This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Adware/Toolbars [Solved]

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Only had the computer for about 2 weeks, and my brother has already managed to download a bunch of junk on it. DDS (Ver_2012-11-20.01) - NTFS_AMD64 Internet Explorer: 10.0.9200.16635 Run by [removed] at 20:06:45 on 2013-07-14 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.4094.2592 [GMT -4:00] . AV: Microsoft Security Essentials *Enabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Microsoft Security Essentials *Enabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508} . ============== Running Processes =============== . C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS c:\Program Files\Microsoft Security Client\MsMpEng.exe C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\atieclxx.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe C:\Windows\system32\svchost.exe -k apphost C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\SysWOW64\PnkBstrA.exe C:\Windows\SysWOW64\PnkBstrB.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\svchost.exe -k iissvcs c:\Program Files\Microsoft Security Client\NisSrv.exe C:\Windows\System32\WUDFHost.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe C:\Windows\servicing\TrustedInstaller.exe c:\Program Files\Microsoft Security Client\MpCmdRun.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\System32\cscript.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.ca/ mWinlogon: Userinit = userinit.exe mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml mRun: [KeePass 2 PreLoad] "C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe" –preload mPolicies-Explorer: NoActiveDesktop = dword:1 mPolicies-Explorer: NoActiveDesktopChanges = dword:1 mPolicies-System: ConsentPromptBehaviorAdmin = dword:5 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableUIADesktopToggle = dword:0 TCP: NameServer = 10.0.0.1 TCP: Interfaces\{06F2236A-F09A-4D63-8F85-BD2C0BDD72CA} : DHCPNameServer = 10.0.0.1 TCP: Interfaces\{A7F6ED93-D986-455F-B900-6159C88CCC8D} : DHCPNameServer = 192.168.1.254 Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll SSODL: WebCheck - mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.72\Installer\chrmstp.exe" –configure-user-settings –verbose-logging –system-level –multi-install –chrome x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - x64-SSODL: WebCheck - . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\AthlonX4\AppData\Roaming\Mozilla\Firefox\Profiles\9njvwb2g.default\ FF - plugin: C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll FF - ExtSQL: 2013-07-14 18:39; [removed]; C:\Users\AthlonX4\AppData\Roaming\Mozilla\Firefox\Profiles\9njvwb2g.default\extensions\[removed] FF - ExtSQL: 2013-07-14 18:39; {906000a4-88d9-4d52-b209-7a772970d91f}; C:\Users\AthlonX4\AppData\Roaming\Mozilla\Firefox\Profiles\9njvwb2g.default\extensions\{906000a4-88d9-4d52-b209-7a772970d91f} . ============= SERVICES / DRIVERS =============== . R0 amd_sata;amd_sata;C:\Windows\System32\drivers\amd_sata.sys [2013-3-31 82600] R0 amd_xata;amd_xata;C:\Windows\System32\drivers\amd_xata.sys [2013-3-31 42664] R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2013-1-20 230320] R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\System32\drivers\dtsoftbus01.sys [2013-6-18 283200] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2012-11-16 238080] R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-11-16 361984] R2 AODDriver4.1;AODDriver4.1;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys [2012-3-5 53888] R2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [2013-6-26 9216] R2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2013-1-20 130008] R3 amdiox64;AMD IO Driver;C:\Windows\System32\drivers\amdiox64.sys [2013-6-16 46136] R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2012-2-23 95760] R3 netr7364;RT73 USB Extensible Wireless LAN Card Driver;C:\Windows\System32\drivers\netr7364.sys [2011-10-5 729152] R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2013-1-27 379360] R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\System32\drivers\yk62x64.sys [2009-9-28 395264] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2011-4-12 71168] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-6-15 19456] S3 Synth3dVsc;Synth3dVsc;C:\Windows\System32\drivers\Synth3dVsc.sys [2011-4-12 88960] S3 terminpt;Microsoft Remote Desktop Input Driver;C:\Windows\System32\drivers\terminpt.sys [2013-6-15 29696] S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-6-15 57856] S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2013-6-15 30208] S3 tsusbhub;tsusbhub;C:\Windows\System32\drivers\tsusbhub.sys [2011-4-12 117248] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-6-15 1255736] S3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\System32\drivers\wdcsam64.sys [2008-5-6 14464] . =============== Created Last 30 ================ . 2013-07-14 23:59:11 9552976 —-a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{97D9BF3F-9E93-4BA3-9361-CD1D65726EA8}\mpengine.dll 2013-07-14 23:57:13 ——– d—–w- C:\Windows\SysWow64\searchplugins 2013-07-14 23:57:13 ——– d—–w- C:\Windows\SysWow64\Extensions 2013-07-14 23:46:41 ——– d—–w- C:\Users\AthlonX4\AppData\Roaming\Malwarebytes 2013-07-14 23:46:31 ——– d—–w- C:\ProgramData\Malwarebytes 2013-07-14 23:46:29 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-07-14 22:39:46 ——– d—–w- C:\Users\AthlonX4\AppData\Local\DealPlyLive 2013-07-14 22:39:46 ——– d—–w- C:\ProgramData\DealPlyLive 2013-07-14 22:39:46 ——– d—–w- C:\Program Files (x86)\DealPlyLive 2013-07-14 22:39:44 ——– d—–w- C:\Users\AthlonX4\AppData\Roaming\Dealply 2013-07-14 22:39:43 ——– d—–w- C:\Program Files (x86)\DealPly 2013-07-14 22:39:22 ——– d—–w- C:\ProgramData\BrowserDefender 2013-07-14 22:39:18 ——– d—–w- C:\Users\AthlonX4\AppData\Roaming\BabSolution 2013-07-14 22:38:57 ——– d—–w- C:\Users\AthlonX4\AppData\Roaming\Babylon 2013-07-14 22:38:57 ——– d—–w- C:\ProgramData\Babylon 2013-07-12 00:44:09 55296 —-a-w- C:\Windows\System32\admwprox.dll 2013-07-12 00:44:09 192000 —-a-w- C:\Windows\System32\iisRtl.dll 2013-07-12 00:44:09 154624 —-a-w- C:\Windows\SysWow64\iisRtl.dll 2013-07-12 00:44:08 60928 —-a-w- C:\Windows\System32\ahadmin.dll 2013-07-12 00:44:08 50688 —-a-w- C:\Windows\SysWow64\admwprox.dll 2013-07-12 00:44:08 16896 —-a-w- C:\Windows\System32\iisreset.exe 2013-07-12 00:44:08 15360 —-a-w- C:\Windows\SysWow64\iisreset.exe 2013-07-12 00:44:08 14848 —-a-w- C:\Windows\System32\wamregps.dll 2013-07-12 00:44:07 8192 —-a-w- C:\Windows\SysWow64\iisrstap.dll 2013-07-12 00:44:07 26624 —-a-w- C:\Windows\SysWow64\ahadmin.dll 2013-07-12 00:44:07 11264 —-a-w- C:\Windows\System32\iisrstap.dll 2013-07-12 00:44:07 10752 —-a-w- C:\Windows\SysWow64\wamregps.dll 2013-07-11 22:33:24 ——– d—–w- C:\Users\AthlonX4\AppData\Roaming\PeaZip 2013-07-11 21:49:03 ——– d—–r- C:\Users\AthlonX4\Wii U 2013-07-11 21:46:38 ——– d—–w- C:\Windows\SysWow64\BestPractices 2013-07-11 21:46:37 ——– d—–w- C:\Windows\System32\BestPractices 2013-07-11 21:46:37 ——– d—–w- C:\inetpub 2013-07-11 18:36:37 9552976 —-a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2013-07-11 02:06:03 1011712 —-a-w- C:\Program Files\Windows Defender\MpSvc.dll 2013-07-11 02:06:02 9216 —-a-w- C:\Program Files (x86)\Windows Defender\MpAsDesc.dll 2013-07-11 02:06:02 624128 —-a-w- C:\Windows\System32\qedit.dll 2013-07-11 02:06:02 571904 —-a-w- C:\Program Files\Windows Defender\MpClient.dll 2013-07-11 02:06:02 54784 —-a-w- C:\Program Files (x86)\Windows Defender\MpOAV.dll 2013-07-11 02:06:02 4608 —-a-w- C:\Program Files (x86)\Windows Defender\MsMpLics.dll 2013-07-11 02:06:02 392704 —-a-w- C:\Program Files (x86)\Windows Defender\MpClient.dll 2013-07-11 02:06:02 314880 —-a-w- C:\Program Files\Windows Defender\MpCommu.dll 2013-07-11 02:06:01 509440 —-a-w- C:\Windows\SysWow64\qedit.dll 2013-07-11 02:06:01 1887744 —-a-w- C:\Windows\System32\WMVDECOD.DLL 2013-07-11 02:06:01 1620480 —-a-w- C:\Windows\SysWow64\WMVDECOD.DLL 2013-07-11 02:05:47 3153920 —-a-w- C:\Windows\System32\win32k.sys 2013-07-11 02:05:46 936448 —-a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\ink\journal.dll 2013-07-11 02:05:46 1732608 —-a-w- C:\Program Files\Windows Journal\NBDoc.DLL 2013-07-11 02:05:46 1402880 —-a-w- C:\Program Files\Windows Journal\JNWDRV.dll 2013-07-11 02:05:46 1393152 —-a-w- C:\Program Files\Windows Journal\JNTFiltr.dll 2013-07-11 02:05:46 1367040 —-a-w- C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll 2013-07-11 02:05:31 1643520 —-a-w- C:\Windows\System32\DWrite.dll 2013-07-11 02:05:31 1247744 —-a-w- C:\Windows\SysWow64\DWrite.dll 2013-07-10 18:13:44 248320 —-a-w- C:\Windows\System32\Spool\prtprocs\x64\hpfpp70v.dll 2013-07-10 18:12:21 ——– d—–w- C:\Program Files (x86)\Common Files\Hewlett-Packard 2013-07-10 18:12:12 145408 —-a-w- C:\Windows\System32\hpfll70v.dll 2013-07-10 18:12:05 ——– d—–w- C:\Program Files (x86)\HP 2013-07-10 18:10:58 642360 —-a-w- C:\Windows\System32\hpzids40.dll 2013-07-10 18:10:58 551424 —-a-w- C:\Windows\System32\hppldcoi.dll 2013-07-07 16:34:22 ——– d—–w- C:\Users\AthlonX4\AppData\Local\Focus Home Interactive 2013-07-06 03:09:14 ——– d–h–w- C:\Windows\msdownld.tmp 2013-07-06 03:09:14 ——– d—–w- C:\Windows\SysWow64\directx 2013-07-06 03:08:53 ——– d—–w- C:\Program Files (x86)\Microsoft XNA 2013-07-06 03:05:09 ——– d—–w- C:\Windows\System32\appmgmt 2013-06-27 01:29:28 ——– d—–w- C:\ProgramData\Hi-Rez Studios 2013-06-27 01:29:18 ——– d—–w- C:\Program Files (x86)\Hi-Rez Studios 2013-06-26 15:06:44 ——– d—–w- C:\Users\AthlonX4\AppData\Roaming\KeePass 2013-06-26 15:00:56 ——– d—–w- C:\Users\AthlonX4\AppData\Roaming\foobar2000 2013-06-26 14:58:59 ——– d—–w- C:\Program Files\GIMP 2 2013-06-26 14:57:02 ——– d—–w- C:\Users\AthlonX4\AppData\Roaming\Foxit Software 2013-06-26 14:57:02 ——– d—–w- C:\Program Files (x86)\Foxit Software 2013-06-26 14:55:43 ——– d—–r- C:\Program Files (x86)\Skype 2013-06-26 14:55:03 ——– d—–w- C:\Program Files (x86)\VideoLAN 2013-06-26 14:54:22 ——– d—–w- C:\Program Files\PeaZip 2013-06-26 14:54:17 ——– d—–w- C:\Program Files (x86)\foobar2000 2013-06-26 14:54:04 ——– d—–w- C:\Program Files (x86)\KeePass Password Safe 2 2013-06-26 14:53:40 ——– d—–w- C:\Users\AthlonX4\AppData\Roaming\uTorrent 2013-06-26 14:04:11 ——– d—–w- C:\Users\AthlonX4\AppData\Roaming\OpenOffice.org 2013-06-26 14:02:56 ——– d—–w- C:\Program Files (x86)\OpenOffice.org 3 2013-06-26 13:27:28 ——– d—–w- C:\Program Files (x86)\FTL 2013-06-26 13:13:04 ——– d—–w- C:\Program Files (x86)\Common Files\Steam 2013-06-26 13:13:02 ——– d—–w- C:\Program Files (x86)\Steam 2013-06-26 00:14:43 ——– d—–w- C:\Users\AthlonX4\AppData\Local\Macromedia 2013-06-25 21:39:13 964552 —-a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{6DE36369-7E9F-480B-A2E0-A9C31E5655C3}\gapaengine.dll 2013-06-25 21:36:20 ——– d—–w- C:\Program Files (x86)\Microsoft Security Client 2013-06-25 21:36:19 ——– d—–w- C:\Program Files\Microsoft Security Client 2013-06-25 21:35:54 ——– d-s—w- C:\Windows\SysWow64\Microsoft 2013-06-25 20:29:27 ——– d-sh–w- C:\Windows\SysWow64\AI_RecycleBin 2013-06-25 20:29:27 ——– d—–w- C:\Users\AthlonX4\AppData\Local\Mojang 2013-06-24 23:20:24 ——– d—–w- C:\Users\AthlonX4\AppData\Local\Skyrim 2013-06-24 21:29:38 ——– d—–w- C:\ProgramData\Package Cache 2013-06-24 21:25:40 ——– d—–w- C:\Users\AthlonX4\AppData\Local\FLT 2013-06-24 21:22:32 ——– d—–w- C:\Users\AthlonX4\AppData\Local\Programs 2013-06-24 21:16:57 178800 —-a-w- C:\Windows\SysWow64\CmdLineExt_x64.dll 2013-06-24 21:14:27 107832 —-a-w- C:\Windows\SysWow64\PnkBstrB.exe 2013-06-24 21:14:24 66872 —-a-w- C:\Windows\SysWow64\PnkBstrA.exe 2013-06-24 21:14:24 2250024 —-a-w- C:\Windows\SysWow64\pbsvc.exe 2013-06-24 20:38:34 ——– d—–w- C:\Users\AthlonX4\Games 2013-06-19 05:00:12 ——– d—–w- C:\Program Files (x86)\AMD AVT 2013-06-19 05:00:11 ——– d—–w- C:\Program Files (x86)\AMD APP 2013-06-19 05:00:08 ——– d—–w- C:\Program Files\Common Files\ATI Technologies 2013-06-19 05:00:08 ——– d—–w- C:\Program Files (x86)\Common Files\ATI Technologies 2013-06-19 04:58:26 ——– d—–w- C:\Program Files (x86)\ATI Technologies 2013-06-19 04:58:13 ——– d—–w- C:\Program Files\ATI Technologies 2013-06-19 04:58:11 ——– d—–w- C:\Program Files\ATI 2013-06-19 03:11:23 6583664 —-a-w- C:\Program Files\AVAST Sof 2013-06-19 02:55:52 ——– d—–w- C:\Users\AthlonX4\AppData\Local\SKIDROW 2013-06-19 02:53:59 529424 —-a-w- C:\Windows\System32\d3dx10_37.dll 2013-06-19 02:34:10 283200 —-a-w- C:\Windows\System32\drivers\dtsoftbus01.sys 2013-06-19 02:34:08 ——– d—–w- C:\Users\AthlonX4\AppData\Roaming\DAEMON Tools Lite 2013-06-19 02:34:06 ——– d—–w- C:\Program Files (x86)\DAEMON Tools Lite 2013-06-19 02:33:42 ——– d—–w- C:\ProgramData\DAEMON Tools Lite 2013-06-19 01:15:05 ——– d—–w- C:\NVIDIA 2013-06-19 01:09:28 ——– d—–w- C:\Users\AthlonX4\AppData\Local\Google 2013-06-19 01:09:15 ——– d—–w- C:\Users\AthlonX4\AppData\Local\Deployment 2013-06-19 01:09:15 ——– d—–w- C:\Users\AthlonX4\AppData\Local\Apps 2013-06-19 00:58:40 ——– d—–w- C:\Program Files (x86)\NVIDIA Corporation 2013-06-19 00:57:48 ——– d—–w- C:\Program Files\NVIDIA Corporation 2013-06-16 09:52:43 ——– d—–w- C:\Program Files\AVAST Software 2013-06-16 09:52:07 ——– d—–w- C:\ProgramData\AVAST Software 2013-06-16 09:50:27 ——– d—–w- C:\Users\AthlonX4\AppData\Local\AMD 2013-06-16 09:50:18 ——– d—–w- C:\Users\AthlonX4\AppData\Local\ATI 2013-06-16 09:49:35 ——– d—–w- C:\ProgramData\AMD 2013-06-16 09:49:32 46136 —-a-w- C:\Windows\System32\drivers\amdiox64.sys 2013-06-16 09:47:17 ——– d—–w- C:\AMD 2013-06-16 03:23:28 71048 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2013-06-16 03:23:28 692104 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2013-06-16 03:22:58 ——– d—–w- C:\Users\AthlonX4\AppData\Local\Adobe 2013-06-16 02:50:04 ——– d-sh–w- C:\Windows\Installer 2013-06-16 00:51:38 ——– d—–w- C:\Windows\SysWow64\Wat 2013-06-16 00:51:38 ——– d—–w- C:\Windows\System32\Wat 2013-06-16 00:49:49 458712 —-a-w- C:\Windows\System32\drivers\cng.sys 2013-06-16 00:49:49 340992 —-a-w- C:\Windows\System32\schannel.dll 2013-06-16 00:49:49 247808 —-a-w- C:\Windows\SysWow64\schannel.dll 2013-06-16 00:49:48 96768 —-a-w- C:\Windows\SysWow64\sspicli.dll 2013-06-16 00:49:48 22016 —-a-w- C:\Windows\SysWow64\secur32.dll 2013-06-16 00:49:48 154480 —-a-w- C:\Windows\System32\drivers\ksecpkg.sys 2013-06-16 00:49:48 1448448 —-a-w- C:\Windows\System32\lsasrv.dll 2013-06-16 00:49:45 514560 —-a-w- C:\Windows\SysWow64\qdvd.dll 2013-06-16 00:49:45 366592 —-a-w- C:\Windows\System32\qdvd.dll 2013-06-15 12:45:58 0 —-a-w- C:\Windows\ativpsrm.bin 2013-06-15 10:48:15 8199504 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll 2013-06-15 10:48:11 9460464 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B2C0CA36-723A-4DAF-87D2-5BD67C5B9218}\mpengine.dll 2013-06-15 10:45:10 9728 —-a-w- C:\Windows\System32\Wdfres.dll 2013-06-15 10:45:10 785512 —-a-w- C:\Windows\System32\drivers\Wdf01000.sys 2013-06-15 10:45:10 54376 —-a-w- C:\Windows\System32\drivers\WdfLdr.sys 2013-06-15 10:45:10 2560 —-a-w- C:\Windows\System32\drivers\en-US\wdf01000.sys.mui 2013-06-15 10:35:11 9728 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-06-15 10:17:36 81408 —-a-w- C:\Windows\System32\imagehlp.dll 2013-06-15 10:17:36 5120 —-a-w- C:\Windows\SysWow64\wmi.dll 2013-06-15 10:17:36 5120 —-a-w- C:\Windows\System32\wmi.dll 2013-06-15 10:17:36 23408 —-a-w- C:\Windows\System32\drivers\fs_rec.sys 2013-06-15 10:17:36 159232 —-a-w- C:\Windows\SysWow64\imagehlp.dll 2013-06-15 10:10:56 46592 —-a-w- C:\Windows\SysWow64\fpb.rs 2013-06-15 10:08:58 6656 —-a-w- C:\Windows\SysWow64\apisetschema.dll 2013-06-15 09:58:39 826880 —-a-w- C:\Windows\SysWow64\rdpcore.dll 2013-06-15 09:58:39 23552 —-a-w- C:\Windows\System32\drivers\tdtcp.sys 2013-06-15 09:58:39 1031680 —-a-w- C:\Windows\System32\rdpcore.dll 2013-06-15 09:54:53 2622464 —-a-w- C:\Windows\System32\wucltux.dll 2013-06-15 09:54:48 99840 —-a-w- C:\Windows\System32\wudriver.dll 2013-06-15 09:54:28 36864 —-a-w- C:\Windows\System32\wuapp.exe 2013-06-15 09:54:28 186752 —-a-w- C:\Windows\System32\wuwebv.dll 2013-06-15 07:29:51 ——– d—–w- C:\Windows\Panther . ==================== Find3M ==================== . 2013-06-15 10:35:11 9728 —ha-w- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-06-11 23:43:37 1767936 —-a-w- C:\Windows\SysWow64\wininet.dll 2013-06-11 23:43:00 2877440 —-a-w- C:\Windows\SysWow64\jscript9.dll 2013-06-11 23:42:58 61440 —-a-w- C:\Windows\SysWow64\iesetup.dll 2013-06-11 23:42:58 109056 —-a-w- C:\Windows\SysWow64\iesysprep.dll 2013-06-11 23:26:20 2241024 —-a-w- C:\Windows\System32\wininet.dll 2013-06-11 23:25:16 3958784 —-a-w- C:\Windows\System32\jscript9.dll 2013-06-11 23:25:13 67072 —-a-w- C:\Windows\System32\iesetup.dll 2013-06-11 23:25:13 136704 —-a-w- C:\Windows\System32\iesysprep.dll 2013-06-11 22:51:45 71680 —-a-w- C:\Windows\SysWow64\RegisterIEPKEYs.exe 2013-06-11 22:50:58 89600 —-a-w- C:\Windows\System32\RegisterIEPKEYs.exe 2013-06-07 03:22:18 2706432 —-a-w- C:\Windows\System32\mshtml.tlb 2013-06-07 02:37:52 2706432 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2013-05-13 05:51:01 184320 —-a-w- C:\Windows\System32\cryptsvc.dll 2013-05-13 05:51:00 1464320 —-a-w- C:\Windows\System32\crypt32.dll 2013-05-13 05:51:00 139776 —-a-w- C:\Windows\System32\cryptnet.dll 2013-05-13 05:50:40 52224 —-a-w- C:\Windows\System32\certenc.dll 2013-05-13 04:45:55 140288 —-a-w- C:\Windows\SysWow64\cryptsvc.dll 2013-05-13 04:45:55 1160192 —-a-w- C:\Windows\SysWow64\crypt32.dll 2013-05-13 04:45:55 103936 —-a-w- C:\Windows\SysWow64\cryptnet.dll 2013-05-13 03:43:55 1192448 —-a-w- C:\Windows\System32\certutil.exe 2013-05-13 03:08:10 903168 —-a-w- C:\Windows\SysWow64\certutil.exe 2013-05-13 03:08:06 43008 —-a-w- C:\Windows\SysWow64\certenc.dll 2013-05-10 05:49:27 30720 —-a-w- C:\Windows\System32\cryptdlg.dll 2013-05-10 03:20:54 24576 —-a-w- C:\Windows\SysWow64\cryptdlg.dll 2013-05-08 06:39:01 1910632 —-a-w- C:\Windows\System32\drivers\tcpip.sys 2013-05-02 15:29:56 278800 —-a-w- C:\Windows\System32\MpSigStub.exe 2013-04-26 05:51:36 751104 —-a-w- C:\Windows\System32\win32spl.dll 2013-04-26 04:55:21 492544 —-a-w- C:\Windows\SysWow64\win32spl.dll 2013-04-25 23:30:32 1505280 —-a-w- C:\Windows\SysWow64\d3d11.dll 2013-04-17 07:02:06 1230336 —-a-w- C:\Windows\SysWow64\WindowsCodecs.dll 2013-04-17 06:24:46 1424384 —-a-w- C:\Windows\System32\WindowsCodecs.dll . ============= FINISH: 20:07:22.37 ===============
Hi there,
my name is Marius and I will be assisting you with your Malware related problems.

Before we move on, please read the following points carefully.
  • First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while you are follow my instructions, Stop there and tell me the exact nature of your problem.
  • Do not run any other scans without instruction or Add/ Remove Software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
  • Post all Logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.



Scan with adwCleaner


Please download AdwCleaner to your desktop.


  • Run adwcleaner.exe.
  • Hit delete.
  • When the run is finished, it will open up a text file.
  • Please post its contents within your next reply.
  • You´ll find the log file at C:\AdwCleaner[S1].txt also.
Hi, thank you for the help. After the scan finished, and the computer restarted, I was unable to connect to the internet through my ethernet connection, but I was able to connect via Wi-Fi. # AdwCleaner v2.305 - Logfile created 07/15/2013 at 09:06:17 # Updated 11/07/2013 by Xplode # Operating system : Windows 7 Ultimate Service Pack 1 (64 bits) # User : AthlonX4 - ATHLONX4-PC # Boot Mode : Normal # Running from : C:\Users\AthlonX4\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** File Deleted : C:\Users\AthlonX4\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data File Deleted : C:\Users\AthlonX4\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences File Deleted : C:\Users\AthlonX4\AppData\Roaming\Mozilla\Firefox\Profiles\9njvwb2g.default\bprotector_extensions.sqlite File Deleted : C:\Users\AthlonX4\AppData\Roaming\Mozilla\Firefox\Profiles\9njvwb2g.default\searchplugins\Babylon.xml File Deleted : C:\Users\AthlonX4\AppData\Roaming\Mozilla\Firefox\Profiles\9njvwb2g.default\searchplugins\delta.xml Folder Deleted : C:\Program Files (x86)\DealPly Folder Deleted : C:\Program Files (x86)\DealPlyLive Folder Deleted : C:\ProgramData\Babylon Folder Deleted : C:\ProgramData\BrowserDefender Folder Deleted : C:\ProgramData\DealPlyLive Folder Deleted : C:\Users\AthlonX4\AppData\Local\DealPlyLive Folder Deleted : C:\Users\AthlonX4\AppData\Local\Google\Chrome\User Data\Default\Extensions\mphpbdjcljebbcnfopfngmfdackbbdgf Folder Deleted : C:\Users\AthlonX4\AppData\LocalLow\delta Folder Deleted : C:\Users\AthlonX4\AppData\Roaming\BabSolution Folder Deleted : C:\Users\AthlonX4\AppData\Roaming\Babylon Folder Deleted : C:\Users\AthlonX4\AppData\Roaming\DealPly Folder Deleted : C:\Users\AthlonX4\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly Folder Deleted : C:\Users\AthlonX4\AppData\Roaming\Mozilla\Firefox\Profiles\9njvwb2g.default\extensions\{906000a4-88d9-4d52-b209-7a772970d91f} Folder Deleted : C:\Users\AthlonX4\AppData\Roaming\Mozilla\Firefox\Profiles\9njvwb2g.default\extensions\[removed] ***** [Registry] ***** Key Deleted : HKCU\Software\APN PIP Key Deleted : HKLM\Software\PIP ***** [Internet Browsers] ***** -\\ Internet Explorer v10.0.9200.16635 [OK] Registry is clean. -\\ Mozilla Firefox v22.0 (en-US) File : C:\Users\AthlonX4\AppData\Roaming\Mozilla\Firefox\Profiles\9njvwb2g.default\prefs.js [OK] File is clean. -\\ Google Chrome v28.0.1500.72 File : C:\Users\AthlonX4\AppData\Local\Google\Chrome\User Data\Default\Preferences Deleted [l.40] : icon_url = "hxxp://www.delta-search.com/favicon.ico", Deleted [l.43] : keyword = "delta-search.com", Deleted [l.47] : search_url = "hxxp://www1.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=A61B0016441A3[…] Deleted [l.2369] : homepage = "hxxp://www1.delta-search.com/?babsrc=HP_ss&mntrId=A61B0016441A3C99&affID=119820&tt=1[…] Deleted [l.3278] : urls_to_restore_on_startup = [ "hxxp://www1.delta-search.com/?babsrc=HP_ss&mntrId=A61B0016441[…] ************************* AdwCleaner[S1].txt - [2937 octets] - [15/07/2013 09:06:17] ########## EOF - C:\AdwCleaner[S1].txt - [2997 octets] ##########
Scan with OTL

  • Download OTL by OldTimer and save it to your desktop.
  • Double click on the OTL.exe icon on your desktop. If you are using Vista, please right-click and select run as administrator
  • Click the "Scan All Users" checkbox.


    Note: If you are using a Windows 64bit machine, please make sure the checkbox next to Include 64Bit Scans is checked. It will be checked by default.

  • Push the [external image: Posted Image] button.
  • It will now begin to scan, please be paitent while it scans.
  • Two reports will open once it's done.
  • Please copy and paste them in your next reply:
  • OTL.txt <– Will be opened
  • Extras.txt <– Will be minimized

OTL logfile created on: 7/16/2013 1:43:32 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\AthlonX4\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.82 Gb Available Physical Memory | 70.47% Memory free
7.99 Gb Paging File | 6.55 Gb Available in Paging File | 81.96% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 362.68 Gb Total Space | 292.05 Gb Free Space | 80.53% Space Free | Partition Type: NTFS
Drive X: | 335.85 Gb Total Space | 300.66 Gb Free Space | 89.52% Space Free | Partition Type: NTFS

Computer Name: ATHLONX4-PC | User Name: AthlonX4 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/07/16 01:42:35 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\AthlonX4\Desktop\OTL.exe
PRC - [2013/06/24 17:14:34 | 000,107,832 | —- | M] () – C:\Windows\SysWOW64\PnkBstrB.exe
PRC - [2013/06/24 17:14:25 | 000,066,872 | —- | M] () – C:\Windows\SysWOW64\PnkBstrA.exe


========== Modules (No Company Name) ==========


========== Services (SafeList) ==========

SRV:64bit: - [2013/05/27 01:50:47 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2013/01/27 11:34:32 | 000,379,360 | —- | M] (Microsoft Corporation) [On_Demand | Running] – c:\Program Files\Microsoft Security Client\NisSrv.exe – (NisSrv)
SRV:64bit: - [2013/01/27 11:34:32 | 000,022,056 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\MsMpEng.exe – (MsMpSvc)
SRV:64bit: - [2012/11/16 16:44:58 | 000,238,080 | —- | M] (AMD) [Auto | Running] – C:\Windows\SysNative\atiesrxx.exe – (AMD External Events Utility)
SRV:64bit: - [2012/11/16 15:27:28 | 000,361,984 | —- | M] (Advanced Micro Devices, Inc.) [Auto | Running] – C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe – (AMD FUEL Service)
SRV:64bit: - [2009/07/13 21:40:01 | 000,193,536 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\appmgmts.dll – (AppMgmt)
SRV - [2013/07/15 18:32:38 | 000,563,112 | —- | M] (Valve Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Steam\SteamService.exe – (Steam Client Service)
SRV - [2013/06/25 19:59:03 | 000,256,904 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2013/06/24 17:14:34 | 000,107,832 | —- | M] () [Auto | Running] – C:\Windows\SysWOW64\PnkBstrB.exe – (PnkBstrB)
SRV - [2013/06/24 17:14:25 | 000,066,872 | —- | M] () [Auto | Running] – C:\Windows\SysWOW64\PnkBstrA.exe – (PnkBstrA)
SRV - [2013/06/18 10:42:28 | 000,009,216 | —- | M] (Hi-Rez Studios) [Auto | Running] – C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe – (HiPatchService)
SRV - [2013/06/18 10:21:21 | 000,117,144 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2010/11/20 23:24:51 | 000,397,824 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysWOW64\inetsrv\iisw3adm.dll – (WAS)
SRV - [2010/11/20 23:24:51 | 000,397,824 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysWOW64\inetsrv\iisw3adm.dll – (W3SVC)
SRV - [2010/11/20 23:24:51 | 000,061,440 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysWOW64\inetsrv\apphostsvc.dll – (AppHostSvc)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 17:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2013/06/18 22:34:10 | 000,283,200 | —- | M] (DT Soft Ltd) [Kernel | System | Running] – C:\Windows\SysNative\drivers\dtsoftbus01.sys – (dtsoftbus01)
DRV:64bit: - [2013/03/31 18:32:04 | 000,082,600 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amd_sata.sys – (amd_sata)
DRV:64bit: - [2013/03/31 18:32:04 | 000,042,664 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amd_xata.sys – (amd_xata)
DRV:64bit: - [2013/01/20 15:59:04 | 000,130,008 | —- | M] (Microsoft Corporation) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\NisDrvWFP.sys – (NisDrv)
DRV:64bit: - [2012/11/16 17:08:32 | 011,922,944 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\atikmdag.sys – (atikmdag)
DRV:64bit: - [2012/11/16 17:08:32 | 011,922,944 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\atikmdag.sys – (amdkmdag)
DRV:64bit: - [2012/11/16 15:39:12 | 000,359,936 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\atikmpag.sys – (amdkmdap)
DRV:64bit: - [2012/08/23 10:12:16 | 000,029,696 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\terminpt.sys – (terminpt)
DRV:64bit: - [2012/08/23 10:10:20 | 000,019,456 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\rdpvideominiport.sys – (RdpVideoMiniport)
DRV:64bit: - [2012/08/23 10:08:26 | 000,030,208 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbGD.sys – (TsUsbGD)
DRV:64bit: - [2012/08/23 10:07:35 | 000,057,856 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2012/03/05 15:04:30 | 000,053,888 | —- | M] (Advanced Micro Devices) [Kernel | Auto | Running] – C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys – (AODDriver4.1)
DRV:64bit: - [2012/03/01 02:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2012/02/23 08:32:04 | 000,095,760 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\AtihdW76.sys – (AtiHDAudioService)
DRV:64bit: - [2011/10/05 09:55:02 | 000,729,152 | —- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\netr7364.sys – (netr7364)
DRV:64bit: - [2011/03/11 02:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/11 02:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2010/11/20 23:23:48 | 000,117,248 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\tsusbhub.sys – (tsusbhub)
DRV:64bit: - [2010/11/20 23:23:48 | 000,088,960 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\Synth3dVsc.sys – (Synth3dVsc)
DRV:64bit: - [2010/11/20 23:23:48 | 000,071,168 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\dmvsc.sys – (dmvsc)
DRV:64bit: - [2010/11/20 23:23:47 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/02/18 09:18:24 | 000,046,136 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\amdiox64.sys – (amdiox64)
DRV:64bit: - [2009/09/28 09:22:00 | 000,395,264 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\yk62x64.sys – (yukonw7)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/04/08 14:28:46 | 000,068,992 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\xusb21.sys – (xusb21)
DRV:64bit: - [2008/05/06 16:06:00 | 000,014,464 | —- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\wdcsam64.sys – (WDC_SAM)
DRV - [2009/07/13 21:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-21-3478498415-794229227-1261764834-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKU\S-1-5-21-3478498415-794229227-1261764834-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-3478498415-794229227-1261764834-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKU\S-1-5-21-3478498415-794229227-1261764834-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:22.0
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.7: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2013/06/29 19:34:07 | 000,000,000 | —D | M] (No name found) – C:\Users\AthlonX4\AppData\Roaming\Mozilla\Extensions
[2013/07/15 09:06:24 | 000,000,000 | —D | M] (No name found) – C:\Users\AthlonX4\AppData\Roaming\Mozilla\Firefox\Profiles\9njvwb2g.default\extensions
[2013/07/14 18:39:24 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\Extensions
[2013/06/25 16:22:46 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2013/06/25 16:22:46 | 000,000,000 | —D | M] (Default) – C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyPar
ameter}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.72\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.72\pdf.dll
CHR - plugin: Foxit Reader Plugin for Mozilla (Enabled) = C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [AMD AVT] C:\Windows\SysWow64\cmd.exe (Microsoft Corporation)
O4 - HKLM..\Run: [KeePass 2 PreLoad] C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe (Dominik Reichl)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{06F2236A-F09A-4D63-8F85-BD2C0BDD72CA}: DhcpNameServer = 10.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A7F6ED93-D986-455F-B900-6159C88CCC8D}: DhcpNameServer = 10.0.0.1
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{5358d9e2-d87c-11e2-af39-90fba64bf37d}\Shell - "" = AutoRun
O33 - MountPoints2\{5358d9e2-d87c-11e2-af39-90fba64bf37d}\Shell\AutoRun\command - "" = J:\INSTALL.EXE
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/07/16 01:42:31 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\AthlonX4\Desktop\OTL.exe
[2013/07/15 23:28:50 | 000,466,456 | —- | C] (Creative Labs) – C:\Windows\SysNative\wrap_oal.dll
[2013/07/15 23:28:50 | 000,444,952 | —- | C] (Creative Labs) – C:\Windows\SysWow64\wrap_oal.dll
[2013/07/15 23:28:50 | 000,122,904 | —- | C] (Portions © Creative Labs Inc. and NVIDIA Corp.) – C:\Windows\SysNative\OpenAL32.dll
[2013/07/15 23:28:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\OpenAL
[2013/07/15 23:28:49 | 000,109,080 | —- | C] (Portions © Creative Labs Inc. and NVIDIA Corp.) – C:\Windows\SysWow64\OpenAL32.dll
[2013/07/14 20:05:15 | 000,688,992 | R— | C] (Swearware) – C:\Users\AthlonX4\Desktop\dds.scr
[2013/07/14 19:57:13 | 000,000,000 | —D | C] – C:\Windows\SysWow64\searchplugins
[2013/07/14 19:57:13 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Extensions
[2013/07/14 19:46:41 | 000,000,000 | —D | C] – C:\Users\AthlonX4\AppData\Roaming\Malwarebytes
[2013/07/14 19:46:31 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/07/14 19:46:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/07/14 18:41:25 | 000,000,000 | —D | C] – C:\ProgramData\TEMP
[2013/07/11 20:44:09 | 000,192,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iisRtl.dll
[2013/07/11 20:44:09 | 000,154,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iisRtl.dll
[2013/07/11 20:44:09 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\admwprox.dll
[2013/07/11 20:44:08 | 000,060,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ahadmin.dll
[2013/07/11 20:44:08 | 000,050,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\admwprox.dll
[2013/07/11 20:44:08 | 000,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iisreset.exe
[2013/07/11 20:44:08 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iisreset.exe
[2013/07/11 20:44:08 | 000,014,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wamregps.dll
[2013/07/11 20:44:07 | 000,026,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ahadmin.dll
[2013/07/11 20:44:07 | 000,011,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iisrstap.dll
[2013/07/11 20:44:07 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wamregps.dll
[2013/07/11 20:44:07 | 000,008,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iisrstap.dll
[2013/07/11 18:33:24 | 000,000,000 | —D | C] – C:\Users\AthlonX4\AppData\Roaming\PeaZip
[2013/07/11 17:49:03 | 000,000,000 | R–D | C] – C:\Users\AthlonX4\Wii U
[2013/07/11 17:46:38 | 000,000,000 | —D | C] – C:\Windows\SysWow64\BestPractices
[2013/07/11 17:46:37 | 000,000,000 | —D | C] – C:\inetpub
[2013/07/11 17:46:37 | 000,000,000 | —D | C] – C:\Windows\SysNative\BestPractices
[2013/07/11 03:04:37 | 000,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/07/11 03:04:37 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/07/11 03:04:36 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/07/11 03:04:36 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/07/11 03:04:36 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/07/11 03:04:35 | 000,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/07/11 03:04:35 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/07/11 03:04:35 | 000,089,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/07/11 03:04:35 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/07/11 03:04:35 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/07/11 03:04:35 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/07/11 03:04:34 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/07/11 03:04:33 | 003,958,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/07/11 03:04:33 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/07/11 03:04:33 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/07/10 22:06:02 | 000,624,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qedit.dll
[2013/07/10 22:06:01 | 001,887,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMVDECOD.DLL
[2013/07/10 22:06:01 | 001,620,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMVDECOD.DLL
[2013/07/10 22:06:01 | 000,509,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qedit.dll
[2013/07/10 22:05:31 | 001,643,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2013/07/10 14:12:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Hewlett-Packard
[2013/07/10 14:12:12 | 000,145,408 | —- | C] (Hewlett-Packard Company) – C:\Windows\SysNative\hpfll70v.dll
[2013/07/10 14:12:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\HP
[2013/07/10 14:12:04 | 000,000,000 | -H-D | C] – C:\Config.Msi
[2013/07/10 14:11:10 | 000,000,000 | —D | C] – C:\ProgramData\HP
[2013/07/10 14:10:58 | 000,642,360 | —- | C] (Hewlett-Packard) – C:\Windows\SysNative\hpzids40.dll
[2013/07/10 14:10:58 | 000,551,424 | —- | C] (Hewlett-Packard) – C:\Windows\SysNative\hppldcoi.dll
[2013/07/07 12:34:22 | 000,000,000 | —D | C] – C:\Users\AthlonX4\AppData\Local\Focus Home Interactive
[2013/07/07 12:33:10 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cities XL Platinum
[2013/07/05 23:09:14 | 000,000,000 | —D | C] – C:\Windows\SysWow64\directx
[2013/07/05 23:08:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft XNA
[2013/07/05 23:05:09 | 000,000,000 | —D | C] – C:\Windows\SysNative\appmgmt
[2013/06/29 20:36:41 | 000,000,000 | —D | C] – C:\Users\AthlonX4\AppData\Roaming\vlc
[2013/06/28 19:59:29 | 000,000,000 | —D | C] – C:\Users\AthlonX4\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
[2013/06/26 21:29:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hi-Rez Studios
[2013/06/26 21:29:28 | 000,000,000 | —D | C] – C:\ProgramData\Hi-Rez Studios
[2013/06/26 21:29:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\Hi-Rez Studios
[2013/06/26 13:23:55 | 000,000,000 | —D | C] – C:\Users\AthlonX4\AppData\Roaming\Skype
[2013/06/26 11:06:44 | 000,000,000 | —D | C] – C:\Users\AthlonX4\AppData\Roaming\KeePass
[2013/06/26 11:00:56 | 000,000,000 | —D | C] – C:\Users\AthlonX4\AppData\Roaming\foobar2000
[2013/06/26 10:58:59 | 000,000,000 | —D | C] – C:\Program Files\GIMP 2
[2013/06/26 10:57:12 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader
[2013/06/26 10:57:02 | 000,000,000 | —D | C] – C:\Users\AthlonX4\AppData\Roaming\Foxit Software
[2013/06/26 10:57:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Foxit Software
[2013/06/26 10:55:45 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2013/06/26 10:55:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Skype
[2013/06/26 10:55:43 | 000,000,000 | R–D | C] – C:\Program Files (x86)\Skype
[2013/06/26 10:55:41 | 000,000,000 | —D | C] – C:\ProgramData\Skype
[2013/06/26 10:55:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2013/06/26 10:55:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\VideoLAN
[2013/06/26 10:54:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PeaZip
[2013/06/26 10:54:22 | 000,000,000 | —D | C] – C:\Program Files\PeaZip
[2013/06/26 10:54:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\foobar2000
[2013/06/26 10:54:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\KeePass Password Safe 2
[2013/06/26 10:53:40 | 000,000,000 | —D | C] – C:\Users\AthlonX4\AppData\Roaming\uTorrent
[2013/06/26 10:04:11 | 000,000,000 | —D | C] – C:\Users\AthlonX4\AppData\Roaming\OpenOffice.org
[2013/06/26 10:03:29 | 000,000,000 | –SD | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice.org 3.4.1
[2013/06/26 10:02:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\OpenOffice.org 3
[2013/06/26 10:01:47 | 000,000,000 | —D | C] – C:\Users\AthlonX4\Documents\OpenOffice.org 3.4.1 (en-US) Installation Files
[2013/06/26 09:27:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FTL Faster Than Light
[2013/06/26 09:27:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\FTL
[2013/06/26 09:13:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Steam
[2013/06/26 09:13:03 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
[2013/06/26 09:13:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Steam
[2013/06/25 20:14:43 | 000,000,000 | —D | C] – C:\Users\AthlonX4\AppData\Local\Macromedia
[2013/06/25 19:59:11 | 000,000,000 | —D | C] – C:\ProgramData\McAfee
[2013/06/25 17:36:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Security Client
[2013/06/25 17:36:19 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2013/06/25 17:35:54 | 000,000,000 | –SD | C] – C:\Windows\SysWow64\Microsoft
[2013/06/25 16:29:27 | 000,000,000 | -HSD | C] – C:\Windows\SysWow64\AI_RecycleBin
[2013/06/25 16:29:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Scrolls
[2013/06/25 16:29:27 | 000,000,000 | —D | C] – C:\Users\AthlonX4\AppData\Local\Mojang
[2013/06/25 16:22:54 | 000,000,000 | —D | C] – C:\Users\AthlonX4\AppData\Roaming\Mozilla
[2013/06/25 16:22:54 | 000,000,000 | —D | C] – C:\Users\AthlonX4\AppData\Local\Mozilla
[2013/06/25 16:22:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Maintenance Service
[2013/06/25 16:22:47 | 000,000,000 | —D | C] – C:\ProgramData\Mozilla
[2013/06/25 16:22:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2013/06/24 19:20:24 | 000,000,000 | —D | C] – C:\Users\AthlonX4\AppData\Local\Skyrim
[2013/06/24 19:18:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razor 1911
[2013/06/24 17:29:38 | 000,000,000 | —D | C] – C:\ProgramData\Package Cache
[2013/06/24 17:25:40 | 000,000,000 | —D | C] – C:\Users\AthlonX4\AppData\Local\FLT
[2013/06/24 17:22:32 | 000,000,000 | —D | C] – C:\Users\AthlonX4\AppData\Local\Programs
[2013/06/24 17:16:57 | 000,178,800 | —- | C] (Sony DADC Austria AG.) – C:\Windows\SysWow64\CmdLineExt_x64.dll
[2013/06/24 17:12:05 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\InstallShield Installation Information
[2013/06/24 17:10:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Strange Loop Games
[2013/06/24 16:38:34 | 000,000,000 | —D | C] – C:\Users\AthlonX4\Games
[2013/06/19 01:00:17 | 000,000,000 | —D | C] – C:\ProgramData\ATI
[2013/06/19 01:00:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\AMD AVT
[2013/06/19 01:00:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\AMD APP
[2013/06/19 01:00:08 | 000,000,000 | —D | C] – C:\Program Files\Common Files\ATI Technologies
[2013/06/19 01:00:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\ATI Technologies
[2013/06/19 01:00:00 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD VISION Engine Control Center
[2013/06/19 00:58:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\ATI Technologies
[2013/06/19 00:58:13 | 000,000,000 | —D | C] – C:\Program Files\ATI Technologies
[2013/06/19 00:58:11 | 000,000,000 | —D | C] – C:\Program Files\ATI
[2013/06/18 23:11:23 | 006,583,664 | —- | C] (AVAST Software) – C:\Program Files\AVAST Sof
[2013/06/18 22:55:52 | 000,000,000 | —D | C] – C:\Users\AthlonX4\AppData\Local\SKIDROW
[2013/06/18 22:55:52 | 000,000,000 | —D | C] – C:\Users\AthlonX4\Documents\My Games
[2013/06/18 22:54:20 | 000,527,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_7.dll
[2013/06/18 22:54:20 | 000,518,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_7.dll
[2013/06/18 22:54:20 | 000,239,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_7.dll
[2013/06/18 22:54:20 | 000,176,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_7.dll
[2013/06/18 22:54:20 | 000,077,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_5.dll
[2013/06/18 22:54:20 | 000,074,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_5.dll
[2013/06/18 22:54:19 | 002,526,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_43.dll
[2013/06/18 22:54:19 | 002,106,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_43.dll
[2013/06/18 22:54:18 | 001,907,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dcsx_43.dll
[2013/06/18 22:54:18 | 001,868,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dcsx_43.dll
[2013/06/18 22:54:18 | 000,511,328 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_43.dll
[2013/06/18 22:54:18 | 000,470,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_43.dll
[2013/06/18 22:54:18 | 000,276,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx11_43.dll
[2013/06/18 22:54:18 | 000,248,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx11_43.dll
[2013/06/18 22:54:17 | 002,401,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_43.dll
[2013/06/18 22:54:17 | 001,998,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_43.dll
[2013/06/18 22:54:17 | 000,530,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_6.dll
[2013/06/18 22:54:17 | 000,528,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_6.dll
[2013/06/18 22:54:17 | 000,238,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_6.dll
[2013/06/18 22:54:17 | 000,176,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_6.dll
[2013/06/18 22:54:17 | 000,078,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_4.dll
[2013/06/18 22:54:17 | 000,074,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_4.dll
[2013/06/18 22:54:16 | 000,517,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_5.dll
[2013/06/18 22:54:16 | 000,515,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_5.dll
[2013/06/18 22:54:16 | 000,024,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_7.dll
[2013/06/18 22:54:16 | 000,022,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_7.dll
[2013/06/18 22:54:15 | 002,582,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_42.dll
[2013/06/18 22:54:15 | 001,974,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_42.dll
[2013/06/18 22:54:15 | 000,238,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_5.dll
[2013/06/18 22:54:15 | 000,176,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_5.dll
[2013/06/18 22:54:14 | 005,554,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dcsx_42.dll
[2013/06/18 22:54:14 | 005,501,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dcsx_42.dll
[2013/06/18 22:54:14 | 000,285,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx11_42.dll
[2013/06/18 22:54:14 | 000,235,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx11_42.dll
[2013/06/18 22:54:13 | 000,523,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_42.dll
[2013/06/18 22:54:13 | 000,453,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_42.dll
[2013/06/18 22:54:12 | 002,475,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_42.dll
[2013/06/18 22:54:12 | 002,430,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_41.dll
[2013/06/18 22:54:12 | 001,892,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_42.dll
[2013/06/18 22:54:12 | 001,846,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_41.dll
[2013/06/18 22:54:12 | 000,520,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_41.dll
[2013/06/18 22:54:12 | 000,453,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_41.dll
[2013/06/18 22:54:11 | 005,425,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_41.dll
[2013/06/18 22:54:11 | 004,178,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_41.dll
[2013/06/18 22:54:10 | 000,521,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_4.dll
[2013/06/18 22:54:10 | 000,517,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_4.dll
[2013/06/18 22:54:10 | 000,235,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_4.dll
[2013/06/18 22:54:10 | 000,174,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_4.dll
[2013/06/18 22:54:10 | 000,073,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_3.dll
[2013/06/18 22:54:10 | 000,069,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_3.dll
[2013/06/18 22:54:09 | 002,605,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_40.dll
[2013/06/18 22:54:09 | 002,036,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_40.dll
[2013/06/18 22:54:09 | 000,519,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_40.dll
[2013/06/18 22:54:09 | 000,452,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_40.dll
[2013/06/18 22:54:09 | 000,024,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_6.dll
[2013/06/18 22:54:09 | 000,022,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_6.dll
[2013/06/18 22:54:08 | 005,631,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_40.dll
[2013/06/18 22:54:08 | 004,379,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_40.dll
[2013/06/18 22:54:07 | 000,518,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_3.dll
[2013/06/18 22:54:07 | 000,514,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_3.dll
[2013/06/18 22:54:07 | 000,074,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_2.dll
[2013/06/18 22:54:07 | 000,070,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_2.dll
[2013/06/18 22:54:06 | 000,513,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_2.dll
[2013/06/18 22:54:06 | 000,509,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_2.dll
[2013/06/18 22:54:06 | 000,235,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_3.dll
[2013/06/18 22:54:06 | 000,175,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_3.dll
[2013/06/18 22:54:06 | 000,072,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_1.dll
[2013/06/18 22:54:06 | 000,068,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_1.dll
[2013/06/18 22:54:06 | 000,025,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_5.dll
[2013/06/18 22:54:06 | 000,023,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_5.dll
[2013/06/18 22:54:05 | 001,942,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_39.dll
[2013/06/18 22:54:05 | 001,493,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_39.dll
[2013/06/18 22:54:05 | 000,540,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_39.dll
[2013/06/18 22:54:05 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_39.dll
[2013/06/18 22:54:05 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_2.dll
[2013/06/18 22:54:05 | 000,177,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_2.dll
[2013/06/18 22:54:04 | 004,992,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_39.dll
[2013/06/18 22:54:04 | 003,851,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_39.dll
[2013/06/18 22:54:04 | 000,511,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_1.dll
[2013/06/18 22:54:04 | 000,507,400 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_1.dll
[2013/06/18 22:54:04 | 000,068,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_0.dll
[2013/06/18 22:54:04 | 000,065,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_0.dll
[2013/06/18 22:54:03 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_1.dll
[2013/06/18 22:54:03 | 000,177,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_1.dll
[2013/06/18 22:54:03 | 000,028,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_4.dll
[2013/06/18 22:54:03 | 000,025,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_4.dll
[2013/06/18 22:54:02 | 004,991,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_38.dll
[2013/06/18 22:54:02 | 003,850,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_38.dll
[2013/06/18 22:54:02 | 001,941,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_38.dll
[2013/06/18 22:54:02 | 001,491,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_38.dll
[2013/06/18 22:54:02 | 000,540,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_38.dll
[2013/06/18 22:54:02 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_38.dll
[2013/06/18 22:54:01 | 000,489,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_0.dll
[2013/06/18 22:54:01 | 000,479,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_0.dll
[2013/06/18 22:54:00 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_0.dll
[2013/06/18 22:54:00 | 000,177,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_0.dll
[2013/06/18 22:54:00 | 000,028,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_3.dll
[2013/06/18 22:54:00 | 000,025,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_3.dll
[2013/06/18 22:53:59 | 001,860,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_37.dll
[2013/06/18 22:53:59 | 001,420,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_37.dll
[2013/06/18 22:53:59 | 000,529,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_37.dll
[2013/06/18 22:53:59 | 000,462,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_37.dll
[2013/06/18 22:53:58 | 004,910,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_37.dll
[2013/06/18 22:53:58 | 003,786,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_37.dll
[2013/06/18 22:53:58 | 000,411,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_10.dll
[2013/06/18 22:53:58 | 000,267,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_10.dll
[2013/06/18 22:53:57 | 002,006,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_36.dll
[2013/06/18 22:53:57 | 001,374,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_36.dll
[2013/06/18 22:53:57 | 000,508,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_36.dll
[2013/06/18 22:53:57 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_36.dll
[2013/06/18 22:53:56 | 005,081,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_36.dll
[2013/06/18 22:53:56 | 003,734,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_36.dll
[2013/06/18 22:53:55 | 000,411,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_9.dll
[2013/06/18 22:53:55 | 000,267,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_9.dll
[2013/06/18 22:53:54 | 001,985,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_35.dll
[2013/06/18 22:53:54 | 001,358,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_35.dll
[2013/06/18 22:53:54 | 000,508,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_35.dll
[2013/06/18 22:53:54 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_35.dll
[2013/06/18 22:53:53 | 005,073,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_35.dll
[2013/06/18 22:53:53 | 003,727,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_35.dll
[2013/06/18 22:53:52 | 000,506,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_34.dll
[2013/06/18 22:53:52 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_34.dll
[2013/06/18 22:53:52 | 000,409,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_8.dll
[2013/06/18 22:53:52 | 000,266,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_8.dll
[2013/06/18 22:53:52 | 000,021,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_2.dll
[2013/06/18 22:53:52 | 000,017,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_2.dll
[2013/06/18 22:53:51 | 001,401,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_34.dll
[2013/06/18 22:53:51 | 001,124,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_34.dll
[2013/06/18 22:53:50 | 004,496,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_34.dll
[2013/06/18 22:53:50 | 003,497,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_34.dll
[2013/06/18 22:53:50 | 000,403,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_7.dll
[2013/06/18 22:53:50 | 000,261,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_7.dll
[2013/06/18 22:53:50 | 000,107,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_3.dll
[2013/06/18 22:53:50 | 000,081,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_3.dll
[2013/06/18 22:53:49 | 001,400,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_33.dll
[2013/06/18 22:53:49 | 001,123,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_33.dll
[2013/06/18 22:53:49 | 000,506,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_33.dll
[2013/06/18 22:53:49 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_33.dll
[2013/06/18 22:53:48 | 004,494,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_33.dll
[2013/06/18 22:53:48 | 003,495,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_33.dll
[2013/06/18 22:53:48 | 000,393,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_6.dll
[2013/06/18 22:53:48 | 000,255,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_6.dll
[2013/06/18 22:53:47 | 000,469,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10.dll
[2013/06/18 22:53:47 | 000,440,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10.dll
[2013/06/18 22:53:47 | 000,390,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_5.dll
[2013/06/18 22:53:47 | 000,251,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_5.dll
[2013/06/18 22:53:46 | 004,398,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_32.dll
[2013/06/18 22:53:46 | 003,426,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_32.dll
[2013/06/18 22:53:46 | 000,364,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_4.dll
[2013/06/18 22:53:46 | 000,237,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_4.dll
[2013/06/18 22:53:46 | 000,017,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\x3daudio1_1.dll
[2013/06/18 22:53:46 | 000,015,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\x3daudio1_1.dll
[2013/06/18 22:53:45 | 003,977,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_31.dll
[2013/06/18 22:53:45 | 002,414,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_31.dll
[2013/06/18 22:53:43 | 000,363,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_3.dll
[2013/06/18 22:53:43 | 000,236,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_3.dll
[2013/06/18 22:53:42 | 000,083,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_2.dll
[2013/06/18 22:53:42 | 000,062,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_2.dll
[2013/06/18 22:53:41 | 000,354,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_2.dll
[2013/06/18 22:53:41 | 000,230,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_2.dll
[2013/06/18 22:53:40 | 000,083,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_1.dll
[2013/06/18 22:53:40 | 000,062,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_1.dll
[2013/06/18 22:53:38 | 000,352,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_1.dll
[2013/06/18 22:53:38 | 000,229,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_1.dll
[2013/06/18 22:53:30 | 003,927,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_30.dll
[2013/06/18 22:53:30 | 002,388,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_30.dll
[2013/06/18 22:53:28 | 000,355,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_0.dll
[2013/06/18 22:53:28 | 000,230,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_0.dll
[2013/06/18 22:53:28 | 000,016,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\x3daudio1_0.dll
[2013/06/18 22:53:28 | 000,014,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\x3daudio1_0.dll
[2013/06/18 22:53:27 | 003,830,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_29.dll
[2013/06/18 22:53:27 | 002,332,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_29.dll
[2013/06/18 22:53:26 | 003,815,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_28.dll
[2013/06/18 22:53:26 | 002,323,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_28.dll
[2013/06/18 22:53:25 | 003,807,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_27.dll
[2013/06/18 22:53:25 | 002,319,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_27.dll
[2013/06/18 22:53:23 | 003,767,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_26.dll
[2013/06/18 22:53:23 | 002,297,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_26.dll
[2013/06/18 22:53:22 | 003,823,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_25.dll
[2013/06/18 22:53:22 | 002,337,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_25.dll
[2013/06/18 22:53:21 | 003,544,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_24.dll
[2013/06/18 22:53:21 | 002,222,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_24.dll
[2013/06/18 22:48:08 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\2K Games
[2013/06/18 22:34:29 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
[2013/06/18 22:34:10 | 000,283,200 | —- | C] (DT Soft Ltd) – C:\Windows\SysNative\drivers\dtsoftbus01.sys
[2013/06/18 22:34:08 | 000,000,000 | —D | C] – C:\Users\AthlonX4\AppData\Roaming\DAEMON Tools Lite
[2013/06/18 22:34:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\DAEMON Tools Lite
[2013/06/18 22:33:42 | 000,000,000 | —D | C] – C:\ProgramData\DAEMON Tools Lite
[2013/06/18 21:19:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\AGEIA Technologies
[2013/06/18 21:15:05 | 000,000,000 | —D | C] – C:\NVIDIA
[2013/06/18 21:10:13 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/06/18 21:09:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\Google
[2013/06/18 21:09:28 | 000,000,000 | —D | C] – C:\Users\AthlonX4\AppData\Local\Google
[2013/06/18 21:09:15 | 000,000,000 | —D | C] – C:\Users\AthlonX4\AppData\Local\Deployment
[2013/06/18 21:09:15 | 000,000,000 | —D | C] – C:\Users\AthlonX4\AppData\Local\Apps
[2013/06/18 20:58:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\NVIDIA Corporation
[2013/06/18 20:57:48 | 000,000,000 | —D | C] – C:\Program Files\NVIDIA Corporation
[2013/06/16 05:55:37 | 000,000,000 | —D | C] – C:\Windows\SysNative\DRVSTORE
[2013/06/16 05:53:31 | 000,287,840 | —- | C] (AVAST Software) – C:\Windows\SysNative\aswBoot.exe
[2013/06/16 05:52:43 | 000,000,000 | —D | C] – C:\Program Files\AVAST Software
[2013/06/16 05:52:07 | 000,000,000 | —D | C] – C:\ProgramData\AVAST Software
[2013/06/16 05:50:27 | 000,000,000 | —D | C] – C:\Users\AthlonX4\AppData\Local\AMD
[2013/06/16 05:50:18 | 000,000,000 | —D | C] – C:\Users\AthlonX4\AppData\Roaming\ATI
[2013/06/16 05:50:18 | 000,000,000 | —D | C] – C:\Users\AthlonX4\AppData\Local\ATI
[2013/06/16 05:49:35 | 000,000,000 | —D | C] – C:\ProgramData\AMD
[2013/06/16 05:49:32 | 000,046,136 | —- | C] (Advanced Micro Devices) – C:\Windows\SysNative\drivers\amdiox64.sys
[2013/06/16 05:47:17 | 000,000,000 | —D | C] – C:\AMD
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/07/16 01:42:35 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\AthlonX4\Desktop\OTL.exe
[2013/07/16 01:25:00 | 000,000,902 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/07/16 01:24:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/07/15 23:28:50 | 000,466,456 | —- | M] (Creative Labs) – C:\Windows\SysNative\wrap_oal.dll
[2013/07/15 23:28:50 | 000,444,952 | —- | M] (Creative Labs) – C:\Windows\SysWow64\wrap_oal.dll
[2013/07/15 23:28:50 | 000,122,904 | —- | M] (Portions © Creative Labs Inc. and NVIDIA Corp.) – C:\Windows\SysNative\OpenAL32.dll
[2013/07/15 23:28:49 | 000,109,080 | —- | M] (Portions © Creative Labs Inc. and NVIDIA Corp.) – C:\Windows\SysWow64\OpenAL32.dll
[2013/07/15 21:25:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/07/15 21:07:07 | 000,026,576 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/07/15 21:07:07 | 000,026,576 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/07/15 21:05:48 | 000,815,466 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/07/15 21:05:48 | 000,688,384 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/07/15 21:05:48 | 000,128,616 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/07/15 20:59:43 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/07/15 20:59:37 | 3219,877,888 | -HS- | M] () – C:\hiberfil.sys
[2013/07/15 09:05:27 | 000,662,345 | —- | M] () – C:\Users\AthlonX4\Desktop\adwcleaner.exe
[2013/07/14 20:05:22 | 000,688,992 | R— | M] (Swearware) – C:\Users\AthlonX4\Desktop\dds.scr
[2013/07/13 23:37:18 | 000,006,750 | —- | M] () – C:\Users\AthlonX4\Documents\NewDatabase.kdbx
[2013/07/11 03:25:37 | 000,294,024 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/07/10 14:14:13 | 000,136,514 | —- | M] () – C:\Windows\hphins33.dat
[2013/06/26 10:57:13 | 000,002,074 | —- | M] () – C:\Users\AthlonX4\Application Data\Microsoft\Internet Explorer\Quick Launch\Foxit Reader.lnk
[2013/06/25 21:16:28 | 000,772,214 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2013/06/25 19:59:03 | 000,692,104 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/06/25 19:59:03 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/06/25 17:36:31 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif
[2013/06/24 17:16:57 | 000,178,800 | —- | M] (Sony DADC Austria AG.) – C:\Windows\SysWow64\CmdLineExt_x64.dll
[2013/06/24 17:14:34 | 000,107,832 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.exe
[2013/06/24 17:14:25 | 000,066,872 | —- | M] () – C:\Windows\SysWow64\PnkBstrA.exe
[2013/06/24 17:14:24 | 002,250,024 | —- | M] () – C:\Windows\SysWow64\pbsvc.exe
[2013/06/18 23:32:10 | 000,002,279 | —- | M] () – C:\Users\AthlonX4\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/06/18 23:18:29 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_Kernel_xusb21_01007.Wdf
[2013/06/18 22:34:10 | 000,283,200 | —- | M] (DT Soft Ltd) – C:\Windows\SysNative\drivers\dtsoftbus01.sys
[2013/06/16 05:53:32 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/07/15 09:05:15 | 000,662,345 | —- | C] () – C:\Users\AthlonX4\Desktop\adwcleaner.exe
[2013/07/13 23:37:18 | 000,006,750 | —- | C] () – C:\Users\AthlonX4\Documents\NewDatabase.kdbx
[2013/07/10 14:11:11 | 000,136,514 | —- | C] () – C:\Windows\hphins33.dat
[2013/07/10 14:11:11 | 000,000,512 | —- | C] () – C:\Windows\hphmdl33.dat
[2013/06/29 14:32:58 | 000,007,004 | —- | C] () – C:\Users\AthlonX4\Documents\Database.kdb
[2013/06/26 10:59:47 | 000,000,892 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
[2013/06/26 10:57:13 | 000,002,074 | —- | C] () – C:\Users\AthlonX4\Application Data\Microsoft\Internet Explorer\Quick Launch\Foxit Reader.lnk
[2013/06/26 10:54:19 | 000,001,113 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\foobar2000.lnk
[2013/06/26 10:54:05 | 000,001,117 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KeePass 2.lnk
[2013/06/25 19:59:03 | 000,000,830 | —- | C] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/06/25 17:36:30 | 000,001,945 | —- | C] () – C:\Windows\epplauncher.mif
[2013/06/25 17:36:23 | 000,002,117 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2013/06/25 16:22:49 | 000,001,159 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2013/06/24 17:14:27 | 000,107,832 | —- | C] () – C:\Windows\SysWow64\PnkBstrB.exe
[2013/06/24 17:14:24 | 002,250,024 | —- | C] () – C:\Windows\SysWow64\pbsvc.exe
[2013/06/24 17:14:24 | 000,066,872 | —- | C] () – C:\Windows\SysWow64\PnkBstrA.exe
[2013/06/18 23:18:29 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_Kernel_xusb21_01007.Wdf
[2013/06/18 21:17:49 | 000,772,214 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2013/06/18 21:10:13 | 000,002,279 | —- | C] () – C:\Users\AthlonX4\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/06/18 21:09:37 | 000,000,902 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/18 21:09:36 | 000,000,898 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/06/16 05:53:31 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\config.nt
[2013/06/15 08:45:58 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2012/11/16 16:01:08 | 000,204,952 | —- | C] () – C:\Windows\SysWow64\ativvsvl.dat
[2012/11/16 16:01:08 | 000,157,144 | —- | C] () – C:\Windows\SysWow64\ativvsva.dat
[2012/04/18 18:39:10 | 000,028,672 | —- | C] () – C:\Windows\SysWow64\kdbsdk32.dll
[2011/09/12 18:06:16 | 000,003,917 | —- | C] () – C:\Windows\SysWow64\atipblag.dat

========== ZeroAccess Check ==========

[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/02/27 01:52:56 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/27 00:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 21:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 23:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 21:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

< End of report >





OTL Extras logfile created on: 7/16/2013 1:43:32 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\AthlonX4\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.82 Gb Available Physical Memory | 70.47% Memory free
7.99 Gb Paging File | 6.55 Gb Available in Paging File | 81.96% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 362.68 Gb Total Space | 292.05 Gb Free Space | 80.53% Space Free | Partition Type: NTFS
Drive X: | 335.85 Gb Total Space | 300.66 Gb Free Space | 89.52% Space Free | Partition Type: NTFS

Computer Name: ATHLONX4-PC | User Name: AthlonX4 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-3478498415-794229227-1261764834-1000\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" (VideoLAN)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PeaZip] – Reg Error: Value error.
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" (VideoLAN)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" (VideoLAN)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PeaZip] – Reg Error: Value error.
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" (VideoLAN)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – Reg Error: Value error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04DC58A2-883F-460D-8D8D-D91D55C65153}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{130712A6-3928-4E58-B00A-2FA8E8F35556}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{2BAD1A30-1704-4CAB-BC78-0DD9707B8A7F}" = lport=137 | protocol=17 | dir=in | app=system |
"{2D6AA527-36C8-4BDC-866A-72EECD9AEFFB}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{2F1CEEA1-8A4F-4E56-9321-94A1C8A0437D}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{3B115226-6A97-4DDD-8614-3267C08679A4}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{442ABBD0-F2ED-4085-ADED-6E7C907DB42B}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{4B7FC6A5-C027-4AE2-A9B6-74B48CB2149E}" = rport=10243 | protocol=6 | dir=out | app=system |
"{6280E7B1-9547-44A4-AD55-AEDF50025122}" = lport=445 | protocol=6 | dir=in | app=system |
"{6EDC099C-CA48-4398-901E-D8CD0238BB94}" = lport=10243 | protocol=6 | dir=in | app=system |
"{719E9A51-658E-4370-89F3-6531E7E876C9}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{7BA8F363-3EAA-47ED-9A15-50458A49748C}" = rport=138 | protocol=17 | dir=out | app=system |
"{C158D042-F3EC-45BD-BF99-6174664A6A0B}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{C536A92D-24F8-4942-991F-C367D7CD4602}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{C60D0A6A-064E-443A-9F4A-F870044D9B47}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{CB4289D6-ADA6-4161-84AE-EDDF00A24188}" = rport=137 | protocol=17 | dir=out | app=system |
"{CCDF6C79-BBA0-465F-BD58-74F2BBD6C376}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{CDEB6E66-2D37-4CC0-8F10-86648AFDBD9F}" = rport=445 | protocol=6 | dir=out | app=system |
"{D9A16BE6-8548-4A26-98C0-388F21069FD1}" = lport=139 | protocol=6 | dir=in | app=system |
"{E0F99B54-E9FD-4846-AD56-C184C23F1886}" = rport=139 | protocol=6 | dir=out | app=system |
"{EA43FFC8-5096-4D76-AC70-E62F61F67A2B}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F34737DB-AC85-48C4-9C35-A9F7CC9FDC86}" = lport=2869 | protocol=6 | dir=in | app=system |
"{FE37703D-52B3-4E22-9FF2-390A22E0EE6C}" = lport=138 | protocol=17 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0A87B7DC-2D03-4366-BAAF-93E0FE74DA51}" = protocol=6 | dir=in | app=x:\games2\farcry2\far cry 2\bin\farcry2.exe |
"{152A697F-47B7-45F7-AFDC-11CEC34CEA65}" = protocol=6 | dir=in | app=c:\users\athlonx4\appdata\roaming\utorrent\utorrent.exe |
"{1B3E5180-66D2-4658-9442-81CE5DEEED8E}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{225CC847-8523-467E-B886-9C980EFA71DD}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{23F11BA7-D58D-4ED9-B544-0CEF3E04CA47}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\hotline_miami\hotlinemiami.exe |
"{29D53F99-4092-44EE-8339-9B3072D9FD92}" = protocol=6 | dir=in | app=x:\games2\farcry2\far cry 2\bin\fc2launcher.exe |
"{2C1F0D42-3F25-4E5B-9E81-3BE10B75F872}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bastion\bastion.exe |
"{312D5032-8684-4CA4-A3D0-71063319E3C2}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{3CCF05D1-E691-43FD-9CFA-DDCB1C897599}" = protocol=17 | dir=in | app=x:\games2\farcry2\far cry 2\bin\fc2editor.exe |
"{43155E08-E108-4B4A-A815-B14850433875}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{47542648-A3A7-4DE2-B599-451582BDD65E}" = protocol=17 | dir=in | app=c:\users\athlonx4\appdata\roaming\utorrent\utorrent.exe |
"{475C2488-BB82-44F7-B603-8F2B78BAAD9C}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{4FF2D89D-060A-4B6E-B594-B4BC0484D726}" = protocol=6 | dir=out | app=system |
"{5A3E45DC-B5E8-4FD1-91A5-E7D2B03C2FD3}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{5C020A89-162E-4856-8BC2-1BDB654C9C3F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\team fortress 2\hl2.exe |
"{622DEEE8-F5C6-4837-A9AF-C8014661D359}" = protocol=17 | dir=in | app=x:\games2\farcry2\far cry 2\bin\fc2launcher.exe |
"{66B5BA28-D9C2-4B78-A39C-6AB48B271483}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{6B678BBA-D20F-44E2-9A0C-02D6F583A688}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{70D3BF17-1D3D-42FF-BEBD-0A41D98EB1DA}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\hotline_miami\hotlinemiami.exe |
"{7C87709D-91B5-45AA-9F41-F50AAA89A16B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\team fortress 2\hl2.exe |
"{7E19D1C8-6EDF-4E69-8828-ACFEBAD3C3EE}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{7FEA28D6-4EBF-4270-99B9-C3B7A779304E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{8255444D-1262-4687-8732-47A5AF5E2CF7}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{91ED60F7-668E-4A10-8763-3612B32FC298}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9C85228D-3CA7-4F6A-BC54-03BA34BA0678}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{9F2AFC6F-1B14-4386-BAFA-BCBA665C0365}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{A354F344-722B-406A-A2F9-A1C1A74FEDF4}" = protocol=6 | dir=in | app=x:\games2\farcry2\far cry 2\bin\fc2editor.exe |
"{ABA51383-A025-4694-B138-4C65E703BC63}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{CA172DCE-7409-418E-8C93-19E3F752D6EA}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{CF49C5D2-5B4C-4F2A-AAB2-213424DFF3FD}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{D0D81C20-A724-4D1C-9CD6-C5B60751C549}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bastion\bastion.exe |
"{D5095250-692A-42C1-BAE4-E602AE8B8D11}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{D83C11D5-6D31-4161-BF1D-D7DCEEB4ABF1}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{D85290A5-B94B-4A9A-84AD-E7B478A633B0}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{E16ABFDE-ED9B-4AA2-BD19-20A60E1CA866}" = protocol=17 | dir=in | app=x:\games2\farcry2\far cry 2\bin\farcry2.exe |
"{E5B11321-7662-41CA-8CFC-AEFBE3F2D254}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{F06D5E88-F54E-4A68-85C2-5E2446F76EB9}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{F8755009-E521-47FD-B4C8-D683DA4C6E8F}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{FE703B22-EC5A-4199-ADE7-A643318548AE}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{FF87C623-853E-4BDD-8CC7-0B7CEABA4CF8}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"TCP Query User{450E75C6-3783-4DD8-A9BE-9362F8FADD93}C:\program files (x86)\hi-rez studios\hirezgames\tribes\binaries\win32\tribesascend.exe" = protocol=6 | dir=in | app=c:\program files (x86)\hi-rez studios\hirezgames\tribes\binaries\win32\tribesascend.exe |
"TCP Query User{88F53F0F-71DC-4BE2-BF8F-CB8DCC726E9E}X:\games\left4dead 2 (copy & paste)\left4dead2.exe" = protocol=6 | dir=in | app=x:\games\left4dead 2 (copy & paste)\left4dead2.exe |
"TCP Query User{8F5E3ED6-A236-45A0-8B34-A79502A4A887}C:\users\athlonx4\downloads\download_1.0_win\vidiiustreamer\dist\vidiiustreamer.exe" = protocol=6 | dir=in | app=c:\users\athlonx4\downloads\download_1.0_win\vidiiustreamer\dist\vidiiustreamer.exe |
"TCP Query User{AA3763C6-9F9A-4BDF-BC3C-4F42B63BBADE}X:\games\left4dead 2\left4dead2.exe" = protocol=6 | dir=in | app=x:\games\left4dead 2\left4dead2.exe |
"UDP Query User{18284C6D-34EA-4151-A4CA-7A68D27F8170}C:\program files (x86)\hi-rez studios\hirezgames\tribes\binaries\win32\tribesascend.exe" = protocol=17 | dir=in | app=c:\program files (x86)\hi-rez studios\hirezgames\tribes\binaries\win32\tribesascend.exe |
"UDP Query User{5AF747FA-82E2-4442-9342-F14FDEE5AC6C}C:\users\athlonx4\downloads\download_1.0_win\vidiiustreamer\dist\vidiiustreamer.exe" = protocol=17 | dir=in | app=c:\users\athlonx4\downloads\download_1.0_win\vidiiustreamer\dist\vidiiustreamer.exe |
"UDP Query User{65CD89A2-B36E-49A6-BBCF-F761A0C1EDB2}X:\games\left4dead 2 (copy & paste)\left4dead2.exe" = protocol=17 | dir=in | app=x:\games\left4dead 2 (copy & paste)\left4dead2.exe |
"UDP Query User{AA1C5969-0FC9-4800-AF21-46E8A561F256}X:\games\left4dead 2\left4dead2.exe" = protocol=17 | dir=in | app=x:\games\left4dead 2\left4dead2.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{1F6306D6-FB66-10D2-D474-5ADE4D57EE6B}" = AMD Fuel
"{1F85668C-CEB7-7A2E-356C-C42F950A982C}" = AMD Accelerated Video Transcoding
"{4161341F-AE84-E404-4291-4E0322CCE809}" = AMD Media Foundation Decoders
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{5A2BC38A-406C-4A5B-BF45-6991F9A05325}_is1" = PeaZip 5.0 (WIN64)
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{7FD0FD0D-AC40-A3BF-F2D4-54EFEDB0008F}" = AMD Drag and Drop Transcoding
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{96178C0A-BAF9-4E49-A2A5-CDE76722105B}" = HP Deskjet D1600 Printer Driver 14.0 Rel. 6
"{AB58402A-43DE-551C-2B40-DD1CF0E21240}" = ccc-utility64
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.12.1031
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{BE930E38-7BB3-45B6-85B2-5251F374F844}" = 64 Bit HP CIO Components Installer
"{D954C6C2-544B-4091-A47F-11E77162883E}" = Microsoft Security Client
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FAF03106-1653-15E1-3C0C-E7AE4FAE6EBF}" = AMD Catalyst Install Manager
"GIMP-2_is1" = GIMP 2.8.6
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Security Client" = Microsoft Security Essentials

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0B03071A-C96E-34CA-E5A3-4D8DA8ACCB3D}" = CCC Help Polish
"{1472627A-6E9F-DCB1-8894-E2BD249FD5E4}" = CCC Help Thai
"{1845470B-EB14-4ABC-835B-E36C693DC07D}" = Skype™ 6.5
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1A2C316B-F842-6FB3-3C87-6FE02861F396}" = AMD VISION Engine Control Center
"{20E23A40-38E5-4DD6-B738-BC8097AE66B6}_is1" = FTL version 1.03.3
"{218BE476-B206-2879-B912-971E6E89E44D}" = CCC Help Finnish
"{292F0F52-B62D-4E71-921B-89A682402201}" = Toolbox
"{2DFFE333-1B60-4CAA-F836-3CF0C99777CA}" = CCC Help Norwegian
"{2FFBF70A-9D40-4C3C-8F6C-6C3237B419BA}" = Scrolls
"{364374D2-FE10-2170-2397-5B01F9D00093}" = CCC Help Spanish
"{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF010}" = Tribes Ascend
"{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}" = Hi-Rez Studios Authenticate and Update Service
"{40786C7F-7078-5147-444E-D45DE808B684}" = CCC Help Portuguese
"{43D3EA3E-2B72-57F3-40E0-318A614D0FDD}" = CCC Help Czech
"{4F7823C4-BB28-A63E-CE08-1B463D4682DE}" = CCC Help Dutch
"{6C772996-BFF3-3C8C-860B-B3D48FF05D65}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106
"{6D7B8E2C-4356-619D-134F-FB36B0809958}" = CCC Help German
"{6F173E00-2766-E174-C2E0-AD88F24685BD}" = CCC Help Swedish
"{6FAEC41D-0654-12C1-0068-770D19FC2446}" = CCC Help Italian
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{73D239CC-D6B1-ADEC-A7BE-E100C7112004}" = CCC Help Korean
"{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}" = NVIDIA PhysX
"{8D3D92F0-852F-D832-FD8B-029C8C231C13}" = CCC Help Russian
"{8e70e4e1-06d7-470b-9f74-a51bef21088e}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106
"{963FFEAB-16E5-EB69-4E64-338B3D319FB4}" = CCC Help Chinese Standard
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F1F2AEA-C72A-4DD6-991E-C5506A5625E4}" = OpenOffice.org 3.4.1
"{9F7E9D7B-3291-96CE-A27F-DD4F6EB230EA}" = CCC Help Chinese Traditional
"{A11E24AD-A7EB-78C9-F792-AD9CDDB8B651}" = Catalyst Control Center InstallProxy
"{A6FDE264-C48D-36CE-CFA7-ABBEB861AC10}" = Catalyst Control Center Localization All
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{B31A9284-632D-683E-3BD0-F6926D445A7B}" = CCC Help Danish
"{B7A75523-3D7F-CF23-12F7-999EAF6C7167}" = CCC Help Japanese
"{C821D689-95BE-0D60-255E-D9B89CB3019F}" = Catalyst Control Center Graphics Previews Common
"{C9B2F671-870B-43A0-8B9D-7DB30CEBD87E}" = DJ_SF_06_D1600_SW_Min
"{CE1458AA-23A7-332D-68D9-86B799898DA6}" = CCC Help Greek
"{E0655E94-1D4D-8484-64C6-E6F847B7BE92}" = CCC Help Turkish
"{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}" = Catalyst Control Center - Branding
"{E555950B-1496-C37C-CA2C-2DF8745A5BE9}" = CCC Help English
"{E824E81C-80A4-3DFF-B5F9-4842A9FF5F7F}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106
"{EE229D0E-3D9E-636C-6E75-9436A87C7E49}" = CCC Help French
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F2835483-37F2-4123-B4FE-0E77D58447F2}" = Far Cry 2
"{F536CCF1-C4C1-5FB9-6B17-F883DFFAE569}" = CCC Help Hungarian
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Cities XL Platinum_is1" = Cities XL Platinum
"DAEMON Tools Lite" = DAEMON Tools Lite
"foobar2000" = foobar2000 v1.2.8
"Foxit Reader_is1" = Foxit Reader
"Google Chrome" = Google Chrome
"KeePassPasswordSafe2_is1" = KeePass Password Safe 2.22
"Mark of the Ninja_is1" = Mark of the Ninja
"Mozilla Firefox 22.0 (x86 en-US)" = Mozilla Firefox 22.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"OpenAL" = OpenAL
"PunkBusterSvc" = PunkBuster Services
"Scrolls 1.0.0" = Scrolls
"Spec Ops The Line_is1" = Spec Ops The Line
"Steam App 107100" = Bastion
"Steam App 219150" = Hotline Miami
"Steam App 440" = Team Fortress 2
"Vessel_is1" = Vessel
"VLC media player" = VLC media player 2.0.7

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-3478498415-794229227-1261764834-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent" = µTorrent

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 7/14/2013 6:39:54 PM | Computer Name = AthlonX4-PC | Source = MsiInstaller | ID = 11316
Description =

Error - 7/14/2013 7:54:17 PM | Computer Name = AthlonX4-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/14/2013 8:00:48 PM | Computer Name = AthlonX4-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/14/2013 11:35:58 PM | Computer Name = AthlonX4-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/15/2013 9:04:50 AM | Computer Name = AthlonX4-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/15/2013 9:09:39 AM | Computer Name = AthlonX4-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/15/2013 10:27:56 AM | Computer Name = AthlonX4-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/15/2013 5:44:37 PM | Computer Name = AthlonX4-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/15/2013 7:56:46 PM | Computer Name = AthlonX4-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/15/2013 9:01:29 PM | Computer Name = AthlonX4-PC | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 7/15/2013 9:20:56 PM | Computer Name = AthlonX4-PC | Source = BROWSER | ID = 8020
Description =

Error - 7/15/2013 9:26:06 PM | Computer Name = AthlonX4-PC | Source = NetBT | ID = 4321
Description = The name "WORKGROUP :1d" could not be registered on the interface
with IP address 10.0.0.6. The computer with the IP address 10.0.0.2 did not allow
the name to be claimed by this computer.

Error - 7/15/2013 9:31:16 PM | Computer Name = AthlonX4-PC | Source = NetBT | ID = 4321
Description = The name "WORKGROUP :1d" could not be registered on the interface
with IP address 10.0.0.6. The computer with the IP address 10.0.0.2 did not allow
the name to be claimed by this computer.

Error - 7/15/2013 9:36:26 PM | Computer Name = AthlonX4-PC | Source = NetBT | ID = 4321
Description = The name "WORKGROUP :1d" could not be registered on the interface
with IP address 10.0.0.6. The computer with the IP address 10.0.0.2 did not allow
the name to be claimed by this computer.

Error - 7/15/2013 9:41:37 PM | Computer Name = AthlonX4-PC | Source = NetBT | ID = 4321
Description = The name "WORKGROUP :1d" could not be registered on the interface
with IP address 10.0.0.6. The computer with the IP address 10.0.0.2 did not allow
the name to be claimed by this computer.

Error - 7/15/2013 9:46:48 PM | Computer Name = AthlonX4-PC | Source = NetBT | ID = 4321
Description = The name "WORKGROUP :1d" could not be registered on the interface
with IP address 10.0.0.6. The computer with the IP address 10.0.0.2 did not allow
the name to be claimed by this computer.

Error - 7/15/2013 9:52:03 PM | Computer Name = AthlonX4-PC | Source = NetBT | ID = 4321
Description = The name "WORKGROUP :1d" could not be registered on the interface
with IP address 10.0.0.6. The computer with the IP address 10.0.0.2 did not allow
the name to be claimed by this computer.

Error - 7/15/2013 10:36:24 PM | Computer Name = AthlonX4-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Steam
Client Service service to connect.

Error - 7/15/2013 10:36:24 PM | Computer Name = AthlonX4-PC | Source = Service Control Manager | ID = 7000
Description = The Steam Client Service service failed to start due to the following
error: %%1053

Error - 7/16/2013 1:41:28 AM | Computer Name = AthlonX4-PC | Source = NetBT | ID = 4321
Description = The name "WORKGROUP :1d" could not be registered on the interface
with IP address 10.0.0.6. The computer with the IP address 10.0.0.2 did not allow
the name to be claimed by this computer.


< End of report >
Scan with ESET Online Scan

Please go to here to run the online scannner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked
  • Click on Advanced Settings and ensure these options are ticked:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Click Scan
  • Wait for the scan to finish
  • If any threats were found, click the 'List of found threats' , then click Export to text file….
  • Save it to your desktop, then please copy and paste that log as a reply to this topic.
C:\Users\AthlonX4\Downloads\Setup.exe Win32/Adware.iBryte.G application C:\Windows\Temp\Optimizer_Pro.exe multiple threats
C:\Users\AthlonX4\Downloads\Setup.exe Win32/Adware.iBryte.G application
C:\Windows\Temp\Optimizer_Pro.exe multiple threats

Delete these files.



Then we can do the cleanup - if you are facing any issues, report that immediately.

Delete junk with adwCleaner


Please download AdwCleaner to your desktop.


  • Run adwcleaner.exe.
  • Hit delete.
  • When the run is finished, it will open up a text file.
  • Please post its contents within your next reply.
  • You´ll find the log file at C:\AdwCleaner[S1].txt also.

SecurityCheck

Please download SecurityCheck: LINK1 LINK2

  • Save it to your desktop, start it and follow the instructions in the window.
  • After the scan finished the (checkup.txt) will open. Copy its content to your thread.
# AdwCleaner v2.305 - Logfile created 07/17/2013 at 09:05:05
# Updated 11/07/2013 by Xplode
# Operating system : Windows 7 Ultimate Service Pack 1 (64 bits)
# User : AthlonX4 - ATHLONX4-PC
# Boot Mode : Normal
# Running from : C:\Users\AthlonX4\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****


***** [Registry] *****


***** [Internet Browsers] *****

-\\ Internet Explorer v10.0.9200.16635

[OK] Registry is clean.

-\\ Mozilla Firefox v22.0 (en-US)

File : C:\Users\AthlonX4\AppData\Roaming\Mozilla\Firefox\Profiles\9njvwb2g.default\prefs.js

[OK] File is clean.

-\\ Google Chrome v28.0.1500.72

File : C:\Users\AthlonX4\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[S1].txt - [3066 octets] - [15/07/2013 09:06:17]
AdwCleaner[S2].txt - [880 octets] - [17/07/2013 09:05:05]

########## EOF - C:\AdwCleaner[S2].txt - [939 octets] ##########





Results of screen317's Security Check version 0.99.69
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 10
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Microsoft Security Essentials
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Adobe Flash Player 11.7.700.224
Mozilla Firefox (22.0)
Google Chrome 28.0.1500.71
Google Chrome 28.0.1500.72
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 1%
````````````````````End of Log``````````````````````
Then your system is all clean now! :)


Uninstall our tools using delfix

Please follow these steps in order:

  • In the case we used Defogger to turn off your CD emulation software. You can start it again and use the Enable button.
  • In the case we used Combofix. Deactivate your antivirus software once more, then rename the combofix.exe to uninstall.exe and run it one last time. You shall be noted that Combofix has been removed.
  • In any case please download delfix to your desktop.
    • Close all other programms and start delfix.
    • Please check all the boxes and run the tool.
    • delfix will now delete all found traces of our removal process
  • If there is still something left please delete it manualy.



How to protect yourself

  • System Updates
    Beeing up to date is very important. Please be sure to activate automatic updates in your control panel.
    Windows XP | Windows Vista |
    Windows 7 | windows 8
  • Protection
    What you need is one (not more) good virus scanner with backgroud protection. Additionally I recommend a special malwarescanner that you run from time to time.
    Personally I am using the avast! Antivirus Free Edition and Malwarebytes Anti-Malware. They offer you good protection for free use. But please remember: You get only the full protection if you use the payed versions of your security software.
  • Up to date Software
    Stay up to date with all the programs you use. Some of those really have to have an eye on are: your browser(s) including add-ons and plug-ins, Java, Flash Player, your virus scanner, and basically every software you use often. These link may help you to check:
    • Secunia Online Software Inspector - Checks if your software has updates available.
    • Filehippo Update Checkere - This tool also scans your computer for outdated software.
    • Mozilla: Check your plugins - The webpage will tell you if you have outdated plugins in your Firefox browser.
  • Backups
    There are chances for an emergency every day. So be prepared. Back up your data on a regular basis. If you burn it to DVDs from time to time, use a cloud-drive or a professional network backup system is your choice.
  • Brains
    It's no joke! You really need one of those things. :) It is very important not just to click anywhere it is colored or flashing while you surfing on the web. Do not click an OK button on any popping window without reading what it says. While installing software always choose the custom mode, read what those windows says and uncheck adware that will be installed along the software you want.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI