenuAndBtns.dll
TB: MediaBar: {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - c:\progra~1\bearsh~1\mediabar\datamngr\toolbar\bsdtxmltbpi.dll
TB: !{2318C2B1-4965-11d4-9B18-009027A5CD4F} - No File
TB: !{7ff70c81-f37a-4d7b-9d30-ba8ee8c80d5f} - No File
TB: !{872b5b88-9db5-4310-bdd0-ac189557e5f5} - No File
TB: {95B7759C-8C7F-4BF1-B163-73684A933233} - No File
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
uRun: [Google Update] "c:\users\user\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [MPOptimizer] "c:\program files\maxperforma optimizer\MaxPerforma.exe" /scan
uRun: [BreakingNews] c:\program files\breakingnews\breakingnews\DesktopContainer.exe
dRunOnce: [SPReview] "c:\windows\system32\spreview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\acervc~1.lnk - c:\program files\acer\acer vcm\AcerVCM.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Free YouTube to MP3 Converter - c:\program files\common files\dvdvideosoft\plugins\freeytmp3downloader.htm
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - c:\program files\common files\dvdvideosoft\bin\IEDownloadMenuAndBtns.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\common files\avg secure search\viprotocolinstaller\15.2.0\ViProtocol.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs:
Hosts: 127.0.0.1 www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [2013-2-8 60216]
R0 Avglogx;AVG Logging Driver;c:\windows\system32\drivers\avglogx.sys [2013-2-8 245048]
R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2013-2-8 96568]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2013-2-8 39224]
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2013-1-20 195296]
R1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [2013-3-29 208184]
R1 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [2013-3-1 22328]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2013-2-8 170808]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2013-3-21 182072]
R1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [2013-6-17 37664]
R1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\drivers\mwlPSDFilter.sys [2009-6-3 18992]
R1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\drivers\mwlPSDNserv.sys [2009-6-3 16432]
R1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\drivers\mwlPSDVDisk.sys [2009-6-3 60976]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2013\avgidsagent.exe [2013-5-14 4937264]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg2013\avgwdsvc.exe [2013-4-18 283136]
R2 cvhsvc;Client Virtualization Handler;c:\program files\common files\microsoft shared\virtualization handler\CVHSVC.EXE [2012-1-4 822624]
R2 DsiWMIService;Dritek WMI Service;c:\program files\launch manager\dsiwmis.exe [2010-9-17 321104]
R2 ePowerSvc;Acer ePower Service;c:\program files\acer\acer epower management\ePowerSvc.exe [2010-11-21 735776]
R2 GREGService;GREGService;c:\program files\acer\registration\GREGsvc.exe [2010-1-8 23584]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files\intel\intel® rapid storage technology\IAStorDataMgrSvc.exe [2010-9-17 13336]
R2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2013-1-20 100328]
R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files\realnetworks\realdownloader\rndlresolversvc.exe [2013-4-16 39056]
R2 RS_Service;Raw Socket Service;c:\program files\acer\acer vcm\RS_Service.exe [2010-9-17 260640]
R2 sftlist;Application Virtualization Client;c:\program files\microsoft application virtualization client\sftlist.exe [2011-10-1 508776]
R2 Updater Service;Updater Service;c:\program files\acer\acer updater\UpdaterService.exe [2010-9-17 243232]
R2 vToolbarUpdater15.2.0;vToolbarUpdater15.2.0;c:\program files\common files\avg secure search\vtoolbarupdater\15.2.0\ToolbarUpdater.exe [2013-6-17 1015984]
R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\NisSrv.exe [2013-1-27 295232]
R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfslh.sys [2011-10-1 579944]
R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplaylh.sys [2011-10-1 194408]
R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirlh.sys [2011-10-1 21864]
R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvollh.sys [2011-10-1 19304]
R3 sftvsa;Application Virtualization Service Agent;c:\program files\microsoft application virtualization client\sftvsa.exe [2011-10-1 219496]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2013-6-8 116648]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 EUCR;EUCR;c:\windows\system32\drivers\EUCR6SK.sys [2010-9-17 82768]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2013-6-8 116648]
S3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [2012-8-13 9216]
S3 MWLService;MyWinLocker Service;c:\program files\egistec mywinlocker\x86\MWLService.exe [2010-5-27 305520]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-6-23 52224]
S3 ZTEusbnet;ZTE USB-NDIS miniport;c:\windows\system32\drivers\ZTEusbnet.sys [2012-8-13 114688]
.
=============== Created Last 30 ================
.
2013-06-19 18:51:38 7068072 —-a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{b7209bf1-15b7-483a-9ae9-502ea5d51db4}\mpengine.dll
2013-06-18 21:58:00 0 —-a-w- c:\windows\system32\sho4CCA.tmp
2013-06-18 21:47:25 9728 —ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-06-18 05:12:36 7068072 —-a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2013-06-17 19:54:47 ——– d—–w- c:\program files\VS Revo Group
2013-06-17 18:09:47 712048 —-a-w- c:\windows\system32\drivers\ndis.sys
2013-06-17 18:09:46 33280 —-a-w- c:\windows\system32\drivers\RNDISMP.sys
2013-06-17 18:08:16 1505280 —-a-w- c:\windows\system32\d3d11.dll
2013-06-17 18:05:54 245760 —-a-w- c:\windows\system32\OxpsConverter.exe
2013-06-17 18:05:41 40960 —-a-w- c:\windows\system32\wwanprotdim.dll
2013-06-17 18:05:41 186368 —-a-w- c:\windows\system32\wwansvc.dll
2013-06-17 18:05:31 24576 —-a-w- c:\windows\system32\cryptdlg.dll
2013-06-17 18:04:36 2347520 —-a-w- c:\windows\system32\win32k.sys
2013-06-17 18:04:31 492544 —-a-w- c:\windows\system32\win32spl.dll
2013-06-17 18:04:22 903168 —-a-w- c:\windows\system32\certutil.exe
2013-06-17 18:04:20 1160192 —-a-w- c:\windows\system32\crypt32.dll
2013-06-17 18:04:19 140288 —-a-w- c:\windows\system32\cryptsvc.dll
2013-06-17 18:04:19 103936 —-a-w- c:\windows\system32\cryptnet.dll
2013-06-17 18:04:18 43008 —-a-w- c:\windows\system32\certenc.dll
2013-06-17 18:03:14 156672 —-a-w- c:\windows\system32\ncsi.dll
2013-06-17 18:03:13 499712 —-a-w- c:\windows\system32\iphlpsvc.dll
2013-06-17 18:03:12 175104 —-a-w- c:\windows\system32\netcorehc.dll
2013-06-17 18:03:11 242176 —-a-w- c:\windows\system32\nlasvc.dll
2013-06-17 18:03:10 52224 —-a-w- c:\windows\system32\nlaapi.dll
2013-06-17 18:03:10 35328 —-a-w- c:\windows\system32\drivers\tcpipreg.sys
2013-06-17 18:03:09 18944 —-a-w- c:\windows\system32\netevent.dll
2013-06-17 18:01:40 3913576 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-06-17 18:01:39 3968872 —-a-w- c:\windows\system32\ntkrnlpa.exe
2013-06-17 18:00:49 728424 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-06-17 18:00:49 218984 —-a-w- c:\windows\system32\drivers\dxgmms1.sys
2013-06-17 18:00:47 49152 —-a-w- c:\windows\system32\taskhost.exe
2013-06-17 18:00:44 1293672 —-a-w- c:\windows\system32\drivers\tcpip.sys
2013-06-17 18:00:38 44032 —-a-w- c:\windows\system32\dhcpcsvc6.dll
2013-06-17 18:00:38 193536 —-a-w- c:\windows\system32\dhcpcore6.dll
2013-06-17 17:59:57 101720 —-a-w- c:\windows\system32\consent.exe
2013-06-17 17:59:56 1796096 —-a-w- c:\windows\system32\authui.dll
2013-06-17 17:59:55 47104 —-a-w- c:\windows\system32\appinfo.dll
2013-06-17 17:52:33 ——– d—–w- c:\users\user\appdata\roaming\AVG2013
2013-06-17 17:50:57 ——– d—–w- c:\users\user\appdata\local\AVG Secure Search
2013-06-17 17:49:56 ——– d—–w- c:\progra~2\AVG Secure Search
2013-06-17 17:49:16 37664 —-a-w- c:\windows\system32\drivers\avgtpx86.sys
2013-06-17 17:49:00 ——– d—–w- c:\program files\common files\AVG Secure Search
2013-06-17 17:48:55 ——– d—–w- c:\program files\AVG Secure Search
2013-06-17 17:44:09 ——– d–h–w- C:\$AVG
2013-06-17 17:44:09 ——– d—–w- c:\progra~2\AVG2013
2013-06-17 17:42:08 ——– d—–w- c:\program files\AVG
2013-06-17 17:36:05 ——– d—–w- c:\users\user\appdata\local\MFAData
2013-06-17 17:36:05 ——– d—–w- c:\users\user\appdata\local\Avg2013
2013-06-17 17:36:05 ——– d—–w- c:\progra~2\MFAData
2013-06-17 05:47:45 ——– d—–w- C:\9e856ef85da9b57ffd821680f163a2
2013-06-17 04:47:58 295424 —-a-w- c:\windows\system32\atmfd.dll
2013-06-17 04:47:57 34304 —-a-w- c:\windows\system32\atmlib.dll
2013-06-17 04:19:38 ——– d—–w- c:\windows\system32\SPReview
2013-06-17 04:18:04 ——– d—–w- c:\windows\system32\EventProviders
2013-06-16 22:46:00 ——– d—–w- c:\program files\Spybot - Search & Destroy
2013-06-16 22:46:00 ——– d—–w- c:\progra~2\Spybot - Search & Destroy
2013-06-16 22:34:06 161736 —-a-w- c:\program files\2bres.dll
2013-06-16 22:00:17 724464 ——w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{c45f00ed-9dba-4992-a20d-0051a8b4cf67}\gapaengine.dll
2013-06-16 21:45:20 ——– d—–w- c:\program files\Microsoft Security Client
2013-06-16 21:33:15 ——– d—–w- c:\program files\CCleaner
2013-06-16 21:32:47 ——– d—–w- c:\users\user\appdata\roaming\AVSoftware
2013-06-14 20:27:56 7016152 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\{eba164d0-17dd-4ad6-bce3-2bf1b2529c8c}\mpengine.dll
2013-06-14 11:58:13 9728 —-a-w- c:\windows\system32\Wdfres.dll
2013-06-14 11:58:13 526952 —-a-w- c:\windows\system32\drivers\Wdf01000.sys
2013-06-14 11:58:13 47720 —-a-w- c:\windows\system32\drivers\WdfLdr.sys
2013-06-14 11:57:18 3217408 —-a-w- c:\windows\system32\mstscax.dll
2013-06-14 11:57:16 36864 —-a-w- c:\windows\system32\tsgqec.dll
2013-06-14 11:57:16 131584 —-a-w- c:\windows\system32\aaclient.dll
2013-06-14 11:56:42 66560 —-a-w- c:\windows\system32\drivers\WUDFPf.sys
2013-06-14 11:56:42 155136 —-a-w- c:\windows\system32\drivers\WUDFRd.sys
2013-06-14 11:56:41 73216 —-a-w- c:\windows\system32\WUDFSvc.dll
2013-06-14 11:56:41 172032 —-a-w- c:\windows\system32\WUDFPlatform.dll
2013-06-14 11:56:39 613888 —-a-w- c:\windows\system32\WUDFx.dll
2013-06-14 11:56:39 38912 —-a-w- c:\windows\system32\WUDFCoinstaller.dll
2013-06-14 11:56:39 196608 —-a-w- c:\windows\system32\WUDFHost.exe
2013-06-14 11:56:03 400896 —-a-w- c:\windows\system32\srcore.dll
2013-06-14 11:56:03 262656 —-a-w- c:\windows\system32\rstrui.exe
2013-06-14 11:56:01 317440 —-a-w- c:\windows\system32\spoolsv.exe
2013-06-14 11:55:58 1211752 —-a-w- c:\windows\system32\drivers\ntfs.sys
2013-06-14 11:55:57 626688 —-a-w- c:\windows\system32\usp10.dll
2013-06-14 11:55:55 15872 —-a-w- c:\windows\system32\drivers\usb8023.sys
2013-06-14 11:55:51 172544 —-a-w- c:\windows\system32\wintrust.dll
2013-06-14 11:55:20 376832 —-a-w- c:\windows\system32\dpnet.dll
2013-06-14 11:55:20 2560 —-a-w- c:\windows\system32\dpnaddr.dll
2013-06-14 11:54:54 196328 —-a-w- c:\windows\system32\drivers\fvevol.sys
2013-06-14 11:54:48 69632 —-a-w- c:\windows\system32\smss.exe
2013-06-14 11:54:48 38912 —-a-w- c:\windows\system32\csrsrv.dll
2013-06-14 11:53:59 19824 —-a-w- c:\windows\system32\drivers\fs_rec.sys
2013-06-14 11:53:58 5120 —-a-w- c:\windows\system32\wmi.dll
2013-06-14 11:53:58 159232 —-a-w- c:\windows\system32\imagehlp.dll
2013-06-14 11:53:36 183808 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2013-06-14 11:53:34 67440 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2013-06-14 11:53:34 369336 —-a-w- c:\windows\system32\drivers\cng.sys
2013-06-14 11:53:34 225280 —-a-w- c:\windows\system32\schannel.dll
2013-06-14 11:53:34 134000 —-a-w- c:\windows\system32\drivers\ksecpkg.sys
2013-06-14 11:53:27 2048 —-a-w- c:\windows\system32\msxml3r.dll
2013-06-14 11:53:27 1236992 —-a-w- c:\windows\system32\msxml3.dll
2013-06-14 11:53:14 936960 —-a-w- c:\program files\common files\microsoft shared\ink\journal.dll
2013-06-14 11:52:06 1389568 —-a-w- c:\windows\system32\msxml6.dll
2013-06-14 11:50:54 805376 —-a-w- c:\windows\system32\cdosys.dll
2013-06-14 11:50:53 372736 —-a-w- c:\program files\common files\system\ado\msadox.dll
2013-06-14 11:50:53 352256 —-a-w- c:\program files\common files\system\ado\msadomd.dll
2013-06-14 11:50:53 1019904 —-a-w- c:\program files\common files\system\ado\msado15.dll
2013-06-14 11:50:52 57344 —-a-w- c:\program files\common files\system\ado\msador15.dll
2013-06-14 11:50:52 212992 —-a-w- c:\program files\common files\system\msadc\msadco.dll
2013-06-14 11:50:52 143360 —-a-w- c:\program files\common files\system\ado\msjro.dll
2013-06-14 11:32:03 41984 —-a-w- c:\windows\system32\browcli.dll
2013-06-14 11:32:03 102912 —-a-w- c:\windows\system32\browser.dll
2013-06-14 11:31:36 542208 —-a-w- c:\windows\system32\kerberos.dll
2013-06-14 11:31:33 2342400 —-a-w- c:\windows\system32\msi.dll
2013-06-14 11:29:39 2048 —-a-w- c:\windows\system32\tzres.dll
2013-06-14 11:28:51 169984 —-a-w- c:\windows\system32\winsrv.dll
2013-06-11 21:14:09 826880 —-a-w- c:\windows\system32\rdpcore.dll
2013-06-11 21:14:09 24576 —-a-w- c:\windows\system32\drivers\tdtcp.sys
2013-06-11 21:14:09 18432 —-a-w- c:\windows\system32\drivers\tdpipe.sys
2013-06-11 21:03:01 2422272 —-a-w- c:\windows\system32\wucltux.dll
2013-06-11 21:02:34 88576 —-a-w- c:\windows\system32\wudriver.dll
2013-06-11 21:02:12 33792 —-a-w- c:\windows\system32\wuapp.exe
2013-06-11 21:02:12 171904 —-a-w- c:\windows\system32\wuwebv.dll
2013-06-08 21:23:30 ——– d—–w- c:\users\user\appdata\local\Programs
2013-06-08 21:23:13 ——– d—–w- c:\users\user\appdata\roaming\RealNetworks
2013-06-08 21:22:14 ——– d—–w- c:\program files\RealNetworks
2013-06-08 21:22:09 ——– d—–w- c:\progra~2\RealNetworks
2013-06-08 21:21:46 ——– d—–w- c:\program files\common files\xing shared
2013-06-08 21:21:05 348160 —-a-w- c:\windows\system32\msvcr71.dll
2013-06-08 21:21:04 499712 —-a-w- c:\windows\system32\msvcp71.dll
2013-06-08 21:17:05 ——– d—–w- c:\program files\common files\DVDVideoSoft
.
==================== Find3M ====================
.
2013-06-18 21:47:25 5632 —ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-06-17 05:12:44 152576 —-a-w- c:\windows\system32\msclmd.dll
2013-05-02 15:28:50 238872 ——w- c:\windows\system32\MpSigStub.exe
2013-04-13 04:45:16 474624 —-a-w- c:\windows\apppatch\AcSpecfc.dll
2013-04-13 04:45:15 2176512 —-a-w- c:\windows\apppatch\AcGenral.dll
.
============= FINISH: 21:13:24.16 ===============
Hi and Welcome!! Declan :)

My name is Robybel.

I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


Vista and Windows 7 users:

These tools MUST be run from the executable. (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

Having said that….Let's get going!! ;)

===========================

Still need help?
Good to hear from you and thank you for your efforts - look forward to hearing from you again in the not too distant future. Kind regards, Cathal.
Hi Declan :)

So Good!!

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

Next

AdwCleaner

  • Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

Next

[external image: Posted Image] Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.


Next


  • Download RogueKiller and save it to your desktop.
  • Quit all other programs
  • Start RogueKiller.exe
  • Wait until the Prescan has finished …
  • Click on Scan
    [external image: Posted Image]
  • Wait for the end of the scan
  • A report will be created on your desktop.
  • Click on the Delete button
    [external image: Posted Image]
  • Next click on the ShortcutsFix
    [external image: Posted Image]
  • another report will be created on your desktop.

Please post: All RKreport.txt text files located on your desktop.

On your next reply please post :
  • checkup.txt
  • AdwCleaner[S1].txt
  • JRT.txt
  • All RKreport.txt

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Hi, thanks for your efforts - I have had some issues with Rogue Killer - twice it allowed a download and install but only managed half way through the prescan before crashing … now I can't even download it as it suggests there are "Insufficient Permissions" … I have loaded the other scan results below.

Checkup

Results of screen317's Security Check version 0.99.67
Windows 7 Service Pack 1 x86 (UAC is enabled)
Internet Explorer 10
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
AVG AntiVirus Free Edition 2013
Microsoft Security Essentials
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
MVPS Hosts File
Spybot - Search & Destroy
CCleaner
Java™ 6 Update 27
Java version out of Date!
Adobe Flash Player 10 Flash Player out of Date!
Adobe Reader 9 Adobe Reader out of Date!
Google Chrome 26.0.1410.64
Google Chrome 27.0.1453.110
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
AVG avgwdsvc.exe
AVG avgrsx.exe
AVG avgnsx.exe
AVG avgemc.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 0%
````````````````````End of Log``````````````````````


ADW Cleaner

# AdwCleaner v2.303 - Logfile created 06/22/2013 at 17:09:56
# Updated 08/06/2013 by Xplode
# Operating system : Windows 7 Starter Service Pack 1 (32 bits)
# User : User - USER-PC
# Boot Mode : Normal
# Running from : C:\Users\User\Downloads\AdwCleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Deleted on reboot : C:\Program Files\Common Files\AVG Secure Search
Folder Deleted : C:\Program Files\AVG Secure Search
Folder Deleted : C:\Program Files\Conduit
Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\ProgramData\boost_interprocess
Folder Deleted : C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof

***** [Registry] *****

Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\AVG Secure Search
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Google\Chrome\Extensions\plmlpkfpkijnlijgalnjaacllnjmoamo
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A531D99C-5A22-449b-83DA-872725C6D0ED}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30F9B915-B755-4826-820B-08FBA6BD249D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C2D64FF7-0AB8-4263-89C9-EA3B0F8F050C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C2D64FF7-0AB8-4263-89C9-EA3B0F8F050C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\grusskartencenter.com
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\grusskartencenter.com
Key Deleted : HKCU\Software\PriceGong
Key Deleted : HKLM\Software\AVG Secure Search
Key Deleted : HKLM\Software\AVG Security Toolbar
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C2D64FF7-0AB8-4263-89C9-EA3B0F8F050C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine
Key Deleted : HKLM\SOFTWARE\Classes\IMsiDe1egate.Application.1
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2269050
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\plmlpkfpkijnlijgalnjaacllnjmoamo
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C2D64FF7-0AB8-4263-89C9-EA3B0F8F050C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{C2D64FF7-0AB8-4263-89C9-EA3B0F8F050C}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [10]

***** [Internet Browsers] *****

-\\ Internet Explorer v10.0.9200.16618

[OK] Registry is clean.

-\\ Google Chrome v27.0.1453.110

*************************

AdwCleaner[S1].txt - [6974 octets] - [22/06/2013 17:09:56]

########## EOF - C:\AdwCleaner[S1].txt - [7034 octets] ##########


JRT

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.9.4 (05.06.2013:1)
OS: Windows 7 Starter x86
Ran by [removed] on 22/06/2013 at 17:22:33.39
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{37D5285D-E43C-4DF7-9108-533774FD7A78}



~~~ Files

Successfully deleted: [File] C:\Windows\system32\sho1104.tmp
Successfully deleted: [File] C:\Windows\system32\sho4588.tmp
Successfully deleted: [File] C:\Windows\system32\sho4CCA.tmp
Successfully deleted: [File] C:\Windows\system32\sho4D89.tmp
Successfully deleted: [File] C:\Windows\system32\sho506A.tmp
Successfully deleted: [File] C:\Windows\system32\sho5479.tmp
Successfully deleted: [File] C:\Windows\system32\sho6828.tmp
Successfully deleted: [File] C:\Windows\system32\sho767B.tmp
Successfully deleted: [File] C:\Windows\system32\shoA305.tmp
Successfully deleted: [File] C:\Windows\system32\shoC7B6.tmp
Successfully deleted: [File] C:\Windows\system32\shoC9C5.tmp
Successfully deleted: [File] C:\Windows\system32\shoD529.tmp
Successfully deleted: [File] C:\Windows\system32\shoD871.tmp
Successfully deleted: [File] C:\Windows\prefetch\BABYLONTOOLBARSRV.EXE-DB68883D.pf



~~~ Folders

Successfully deleted: [Folder] "C:\Users\User\AppData\Roaming\dvdvideosoftiehelpers"
Successfully deleted: [Folder] "C:\Users\User\AppData\Roaming\opencandy"
Successfully deleted: [Folder] "C:\Users\User\AppData\Roaming\pricegong"
Successfully deleted: [Folder] "C:\Users\User\appdata\local\conduitengine"
Successfully deleted: [Folder] "C:\Users\User\appdata\local\dvdvideosofttb"
Successfully deleted: [Folder] "C:\Users\User\appdata\locallow\babylontoolbar"
Successfully deleted: [Folder] "C:\Users\User\appdata\locallow\conduit"
Successfully deleted: [Folder] "C:\Users\User\appdata\locallow\pricegong"



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 22/06/2013 at 17:27:56.44
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Hi Declan ;)

I have had some issues with Rogue Killer

No problem

Please read carefully and follow these steps.
Please see report below - thank you. 06:51:51.0362 5556 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42 06:51:51.0906 5556 ============================================================ 06:51:51.0906 5556 Current date / time: 2013/06/23 06:51:51.0906 06:51:51.0906 5556 SystemInfo: 06:51:51.0906 5556 06:51:51.0907 5556 OS Version: 6.1.7601 ServicePack: 1.0 06:51:51.0907 5556 Product type: Workstation 06:51:51.0907 5556 ComputerName: USER-PC 06:51:51.0907 5556 UserName: User 06:51:51.0907 5556 Windows directory: C:\Windows 06:51:51.0907 5556 System windows directory: C:\Windows 06:51:51.0908 5556 Processor architecture: Intel x86 06:51:51.0908 5556 Number of processors: 2 06:51:51.0908 5556 Page size: 0x1000 06:51:51.0908 5556 Boot type: Normal boot 06:51:51.0908 5556 ============================================================ 06:51:56.0674 5556 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050 06:51:56.0683 5556 ============================================================ 06:51:56.0683 5556 \Device\Harddisk0\DR0: 06:51:56.0684 5556 MBR partitions: 06:51:56.0685 5556 \Device\Harddisk0\DR0\Partition1: MBR, Type 0xC, StartLBA 0x1A00800, BlocksNum 0x800000 06:51:56.0685 5556 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x2200800, BlocksNum 0x32000 06:51:56.0702 5556 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x2233000, BlocksNum 0x1AF92000 06:51:56.0702 5556 ============================================================ 06:51:56.0749 5556 C: <-> \Device\Harddisk0\DR0\Partition3 06:51:56.0776 5556 D: <-> \Device\Harddisk0\DR0\Partition1 06:51:56.0920 5556 ============================================================ 06:51:56.0920 5556 Initialize success 06:51:56.0921 5556 ============================================================ 06:52:02.0932 3764 ============================================================ 06:52:02.0932 3764 Scan started 06:52:02.0932 3764 Mode: Manual; 06:52:02.0932 3764 ============================================================ 06:52:03.0215 3764 ================ Scan system memory ======================== 06:52:03.0215 3764 System memory - ok 06:52:03.0217 3764 ================ Scan services ============================= 06:52:03.0929 3764 [ 1B133875B8AA8AC48969BD3458AFE9F5 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys 06:52:04.0740 3764 1394ohci - ok 06:52:04.0795 3764 [ CEA80C80BED809AA0DA6FEBC04733349 ] ACPI C:\Windows\system32\drivers\ACPI.sys 06:52:04.0807 3764 ACPI - ok 06:52:04.0859 3764 [ 1EFBC664ABFF416D1D07DB115DCB264F ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 06:52:05.0091 3764 AcpiPmi - ok 06:52:05.0236 3764 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\Windows\system32\drivers\adp94xx.sys 06:52:05.0301 3764 adp94xx - ok 06:52:05.0352 3764 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\Windows\system32\drivers\adpahci.sys 06:52:05.0364 3764 adpahci - ok 06:52:05.0397 3764 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\Windows\system32\drivers\adpu320.sys 06:52:05.0405 3764 adpu320 - ok 06:52:05.0484 3764 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 06:52:05.0488 3764 AeLookupSvc - ok 06:52:05.0637 3764 [ 9EBBBA55060F786F0FCAA3893BFA2806 ] AFD C:\Windows\system32\drivers\afd.sys 06:52:05.0648 3764 AFD - ok 06:52:05.0710 3764 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\Windows\system32\drivers\agp440.sys 06:52:05.0716 3764 agp440 - ok 06:52:05.0817 3764 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\Windows\system32\drivers\djsvs.sys 06:52:05.0824 3764 aic78xx - ok 06:52:05.0917 3764 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\Windows\System32\alg.exe 06:52:05.0922 3764 ALG - ok 06:52:05.0979 3764 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\Windows\system32\drivers\aliide.sys 06:52:05.0984 3764 aliide - ok 06:52:06.0026 3764 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\Windows\system32\drivers\amdagp.sys 06:52:06.0044 3764 amdagp - ok 06:52:06.0069 3764 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\Windows\system32\drivers\amdide.sys 06:52:06.0085 3764 amdide - ok 06:52:06.0146 3764 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys 06:52:06.0350 3764 AmdK8 - ok 06:52:06.0399 3764 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\Windows\system32\drivers\amdppm.sys 06:52:06.0630 3764 AmdPPM - ok 06:52:06.0709 3764 [ D320BF87125326F996D4904FE24300FC ] amdsata C:\Windows\system32\drivers\amdsata.sys 06:52:06.0742 3764 amdsata - ok 06:52:06.0817 3764 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\Windows\system32\drivers\amdsbs.sys 06:52:06.0824 3764 amdsbs - ok 06:52:06.0849 3764 [ 46387FB17B086D16DEA267D5BE23A2F2 ] amdxata C:\Windows\system32\drivers\amdxata.sys 06:52:06.0855 3764 amdxata - ok 06:52:06.0907 3764 [ AEA177F783E20150ACE5383EE368DA19 ] AppID C:\Windows\system32\drivers\appid.sys 06:52:07.0280 3764 AppID - ok 06:52:07.0316 3764 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\Windows\System32\appidsvc.dll 06:52:07.0320 3764 AppIDSvc - ok 06:52:07.0374 3764 [ EACFDF31921F51C097629F1F3C9129B4 ] Appinfo C:\Windows\System32\appinfo.dll 06:52:07.0377 3764 Appinfo - ok 06:52:07.0431 3764 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\Windows\system32\drivers\arc.sys 06:52:07.0436 3764 arc - ok 06:52:07.0492 3764 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\Windows\system32\drivers\arcsas.sys 06:52:07.0497 3764 arcsas - ok 06:52:07.0559 3764 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 06:52:07.0794 3764 AsyncMac - ok 06:52:07.0877 3764 [ 338C86357871C167A96AB976519BF59E ] atapi C:\Windows\system32\drivers\atapi.sys 06:52:07.0881 3764 atapi - ok 06:52:08.0151 3764 [ C35AF075C15827D74B5C9702CBCB175B ] athr C:\Windows\system32\DRIVERS\athr.sys 06:52:08.0219 3764 athr - ok 06:52:08.0365 3764 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 06:52:08.0431 3764 AudioEndpointBuilder - ok 06:52:08.0455 3764 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] Audiosrv C:\Windows\System32\Audiosrv.dll 06:52:08.0462 3764 Audiosrv - ok 06:52:09.0652 3764 [ 50185186719134FA8F307D269106A51C ] AVGIDSAgent C:\Program Files\AVG\AVG2013\avgidsagent.exe 06:52:09.0820 3764 AVGIDSAgent - ok 06:52:09.0931 3764 [ 4750A2A188D39034F5DDDDAE1BF38BF8 ] AVGIDSDriver C:\Windows\system32\DRIVERS\avgidsdriverx.sys 06:52:09.0941 3764 AVGIDSDriver - ok 06:52:10.0049 3764 [ B0DEF92F4E1E6B9242E6C8FAB82703F7 ] AVGIDSHX C:\Windows\system32\DRIVERS\avgidshx.sys 06:52:10.0057 3764 AVGIDSHX - ok 06:52:10.0090 3764 [ A426B2DC795531D99E2EE1952AEC051A ] AVGIDSShim C:\Windows\system32\DRIVERS\avgidsshimx.sys 06:52:10.0094 3764 AVGIDSShim - ok 06:52:10.0175 3764 [ 08FA13787D77A75DC413E27FD92B44E8 ] Avgldx86 C:\Windows\system32\DRIVERS\avgldx86.sys 06:52:10.0182 3764 Avgldx86 - ok 06:52:10.0274 3764 [ 3E587EE55C70E6DB78A98D7121D3052E ] Avglogx C:\Windows\system32\DRIVERS\avglogx.sys 06:52:10.0284 3764 Avglogx - ok 06:52:10.0326 3764 [ 5AC56B2CF8EE751796C5A8FC5C631B66 ] Avgmfx86 C:\Windows\system32\DRIVERS\avgmfx86.sys 06:52:10.0331 3764 Avgmfx86 - ok 06:52:10.0412 3764 [ C29E6070396E437FDE184D739CCBA2C7 ] Avgrkx86 C:\Windows\system32\DRIVERS\avgrkx86.sys 06:52:10.0416 3764 Avgrkx86 - ok 06:52:10.0461 3764 [ 14370FB29526F593C04FA48B5D69F7F0 ] Avgtdix C:\Windows\system32\DRIVERS\avgtdix.sys 06:52:10.0498 3764 Avgtdix - ok 06:52:10.0561 3764 [ 02A43ADBA362B89B7D5715221D5F3010 ] avgtp C:\Windows\system32\drivers\avgtpx86.sys 06:52:10.0565 3764 avgtp - ok 06:52:10.0612 3764 [ 3A0977CB68AF13E2579E47EB8984056B ] avgwd C:\Program Files\AVG\AVG2013\avgwdsvc.exe 06:52:10.0621 3764 avgwd - ok 06:52:10.0689 3764 [ 6E30D02AAC9CAC84F421622E3A2F6178 ] AxInstSV C:\Windows\System32\AxInstSV.dll 06:52:10.0694 3764 AxInstSV - ok 06:52:10.0828 3764 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\Windows\system32\drivers\bxvbdx.sys 06:52:11.0103 3764 b06bdrv - ok 06:52:11.0207 3764 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys 06:52:11.0630 3764 b57nd60x - ok 06:52:11.0722 3764 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\Windows\System32\bdesvc.dll 06:52:11.0726 3764 BDESVC - ok 06:52:11.0770 3764 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\Windows\system32\drivers\Beep.sys 06:52:12.0055 3764 Beep - ok 06:52:12.0217 3764 [ 1E2BAC209D184BB851E1A187D8A29136 ] BFE C:\Windows\System32\bfe.dll 06:52:12.0230 3764 BFE - ok 06:52:12.0409 3764 [ E585445D5021971FAE10393F0F1C3961 ] BITS C:\Windows\System32\qmgr.dll 06:52:12.0433 3764 BITS - ok 06:52:12.0475 3764 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\Windows\system32\drivers\blbdrive.sys 06:52:13.0001 3764 blbdrive - ok 06:52:13.0066 3764 [ 8F2DA3028D5FCBD1A060A3DE64CD6506 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 06:52:13.0071 3764 bowser - ok 06:52:13.0120 3764 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys 06:52:13.0435 3764 BrFiltLo - ok 06:52:13.0477 3764 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys 06:52:13.0752 3764 BrFiltUp - ok 06:52:13.0819 3764 [ 3DAA727B5B0A45039B0E1C9A211B8400 ] Browser C:\Windows\System32\browser.dll 06:52:13.0825 3764 Browser - ok 06:52:13.0911 3764 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\Windows\System32\Drivers\Brserid.sys 06:52:14.0098 3764 Brserid - ok 06:52:14.0138 3764 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys 06:52:14.0332 3764 BrSerWdm - ok 06:52:14.0381 3764 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys 06:52:14.0594 3764 BrUsbMdm - ok 06:52:14.0619 3764 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys 06:52:14.0910 3764 BrUsbSer - ok 06:52:14.0958 3764 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys 06:52:15.0206 3764 BTHMODEM - ok 06:52:15.0302 3764 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\Windows\system32\bthserv.dll 06:52:15.0307 3764 bthserv - ok 06:52:15.0391 3764 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 06:52:15.0758 3764 cdfs - ok 06:52:15.0840 3764 [ BE167ED0FDB9C1FA1133953C18D5A6C9 ] cdrom C:\Windows\system32\drivers\cdrom.sys 06:52:16.0585 3764 cdrom - ok 06:52:16.0654 3764 [ 319C6B309773D063541D01DF8AC6F55F ] CertPropSvc C:\Windows\System32\certprop.dll 06:52:16.0716 3764 CertPropSvc - ok 06:52:16.0755 3764 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\Windows\system32\drivers\circlass.sys 06:52:17.0014 3764 circlass - ok 06:52:17.0067 3764 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\Windows\system32\CLFS.sys 06:52:17.0146 3764 CLFS - ok 06:52:17.0327 3764 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 06:52:17.0393 3764 clr_optimization_v2.0.50727_32 - ok 06:52:17.0542 3764 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 06:52:17.0600 3764 clr_optimization_v4.0.30319_32 - ok 06:52:17.0677 3764 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\Windows\system32\drivers\CmBatt.sys 06:52:18.0172 3764 CmBatt - ok 06:52:18.0243 3764 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\Windows\system32\drivers\cmdide.sys 06:52:18.0247 3764 cmdide - ok 06:52:18.0366 3764 [ 247B4CE2DAB1160CD422D532D5241E1F ] CNG C:\Windows\system32\Drivers\cng.sys 06:52:18.0376 3764 CNG - ok 06:52:18.0481 3764 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\Windows\system32\drivers\compbatt.sys 06:52:18.0485 3764 Compbatt - ok 06:52:18.0566 3764 [ CBE8C58A8579CFE5FCCF809E6F114E89 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys 06:52:18.0786 3764 CompositeBus - ok 06:52:18.0821 3764 COMSysApp - ok 06:52:18.0875 3764 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys 06:52:18.0902 3764 crcdisk - ok 06:52:19.0020 3764 [ 3897DFF247D9ED0006190349DE264E14 ] CryptSvc C:\Windows\system32\cryptsvc.dll 06:52:19.0027 3764 CryptSvc - ok 06:52:19.0200 3764 [ 72794D112CBAFF3BC0C29BF7350D4741 ] cvhsvc C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE 06:52:19.0235 3764 cvhsvc - ok 06:52:19.0326 3764 [ 7660F01D3B38ACA1747E397D21D790AF ] DcomLaunch C:\Windows\system32\rpcss.dll 06:52:19.0349 3764 DcomLaunch - ok 06:52:19.0394 3764 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\Windows\System32\defragsvc.dll 06:52:19.0406 3764 defragsvc - ok 06:52:19.0486 3764 [ F024449C97EC1E464AAFFDA18593DB88 ] DfsC C:\Windows\system32\Drivers\dfsc.sys 06:52:19.0491 3764 DfsC - ok 06:52:19.0649 3764 [ E9E01EB683C132F7FA27CD607B8A2B63 ] Dhcp C:\Windows\system32\dhcpcore.dll 06:52:19.0657 3764 Dhcp - ok 06:52:19.0728 3764 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\Windows\system32\drivers\discache.sys 06:52:19.0732 3764 discache - ok 06:52:19.0812 3764 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\Windows\system32\drivers\disk.sys 06:52:19.0817 3764 Disk - ok 06:52:19.0878 3764 [ 33EF4861F19A0736B11314AAD9AE28D0 ] Dnscache C:\Windows\System32\dnsrslvr.dll 06:52:19.0885 3764 Dnscache - ok 06:52:19.0948 3764 [ 366BA8FB4B7BB7435E3B9EACB3843F67 ] dot3svc C:\Windows\System32\dot3svc.dll 06:52:19.0955 3764 dot3svc - ok 06:52:20.0009 3764 [ 8EC04CA86F1D68DA9E11952EB85973D6 ] DPS C:\Windows\system32\dps.dll 06:52:20.0039 3764 DPS - ok 06:52:20.0079 3764 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 06:52:20.0327 3764 drmkaud - ok 06:52:20.0590 3764 [ 9CF46FDF163E06B83D03FF929EF2296C ] DsiWMIService C:\Program Files\Launch Manager\dsiwmis.exe 06:52:20.0599 3764 DsiWMIService - ok 06:52:20.0669 3764 [ 16498EBC04AE9DD07049A8884B205C05 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 06:52:20.0732 3764 DXGKrnl - ok 06:52:20.0800 3764 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\Windows\System32\eapsvc.dll 06:52:20.0805 3764 EapHost - ok 06:52:21.0114 3764 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\Windows\system32\drivers\evbdx.sys 06:52:21.0614 3764 ebdrv - ok 06:52:21.0678 3764 [ 81951F51E318AECC2D68559E47485CC4 ] EFS C:\Windows\System32\lsass.exe 06:52:21.0688 3764 EFS - ok 06:52:21.0745 3764 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\Windows\system32\drivers\elxstor.sys 06:52:21.0806 3764 elxstor - ok 06:52:21.0985 3764 [ 2609A5B13DE9B2EEB38F3A83A406D079 ] ePowerSvc C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe 06:52:22.0001 3764 ePowerSvc - ok 06:52:22.0060 3764 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\Windows\system32\drivers\errdev.sys 06:52:22.0229 3764 ErrDev - ok 06:52:22.0298 3764 [ 4FAB8DFAF156E048AD514EABD268AB3A ] EUCR C:\Windows\system32\DRIVERS\EUCR6SK.SYS 06:52:22.0511 3764 EUCR - ok 06:52:22.0591 3764 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\Windows\system32\es.dll 06:52:22.0599 3764 EventSystem - ok 06:52:22.0661 3764 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\Windows\system32\drivers\exfat.sys 06:52:22.0872 3764 exfat - ok 06:52:22.0935 3764 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\Windows\system32\drivers\fastfat.sys 06:52:23.0124 3764 fastfat - ok 06:52:23.0215 3764 [ 967EA5B213E9984CBE270205DF37755B ] Fax C:\Windows\system32\fxssvc.exe 06:52:23.0248 3764 Fax - ok 06:52:23.0277 3764 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\Windows\system32\drivers\fdc.sys 06:52:23.0500 3764 fdc - ok 06:52:23.0595 3764 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\Windows\system32\fdPHost.dll 06:52:23.0603 3764 fdPHost - ok 06:52:23.0641 3764 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\Windows\system32\fdrespub.dll 06:52:23.0647 3764 FDResPub - ok 06:52:23.0679 3764 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 06:52:23.0684 3764 FileInfo - ok 06:52:23.0762 3764 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 06:52:23.0767 3764 Filetrace - ok 06:52:23.0790 3764 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\Windows\system32\drivers\flpydisk.sys 06:52:24.0023 3764 flpydisk - ok 06:52:24.0083 3764 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 06:52:24.0090 3764 FltMgr - ok 06:52:24.0190 3764 [ E12C4928B32ACE04610259647F072635 ] FontCache C:\Windows\system32\FntCache.dll 06:52:24.0246 3764 FontCache - ok 06:52:24.0422 3764 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe 06:52:24.0432 3764 FontCache3.0.0.0 - ok 06:52:24.0456 3764 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 06:52:24.0461 3764 FsDepends - ok 06:52:24.0526 3764 [ 7DAE5EBCC80E45D3253F4923DC424D05 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 06:52:24.0531 3764 Fs_Rec - ok 06:52:24.0626 3764 [ E306A24D9694C724FA2491278BF50FDB ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 06:52:24.0634 3764 fvevol - ok 06:52:24.0681 3764 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys 06:52:24.0686 3764 gagp30kx - ok 06:52:24.0710 3764 GEARAspiWDM - ok 06:52:24.0793 3764 [ E897EAF5ED6BA41E081060C9B447A673 ] gpsvc C:\Windows\System32\gpsvc.dll 06:52:24.0819 3764 gpsvc - ok 06:52:24.0905 3764 [ 0191DEE9B9EB7902AF2CF4F67301095D ] GREGService C:\Program Files\Acer\Registration\GREGsvc.exe 06:52:24.0909 3764 GREGService - ok 06:52:25.0119 3764 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe 06:52:25.0125 3764 gupdate - ok 06:52:25.0166 3764 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe 06:52:25.0170 3764 gupdatem - ok 06:52:25.0279 3764 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys 06:52:25.0534 3764 hcw85cir - ok 06:52:25.0635 3764 [ A5EF29D5315111C80A5C1ABAD14C8972 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 06:52:25.0816 3764 HdAudAddService - ok 06:52:25.0863 3764 [ 9036377B8A6C15DC2EEC53E489D159B5 ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys 06:52:25.0868 3764 HDAudBus - ok 06:52:25.0934 3764 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\Windows\system32\drivers\HidBatt.sys 06:52:26.0172 3764 HidBatt - ok 06:52:26.0212 3764 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\Windows\system32\drivers\hidbth.sys 06:52:26.0512 3764 HidBth - ok 06:52:26.0545 3764 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\Windows\system32\drivers\hidir.sys 06:52:26.0775 3764 HidIr - ok 06:52:26.0818 3764 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\Windows\system32\hidserv.dll 06:52:26.0827 3764 hidserv - ok 06:52:26.0878 3764 [ 10C19F8290891AF023EAEC0832E1EB4D ] HidUsb C:\Windows\system32\drivers\hidusb.sys 06:52:27.0041 3764 HidUsb - ok 06:52:27.0100 3764 [ 196B4E3F4CCCC24AF836CE58FACBB699 ] hkmsvc C:\Windows\system32\kmsvc.dll 06:52:27.0111 3764 hkmsvc - ok 06:52:27.0171 3764 [ 6658F4404DE03D75FE3BA09F7ABA6A30 ] HomeGroupListener C:\Windows\system32\ListSvc.dll 06:52:27.0180 3764 HomeGroupListener - ok 06:52:27.0243 3764 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 06:52:27.0257 3764 HomeGroupProvider - ok 06:52:27.0317 3764 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 06:52:27.0323 3764 HpSAMD - ok 06:52:27.0406 3764 [ 871917B07A141BFF43D76D8844D48106 ] HTTP C:\Windows\system32\drivers\HTTP.sys 06:52:27.0418 3764 HTTP - ok 06:52:27.0475 3764 [ 348C3A9D01E68A0222A246346924AA55 ] hwdatacard C:\Windows\system32\DRIVERS\ewusbmdm.sys 06:52:27.0682 3764 hwdatacard - ok 06:52:27.0729 3764 [ 0C4E035C7F105F1299258C90886C64C5 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 06:52:27.0734 3764 hwpolicy - ok 06:52:27.0811 3764 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys 06:52:28.0129 3764 i8042prt - ok 06:52:28.0200 3764 [ D80AA0907748D7CC8EFAB3773F32629B ] iaStor C:\Windows\system32\drivers\iaStor.sys 06:52:28.0207 3764 iaStor - ok 06:52:28.0378 3764 [ A9BE186ABF28B3D3D698CB855EDF457E ] IAStorDataMgrSvc C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe 06:52:28.0386 3764 IAStorDataMgrSvc - ok 06:52:28.0451 3764 [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 06:52:28.0460 3764 iaStorV - ok 06:52:28.0691 3764 [ C521D7EB6497BB1AF6AFA89E322FB43C ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 06:52:28.0718 3764 idsvc - ok 06:52:29.0099 3764 [ D0074897C6BC132F3980EA4654BF7FB9 ] igfx C:\Windows\system32\DRIVERS\igdkmd32.sys 06:52:29.0455 3764 igfx - ok 06:52:29.0510 3764 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\Windows\system32\drivers\iirsp.sys 06:52:29.0516 3764 iirsp - ok 06:52:29.0682 3764 [ F95622F161474511B8D80D6B093AA610 ] IKEEXT C:\Windows\System32\ikeext.dll 06:52:29.0707 3764 IKEEXT - ok 06:52:30.0568 3764 [ 8C92829CCAE93139B90C46389FBEF4CF ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys 06:52:30.0683 3764 IntcAzAudAddService - ok 06:52:30.0741 3764 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\Windows\system32\drivers\intelide.sys 06:52:30.0744 3764 intelide - ok 06:52:30.0842 3764 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 06:52:30.0847 3764 intelppm - ok 06:52:30.0902 3764 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\Windows\system32\ipbusenum.dll 06:52:30.0911 3764 IPBusEnum - ok 06:52:30.0952 3764 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 06:52:31.0099 3764 IpFilterDriver - ok 06:52:31.0276 3764 [ 58F67245D041FBE7AF88F4EAF79DF0FA ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 06:52:31.0293 3764 iphlpsvc - ok 06:52:31.0333 3764 [ 4BD7134618C1D2A27466A099062547BF ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys 06:52:31.0480 3764 IPMIDRV - ok 06:52:31.0508 3764 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\Windows\system32\drivers\ipnat.sys 06:52:31.0696 3764 IPNAT - ok 06:52:31.0765 3764 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\Windows\system32\drivers\irenum.sys 06:52:31.0769 3764 IRENUM - ok 06:52:31.0807 3764 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\Windows\system32\drivers\isapnp.sys 06:52:31.0813 3764 isapnp - ok 06:52:31.0865 3764 [ CB7A9ABB12B8415BCE5D74994C7BA3AE ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys 06:52:31.0873 3764 iScsiPrt - ok 06:52:31.0921 3764 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\Windows\system32\drivers\kbdclass.sys 06:52:31.0925 3764 kbdclass - ok 06:52:31.0987 3764 [ 9E3CED91863E6EE98C24794D05E27A71 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys 06:52:32.0123 3764 kbdhid - ok 06:52:32.0155 3764 [ 81951F51E318AECC2D68559E47485CC4 ] KeyIso C:\Windows\system32\lsass.exe 06:52:32.0161 3764 KeyIso - ok 06:52:32.0214 3764 [ B7895B4182C0D16F6EFADEB8081E8D36 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 06:52:32.0218 3764 KSecDD - ok 06:52:32.0282 3764 [ D30159AC9237519FBC62C6EC247D2D46 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 06:52:32.0288 3764 KSecPkg - ok 06:52:32.0329 3764 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\Windows\system32\msdtckrm.dll 06:52:32.0529 3764 KtmRm - ok 06:52:32.0552 3764 L1C - ok 06:52:32.0653 3764 [ D64AF876D53ECA3668BB97B51B4E70AB ] LanmanServer C:\Windows\system32\srvsvc.dll 06:52:32.0673 3764 LanmanServer - ok 06:52:32.0708 3764 [ 58405E4F68BA8E4057C6E914F326ABA2 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 06:52:32.0720 3764 LanmanWorkstation - ok 06:52:32.0792 3764 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 06:52:32.0797 3764 lltdio - ok 06:52:32.0857 3764 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\Windows\System32\lltdsvc.dll 06:52:33.0065 3764 lltdsvc - ok 06:52:33.0095 3764 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\Windows\System32\lmhsvc.dll 06:52:33.0102 3764 lmhosts - ok 06:52:33.0168 3764 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys 06:52:33.0174 3764 LSI_FC - ok 06:52:33.0206 3764 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys 06:52:33.0212 3764 LSI_SAS - ok 06:52:33.0245 3764 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys 06:52:33.0250 3764 LSI_SAS2 - ok 06:52:33.0285 3764 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys 06:52:33.0290 3764 LSI_SCSI - ok 06:52:33.0337 3764 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\Windows\system32\drivers\luafv.sys 06:52:33.0343 3764 luafv - ok 06:52:33.0408 3764 [ 59A2783ABA6019BED0C843C706E10A6A ] massfilter C:\Windows\system32\drivers\massfilter.sys 06:52:33.0593 3764 massfilter - ok 06:52:33.0668 3764 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\Windows\system32\drivers\megasas.sys 06:52:33.0673 3764 megasas - ok 06:52:33.0709 3764 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys 06:52:33.0717 3764 MegaSR - ok 06:52:33.0762 3764 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\Windows\system32\mmcss.dll 06:52:33.0769 3764 MMCSS - ok 06:52:33.0807 3764 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\Windows\system32\drivers\modem.sys 06:52:33.0979 3764 Modem - ok 06:52:34.0005 3764 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\Windows\system32\DRIVERS\monitor.sys 06:52:34.0010 3764 monitor - ok 06:52:34.0074 3764 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\Windows\system32\drivers\mouclass.sys 06:52:34.0079 3764 mouclass - ok 06:52:34.0124 3764 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\Windows\system32\drivers\mouhid.sys 06:52:34.0269 3764 mouhid - ok 06:52:34.0336 3764 [ FC8771F45ECCCFD89684E38842539B9B ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 06:52:34.0341 3764 mountmgr - ok 06:52:34.0464 3764 [ CF105EE42E3F71E648CEBB3F666E1CF0 ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys 06:52:34.0472 3764 MpFilter - ok 06:52:34.0525 3764 [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0 ] mpio C:\Windows\system32\drivers\mpio.sys 06:52:34.0532 3764 mpio - ok 06:52:34.0796 3764 [ A69630D039C38018689190234F866D77 ] MpKsld567a700 c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{734EE1D6-A9D3-4F77-B74F-BF4F8BEFDE3A}\MpKsld567a700.sys 06:52:34.0800 3764 MpKsld567a700 - ok 06:52:34.0853 3764 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 06:52:34.0858 3764 mpsdrv - ok 06:52:34.0920 3764 [ 9835584E999D25004E1EE8E5F3E3B881 ] MpsSvc C:\Windows\system32\mpssvc.dll 06:52:34.0954 3764 MpsSvc - ok 06:52:35.0009 3764 [ CEB46AB7C01C9F825F8CC6BABC18166A ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 06:52:35.0242 3764 MRxDAV - ok 06:52:35.0292 3764 [ 5D16C921E3671636C0EBA3BBAAC5FD25 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 06:52:35.0298 3764 mrxsmb - ok 06:52:35.0376 3764 [ 6D17A4791ACA19328C685D256349FEFC ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 06:52:35.0386 3764 mrxsmb10 - ok 06:52:35.0427 3764 [ B81F204D146000BE76651A50670A5E9E ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 06:52:35.0431 3764 mrxsmb20 - ok 06:52:35.0492 3764 [ 012C5F4E9349E711E11E0F19A8589F0A ] msahci C:\Windows\system32\drivers\msahci.sys 06:52:35.0497 3764 msahci - ok 06:52:35.0576 3764 [ 55055F8AD8BE27A64C831322A780A228 ] msdsm C:\Windows\system32\drivers\msdsm.sys 06:52:35.0584 3764 msdsm - ok 06:52:35.0621 3764 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\Windows\System32\msdtc.exe 06:52:35.0939 3764 MSDTC - ok 06:52:36.0020 3764 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\Windows\system32\drivers\Msfs.sys 06:52:36.0231 3764 Msfs - ok 06:52:36.0279 3764 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 06:52:36.0285 3764 mshidkmdf - ok 06:52:36.0328 3764 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 06:52:36.0332 3764 msisadrv - ok 06:52:36.0388 3764 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 06:52:36.0564 3764 MSiSCSI - ok 06:52:36.0585 3764 msiserver - ok 06:52:36.0641 3764 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 06:52:36.0758 3764 MSKSSRV - ok 06:52:36.0865 3764 [ C1F19D2BACBEE9AB64D9AE69E9859AC0 ] MsMpSvc c:\Program Files\Microsoft Security Client\MsMpEng.exe 06:52:36.0867 3764 MsMpSvc - ok 06:52:36.0925 3764 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 06:52:37.0017 3764 MSPCLOCK - ok 06:52:37.0045 3764 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 06:52:37.0181 3764 MSPQM - ok 06:52:37.0256 3764 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 06:52:37.0264 3764 MsRPC - ok 06:52:37.0327 3764 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys 06:52:37.0334 3764 mssmbios - ok 06:52:37.0372 3764 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 06:52:37.0474 3764 MSTEE - ok 06:52:37.0541 3764 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\Windows\system32\drivers\MTConfig.sys 06:52:37.0666 3764 MTConfig - ok 06:52:37.0694 3764 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\Windows\system32\Drivers\mup.sys 06:52:37.0700 3764 Mup - ok 06:52:37.0746 3764 [ CB47C414E083CA6E50E634B148F28F64 ] mwlPSDFilter C:\Windows\system32\DRIVERS\mwlPSDFilter.sys 06:52:37.0769 3764 mwlPSDFilter - ok 06:52:37.0785 3764 [ 647B953019559BFF07536F5C6121F333 ] mwlPSDNServ C:\Windows\system32\DRIVERS\mwlPSDNServ.sys 06:52:37.0795 3764 mwlPSDNServ - ok 06:52:37.0813 3764 [ 5A236A36DB8687D1E64DC81C03EAABE1 ] mwlPSDVDisk C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys 06:52:37.0822 3764 mwlPSDVDisk - ok 06:52:37.0947 3764 [ 3E5E20817259F7328C8F3BE5421F35B9 ] MWLService C:\Program Files\EgisTec MyWinLocker\x86\MWLService.exe 06:52:37.0959 3764 MWLService - ok 06:52:38.0079 3764 [ 61D57A5D7C6D9AFE10E77DAE6E1B445E ] napagent C:\Windows\system32\qagentRT.dll 06:52:38.0100 3764 napagent - ok 06:52:38.0162 3764 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 06:52:38.0171 3764 NativeWifiP - ok 06:52:38.0248 3764 [ 8C9C922D71F1CD4DEF73F186416B7896 ] NDIS C:\Windows\system32\drivers\ndis.sys 06:52:38.0279 3764 NDIS - ok 06:52:38.0311 3764 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 06:52:38.0386 3764 NdisCap - ok 06:52:38.0418 3764 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 06:52:38.0547 3764 NdisTapi - ok 06:52:38.0615 3764 [ D8A65DAFB3EB41CBB622745676FCD072 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 06:52:38.0619 3764 Ndisuio - ok 06:52:38.0673 3764 [ 38FBE267E7E6983311179230FACB1017 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 06:52:38.0917 3764 NdisWan - ok 06:52:38.0962 3764 [ A4BDC541E69674FBFF1A8FF00BE913F2 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 06:52:39.0112 3764 NDProxy - ok 06:52:39.0157 3764 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 06:52:39.0280 3764 NetBIOS - ok 06:52:39.0352 3764 [ 280122DDCF04B378EDD1AD54D71C1E54 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 06:52:39.0367 3764 NetBT - ok 06:52:39.0411 3764 [ 81951F51E318AECC2D68559E47485CC4 ] Netlogon C:\Windows\system32\lsass.exe 06:52:39.0417 3764 Netlogon - ok 06:52:39.0501 3764 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\Windows\System32\netman.dll 06:52:39.0512 3764 Netman - ok 06:52:39.0553 3764 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\Windows\System32\netprofm.dll 06:52:39.0566 3764 netprofm - ok 06:52:39.0630 3764 [ F476EC40033CDB91EFBE73EB99B8362D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 06:52:39.0635 3764 NetTcpPortSharing - ok 06:52:39.0689 3764 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys 06:52:39.0694 3764 nfrd960 - ok 06:52:39.0776 3764 [ 832E098BCA8235436FE2D8AE50AC3718 ] NisDrv C:\Windows\system32\DRIVERS\NisDrvWFP.sys 06:52:39.0782 3764 NisDrv - ok 06:52:39.0851 3764 [ E570ECA850F30EB740C2E9699DF3D2BD ] NisSrv c:\Program Files\Microsoft Security Client\NisSrv.exe 06:52:39.0862 3764 NisSrv - ok 06:52:39.0937 3764 [ 374071043F9E4231EE43BE2BB48DD36D ] NlaSvc C:\Windows\System32\nlasvc.dll 06:52:39.0952 3764 NlaSvc - ok 06:52:39.0986 3764 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\Windows\system32\drivers\Npfs.sys 06:52:40.0155 3764 Npfs - ok 06:52:40.0222 3764 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\Windows\system32\nsisvc.dll 06:52:40.0234 3764 nsi - ok 06:52:40.0267 3764 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 06:52:40.0273 3764 nsiproxy - ok 06:52:40.0525 3764 [ 5E43D2B0EE64123D4880DFA6626DEFDE ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 06:52:40.0559 3764 Ntfs - ok 06:52:40.0615 3764 [ F9756A98D69098DCA8945D62858A812C ] Null C:\Windows\system32\drivers\Null.sys 06:52:40.0714 3764 Null - ok 06:52:40.0801 3764 [ B3E25EE28883877076E0E1FF877D02E0 ] nvraid C:\Windows\system32\drivers\nvraid.sys 06:52:40.0807 3764 nvraid - ok 06:52:40.0884 3764 [ 4380E59A170D88C4F1022EFF6719A8A4 ] nvstor C:\Windows\system32\drivers\nvstor.sys 06:52:40.0899 3764 nvstor - ok 06:52:40.0946 3764 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 06:52:40.0951 3764 nv_agp - ok 06:52:40.0986 3764 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys 06:52:41.0176 3764 ohci1394 - ok 06:52:41.0275 3764 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 06:52:41.0285 3764 ose - ok 06:52:41.0648 3764 [ 358A9CCA612C68EB2F07DDAD4CE1D8D7 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 06:52:41.0837 3764 osppsvc - ok 06:52:41.0944 3764 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 06:52:41.0964 3764 p2pimsvc - ok 06:52:42.0019 3764 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\Windows\system32\p2psvc.dll 06:52:42.0040 3764 p2psvc - ok 06:52:42.0097 3764 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\Windows\system32\drivers\parport.sys 06:52:42.0101 3764 Parport - ok 06:52:42.0156 3764 [ 3F34A1B4C5F6475F320C275E63AFCE9B ] partmgr C:\Windows\system32\drivers\partmgr.sys 06:52:42.0177 3764 partmgr - ok 06:52:42.0223 3764 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\Windows\system32\drivers\parvdm.sys 06:52:42.0412 3764 Parvdm - ok 06:52:42.0517 3764 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\Windows\System32\pcasvc.dll 06:52:42.0534 3764 PcaSvc - ok 06:52:42.0579 3764 [ 673E55C3498EB970088E812EA820AA8F ] pci C:\Windows\system32\drivers\pci.sys 06:52:42.0585 3764 pci - ok 06:52:42.0629 3764 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\Windows\system32\drivers\pciide.sys 06:52:42.0634 3764 pciide - ok 06:52:42.0680 3764 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys 06:52:42.0687 3764 pcmcia - ok 06:52:42.0716 3764 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\Windows\system32\drivers\pcw.sys 06:52:42.0721 3764 pcw - ok 06:52:42.0771 3764 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\Windows\system32\drivers\peauth.sys 06:52:42.0784 3764 PEAUTH - ok 06:52:43.0109 3764 [ 414BBA67A3DED1D28437EB66AEB8A720 ] pla C:\Windows\system32\pla.dll 06:52:43.0172 3764 pla - ok 06:52:43.0273 3764 [ EC7BC28D207DA09E79B3E9FAF8B232CA ] PlugPlay C:\Windows\system32\umpnpmgr.dll 06:52:43.0303 3764 PlugPlay - ok 06:52:43.0364 3764 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 06:52:43.0374 3764 PNRPAutoReg - ok 06:52:43.0410 3764 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 06:52:43.0421 3764 PNRPsvc - ok 06:52:43.0529 3764 [ 53946B69BA0836BD95B03759530C81EC ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 06:52:43.0739 3764 PolicyAgent - ok 06:52:43.0827 3764 [ F87D30E72E03D579A5199CCB3831D6EA ] Power C:\Windows\system32\umpo.dll 06:52:43.0847 3764 Power - ok 06:52:43.0923 3764 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 06:52:44.0101 3764 PptpMiniport - ok 06:52:44.0153 3764 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\Windows\system32\drivers\processr.sys 06:52:44.0253 3764 Processor - ok 06:52:44.0320 3764 [ CADEFAC453040E370A1BDFF3973BE00D ] ProfSvc C:\Windows\system32\profsvc.dll 06:52:44.0335 3764 ProfSvc - ok 06:52:44.0367 3764 [ 81951F51E318AECC2D68559E47485CC4 ] ProtectedStorage C:\Windows\system32\lsass.exe 06:52:44.0374 3764 ProtectedStorage - ok 06:52:44.0474 3764 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\Windows\system32\DRIVERS\pacer.sys 06:52:44.0480 3764 Psched - ok 06:52:44.0689 3764 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\Windows\system32\drivers\ql2300.sys 06:52:44.0732 3764 ql2300 - ok 06:52:44.0791 3764 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\Windows\system32\drivers\ql40xx.sys 06:52:44.0796 3764 ql40xx - ok 06:52:44.0844 3764 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\Windows\system32\qwave.dll 06:52:44.0856 3764 QWAVE - ok 06:52:44.0880 3764 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 06:52:44.0885 3764 QWAVEdrv - ok 06:52:44.0914 3764 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 06:52:45.0022 3764 RasAcd - ok 06:52:45.0071 3764 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 06:52:45.0227 3764 RasAgileVpn - ok 06:52:45.0272 3764 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\Windows\System32\rasauto.dll 06:52:45.0282 3764 RasAuto - ok 06:52:45.0330 3764 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 06:52:45.0438 3764 Rasl2tp - ok 06:52:45.0535 3764 [ CB9E04DC05EACF5B9A36CA276D475006 ] RasMan C:\Windows\System32\rasmans.dll 06:52:45.0547 3764 RasMan - ok 06:52:45.0584 3764 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 06:52:45.0668 3764 RasPppoe - ok 06:52:45.0707 3764 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 06:52:45.0883 3764 RasSstp - ok 06:52:46.0007 3764 [ D528BC58A489409BA40334EBF96A311B ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 06:52:46.0172 3764 rdbss - ok 06:52:46.0214 3764 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\Windows\system32\drivers\rdpbus.sys 06:52:46.0385 3764 rdpbus - ok 06:52:46.0442 3764 [ 23DAE03F29D253AE74C44F99E515F9A1 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 06:52:46.0447 3764 RDPCDD - ok 06:52:46.0516 3764 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 06:52:46.0520 3764 RDPENCDD - ok 06:52:46.0557 3764 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys 06:52:46.0560 3764 RDPREFMP - ok 06:52:46.0610 3764 [ F031683E6D1FEA157ABB2FF260B51E61 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 06:52:46.0765 3764 RDPWD - ok 06:52:46.0866 3764 [ 518395321DC96FE2C9F0E96AC743B656 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 06:52:46.0875 3764 rdyboost - ok 06:52:46.0992 3764 [ B2D01290C0E0465ACA54C2088E947823 ] RealNetworks Downloader Resolver Service C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe 06:52:47.0006 3764 RealNetworks Downloader Resolver Service - ok 06:52:47.0053 3764 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\Windows\System32\mprdim.dll 06:52:47.0061 3764 RemoteAccess - ok 06:52:47.0104 3764 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll 06:52:47.0114 3764 RemoteRegistry - ok 06:52:47.0163 3764 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 06:52:47.0171 3764 RpcEptMapper - ok 06:52:47.0214 3764 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\Windows\system32\locator.exe 06:52:47.0222 3764 RpcLocator - ok 06:52:47.0258 3764 [ 7660F01D3B38ACA1747E397D21D790AF ] RpcSs C:\Windows\system32\rpcss.dll 06:52:47.0270 3764 RpcSs - ok 06:52:47.0335 3764 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 06:52:47.0340 3764 rspndr - ok 06:52:47.0487 3764 [ 7CB9F0FDD730F4A4ECF6CDE15EA12E8A ] RS_Service C:\Program Files\Acer\Acer VCM\RS_Service.exe 06:52:47.0499 3764 RS_Service - ok 06:52:47.0544 3764 [ 81951F51E318AECC2D68559E47485CC4 ] SamSs C:\Windows\system32\lsass.exe 06:52:47.0550 3764 SamSs - ok 06:52:47.0624 3764 [ 05D860DA1040F111503AC416CCEF2BCA ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 06:52:47.0631 3764 sbp2port - ok 06:52:47.0712 3764 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\Windows\System32\SCardSvr.dll 06:52:47.0730 3764 SCardSvr - ok 06:52:47.0785 3764 [ 0693B5EC673E34DC147E195779A4DCF6 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 06:52:47.0789 3764 scfilter - ok 06:52:47.0876 3764 [ A04BB13F8A72F8B6E8B4071723E4E336 ] Schedule C:\Windows\system32\schedsvc.dll 06:52:47.0902 3764 Schedule - ok 06:52:47.0931 3764 [ 319C6B309773D063541D01DF8AC6F55F ] SCPolicySvc C:\Windows\System32\certprop.dll 06:52:47.0934 3764 SCPolicySvc - ok 06:52:48.0010 3764 [ 08236C4BCE5EDD0A0318A438AF28E0F7 ] SDRSVC C:\Windows\System32\SDRSVC.dll 06:52:48.0020 3764 SDRSVC - ok 06:52:48.0082 3764 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys 06:52:48.0086 3764 secdrv - ok 06:52:48.0134 3764 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\Windows\system32\seclogon.dll 06:52:48.0144 3764 seclogon - ok 06:52:48.0173 3764 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\Windows\System32\sens.dll 06:52:48.0183 3764 SENS - ok 06:52:48.0207 3764 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\Windows\system32\drivers\serenum.sys 06:52:48.0417 3764 Serenum - ok 06:52:48.0482 3764 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\Windows\system32\drivers\serial.sys 06:52:48.0713 3764 Serial - ok 06:52:48.0756 3764 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\Windows\system32\drivers\sermouse.sys 06:52:48.0874 3764 sermouse - ok 06:52:48.0975 3764 [ 4AE380F39A0032EAB7DD953030B26D28 ] SessionEnv C:\Windows\system32\sessenv.dll 06:52:48.0993 3764 SessionEnv - ok 06:52:49.0036 3764 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 06:52:49.0184 3764 sffdisk - ok 06:52:49.0229 3764 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 06:52:49.0425 3764 sffp_mmc - ok 06:52:49.0460 3764 [ 6D4CCAEDC018F1CF52866BBBAA235982 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 06:52:49.0675 3764 sffp_sd - ok 06:52:49.0737 3764 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys 06:52:49.0836 3764 sfloppy - ok 06:52:50.0036 3764 [ D9B734638DD8DBA9D59AAD3189CD0FAD ] Sftfs C:\Windows\system32\DRIVERS\Sftfslh.sys 06:52:50.0056 3764 Sftfs - ok 06:52:50.0218 3764 [ CB73BC422C07FB611F194DA18D1E7F36 ] sftlist C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe 06:52:50.0236 3764 sftlist - ok 06:52:50.0347 3764 [ 2F61BD46C0BFF4EB36E1E359CA17BFC5 ] Sftplay C:\Windows\system32\DRIVERS\Sftplaylh.sys 06:52:50.0354 3764 Sftplay - ok 06:52:50.0378 3764 [ 518BAC0179F94304F422696B47C0EC12 ] Sftredir C:\Windows\system32\DRIVERS\Sftredirlh.sys 06:52:50.0384 3764 Sftredir - ok 06:52:50.0448 3764 [ 747325236D88B3F05FFD27FF9EC711C5 ] Sftvol C:\Windows\system32\DRIVERS\Sftvollh.sys 06:52:50.0452 3764 Sftvol - ok 06:52:50.0501 3764 [ A5812F0281CA5081BF696626F9BF324D ] sftvsa C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe 06:52:50.0508 3764 sftvsa - ok 06:52:50.0594 3764 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\Windows\System32\ipnathlp.dll 06:52:50.0605 3764 SharedAccess - ok 06:52:50.0667 3764 [ 414DA952A35BF5D50192E28263B40577 ] ShellHWDetection C:\Windows\System32\shsvcs.dll 06:52:50.0681 3764 ShellHWDetection - ok 06:52:50.0709 3764 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\Windows\system32\drivers\sisagp.sys 06:52:50.0714 3764 sisagp - ok 06:52:50.0759 3764 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys 06:52:50.0764 3764 SiSRaid2 - ok 06:52:50.0795 3764 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys 06:52:50.0802 3764 SiSRaid4 - ok 06:52:50.0840 3764 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\Windows\system32\DRIVERS\smb.sys 06:52:50.0983 3764 Smb - ok 06:52:51.0077 3764 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe 06:52:51.0086 3764 SNMPTRAP - ok 06:52:51.0130 3764 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\Windows\system32\drivers\spldr.sys 06:52:51.0134 3764 spldr - ok 06:52:51.0238 3764 [ 9AEA093B8F9C37CF45538382CABA2475 ] Spooler C:\Windows\System32\spoolsv.exe 06:52:51.0259 3764 Spooler - ok 06:52:51.0692 3764 [ CF87A1DE791347E75B98885214CED2B8 ] sppsvc C:\Windows\system32\sppsvc.exe 06:52:51.0826 3764 sppsvc - ok 06:52:51.0916 3764 [ B0180B20B065D89232A78A40FE56EAA6 ] sppuinotify C:\Windows\system32\sppuinotify.dll 06:52:51.0926 3764 sppuinotify - ok 06:52:52.0020 3764 [ E4C2764065D66EA1D2D3EBC28FE99C46 ] srv C:\Windows\system32\DRIVERS\srv.sys 06:52:52.0033 3764 srv - ok 06:52:52.0082 3764 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 06:52:52.0092 3764 srv2 - ok 06:52:52.0119 3764 [ BE6BD660CAA6F291AE06A718A4FA8ABC ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 06:52:52.0124 3764 srvnet - ok 06:52:52.0191 3764 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 06:52:52.0210 3764 SSDPSRV - ok 06:52:52.0238 3764 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\Windows\system32\sstpsvc.dll 06:52:52.0250 3764 SstpSvc - ok 06:52:52.0284 3764 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\Windows\system32\drivers\stexstor.sys 06:52:52.0288 3764 stexstor - ok 06:52:52.0355 3764 [ E1FB3706030FB4578A0D72C2FC3689E4 ] StiSvc C:\Windows\System32\wiaservc.dll 06:52:52.0399 3764 StiSvc - ok 06:52:52.0460 3764 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\Windows\system32\drivers\swenum.sys 06:52:52.0464 3764 swenum - ok 06:52:52.0509 3764 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\Windows\System32\swprv.dll 06:52:52.0522 3764 swprv - ok 06:52:52.0586 3764 [ 5CDD124913E91C7F79B4D5CAE1C7C4DE ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys 06:52:52.0606 3764 SynTP - ok 06:52:52.0721 3764 [ 36650D618CA34C9D357DFD3D89B2C56F ] SysMain C:\Windows\system32\sysmain.dll 06:52:52.0763 3764 SysMain - ok 06:52:52.0823 3764 [ 763FECDC3D30C815FE72DD57936C6CD1 ] TabletInputService C:\Windows\System32\TabSvc.dll 06:52:52.0835 3764 TabletInputService - ok 06:52:52.0900 3764 [ 613BF4820361543956909043A265C6AC ] TapiSrv C:\Windows\System32\tapisrv.dll 06:52:52.0913 3764 TapiSrv - ok 06:52:52.0959 3764 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\Windows\System32\tbssvc.dll 06:52:52.0970 3764 TBS - ok 06:52:53.0176 3764 [ D32FDAC73FCD76B85389C39BC1087F2A ] Tcpip C:\Windows\system32\drivers\tcpip.sys 06:52:53.0201 3764 Tcpip - ok 06:52:53.0261 3764 [ D32FDAC73FCD76B85389C39BC1087F2A ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 06:52:53.0277 3764 TCPIP6 - ok 06:52:53.0349 3764 [ 3EEBD3BD93DA46A26E89893C7AB2FF3B ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 06:52:53.0354 3764 tcpipreg - ok 06:52:53.0431 3764 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 06:52:53.0602 3764 TDPIPE - ok 06:52:53.0674 3764 [ 2C2C5AFE7EE4F620D69C23C0617651A8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 06:52:53.0855 3764 TDTCP - ok 06:52:53.0913 3764 [ B459575348C20E8121D6039DA063C704 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 06:52:54.0048 3764 tdx - ok 06:52:54.0112 3764 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] TermDD C:\Windows\system32\drivers\termdd.sys 06:52:54.0117 3764 TermDD - ok 06:52:54.0261 3764 [ 382C804C92811BE57829D8E550A900E2 ] TermService C:\Windows\System32\termsrv.dll 06:52:54.0287 3764 TermService - ok 06:52:54.0324 3764 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\Windows\system32\themeservice.dll 06:52:54.0334 3764 Themes - ok 06:52:54.0362 3764 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\Windows\system32\mmcss.dll 06:52:54.0372 3764 THREADORDER - ok 06:52:54.0418 3764 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\Windows\System32\trkwks.dll 06:52:54.0430 3764 TrkWks - ok 06:52:54.0552 3764 [ 2C49B175AEE1D4364B91B531417FE583 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 06:52:54.0572 3764 TrustedInstaller - ok 06:52:54.0619 3764 [ 254BB140EEE3C59D6114C1A86B636877 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 06:52:54.0625 3764 tssecsrv - ok 06:52:54.0731 3764 [ FD1D6C73E6333BE727CBCC6054247654 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 06:52:54.0737 3764 TsUsbFlt - ok 06:52:54.0816 3764 [ B2FA25D9B17A68BB93D58B0556E8C90D ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 06:52:55.0060 3764 tunnel - ok 06:52:55.0096 3764 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\Windows\system32\drivers\uagp35.sys 06:52:55.0101 3764 uagp35 - ok 06:52:55.0136 3764 [ EE43346C7E4B5E63E54F927BABBB32FF ] udfs C:\Windows\system32\DRIVERS\udfs.sys 06:52:55.0358 3764 udfs - ok 06:52:55.0438 3764 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\Windows\system32\UI0Detect.exe 06:52:55.0449 3764 UI0Detect - ok 06:52:55.0508 3764 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 06:52:55.0516 3764 uliagpkx - ok 06:52:55.0589 3764 [ D295BED4B898F0FD999FCFA9B32B071B ] umbus C:\Windows\system32\drivers\umbus.sys 06:52:55.0697 3764 umbus - ok 06:52:55.0776 3764 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\Windows\system32\drivers\umpass.sys 06:52:55.0997 3764 UmPass - ok 06:52:56.0131 3764 [ F9EC9ACD504D823D9B9CA98A4F8D3CA2 ] Updater Service C:\Program Files\Acer\Acer Updater\UpdaterService.exe 06:52:56.0140 3764 Updater Service - ok 06:52:56.0222 3764 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\Windows\System32\upnphost.dll 06:52:56.0244 3764 upnphost - ok 06:52:56.0321 3764 [ BD9C55D7023C5DE374507ACC7A14E2AC ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 06:52:56.0443 3764 usbccgp - ok 06:52:56.0509 3764 [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir C:\Windows\system32\drivers\usbcir.sys 06:52:56.0621 3764 usbcir - ok 06:52:56.0659 3764 [ F92DE757E4B7CE9C07C5E65423F3AE3B ] usbehci C:\Windows\system32\drivers\usbehci.sys 06:52:56.0829 3764 usbehci - ok 06:52:56.0920 3764 [ 8DC94AEC6A7E644A06135AE7506DC2E9 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 06:52:57.0069 3764 usbhub - ok 06:52:57.0122 3764 [ E185D44FAC515A18D9DEDDC23C2CDF44 ] usbohci C:\Windows\system32\drivers\usbohci.sys 06:52:57.0257 3764 usbohci - ok 06:52:57.0300 3764 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\Windows\system32\drivers\usbprint.sys 06:52:57.0429 3764 usbprint - ok 06:52:57.0499 3764 [ F991AB9CC6B908DB552166768176896A ] USBSTOR C:\Windows\system32\drivers\USBSTOR.SYS 06:52:57.0603 3764 USBSTOR - ok 06:52:57.0660 3764 [ 68DF884CF41CDADA664BEB01DAF67E3D ] usbuhci C:\Windows\system32\drivers\usbuhci.sys 06:52:57.0798 3764 usbuhci - ok 06:52:57.0855 3764 [ 45F4E7BF43DB40A6C6B4D92C76CBC3F2 ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys 06:52:57.0969 3764 usbvideo - ok 06:52:58.0021 3764 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\Windows\System32\uxsms.dll 06:52:58.0030 3764 UxSms - ok 06:52:58.0056 3764 [ 81951F51E318AECC2D68559E47485CC4 ] VaultSvc C:\Windows\system32\lsass.exe 06:52:58.0062 3764 VaultSvc - ok 06:52:58.0129 3764 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 06:52:58.0133 3764 vdrvroot - ok 06:52:58.0207 3764 [ C3CD30495687C2A2F66A65CA6FD89BE9 ] vds C:\Windows\System32\vds.exe 06:52:58.0226 3764 vds - ok 06:52:58.0289 3764 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 06:52:58.0358 3764 vga - ok 06:52:58.0409 3764 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\Windows\System32\drivers\vga.sys 06:52:58.0528 3764 VgaSave - ok 06:52:58.0601 3764 [ 5461686CCA2FDA57B024547733AB42E3 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys 06:52:58.0611 3764 vhdmp - ok 06:52:58.0663 3764 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\Windows\system32\drivers\viaagp.sys 06:52:58.0668 3764 viaagp - ok 06:52:58.0703 3764 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\Windows\system32\drivers\viac7.sys 06:52:58.0813 3764 ViaC7 - ok 06:52:58.0873 3764 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\Windows\system32\drivers\viaide.sys 06:52:58.0879 3764 viaide - ok 06:52:58.0925 3764 [ 4C63E00F2F4B5F86AB48A58CD990F212 ] volmgr C:\Windows\system32\drivers\volmgr.sys 06:52:58.0930 3764 volmgr - ok 06:52:59.0013 3764 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 06:52:59.0025 3764 volmgrx - ok 06:52:59.0071 3764 [ F497F67932C6FA693D7DE2780631CFE7 ] volsnap C:\Windows\system32\drivers\volsnap.sys 06:52:59.0080 3764 volsnap - ok 06:52:59.0152 3764 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys 06:52:59.0159 3764 vsmraid - ok 06:52:59.0245 3764 [ 209A3B1901B83AEB8527ED211CCE9E4C ] VSS C:\Windows\system32\vssvc.exe 06:52:59.0313 3764 VSS - ok 06:52:59.0428 3764 [ 4B817450226F93C31ADD5BCC27FED27A ] vToolbarUpdater15.2.0 C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe 06:52:59.0453 3764 vToolbarUpdater15.2.0 - ok 06:52:59.0532 3764 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys 06:52:59.0656 3764 vwifibus - ok 06:52:59.0770 3764 [ 7090D3436EEB4E7DA3373090A23448F7 ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys 06:52:59.0911 3764 vwififlt - ok 06:53:00.0035 3764 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\Windows\system32\w32time.dll 06:53:00.0060 3764 W32Time - ok 06:53:00.0097 3764 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\Windows\system32\drivers\wacompen.sys 06:53:00.0227 3764 WacomPen - ok 06:53:00.0290 3764 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys 06:53:00.0345 3764 WANARP - ok 06:53:00.0362 3764 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 06:53:00.0365 3764 Wanarpv6 - ok 06:53:00.0492 3764 [ 691E3285E53DCA558E1A84667F13E15A ] wbengine C:\Windows\system32\wbengine.exe 06:53:00.0563 3764 wbengine - ok 06:53:00.0665 3764 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 06:53:00.0683 3764 WbioSrvc - ok 06:53:00.0797 3764 [ 34EEE0DFAADB4F691D6D5308A51315DC ] wcncsvc C:\Windows\System32\wcncsvc.dll 06:53:00.0827 3764 wcncsvc - ok 06:53:00.0883 3764 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 06:53:00.0900 3764 WcsPlugInService - ok 06:53:00.0952 3764 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\Windows\system32\drivers\wd.sys 06:53:00.0956 3764 Wd - ok 06:53:01.0120 3764 [ A840213F1ACDCC175B4D1D5AAEAC0D7A ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 06:53:01.0135 3764 Wdf01000 - ok 06:53:01.0179 3764 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\Windows\system32\wdi.dll 06:53:01.0193 3764 WdiServiceHost - ok 06:53:01.0209 3764 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\Windows\system32\wdi.dll 06:53:01.0223 3764 WdiSystemHost - ok 06:53:01.0313 3764 [ A9D880F97530D5B8FEE278923349929D ] WebClient C:\Windows\System32\webclnt.dll 06:53:01.0326 3764 WebClient - ok 06:53:01.0368 3764 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\Windows\system32\wecsvc.dll 06:53:01.0380 3764 Wecsvc - ok 06:53:01.0436 3764 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\Windows\System32\wercplsupport.dll 06:53:01.0446 3764 wercplsupport - ok 06:53:01.0517 3764 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\Windows\System32\WerSvc.dll 06:53:01.0527 3764 WerSvc - ok 06:53:01.0583 3764 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys 06:53:01.0718 3764 WfpLwf - ok 06:53:01.0748 3764 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\Windows\system32\drivers\wimmount.sys 06:53:01.0752 3764 WIMMount - ok 06:53:01.0894 3764 [ 3FAE8F94296001C32EAB62CD7D82E0FD ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll 06:53:02.0184 3764 WinDefend - ok 06:53:02.0207 3764 WinHttpAutoProxySvc - ok 06:53:02.0325 3764 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 06:53:02.0332 3764 Winmgmt - ok 06:53:02.0592 3764 [ 1B91CD34EA3A90AB6A4EF0550174F4CC ] WinRM C:\Windows\system32\WsmSvc.dll 06:53:02.0629 3764 WinRM - ok 06:53:02.0714 3764 [ A67E5F9A400F3BD1BE3D80613B45F708 ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys 06:53:02.0868 3764 WinUsb - ok 06:53:03.0004 3764 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\Windows\System32\wlansvc.dll 06:53:03.0044 3764 Wlansvc - ok 06:53:03.0118 3764 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys 06:53:03.0121 3764 WmiAcpi - ok 06:53:03.0179 3764 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 06:53:03.0187 3764 wmiApSrv - ok 06:53:03.0434 3764 [ 3B40D3A61AA8C21B88AE57C58AB3122E ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe 06:53:03.0456 3764 WMPNetworkSvc - ok 06:53:03.0532 3764 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\Windows\System32\wpcsvc.dll 06:53:03.0550 3764 WPCSvc - ok 06:53:03.0628 3764 [ AA53356D60AF47EACC85BC617A4F3F66 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 06:53:03.0645 3764 WPDBusEnum - ok 06:53:03.0685 3764 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 06:53:03.0690 3764 ws2ifsl - ok 06:53:03.0742 3764 [ 6F5D49EFE0E7164E03AE773A3FE25340 ] wscsvc C:\Windows\System32\wscsvc.dll 06:53:03.0753 3764 wscsvc - ok 06:53:03.0771 3764 WSearch - ok 06:53:03.0923 3764 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll 06:53:04.0007 3764 wuauserv - ok 06:53:04.0066 3764 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 06:53:04.0088 3764 WudfPf - ok 06:53:04.0145 3764 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 06:53:04.0364 3764 WUDFRd - ok 06:53:04.0431 3764 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 06:53:04.0442 3764 wudfsvc - ok 06:53:04.0502 3764 [ 3C5E51C05BE9B56EAFF4E388C3AB25E4 ] WwanSvc C:\Windows\System32\wwansvc.dll 06:53:04.0519 3764 WwanSvc - ok 06:53:04.0650 3764 [ 86187FB5D81781501558F8742DEE4197 ] ZTEusbmdm6k C:\Windows\system32\DRIVERS\ZTEusbmdm6k.sys 06:53:04.0727 3764 ZTEusbmdm6k - ok 06:53:04.0761 3764 [ B7836CA4A95E12135E7E49FEC9C29F2A ] ZTEusbnet C:\Windows\system32\DRIVERS\ZTEusbnet.sys 06:53:04.0928 3764 ZTEusbnet - ok 06:53:04.0962 3764 [ 86187FB5D81781501558F8742DEE4197 ] ZTEusbnmea C:\Windows\system32\DRIVERS\ZTEusbnmea.sys 06:53:05.0002 3764 ZTEusbnmea - ok 06:53:05.0054 3764 [ 86187FB5D81781501558F8742DEE4197 ] ZTEusbser6k C:\Windows\system32\DRIVERS\ZTEusbser6k.sys 06:53:05.0097 3764 ZTEusbser6k - ok 06:53:05.0153 3764 ================ Scan global =============================== 06:53:05.0261 3764 [ DAB748AE0439955ED2FA22357533DDDB ] C:\Windows\system32\basesrv.dll 06:53:05.0321 3764 [ 1F5F07091D50244F17DD8D5147A628CC ] C:\Windows\system32\winsrv.dll 06:53:05.0364 3764 [ 1F5F07091D50244F17DD8D5147A628CC ] C:\Windows\system32\winsrv.dll 06:53:05.0454 3764 [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll 06:53:05.0527 3764 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe 06:53:05.0550 3764 [Global] - ok 06:53:05.0551 3764 ================ Scan MBR ================================== 06:53:05.0607 3764 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0 06:53:07.0646 3764 \Device\Harddisk0\DR0 - ok 06:53:07.0648 3764 ================ Scan VBR ================================== 06:53:07.0686 3764 [ FA82AB9694471F50DC27B9218D7860E3 ] \Device\Harddisk0\DR0\Partition1 06:53:07.0689 3764 \Device\Harddisk0\DR0\Partition1 - ok 06:53:07.0735 3764 [ 435CE5431705E6F5B3092731FE7DA02C ] \Device\Harddisk0\DR0\Partition2 06:53:07.0739 3764 \Device\Harddisk0\DR0\Partition2 - ok 06:53:07.0779 3764 [ 19AF586EF6EA9BCB8F1FCC4793DFCF10 ] \Device\Harddisk0\DR0\Partition3 06:53:07.0787 3764 \Device\Harddisk0\DR0\Partition3 - ok 06:53:07.0788 3764 ============================================================ 06:53:07.0788 3764 Scan finished 06:53:07.0789 3764 ============================================================ 06:53:07.0839 1868 Detected object count: 0 06:53:07.0840 1868 Actual detected object count: 0
Hi Declan ;)


Please read through these instructions to familarize yourself with what to expect when this tool runs

Refer to the ComboFix User's Guide


Download ComboFix from one of these locations:

Link 1
Link 2



* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================


Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs


====================================================


Double click on combofix.exe & follow the prompts.


When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.

NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.
Thanks again for everything, just one or two points re Combifix - this crashed after completing 2 stages. Not sure if it was because it said MSE and AVG were still running, even though I disabled them or not. Anyway I removed them from the system and re-ran Combifix, the log file is as below. ComboFix 13-06-24.01 - User 25/06/2013 5:43.2.2 - x86 Microsoft Windows 7 Starter 6.1.7601.1.1252.44.1033.18.1013.249 [GMT 1:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\BetterCareerSearch_2bEI c:\programdata\FullRemove.exe c:\windows\wininit.ini . . ((((((((((((((((((((((((( Files Created from 2013-05-25 to 2013-06-25 ))))))))))))))))))))))))))))))) . . 2013-06-25 04:58 . 2013-06-25 04:58 ——– d—–w- c:\users\User\AppData\Local\temp 2013-06-25 04:58 . 2013-06-25 04:58 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-06-25 04:36 . 2013-06-25 04:36 60872 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{EBA164D0-17DD-4AD6-BCE3-2BF1B2529C8C}\offreg.dll 2013-06-25 04:10 . 2013-06-25 04:10 0 —-a-w- c:\windows\system32\shoB76C.tmp 2013-06-22 16:52 . 2013-06-23 05:46 ——– d—–w- c:\program files\OpenIt 2013-06-22 16:52 . 2013-06-22 16:52 ——– d—–w- c:\users\User\AppData\Roaming\DSite 2013-06-22 16:22 . 2013-06-22 16:22 ——– d—–w- c:\windows\ERUNT 2013-06-22 16:21 . 2013-06-22 16:21 ——– d—–w- C:\JRT 2013-06-19 18:40 . 2013-04-17 07:02 1230336 —-a-w- c:\windows\system32\WindowsCodecs.dll 2013-06-18 21:47 . 2013-06-18 21:47 9728 —ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-06-17 19:54 . 2013-06-17 19:54 ——– d—–w- c:\program files\VS Revo Group 2013-06-17 18:09 . 2012-08-22 17:16 712048 —-a-w- c:\windows\system32\drivers\ndis.sys 2013-06-17 18:09 . 2012-07-04 19:45 33280 —-a-w- c:\windows\system32\drivers\RNDISMP.sys 2013-06-17 18:08 . 2013-04-25 23:30 1505280 —-a-w- c:\windows\system32\d3d11.dll 2013-06-17 18:05 . 2012-08-21 20:12 245760 —-a-w- c:\windows\system32\OxpsConverter.exe 2013-06-17 18:05 . 2013-03-19 04:53 186368 —-a-w- c:\windows\system32\wwansvc.dll 2013-06-17 18:05 . 2013-03-19 03:33 40960 —-a-w- c:\windows\system32\wwanprotdim.dll 2013-06-17 18:05 . 2013-05-10 03:20 24576 —-a-w- c:\windows\system32\cryptdlg.dll 2013-06-17 18:04 . 2013-04-10 03:14 2347520 —-a-w- c:\windows\system32\win32k.sys 2013-06-17 18:04 . 2013-04-26 04:55 492544 —-a-w- c:\windows\system32\win32spl.dll 2013-06-17 18:04 . 2013-05-13 03:08 903168 —-a-w- c:\windows\system32\certutil.exe 2013-06-17 18:04 . 2013-05-13 04:45 1160192 —-a-w- c:\windows\system32\crypt32.dll 2013-06-17 18:04 . 2013-05-13 04:45 140288 —-a-w- c:\windows\system32\cryptsvc.dll 2013-06-17 18:04 . 2013-05-13 04:45 103936 —-a-w- c:\windows\system32\cryptnet.dll 2013-06-17 18:04 . 2013-05-13 03:08 43008 —-a-w- c:\windows\system32\certenc.dll 2013-06-17 18:03 . 2012-10-03 16:42 156672 —-a-w- c:\windows\system32\ncsi.dll 2013-06-17 18:03 . 2012-10-03 16:40 499712 —-a-w- c:\windows\system32\iphlpsvc.dll 2013-06-17 18:03 . 2012-10-03 16:42 175104 —-a-w- c:\windows\system32\netcorehc.dll 2013-06-17 18:03 . 2012-10-03 16:42 242176 —-a-w- c:\windows\system32\nlasvc.dll 2013-06-17 18:03 . 2012-10-03 16:42 52224 —-a-w- c:\windows\system32\nlaapi.dll 2013-06-17 18:03 . 2012-10-03 15:21 35328 —-a-w- c:\windows\system32\drivers\tcpipreg.sys 2013-06-17 18:03 . 2012-10-03 16:42 18944 —-a-w- c:\windows\system32\netevent.dll 2013-06-17 18:01 . 2013-05-06 05:06 3913576 —-a-w- c:\windows\system32\ntoskrnl.exe 2013-06-17 18:01 . 2013-05-06 05:06 3968872 —-a-w- c:\windows\system32\ntkrnlpa.exe 2013-06-17 18:00 . 2013-04-10 05:18 728424 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys 2013-06-17 18:00 . 2013-04-10 05:18 218984 —-a-w- c:\windows\system32\drivers\dxgmms1.sys 2013-06-17 18:00 . 2012-11-23 02:48 49152 —-a-w- c:\windows\system32\taskhost.exe 2013-06-17 18:00 . 2013-05-08 05:38 1293672 —-a-w- c:\windows\system32\drivers\tcpip.sys 2013-06-17 18:00 . 2012-10-09 17:40 44032 —-a-w- c:\windows\system32\dhcpcsvc6.dll 2013-06-17 18:00 . 2012-10-09 17:40 193536 —-a-w- c:\windows\system32\dhcpcore6.dll 2013-06-17 17:59 . 2013-02-27 05:05 101720 —-a-w- c:\windows\system32\consent.exe 2013-06-17 17:59 . 2013-02-27 04:49 1796096 —-a-w- c:\windows\system32\authui.dll 2013-06-17 17:59 . 2013-02-27 04:49 47104 —-a-w- c:\windows\system32\appinfo.dll 2013-06-17 17:52 . 2013-06-17 17:52 ——– d—–w- c:\users\User\AppData\Roaming\AVG2013 2013-06-17 17:50 . 2013-06-17 17:50 ——– d—–w- c:\users\User\AppData\Local\AVG Secure Search 2013-06-17 17:49 . 2013-06-22 16:10 ——– d—–w- c:\programdata\AVG Secure Search 2013-06-17 17:49 . 2013-06-17 17:48 37664 —-a-w- c:\windows\system32\drivers\avgtpx86.sys 2013-06-17 17:49 . 2013-06-22 16:10 ——– d—–w- c:\program files\Common Files\AVG Secure Search 2013-06-17 17:48 . 2013-06-22 16:10 ——– d—–w- c:\program files\AVG Secure Search 2013-06-17 17:44 . 2013-06-25 04:05 ——– d—–w- c:\programdata\AVG2013 2013-06-17 17:44 . 2013-06-25 04:05 ——– d—–w- C:\$AVG 2013-06-17 17:36 . 2013-06-25 04:10 ——– d—–w- c:\programdata\MFAData 2013-06-17 17:36 . 2013-06-17 18:05 ——– d—–w- c:\users\User\AppData\Local\Avg2013 2013-06-17 17:36 . 2013-06-17 17:36 ——– d—–w- c:\users\User\AppData\Local\MFAData 2013-06-17 05:47 . 2013-06-17 05:47 ——– d—–w- C:\9e856ef85da9b57ffd821680f163a2 2013-06-17 04:47 . 2012-12-16 14:13 295424 —-a-w- c:\windows\system32\atmfd.dll 2013-06-17 04:47 . 2012-12-16 14:13 34304 —-a-w- c:\windows\system32\atmlib.dll 2013-06-17 04:19 . 2013-06-17 04:19 ——– d—–w- c:\windows\system32\SPReview 2013-06-17 04:18 . 2013-06-17 04:18 ——– d—–w- c:\windows\system32\EventProviders 2013-06-16 22:46 . 2013-06-18 05:35 ——– d—–w- c:\programdata\Spybot - Search & Destroy 2013-06-16 22:46 . 2013-06-16 22:46 ——– d—–w- c:\program files\Spybot - Search & Destroy 2013-06-16 22:34 . 2011-10-04 07:48 161736 —-a-w- c:\program files\2bres.dll 2013-06-16 21:33 . 2013-06-16 21:33 ——– d—–w- c:\program files\CCleaner 2013-06-16 21:32 . 2013-06-16 21:32 ——– d—–w- c:\users\User\AppData\Roaming\AVSoftware 2013-06-14 20:27 . 2013-06-10 23:59 7016152 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{EBA164D0-17DD-4AD6-BCE3-2BF1B2529C8C}\mpengine.dll 2013-06-14 11:58 . 2012-07-26 03:39 526952 —-a-w- c:\windows\system32\drivers\Wdf01000.sys 2013-06-14 11:58 . 2012-07-26 03:39 47720 —-a-w- c:\windows\system32\drivers\WdfLdr.sys 2013-06-14 11:58 . 2012-07-26 02:46 9728 —-a-w- c:\windows\system32\Wdfres.dll 2013-06-14 11:57 . 2013-02-15 04:37 3217408 —-a-w- c:\windows\system32\mstscax.dll 2013-06-14 11:57 . 2013-02-15 04:34 131584 —-a-w- c:\windows\system32\aaclient.dll 2013-06-14 11:57 . 2013-02-15 03:25 36864 —-a-w- c:\windows\system32\tsgqec.dll 2013-06-14 11:56 . 2012-07-26 02:33 66560 —-a-w- c:\windows\system32\drivers\WUDFPf.sys 2013-06-14 11:56 . 2012-07-26 02:32 155136 —-a-w- c:\windows\system32\drivers\WUDFRd.sys 2013-06-14 11:56 . 2012-07-26 03:20 73216 —-a-w- c:\windows\system32\WUDFSvc.dll 2013-06-14 11:56 . 2012-07-26 03:20 172032 —-a-w- c:\windows\system32\WUDFPlatform.dll 2013-06-14 11:56 . 2012-07-26 03:21 196608 —-a-w- c:\windows\system32\WUDFHost.exe 2013-06-14 11:56 . 2012-07-26 03:20 613888 —-a-w- c:\windows\system32\WUDFx.dll 2013-06-14 11:56 . 2012-07-26 03:20 38912 —-a-w- c:\windows\system32\WUDFCoinstaller.dll 2013-06-14 11:56 . 2012-05-05 07:46 400896 —-a-w- c:\windows\system32\srcore.dll 2013-06-14 11:56 . 2010-11-20 12:17 262656 —-a-w- c:\windows\system32\rstrui.exe 2013-06-14 11:56 . 2012-02-11 05:37 317440 —-a-w- c:\windows\system32\spoolsv.exe 2013-06-14 11:55 . 2013-04-12 13:45 1211752 —-a-w- c:\windows\system32\drivers\ntfs.sys 2013-06-14 11:55 . 2012-11-22 04:45 626688 —-a-w- c:\windows\system32\usp10.dll 2013-06-14 11:55 . 2013-02-12 03:32 15872 —-a-w- c:\windows\system32\drivers\usb8023.sys 2013-06-14 11:55 . 2012-08-24 16:57 172544 —-a-w- c:\windows\system32\wintrust.dll 2013-06-14 11:55 . 2012-11-02 05:11 376832 —-a-w- c:\windows\system32\dpnet.dll 2013-06-14 11:55 . 2010-11-20 11:57 2560 —-a-w- c:\windows\system32\dpnaddr.dll 2013-06-14 11:54 . 2013-01-24 04:47 196328 —-a-w- c:\windows\system32\drivers\fvevol.sys 2013-06-14 11:54 . 2013-03-19 04:48 38912 —-a-w- c:\windows\system32\csrsrv.dll 2013-06-14 11:54 . 2013-03-19 02:49 69632 —-a-w- c:\windows\system32\smss.exe 2013-06-14 11:53 . 2012-03-01 05:46 19824 —-a-w- c:\windows\system32\drivers\fs_rec.sys 2013-06-14 11:53 . 2012-03-01 05:33 159232 —-a-w- c:\windows\system32\imagehlp.dll 2013-06-14 11:53 . 2012-03-01 05:29 5120 —-a-w- c:\windows\system32\wmi.dll 2013-06-14 11:53 . 2012-04-28 03:17 183808 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2013-06-14 11:53 . 2012-06-02 04:45 67440 —-a-w- c:\windows\system32\drivers\ksecdd.sys 2013-06-14 11:53 . 2012-06-02 04:45 134000 —-a-w- c:\windows\system32\drivers\ksecpkg.sys 2013-06-14 11:53 . 2012-06-02 04:40 369336 —-a-w- c:\windows\system32\drivers\cng.sys 2013-06-14 11:53 . 2012-06-02 04:40 225280 —-a-w- c:\windows\system32\schannel.dll 2013-06-14 11:53 . 2012-06-06 05:05 1236992 —-a-w- c:\windows\system32\msxml3.dll 2013-06-14 11:53 . 2010-06-26 03:24 2048 —-a-w- c:\windows\system32\msxml3r.dll 2013-06-14 11:53 . 2012-03-31 04:29 936960 —-a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll 2013-06-14 11:52 . 2012-11-01 04:47 1389568 —-a-w- c:\windows\system32\msxml6.dll 2013-06-14 11:50 . 2012-06-06 05:03 805376 —-a-w- c:\windows\system32\cdosys.dll 2013-06-14 11:50 . 2012-06-06 05:05 372736 —-a-w- c:\program files\Common Files\System\ado\msadox.dll 2013-06-14 11:50 . 2012-06-06 05:05 352256 —-a-w- c:\program files\Common Files\System\ado\msadomd.dll 2013-06-14 11:50 . 2012-06-06 05:05 1019904 —-a-w- c:\program files\Common Files\System\ado\msado15.dll 2013-06-14 11:50 . 2012-06-06 05:05 143360 —-a-w- c:\program files\Common Files\System\ado\msjro.dll 2013-06-14 11:50 . 2012-06-06 05:05 57344 —-a-w- c:\program files\Common Files\System\ado\msador15.dll 2013-06-14 11:50 . 2012-06-06 05:05 212992 —-a-w- c:\program files\Common Files\System\msadc\msadco.dll 2013-06-14 11:32 . 2012-07-04 21:14 41984 —-a-w- c:\windows\system32\browcli.dll 2013-06-14 11:32 . 2012-07-04 21:14 102912 —-a-w- c:\windows\system32\browser.dll 2013-06-14 11:31 . 2012-08-10 23:56 542208 —-a-w- c:\windows\system32\kerberos.dll 2013-06-14 11:31 . 2012-04-07 11:26 2342400 —-a-w- c:\windows\system32\msi.dll 2013-06-14 11:29 . 2012-11-09 04:42 2048 —-a-w- c:\windows\system32\tzres.dll 2013-06-14 11:28 . 2013-01-04 04:50 169984 —-a-w- c:\windows\system32\winsrv.dll 2013-06-11 21:14 . 2012-02-17 05:34 826880 —-a-w- c:\windows\system32\rdpcore.dll 2013-06-11 21:14 . 2012-02-17 04:13 24576 —-a-w- c:\windows\system32\drivers\tdtcp.sys 2013-06-11 21:14 . 2010-11-20 10:21 18432 —-a-w- c:\windows\system32\drivers\tdpipe.sys 2013-06-11 21:03 . 2012-06-02 22:19 53784 —-a-w- c:\windows\system32\wuauclt.exe 2013-06-11 21:03 . 2012-06-02 22:19 45080 —-a-w- c:\windows\system32\wups2.dll 2013-06-11 21:03 . 2012-06-02 22:12 2422272 —-a-w- c:\windows\system32\wucltux.dll 2013-06-11 21:03 . 2012-06-02 22:19 1933848 —-a-w- c:\windows\system32\wuaueng.dll 2013-06-11 21:02 . 2012-06-02 22:19 35864 —-a-w- c:\windows\system32\wups.dll 2013-06-11 21:02 . 2012-06-02 22:19 577048 —-a-w- c:\windows\system32\wuapi.dll 2013-06-11 21:02 . 2012-06-02 22:12 88576 —-a-w- c:\windows\system32\wudriver.dll . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-06-17 05:12 . 2009-07-14 02:05 152576 —-a-w- c:\windows\system32\msclmd.dll 2013-05-02 15:28 . 2011-12-28 19:52 238872 ——w- c:\windows\system32\MpSigStub.exe 2013-04-13 04:45 . 2013-06-17 18:03 474624 —-a-w- c:\windows\apppatch\AcSpecfc.dll 2013-04-13 04:45 . 2013-06-17 18:03 2176512 —-a-w- c:\windows\apppatch\AcGenral.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2010-05-27 02:40 120176 —-a-w- c:\program files\EgisTec MyWinLocker\x86\PSDProtect.dll . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "SPReview"="c:\windows\System32\SPReview\SPReview.exe" [2013-06-17 280576] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Acer VCM.lnk - c:\program files\Acer\Acer VCM\AcerVCM.exe [2010-9-17 704032] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R3 EUCR;EUCR;c:\windows\system32\DRIVERS\EUCR6SK.SYS [2010-06-17 82768] R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x86.sys [x] R3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [2009-04-27 9216] R3 MWLService;MyWinLocker Service;c:\program files\EgisTec MyWinLocker\x86\MWLService.exe [2010-05-27 305520] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 ZTEusbnet;ZTE USB-NDIS miniport;c:\windows\system32\DRIVERS\ZTEusbnet.sys [2009-07-21 114688] S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [2013-06-17 37664] S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-03 18992] S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-03 16432] S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-03 60976] S2 cvhsvc;Client Virtualization Handler;c:\program files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624] S2 DsiWMIService;Dritek WMI Service;c:\program files\Launch Manager\dsiwmis.exe [2010-08-10 321104] S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2010-06-11 735776] S2 GREGService;GREGService;c:\program files\Acer\Registration\GREGsvc.exe [2010-01-08 23584] S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-06-08 13336] S2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files\RealNetworks\RealDownloader\rndlresolversvc.exe [2013-04-16 39056] S2 RS_Service;Raw Socket Service;c:\program files\Acer\Acer VCM\RS_Service.exe [2010-01-29 260640] S2 sftlist;Application Virtualization Client;c:\program files\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776] S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2010-01-28 243232] S2 vToolbarUpdater15.2.0;vToolbarUpdater15.2.0;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe [2013-06-17 1015984] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 579944] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 194408] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 21864] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 19304] S3 sftvsa;Application Virtualization Service Agent;c:\program files\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496] . . — Other Services/Drivers In Memory — . *NewlyCreated* - AVGTP . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc . Contents of the 'Scheduled Tasks' folder . 2013-06-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2013-06-08 21:21] . 2013-06-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2013-06-08 21:21] . 2013-06-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1724070015-2864343876-1984321240-1000Core.job - c:\users\User\AppData\Local\Google\Update\GoogleUpdate.exe [2011-04-28 20:01] . 2013-06-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1724070015-2864343876-1984321240-1000UA.job - c:\users\User\AppData\Local\Google\Update\GoogleUpdate.exe [2011-04-28 20:01] . . ——- Supplementary Scan ——- . IE: Free YouTube to MP3 Converter - c:\program files\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm TCP: DhcpNameServer = [removed] [removed] . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Toolbar-!{872b5b88-9db5-4310-bdd0-ac189557e5f5} - (no file) HKCU-Run-MPOptimizer - c:\program files\MaxPerforma Optimizer\MaxPerforma.exe HKCU-Run-BreakingNews - c:\program files\BreakingNews\BreakingNews\DesktopContainer.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2013-06-25 06:02:59 ComboFix-quarantined-files.txt 2013-06-25 05:02 . Pre-Run: 178,195,013,632 bytes free Post-Run: 177,763,475,456 bytes free . - - End Of File - - D98DAB6D93ADC2F66CD18AC641F9442A A36C5E4F47E84449FF07ED3517B43A31
Hi Declan ;)

Very good job :)

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

ClearJavaCache


In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]


Next

Please go to: VirusTotal
  • [external image: Posted Image]
  • Click the Browse button and search for the following file:

    c:\windows\system32\shoB76C.tmp

  • Click Open
  • Then click Send File
  • Please be patient while the file is scanned.
  • Once the scan results appear, please provide them in your next reply.
If it says already scanned – click "reanalyze now"

Please post the results in your next reply.

Next

Please let me know what can you find in this folder: C:\9e856ef85da9b57ffd821680f163a2

Next

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.

=============================== Next =======================================



ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

Note: If you are using Windows Vista/7, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as MyEsetScan. Alternatively, look for report in C:\Program Files\ESET\ESET Online Scanner\log.txt. Include the contents of this report in your next reply.
  • Push the Back button.
  • Select Uninstall application on close check box and push [external image: Posted Image]

Please let me know how your machine is running and if there are any outstanding issues


On your next reply please post :
  • MBAM log
  • Eset report

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Hello Robybel, that was a long night! The browser couldn't find VirusTotal - received the 404 error, whether I used Chrome or IE. I checked on my PC, and it does exist :) . Both MBAM and ESET found zero errors, I have attached the MBAM log below, but ESET didn't provide one??? The Netbook itself is operating far better than before, although the response time is slightly slow, and ad pop-ups still appear now and again. Hope this information is useful to you. Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Database version: v2013.06.25.08 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 10.0.9200.16618 User :: USER-PC [administrator] 25/06/2013 20:06:11 mbam-log-2013-06-25 (20-06-11).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 200072 Time elapsed: 21 minute(s), 22 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
Hi Declan ;)

Ok try this

Please go to: VirusTotal
  • [external image: Posted Image]
  • Click the Browse button and search for the following file:

    c:\windows\system32\shoB76C.tmp

  • Click Open
  • Then click Send File
  • Please be patient while the file is scanned.
  • Once the scan results appear, please provide them in your next reply.
If it says already scanned – click "reanalyze now"

Please post the results in your next reply.


NEXT


Run OTL

  • Open OTL again and click the Quick Scan button (don't check the boxes beside LOP Check or Purity this time)
  • Post the OTL.txt log it produces in your next reply.
Hi, had some issues again tonight.
First of all, I wasn't really sure what to expect, result-wise, from Virus Total - hopefully the file was what you were looking for.
OTL created issues too - the LOP and Purity check boxes checked themselves as soon as I clicked on Quick Scan??? Then I wasn't sure if it was even running, there didn't seem to be any recognition of a continuum or progress being made.
I have attached the resulting file. Don't have great hopes for this, but we'll see what you think.
Thanks again.


Virus Total won't upload, as I'm not allowed to upload that sort of file - it wasn't a log as such, so I just saved the page, sorry. Maybe you could advise the best way to do this?

OTL logfile created on: 26/06/2013 21:02:54 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\User\Desktop
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16618)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1013.09 Mb Total Physical Memory | 351.92 Mb Available Physical Memory | 34.74% Memory free
1.99 Gb Paging File | 1.11 Gb Available in Paging File | 55.68% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 215.79 Gb Total Space | 163.29 Gb Free Space | 75.67% Space Free | Partition Type: NTFS
Drive D: | 4.00 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: FAT32

Computer Name: USER-PC | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\User\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG Secure Search\vprot.exe (AVG Secure Search)
PRC - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe (AVG Secure Search)
PRC - C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe ()
PRC - C:\Program Files\AVG\AVG2013\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Launch Manager\dsiwmis.exe (Dritek System Inc.)
PRC - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated)
PRC - C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
PRC - C:\Program Files\Acer\Acer VCM\RS_Service.exe (Acer Incorporated)
PRC - C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Group)
PRC - C:\Program Files\Acer\Registration\GREGsvc.exe (Acer Incorporated)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\15.2.0\SiteSafety.dll ()


========== Services (SafeList) ==========

SRV - (vToolbarUpdater15.2.0) – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe (AVG Secure Search)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (RealNetworks Downloader Resolver Service) – C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe ()
SRV - (NisSrv) – c:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (sftvsa) – C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (DsiWMIService) – C:\Program Files\Launch Manager\dsiwmis.exe (Dritek System Inc.)
SRV - (ePowerSvc) – C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated)
SRV - (IAStorDataMgrSvc) – C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (MWLService) – C:\Program Files\EgisTec MyWinLocker\x86\MWLService.exe (Egis Technology Inc.)
SRV - (RS_Service) – C:\Program Files\Acer\Acer VCM\RS_Service.exe (Acer Incorporated)
SRV - (Updater Service) – C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Group)
SRV - (GREGService) – C:\Program Files\Acer\Registration\GREGsvc.exe (Acer Incorporated)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (L1C) – system32\DRIVERS\L1C62x86.sys File not found
DRV - (GEARAspiWDM) – system32\DRIVERS\GEARAspiWDM.sys File not found
DRV - (catchme) – C:\Users\User\AppData\Local\Temp\catchme.sys File not found
DRV - (avgtp) – C:\Windows\System32\drivers\avgtpx86.sys (AVG Technologies)
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avglogx) – C:\Windows\System32\drivers\avglogx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSHX) – C:\Windows\System32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\Windows\System32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (NisDrv) – C:\Windows\System32\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV - (Sftvol) – C:\Windows\System32\drivers\Sftvollh.sys (Microsoft Corporation)
DRV - (Sftredir) – C:\Windows\System32\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV - (Sftplay) – C:\Windows\System32\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV - (Sftfs) – C:\Windows\System32\drivers\Sftfslh.sys (Microsoft Corporation)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (EUCR) – C:\Windows\System32\drivers\EUCR6SK.sys (ENE Technology Inc.)
DRV - (hwdatacard) – C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (ZTEusbser6k) – C:\Windows\System32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbnmea) – C:\Windows\System32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) – C:\Windows\System32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (ZTEusbnet) – C:\Windows\System32\drivers\ZTEusbnet.sys (ZTE Corporation)
DRV - (Serial) – C:\Windows\System32\drivers\serial.sys (Brother Industries Ltd.)
DRV - (mwlPSDVDisk) – C:\Windows\System32\drivers\mwlPSDVDisk.sys (Egis Technology Inc.)
DRV - (mwlPSDNServ) – C:\Windows\System32\drivers\mwlPSDNserv.sys (Egis Technology Inc.)
DRV - (mwlPSDFilter) – C:\Windows\System32\drivers\mwlPSDFilter.sys (Egis Technology Inc.)
DRV - (massfilter) – C:\Windows\System32\drivers\massfilter.sys (ZTE Incorporated)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://bbc.co.uk/
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\15.2.0\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.2.32: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.2: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.2: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.2: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.2.32: C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\User\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\User\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FCE04E1F-9378-4f39-96F6-5689A9159E45}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2013/06/08 22:22:15 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013/06/08 22:22:15 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - default_search_provider: Search Results (Enabled)
CHR - default_search_provider: search_url = http://dts.search-results.com/sr?src=crb&a…q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - homepage: http://search.conduit.com/?ctid=CT2269050&…amp;sspv=CHSB18
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\Application\27.0.1453.116\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\Application\27.0.1453.116\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\Application\27.0.1453.116\pdf.dll
CHR - plugin: registryAccess (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaaaooaijelonlmbcbjkocdnicdfmo\7.13.0.0_0\background/registryAccess.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.270.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U27 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~4\Office14\NPSPWRAP.DLL
CHR - plugin: MindSpark Toolbar Platform Plugin Stub (Enabled) = C:\Program Files\BetterCareerSearch_2b\bar\1.bin\NP2bStub.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Google Update (Enabled) = C:\Users\User\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - Extension: news.net = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmbbgcooaabknohabmoaikiakkoignai\1.0.12_0\
CHR - Extension: AVG Security Toolbar = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.2.0.5_0\

O1 HOSTS File: ([2013/06/25 05:58:29 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - !{2318C2B1-4965-11d4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe (AVG Secure Search)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Program Files\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm ()
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{37096400-4D72-41DD-B37B-C84267CD79C6}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\15.2.0\ViProtocol.dll (AVG Secure Search)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/06/26 20:53:32 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
[2013/06/26 18:51:40 | 000,000,000 | —D | C] – C:\Users\User\Desktop\VirusTotal_files
[2013/06/25 19:57:35 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Malwarebytes
[2013/06/25 19:56:23 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/06/25 19:56:14 | 000,022,856 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2013/06/25 19:56:13 | 000,000,000 | —D | C] – C:\Users\User\Desktop\Malwarebytes' Anti-Malware
[2013/06/25 19:52:53 | 010,285,040 | —- | C] (Malwarebytes Corporation ) – C:\Users\User\Desktop\mbam-setup-1.75.0.1300.exe
[2013/06/25 19:07:24 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/06/25 06:27:23 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2013/06/25 06:13:54 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013/06/25 06:13:29 | 000,000,000 | —D | C] – C:\Program Files\AVG Secure Search
[2013/06/25 06:09:20 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2013/06/25 06:03:03 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\temp
[2013/06/25 05:40:55 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2013/06/25 05:40:55 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2013/06/25 05:40:55 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2013/06/25 04:59:24 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2013/06/25 04:55:57 | 005,082,330 | R— | C] (Swearware) – C:\Users\User\Desktop\ComboFix.exe
[2013/06/24 22:32:01 | 000,000,000 | —D | C] – C:\Qoobox
[2013/06/23 06:50:57 | 000,000,000 | —D | C] – C:\Users\User\Desktop\tdsskiller
[2013/06/22 17:52:51 | 000,000,000 | —D | C] – C:\Program Files\OpenIt
[2013/06/22 17:52:42 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\DSite
[2013/06/22 17:22:25 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/06/22 17:21:41 | 000,000,000 | —D | C] – C:\JRT
[2013/06/19 21:03:57 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2013/06/19 20:48:32 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\User\Desktop\HiJackThis.exe
[2013/06/19 19:27:12 | 000,000,000 | —D | C] – C:\Users\User\Documents\My Received Files
[2013/06/17 20:54:50 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
[2013/06/17 20:54:47 | 000,000,000 | —D | C] – C:\Program Files\VS Revo Group
[2013/06/17 18:52:33 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\AVG2013
[2013/06/17 18:50:57 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\AVG Secure Search
[2013/06/17 18:49:56 | 000,000,000 | —D | C] – C:\ProgramData\AVG Secure Search
[2013/06/17 18:49:16 | 000,037,664 | —- | C] (AVG Technologies) – C:\Windows\System32\drivers\avgtpx86.sys
[2013/06/17 18:49:00 | 000,000,000 | —D | C] – C:\Program Files\Common Files\AVG Secure Search
[2013/06/17 18:44:09 | 000,000,000 | —D | C] – C:\ProgramData\AVG2013
[2013/06/17 18:44:09 | 000,000,000 | —D | C] – C:\$AVG
[2013/06/17 18:36:05 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\MFAData
[2013/06/17 18:36:05 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2013/06/17 18:36:05 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Avg2013
[2013/06/17 06:47:45 | 000,000,000 | —D | C] – C:\9e856ef85da9b57ffd821680f163a2
[2013/06/17 05:19:38 | 000,000,000 | —D | C] – C:\Windows\System32\SPReview
[2013/06/17 05:18:04 | 000,000,000 | —D | C] – C:\Windows\System32\EventProviders
[2013/06/16 23:46:37 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2013/06/16 23:46:00 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2013/06/16 23:46:00 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2013/06/16 22:33:15 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2013/06/16 22:32:47 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\AVSoftware
[2013/06/08 22:23:30 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Programs
[2013/06/08 22:23:13 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\RealNetworks
[2013/06/08 22:22:14 | 000,000,000 | —D | C] – C:\Program Files\RealNetworks
[2013/06/08 22:22:09 | 000,000,000 | —D | C] – C:\ProgramData\RealNetworks
[2013/06/08 22:21:46 | 000,000,000 | —D | C] – C:\Program Files\Common Files\xing shared
[2013/06/08 22:21:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealNetworks
[2013/06/08 22:21:18 | 000,272,896 | —- | C] (Progressive Networks) – C:\Windows\System32\pncrt.dll
[2013/06/08 22:20:56 | 000,000,000 | —D | C] – C:\Program Files\Real
[2013/06/08 22:20:28 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Real
[2013/06/08 22:20:27 | 000,000,000 | —D | C] – C:\Program Files\Google
[2013/06/08 22:17:21 | 000,000,000 | —D | C] – C:\ProgramData\Real
[2013/06/08 22:17:05 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DVDVideoSoft
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/06/26 20:53:58 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
[2013/06/26 20:31:01 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1724070015-2864343876-1984321240-1000UA.job
[2013/06/26 20:31:00 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/26 20:23:42 | 000,009,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/06/26 20:23:42 | 000,009,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/06/26 20:19:28 | 000,000,878 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/06/26 20:15:58 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/06/26 20:15:55 | 796,729,344 | -HS- | M] () – C:\hiberfil.sys
[2013/06/26 18:51:40 | 000,146,142 | —- | M] () – C:\Users\User\Desktop\VirusTotal.htm
[2013/06/25 22:31:14 | 000,000,852 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1724070015-2864343876-1984321240-1000Core.job
[2013/06/25 19:56:55 | 000,000,744 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/06/25 19:53:25 | 010,285,040 | —- | M] (Malwarebytes Corporation ) – C:\Users\User\Desktop\mbam-setup-1.75.0.1300.exe
[2013/06/25 06:28:25 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif
[2013/06/25 06:13:54 | 000,000,939 | —- | M] () – C:\Users\Public\Desktop\AVG 2013.lnk
[2013/06/25 06:13:20 | 000,037,664 | —- | M] (AVG Technologies) – C:\Windows\System32\drivers\avgtpx86.sys
[2013/06/25 05:58:29 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2013/06/25 04:59:03 | 005,082,330 | R— | M] (Swearware) – C:\Users\User\Desktop\ComboFix.exe
[2013/06/23 07:32:51 | 000,002,329 | —- | M] () – C:\Users\User\Desktop\Google Chrome.lnk
[2013/06/23 06:52:20 | 000,000,005 | —- | M] () – C:\Users\User\AppData\Roaming\WBPU-TTL.DAT
[2013/06/23 06:49:34 | 002,218,636 | —- | M] () – C:\Users\User\Desktop\tdsskiller.zip
[2013/06/19 21:14:29 | 000,000,355 | —- | M] () – C:\Users\User\Computer - Shortcut.lnk
[2013/06/19 21:03:49 | 205,770,716 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/06/19 20:58:07 | 000,625,664 | —- | M] () – C:\Users\User\Desktop\dds.scr
[2013/06/19 20:48:45 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\User\Desktop\HiJackThis.exe
[2013/06/18 22:49:34 | 000,025,185 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2013/06/18 05:59:01 | 000,628,904 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/06/18 05:59:01 | 000,110,798 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/06/18 05:51:14 | 000,259,112 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2013/06/17 20:54:52 | 000,001,230 | —- | M] () – C:\Users\User\Desktop\Revo Uninstaller.lnk
[2013/06/16 23:46:37 | 000,001,224 | —- | M] () – C:\Users\User\Desktop\Spybot - Search & Destroy.lnk
[2013/06/16 22:33:18 | 000,000,973 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2013/06/11 20:49:23 | 000,000,193 | —- | M] () – C:\Windows\WORDPAD.INI
[2013/06/11 20:49:10 | 000,003,439 | —- | M] () – C:\Users\User\Documents\Marks CV.rtf
[2013/06/08 22:22:23 | 000,001,242 | —- | M] () – C:\Users\Public\Desktop\RealPlayer.lnk
[2013/06/08 22:21:18 | 000,272,896 | —- | M] (Progressive Networks) – C:\Windows\System32\pncrt.dll
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/06/26 18:51:32 | 000,146,142 | —- | C] () – C:\Users\User\Desktop\VirusTotal.htm
[2013/06/25 19:56:55 | 000,000,744 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/06/25 06:28:01 | 000,002,121 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2013/06/25 06:13:54 | 000,000,939 | —- | C] () – C:\Users\Public\Desktop\AVG 2013.lnk
[2013/06/25 05:40:55 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/06/25 05:40:55 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/06/25 05:40:55 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/06/25 05:40:55 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/06/25 05:40:55 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2013/06/25 05:38:14 | 000,001,945 | —- | C] () – C:\Windows\epplauncher.mif
[2013/06/23 06:52:20 | 000,000,005 | —- | C] () – C:\Users\User\AppData\Roaming\WBPU-TTL.DAT
[2013/06/23 06:48:56 | 002,218,636 | —- | C] () – C:\Users\User\Desktop\tdsskiller.zip
[2013/06/19 21:14:29 | 000,000,355 | —- | C] () – C:\Users\User\Computer - Shortcut.lnk
[2013/06/19 21:03:49 | 205,770,716 | —- | C] () – C:\Windows\MEMORY.DMP
[2013/06/19 20:57:43 | 000,625,664 | —- | C] () – C:\Users\User\Desktop\dds.scr
[2013/06/18 22:49:34 | 000,025,185 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2013/06/17 20:54:52 | 000,001,230 | —- | C] () – C:\Users\User\Desktop\Revo Uninstaller.lnk
[2013/06/16 23:46:37 | 000,001,224 | —- | C] () – C:\Users\User\Desktop\Spybot - Search & Destroy.lnk
[2013/06/16 23:34:06 | 000,161,736 | —- | C] () – C:\Program Files\2bres.dll
[2013/06/16 22:33:18 | 000,000,973 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2013/06/14 12:58:16 | 000,000,003 | —- | C] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2013/06/14 12:56:39 | 000,000,003 | —- | C] () – C:\Windows\System32\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2013/06/11 20:49:23 | 000,000,193 | —- | C] () – C:\Windows\WORDPAD.INI
[2013/06/11 20:49:10 | 000,003,439 | —- | C] () – C:\Users\User\Documents\Marks CV.rtf
[2013/06/08 22:22:23 | 000,001,242 | —- | C] () – C:\Users\Public\Desktop\RealPlayer.lnk
[2013/06/08 22:21:07 | 000,000,882 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/08 22:21:04 | 000,000,878 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/09/03 15:32:36 | 000,000,017 | —- | C] () – C:\Windows\System32\shortcut_ex.dat
[2012/01/13 23:37:54 | 000,004,096 | —- | C] () – C:\Windows\d3dx.dat
[2011/07/21 15:23:43 | 000,003,584 | —- | C] () – C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/19 19:46:28 | 000,001,940 | —- | C] () – C:\Users\User\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/05/15 21:00:39 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat

========== ZeroAccess Check ==========

[2009/07/14 05:42:31 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/27 05:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 13:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/14 02:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013/06/17 18:52:33 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\AVG2013
[2013/06/16 22:32:47 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\AVSoftware
[2013/06/22 17:52:42 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\DSite
[2013/06/08 22:17:05 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\DVDVideoSoft
[2011/12/21 18:39:41 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\PlayFirst
[2013/03/12 21:08:13 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\SoftGrid Client
[2012/08/13 18:00:02 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Tatara Systems
[2011/12/04 00:00:04 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Tific
[2011/12/04 15:08:47 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\TP
[2013/06/17 18:50:08 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\TuneUp Software
[2011/10/05 10:32:19 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Vodafone
[2011/04/30 15:36:33 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Windows Live Writer

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 149 bytes -> C:\ProgramData\TEMP:93EB7685
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:CDFF58FE
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:E36F5B57
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:E1F04E8D
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:1A60DE96
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:798A3728

< End of report >
Hi Declan ;)

First of all, I wasn't really sure what to expect, result-wise, from Virus Total - hopefully the file was what you were looking for

Do not worry

OTL created issues too

Surely it is my fault, I have to revise my kann

Ok!!

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://bbc.co.uk/
    CHR - default_search_provider: search_url = http://dts.search-results.com/sr?src=crb&a…q={searchTerms}
    CHR - homepage: http://search.conduit.com/?ctid=CT2269050&…amp;sspv=CHSB18
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - !{2318C2B1-4965-11d4-9B18-009027A5CD4F} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
    @Alternate Data Stream - 149 bytes -> C:\ProgramData\TEMP:93EB7685
    @Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:CDFF58FE
    @Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:E36F5B57
    @Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:E1F04E8D
    @Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:1A60DE96
    @Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:798A3728
    
    
    :Files
    ipconfig /flushdns /c
    
    
    :Commands
    [EMPTYFLASH]
    [REBOOT]
    [RESETHOSTS]
    [CREATERESTOREPOINT]
  • Then click the Run Fix button at the top
  • Let the program run unhindered.
  • OTL may ask to reboot the machine. Please do so if asked.
  • The report should appear in Notepad after the reboot.Copy and Paste that report in your next reply.

NEXT

Please download Windows Repair (all in one) from here

Install the program then run it

Go to step 2 and allow it to run Disk check

[external image: Posted Image]

Once that is done then go to step 3 and allow it to run SFC

[external image: Posted Image]

On the the Start Repairs tab => Click the Start

[external image: Posted Image]

Click on the select all check box and then click on Start

DON'T use the computer while each scan is in progress.

Restart may be needed to finish the repair procedure

NEXT

Complete Internet Repair

  • Please download comintrep.exe and save it to your desktop
  • Double click the icon and select Run
  • Click Extract
  • Double click the Complete Internet Repair folder on your desktop
  • Double click the CIntRep.exe icon
  • Place a checkmark next to the following entries:
    • Reset Internet Protocol (TCP/IP)
    • Repair Winsock (Reset Catalog)
    • Renew Internet Connections
    • Flush DNS Resolver Cache
    • Repair Internet Explorer 6.0.2900
    • Clear Windows Update History
    • Repair Windows / Automatic Updates
    • Repair SSL / HTTPS / Cryptography
    • Reset Windows Firewall Configuration
    • Restore the default hosts file
    • Repair Workgroup Computers view
  • Click Go!
  • Ignore any error messages for now
  • Click OK to reboot your computer

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI